Privacy Policy
What DPay collects, why, how long it keeps it, and what it never does. DPay is operated by DOWNLABS, Lahore, Pakistan.
1. The short version
- DPay reads the transaction alerts your bank emails you, and nothing else in your inbox.
- DPay never holds money and never sees your card, because there is no card.
- Your customers' details are collected only as you and they provide them at checkout, and only to verify and record a payment.
- We do not sell data, and we do not use your inbox data for advertising or to train models.
2. What we collect
From you, the merchant
- Account: name, email, password (held by Firebase Authentication, never by DPay in plain text), sign-in times.
- Business: business name, support email, website, and the receiving accounts you register: provider, account title, account number or wallet ID, IBAN, branch. Full account numbers are shown only to a customer at checkout and never returned by the API.
- Billing: which plan you hold, when it started and ends, and the DPay checkouts you paid it with.
- Usage: API calls, webhook deliveries and an audit log of actions in your dashboard, so you and we can see what happened.
From your connected inbox
When you connect Gmail, DPay stores a refresh token, encrypted with AES-256-GCM, and the address of the inbox. While a payment is pending, DPay searches that inbox for messages from known bank and wallet senders received inside that payment's verification window, and reads only those messages. From each alert it keeps the parsed transaction (amount, direction, the paying party's name, bank and masked account, the receiving account's last digits or title, the bank's transaction id and timestamp) and the alert's message id so it is never processed twice. It does not read, store or index any other message.
From your customers
At checkout a customer may choose which bank they pay from and optionally give the last four digits of their account. You may pass a name and email when you create a payment, invoice or subscription. DPay stores these with the payment and, for verified payments with an email, builds a customer record for you. DPay never asks a customer to sign in, and never asks for a card, password or full account number.
3. Google user data
DPay requests the gmail.readonly scope and no other Google scope. DPay's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Gmail data is used only to verify payments into your account and to show you the resulting transaction records; it is not used for advertising; it is not sold; it is not used to train generalised AI or machine-learning models; and it is not read by people except with your consent, for security, or as required by law. You can revoke access at any time from Integrations in your dashboard or from your Google Account's permissions page; DPay then deletes the stored token.
4. Why we process it
- To provide the service you signed up for: checkout, verification, records, webhooks, invoices, subscriptions, analytics and billing (performance of a contract).
- To keep the service secure and prevent fraud: rate limits, audit logs, signature verification (legitimate interest).
- To respond to disputes between you and a customer, using the payment record (legitimate interest).
- To comply with law, including lawful requests from authorities in Pakistan.
5. Who else sees it
DPay runs on Google Cloud and Firebase (authentication, database, hosting) in Google's asia-south1 region, and reads Gmail through Google's API. These providers process data under their own terms as our processors. Your customers see your business name, support email and receiving account at checkout, and receive nothing from DPay directly. Your own systems receive whatever you configure webhooks to send. We do not sell or rent data, and we share it with no one else unless the law requires it.
6. How long we keep it
- Transaction and payment records: for as long as your account is open and for 7 years after, because they are financial records you and your customers may need.
- Gmail refresh token: until you disconnect, revoke access, or close your account; then it is deleted immediately.
- Sandbox and simulated alerts: until you delete them or your account closes.
- Audit logs: 2 years.
- Account details: until 90 days after closure, unless we must keep them longer for disputes or the law.
7. Security
Traffic is encrypted in transit. Inbox tokens are encrypted at rest with a key held outside the database. API keys are stored as SHA-256 hashes and shown once. Webhook payloads are signed. Database access is server-side only; no client may read or write it directly. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.
8. Your rights
You can see and change your business details, receiving accounts and integrations in the dashboard; export your payments and customers through the API; disconnect your inbox; and close your account. Your customers may ask you, or us at the address below, to see or delete the details we hold about them, subject to the retention we are required to keep for financial records. We will answer within 30 days.
9. Children
DPay is for businesses and is not directed at anyone under 18.
10. Changes and contact
We will announce material changes in the dashboard or by email at least 14 days before they take effect. Questions and requests: info@dpay.com.pk. Effective 9 September 2026.