1. Overview & Data Minimization Principle

The Rushpay network adheres to a strict data minimization policy. We only collect the minimal technical parameters necessary to facilitate peer-to-peer liquidity dispatch, maintain account access, and fulfill IMPS and UPI settlements.

2. Data Types Collected

When you register on the client application or browse our repository, we collect:

  • Authentication Information: Your 10-digit mobile phone number, salt-hashed account password, and encrypted withdrawal PIN.
  • Settlement Coordinates: Your designated UPI Virtual Payment Address (VPA) and associated account holder name as verified by bank switches.
  • Transaction Logs: Numerical records including timestamp, order value, commission rebate, and 12-digit banking reference numbers (UTR).
  • Diagnostic Telemetry: Basic hardware characteristics, operating system version, and IP address to mitigate multi-instance fraud and device cloning.

3. Document Verification Notice

The Rushpay software does not collect, process, or store physical identity cards or government-issued registration documents. Registration is completed entirely via cellular SMS OTP confirmation and UPI VPA binding.

4. Storage, Encryption & Security Controls

All sensitive user communications and API transactions are safeguarded via TLS 1.3 encryption protocols. System passwords and withdrawal PINs are hashed using irreversible cryptographic algorithms (bcrypt/Argon2). We do not sell, rent, or lease personal identifiers or payment VPAs to third-party ad networks.

5. Your Privacy Rights

Users maintain full rights to request complete deletion of their account records, withdrawal histories, and mobile identifiers from active node registries. To initiate an account scrub, contact our compliance desk at support@rushpay.net.in.