1
Information We Collect
We collect information that you give us directly, information we gather automatically when you use our services, and information we receive from partners such as billers, banks, and travel suppliers we work with to fulfil your transactions.
Information you give us
- Account details — name, mobile number, email address, and password when you sign up.
- KYC information — PAN, Aadhaar (masked), and business registration details, where required for regulatory compliance.
- Transaction details — biller IDs, consumer numbers, recharge numbers, booking passenger details, and payment instructions you submit through our app or API.
- Support communications — messages, call recordings, and attachments you share with our support team.
Information collected automatically
- Device & usage data — IP address, device identifiers, browser type, app version, and pages or API endpoints accessed.
- Location data — approximate location derived from IP address, used for fraud checks and localised offers.
- Log data — timestamps, error logs, and API request/response metadata for debugging and security monitoring.
We never store full card numbers or CVVs. Card and UPI payment details are tokenised and processed directly by our PCI-DSS certified payment partners.
2
How We Use Your Information
We use the data we collect to operate, secure, and improve Wepego's products, and to meet our legal and regulatory obligations as a payments and travel intermediary.
- Process BBPS bill payments, recharges, gift card issuance, and flight, hotel & bus bookings you initiate.
- Verify your identity and screen transactions for fraud, money laundering, and abuse.
- Send transactional alerts — payment confirmations, booking status, and OTPs.
- Provide customer support and respond to disputes or grievances.
- Improve API reliability, app performance, and personalise product recommendations.
- Comply with RBI, NPCI, and other applicable regulatory reporting requirements.
Where we rely on your consent (for example, marketing communications), you can withdraw it at any time — see Your Rights & Choices below.
3
How We Share Your Information
We share only what's necessary, and only with parties bound by contractual confidentiality and security obligations.
| Who | What we share & why |
| Billers & billing aggregators (BBPS) | Consumer number and payment amount, to complete your bill payment. |
| Telecom operators | Mobile number and plan details, to process recharges. |
| Travel suppliers & GDS partners | Passenger and booking details, to confirm flights, hotels and buses. |
| Payment gateways & banks | Tokenised payment instructions, to settle transactions. |
| Regulators (RBI, NPCI, FIU-IND) | Transaction records, where legally required. |
| Cloud & infrastructure providers | Encrypted data storage and processing, under strict data-processing agreements. |
We do not sell your personal information to advertisers or data brokers.
4
Cookies & Tracking Technologies
Our website and app use cookies and similar technologies to keep you signed in, remember your preferences, and understand how our products are used.
- Essential cookies — required for login sessions and security; cannot be disabled.
- Analytics cookies — help us understand feature usage and improve the product.
- Preference cookies — remember language and display settings.
You can control cookies through your browser settings. Disabling essential cookies may prevent you from logging in or completing transactions.
5
Data Security
We apply industry-standard technical and organisational measures to protect your data:
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for all sensitive data.
- Role-based access controls and multi-factor authentication for internal systems.
- Regular penetration testing and vulnerability scanning by independent security firms.
- ISO 27001-certified information security management and PCI-DSS certified payment handling.
No system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you and the relevant regulator as required by law.
6
Data Retention
We retain personal data only as long as necessary for the purposes described in this policy, or as required by law.
- Transaction records are retained for a minimum of 5 years, per RBI record-keeping requirements.
- KYC documents are retained for 5 years after account closure, per PMLA guidelines.
- Support communications are retained for 2 years for quality and dispute-resolution purposes.
- Marketing preferences are retained until you withdraw consent or close your account.
7
Your Rights & Choices
Under the Digital Personal Data Protection Act and applicable law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your data, subject to our regulatory retention obligations.
- Withdraw consent — opt out of marketing communications at any time.
- Grievance redressal — raise a complaint with our Grievance Officer if you're unhappy with how we've handled your data.
To exercise any of these rights, reach out using the contact details in Section 12. We aim to respond within 30 days.
8
Children's Privacy
Wepego's services are intended for users who are 18 years or older and legally capable of entering into financial transactions. We do not knowingly collect personal data from anyone under 18. If we learn that we've inadvertently collected such data, we will delete it promptly.
9
International Data Transfers
Your data is primarily stored on servers located in India. Where we use international sub-processors (for example, certain cloud infrastructure or travel-booking partners), we ensure appropriate safeguards — such as standard contractual clauses — are in place before any cross-border transfer.
10
Third-Party Services & Links
Our app and website may contain links to third-party sites (such as biller portals or travel suppliers) and integrate with third-party services (such as payment gateways). This policy does not cover their practices — please review their own privacy policies before sharing information with them.
11
Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. We'll post the updated version here with a new "Last updated" date, and for material changes, we'll notify you via email or an in-app notice.