Nirmaata Reconciliation and Provisioning System

Privacy Policy

This policy explains how Nirmaata collects, uses, stores, protects, and shares information while delivering reconciliation, payment-link, provisioning, reporting, support, and related operational services.

Effective Date 19 August 2026
Applies To Merchants, users, and customers
Contact support@nirmaata.com

1. Introduction

Nirmaata operates NRPS to help merchants and platform teams manage reconciliation workflows, payment requests, customer-submitted transaction references, automated provider confirmations, webhook notifications, settlement references, reports, and operational support. We process information only for legitimate business, operational, security, compliance, and service-delivery purposes.

2. Information We Collect

Depending on how NRPS is used, we may collect and process the following information:

  • Merchant information such as business name, contact details, registered address, webhook URLs, whitelisted IPs, allowed domains, bank account routing details, MDR configuration, and operational preferences.
  • User information such as name, username, email address, mobile number, role, permission access, login activity, password reset activity, and account status.
  • Customer transaction information such as name, email, mobile number, order number, customer reference, amount, selected payment method, UTR or transaction reference, proof upload, payment status, and timestamps.
  • Automated provider information such as provider response payloads, callback payloads, status updates, reference numbers, RRN/UTR values, and reconciliation log data.
  • Technical information such as IP address, browser or user agent where available, API request metadata, webhook delivery responses, audit entries, error logs, and system activity records.

3. How We Use Information

We use collected information to:

  • Create, track, verify, reconcile, and report transaction requests.
  • Route payment instructions or automated UPI flows as configured for a merchant.
  • Send merchant webhooks, email notifications, reports, password setup links, support replies, and operational alerts.
  • Maintain audit trails for approvals, rejections, retries, user actions, API calls, provider responses, and system events.
  • Prevent duplicate submissions, detect mismatches, investigate failed confirmations, and support operational dispute handling.
  • Improve reliability, security, analytics, service performance, and platform administration.

4. Legal and Business Basis

We process data where it is necessary to provide contracted services, fulfil operational obligations, protect legitimate business interests, comply with applicable legal or regulatory requirements, prevent misuse, maintain system security, and support merchant-requested transaction workflows.

5. Sharing of Information

We may share information with limited parties where required for service delivery:

  • With the relevant merchant for transaction status, reporting, settlement reference, and support handling.
  • With service providers such as email, hosting, storage, analytics, or automated payment confirmation providers where necessary to operate NRPS.
  • With banks, providers, auditors, regulators, legal advisors, or law enforcement where required by law, dispute resolution, risk review, or compliance obligations.

We do not sell customer or merchant information.

6. Data Security

We use administrative, technical, and operational safeguards such as role-based access, permission controls, password hashing, webhook signing, audit trails, restricted credential access, HTTPS enforcement where configured, and controlled access to sensitive operations. No electronic system is completely risk-free, but we work to protect information with reasonable and appropriate measures.

7. Data Retention

We retain transaction, reconciliation, audit, webhook, provider, support, and reporting data for as long as needed for business operations, merchant reporting, dispute handling, compliance, security monitoring, backup, and legal requirements. Test or temporary records may be retained for shorter periods according to operational policy.

8. Cookies and Sessions

NRPS may use cookies or server-side sessions to keep users logged in, maintain secure authentication state, protect forms, and remember interface preferences. Users can control browser cookies, but disabling required cookies may affect portal access.

9. Your Responsibilities

Merchants and authorized users are responsible for maintaining accurate configuration details, protecting credentials, assigning appropriate user permissions, using secure webhook endpoints, validating their own downstream actions, and ensuring they have a lawful basis to submit customer information into NRPS.

10. Individual Rights

Where applicable, individuals may request access, correction, restriction, or deletion of personal information. Requests may be subject to identity verification, legal obligations, transaction record requirements, dispute handling, and merchant contractual controls.

11. International or Third-Party Processing

Some infrastructure, email, support, or provider services may process data through third-party systems. We use such services only for operational needs and expect them to apply reasonable safeguards.

12. Updates to This Policy

We may update this Privacy Policy from time to time. The latest version will be made available on this page with the effective date updated accordingly.

13. Contact

For privacy questions, support requests, or data-related concerns, contact support@nirmaata.com.