Last updated: October 2026
HexPay is a high-speed UPI payment gateway. Merchants connect their own UPI ID and a mailbox that receives their bank's payment alerts. When a customer pays, we read that alert and mark the order as paid. This page explains what data we handle, why, and what your choices are. It applies to merchants (people with an account) and to customers (people who open a payment page).
| Who | Data | Why |
|---|---|---|
| Merchants | Username, email, password (stored only as a salted hash), plan and expiry, referral and wallet records, UPI ID for referral withdrawals | Account, billing, referral payouts |
| Merchants | Gateway settings: UPI ID, shop name, mail address, mail server, sender address of bank alerts, and the mailbox app password (stored encrypted) | Verify payments automatically |
| Merchants | Optional Telegram bot token (stored encrypted) and chat ID; optional shop name, colour and logo | Payment alerts, branded pay page |
| Merchants | Orders created through the API or payment links: amount, your order ID, status, times, webhook and redirect URLs, delivery attempts | Run the gateway, show transactions, retry webhooks |
| Everyone | IP address (saved with orders and in the admin audit log, and used for rate limits, fraud protection and abuse blocking). | Security and fraud prevention |
| Customers | Nothing beyond the IP address and normal browser request data. We do not ask for your name, phone number or bank details. | Show the payment page, prevent abuse |
To confirm a payment, the server logs in to the merchant's mailbox over IMAP using the app password the merchant saved. It looks only at recent mail from the bank-alert sender address the merchant configured. The message is read in memory to find the amount and a credit keyword. Email content is not stored; we keep only a secure hash so the same email is not counted twice.
Questions or requests: Telegram @FrenzyHex or the support channel t.me/HexPayGateway.