PuranPay
HomeFeaturesPricingContact
Sign inGet started

Legal

Privacy Policy

Last updated 12 September 2026

This policy explains what PuranPay collects when you use puranpay.com, the merchant dashboard, the hosted checkout, the phone app, APIs, and plugins such as WooCommerce — and how that data is used to verify Send Money payments.

1. Who we are

PuranPay (“we”, “us”) is a software service based in Dhaka, Bangladesh. We help shops accept bKash, Nagad, Rocket, and Upay on wallet numbers they already use. We are not a bank, MFS provider, or payment aggregator, and we are not affiliated with those wallet brands.

2. What the service does

A customer Send Money’s to your wallet, types the TrxID on a hosted pay page, and our phone app matches that against the official wallet SMS on your device. When it matches, we mark the payment verified and POST a signed webhook to your site. Customer funds go to your wallet. We never hold the sale, and we do not take a cut of it.

3. Information we collect

What we store depends on who you are:

  • Merchants: name, email, password hash, shop domains, branding, wallet numbers assigned to the account, plan and invoices, API keys, webhook URL and secret, device pairing status, and support messages (including WhatsApp if you write to us).
  • Payers (your customers): amount, currency (BDT), payment method, TrxID, order id / customerRef, optional name, email, and phone that you or a plugin send so checkout and the webhook can identify the order. We do not ask payers to create a PuranPay account.
  • Phone app: pairing tokens and the wallet SMS fields needed to match a payment (typically TrxID, amount, and destination number from official bKash / Nagad / Rocket / Upay messages). We use those messages to verify Send Money. We do not sell SMS content and we do not use it for ads.
  • Technical: IP address, user agent, timestamps, and request logs needed to run the API, rate-limit abuse, and debug failed matches.

4. Checkout, API, and plugins

When a shop creates a payment (REST, Node SDK, or WooCommerce), it may send order amount, order id, and optional billing name / email / phone. That data is stored on the payment, shown on hosted checkout where relevant (customer name), and included on merchant APIs and the verified webhook. WooCommerce does not send order data until a secret key is saved and a customer places an order with PuranPay.

5. How we use information

  • Create accounts, verify email, and keep you signed in.
  • Run hosted checkout and match TrxIDs to official wallet SMS.
  • Notify your website via signed webhooks and show payments in the dashboard.
  • Bill the flat subscription (not a percentage of sales) and send invoices.
  • Prevent fraud, fake TrxIDs, and abuse of sandbox or live APIs.
  • Answer support on WhatsApp or email.

6. Who we share with

We do not sell personal data. We share it only as needed to run the product:

  • With you, the merchant: dashboard, API, and the webhook URL you configure. You are responsible for how you store and use payer data on your own site.
  • With infrastructure vendors that host our app, database, and email (under contract, only to provide the service).
  • If required by Bangladesh law or to protect the service from abuse.

Customers pay bKash, Nagad, Rocket, or Upay directly. Those operators process the Send Money under their own terms. We do not receive the funds and we do not send your customer’s card or wallet PIN anywhere — we never collect PIN or OTP.

7. Cookies and local storage

The dashboard uses first-party session cookies so you stay signed in on the same site. We may also keep non-sensitive UI preferences (for example theme or docs mode) in local storage. We do not run third-party advertising cookies on the marketing site or checkout.

8. Retention and security

We keep payment records, webhook delivery history, and billing records for as long as the merchant account is active and for a reasonable period after, so you can search old TrxIDs and we can handle disputes about a match. Secret keys and webhook secrets are stored so the API can authenticate you; treat them like passwords. Access to production data is limited to operating and supporting the service.

9. Your choices

Merchants can update shop and webhook settings in the dashboard, rotate API keys, and unpair a phone. To correct account details, export what we hold on your user, or close an account, email support@puranpay.com. Payers should contact the shop they paid first — that merchant controls the order. We can help the merchant locate a payment by TrxID or payment id.

10. Children

PuranPay is a business product. It is not directed at children under 18.

11. Changes

If we change how we handle data in a material way, we will update this page and the “Last updated” date. Continued use of the service after that date means the new policy applies.

12. Contact

Questions about privacy: support@puranpay.com. Billing: billing@puranpay.com. We operate from Dhaka, Bangladesh.

These pages describe PuranPay as we operate it today. They are not legal advice. If you need a lawyer-reviewed version for a contract or regulator, email support@puranpay.com. See also our Privacy Policy and Terms of Service.

PuranPay

Verified bKash, Nagad, Rocket and Upay payments on the wallet numbers you already own.

bKashNagadRocketUpay

Product

  • Features
  • Pricing
  • Sandbox

Developers

  • Documentation
  • API keys
  • Phone app

Company

  • Contact
  • Privacy
  • Terms

© 2026 PuranPay. Built in Dhaka, Bangladesh.

PrivacyTerms