Legal

Privacy Policy

This policy explains what data Wepego collects when you use our website, app, or APIs, why we collect it, and the choices you have. We've tried to write it in plain language rather than legalese.

Last updated: August 27, 2026 RBI & DPDP Act compliant ISO 27001 certified
1

Information We Collect

We collect information that you give us directly, information we gather automatically when you use our services, and information we receive from partners such as billers, banks, and travel suppliers we work with to fulfil your transactions.

Information you give us

  • Account details — name, mobile number, email address, and password when you sign up.
  • KYC information — PAN, Aadhaar (masked), and business registration details, where required for regulatory compliance.
  • Transaction details — biller IDs, consumer numbers, recharge numbers, booking passenger details, and payment instructions you submit through our app or API.
  • Support communications — messages, call recordings, and attachments you share with our support team.

Information collected automatically

  • Device & usage data — IP address, device identifiers, browser type, app version, and pages or API endpoints accessed.
  • Location data — approximate location derived from IP address, used for fraud checks and localised offers.
  • Log data — timestamps, error logs, and API request/response metadata for debugging and security monitoring.

We never store full card numbers or CVVs. Card and UPI payment details are tokenised and processed directly by our PCI-DSS certified payment partners.

2

How We Use Your Information

We use the data we collect to operate, secure, and improve Wepego's products, and to meet our legal and regulatory obligations as a payments and travel intermediary.

  • Process BBPS bill payments, recharges, gift card issuance, and flight, hotel & bus bookings you initiate.
  • Verify your identity and screen transactions for fraud, money laundering, and abuse.
  • Send transactional alerts — payment confirmations, booking status, and OTPs.
  • Provide customer support and respond to disputes or grievances.
  • Improve API reliability, app performance, and personalise product recommendations.
  • Comply with RBI, NPCI, and other applicable regulatory reporting requirements.

Where we rely on your consent (for example, marketing communications), you can withdraw it at any time — see Your Rights & Choices below.

3

How We Share Your Information

We share only what's necessary, and only with parties bound by contractual confidentiality and security obligations.

WhoWhat we share & why
Billers & billing aggregators (BBPS)Consumer number and payment amount, to complete your bill payment.
Telecom operatorsMobile number and plan details, to process recharges.
Travel suppliers & GDS partnersPassenger and booking details, to confirm flights, hotels and buses.
Payment gateways & banksTokenised payment instructions, to settle transactions.
Regulators (RBI, NPCI, FIU-IND)Transaction records, where legally required.
Cloud & infrastructure providersEncrypted data storage and processing, under strict data-processing agreements.

We do not sell your personal information to advertisers or data brokers.

4

Cookies & Tracking Technologies

Our website and app use cookies and similar technologies to keep you signed in, remember your preferences, and understand how our products are used.

  • Essential cookies — required for login sessions and security; cannot be disabled.
  • Analytics cookies — help us understand feature usage and improve the product.
  • Preference cookies — remember language and display settings.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from logging in or completing transactions.

5

Data Security

We apply industry-standard technical and organisational measures to protect your data:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for all sensitive data.
  • Role-based access controls and multi-factor authentication for internal systems.
  • Regular penetration testing and vulnerability scanning by independent security firms.
  • ISO 27001-certified information security management and PCI-DSS certified payment handling.

No system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you and the relevant regulator as required by law.

6

Data Retention

We retain personal data only as long as necessary for the purposes described in this policy, or as required by law.

  • Transaction records are retained for a minimum of 5 years, per RBI record-keeping requirements.
  • KYC documents are retained for 5 years after account closure, per PMLA guidelines.
  • Support communications are retained for 2 years for quality and dispute-resolution purposes.
  • Marketing preferences are retained until you withdraw consent or close your account.
7

Your Rights & Choices

Under the Digital Personal Data Protection Act and applicable law, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Erasure — request deletion of your data, subject to our regulatory retention obligations.
  • Withdraw consent — opt out of marketing communications at any time.
  • Grievance redressal — raise a complaint with our Grievance Officer if you're unhappy with how we've handled your data.

To exercise any of these rights, reach out using the contact details in Section 12. We aim to respond within 30 days.

8

Children's Privacy

Wepego's services are intended for users who are 18 years or older and legally capable of entering into financial transactions. We do not knowingly collect personal data from anyone under 18. If we learn that we've inadvertently collected such data, we will delete it promptly.

9

International Data Transfers

Your data is primarily stored on servers located in India. Where we use international sub-processors (for example, certain cloud infrastructure or travel-booking partners), we ensure appropriate safeguards — such as standard contractual clauses — are in place before any cross-border transfer.

10

Third-Party Services & Links

Our app and website may contain links to third-party sites (such as biller portals or travel suppliers) and integrate with third-party services (such as payment gateways). This policy does not cover their practices — please review their own privacy policies before sharing information with them.

11

Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. We'll post the updated version here with a new "Last updated" date, and for material changes, we'll notify you via email or an in-app notice.

12

Contact Us

Questions about this policy, or want to exercise your data rights? Reach out to our Grievance Officer:

Wepego Grievance Officer

We aim to acknowledge every request within 48 hours and resolve it within 30 days.

Email
connect@wepego.com
Phone
+91 9342698728
Registered Address
WEPEGO DIGITAL SERVICES (OPC) PRIVATE LIMITED, 3/53F, Sanniyasigundu, Erumapalayam, Salem, Salem- 636015, Tamil Nadu