1. Scope and data-protection roles
This Privacy Policy applies to the MeraOTP website, customer dashboard, account onboarding, APIs, OTP delivery, payment records, notifications, support, and related services (the "Service"). It does not govern a Customer's own website, app, privacy practices, or other third-party services.
Indian data-protection terminology may describe the party deciding why and how personal data is processed as a "Data Fiduciary" and a service provider processing on its behalf as a "Data Processor". The precise role depends on the data and context:
- MeraOTP as a service provider: for recipient numbers, OTP request content, and related delivery data processed on a Customer's instructions.
- MeraOTP for its own operations: for account administration, verification, billing, fraud prevention, platform security, support, legal compliance, and service improvement.
Customers must provide their users with an appropriate privacy notice and obtain any permission or consent required for the Customer's collection and use of recipient information.
2. Information we collect
Account and contact information
Name, email address, mobile number, password-derived authentication data, account identifiers, communication preferences, support correspondence, and authorised-user information.
Business and verification information
Business or trade name, address, website or application details, intended use, domain, source IP addresses, and verification documents or identifiers you choose or are required to submit. Depending on risk and account needs, this can include identity, address, business-registration, or tax information.
OTP and delivery information
Recipient mobile number, reviewed brand name, sender identifier, message type, request purpose, the server-generated OTP needed transiently to deliver and verify a request, request time, delivery status, provider response, transaction identifier, error information, and associated Customer account. MeraOTP stores a one-way OTP verifier until use or expiry and masks recipient numbers in application reports; authorised delivery systems and providers process the full number to deliver the message.
Technical, security, and usage information
IP address, approved domain, user-agent and browser information, device or operating-system category, session and authentication events, API request metadata, endpoint use, rate-limit events, security alerts, audit records, and diagnostic logs.
Plan, credit, and payment information
Plan selection, validity dates, credit balance and ledger activity, amounts, currency, taxes or fees, payment status, transaction and gateway references, refund information, and billing correspondence. Payment providers may collect payment credentials directly; MeraOTP does not need full card or bank-login credentials to maintain an order record.
Payment Tools information
If you configure Payment Tools, we process your merchant/payee name, Paytm Business VPA, Paytm MID, merchant order ID, requested and confirmed amount, payment-link note, provider transaction reference, status, timestamps, source IP, and response metadata. We do not ask for a Merchant Key, UPI PIN, Paytm password, payer OTP, or bank-login credential.
A payment page is intentionally public to anyone who receives its unguessable link and displays the payee name, VPA, amount, order ID, optional note, expiry, and QR/UPI intent needed to pay. Do not place personal, confidential, or sensitive information in an order ID or note.
Notification information
Email and browser-notification subscription details, delivery state, and preferences where notification features are enabled.
3. Where information comes from
- Directly from you: registration, verification, profile, integration, checkout, support, and legal-rights requests.
- From your application: API requests, recipient numbers, OTP content, sender details, and delivery instructions sent under your account.
- Automatically: server logs, session cookies, security monitoring, API telemetry, and device/browser information generated when the Service is used.
- From service providers: message delivery outcomes, payment status, fraud signals, email or notification results, and hosting/security diagnostics.
- From lawful public or official sources: information used to verify a business, domain, sanction, fraud, abuse, or legal-compliance concern.
4. How and why we use information
We process information when necessary to perform our contract, follow your valid service instructions, meet a legal obligation, protect legitimate operational and security interests, respond to a request, or rely on consent where the law requires it. Uses include:
- creating, authenticating, verifying, maintaining, and recovering accounts;
- reviewing accounts, IP addresses, applications, and intended use for fraud, abuse, and compliance purposes;
- processing OTP requests, routing messages, obtaining provider status, generating delivery reports, and calculating charges;
- administering plans, credits, payment records, refunds, account balances, and transaction records;
- creating customer-requested UPI payment intents and submitting signed order-status checks to Paytm for the Customer's configured merchant account;
- sending requested service, security, balance, plan, policy, and support notifications;
- detecting and preventing spam, phishing, fraud, account takeover, credential exposure, abusive traffic, payment abuse, and other prohibited activity;
- enforcing allowlists, limits, policies, contractual terms, provider rules, and legal requirements;
- debugging, measuring, maintaining, and improving performance, reliability, accessibility, and usability; and
- responding to support requests, disputes, audits, courts, regulators, telecom providers, and lawful government demands.
We do not sell or rent recipient mobile numbers or account contact details. We do not use the OTP content entrusted to us to send unrelated marketing to recipients.
5. When we disclose information
We disclose information only as reasonably necessary for the purposes above, including to:
- Telecom and delivery providers that route a message, validate sender or template information, return status, or investigate delivery and abuse;
- Payment providers and financial institutions, including PhonePe, that process, verify, reconcile, reverse, or investigate a payment;
- Paytm, when a Payment Tools customer requests an order-status check using that customer's MID and order ID;
- The configured hosted-checkout bridge (currently operated at CodeGully's checkout endpoint), which receives the Customer's name, email address, mobile number, order reference, and payable amount to begin checkout. The platform sends these fields in a signed HTTPS form body; PhonePe status is checked independently before wallet credit is granted;
- Infrastructure, security, communication, and support providers that host the Service, store data, send email or push notifications, monitor security, or assist customers under contractual duties;
- Professional advisers such as accountants, auditors, insurers, and legal advisers under duties of confidentiality;
- Authorities, courts, regulators, and affected providers when disclosure is required by law, valid legal process, telecom rules, or reasonably necessary to protect rights, safety, networks, recipients, or the public; and
- A successor organisation in a merger, acquisition, financing, reorganisation, insolvency, or transfer of all or part of the Service, subject to appropriate safeguards.
We may share aggregated or de-identified information that no longer reasonably identifies a person. If a provider processes data outside India, we will use reasonable contractual and technical measures and comply with restrictions applicable to that transfer.
6. Cookies and similar technology
MeraOTP uses first-party cookies or equivalent storage needed for secure sign-in, sessions, preferences, form and fraud protection, and reliable site operation. We do not need third-party advertising cookies to provide the public website.
| Category | Purpose | Choice |
|---|---|---|
| Session and authentication | Keep you signed in, connect requests to the correct account, and protect access. | Required for authenticated features. |
| Security | Help detect suspicious sessions, prevent abuse, and maintain request integrity. | Required where deployed. |
| Preferences | Remember interface or notification choices. | Can generally be reset in your browser or account. |
You can block or delete cookies using browser controls, but login, checkout, account, and security functions may then stop working correctly.
7. How long we retain information
We retain information only for as long as reasonably necessary for the purpose collected, including to provide the Service, maintain account and ledger accuracy, meet tax and accounting duties, investigate fraud or abuse, resolve disputes, enforce agreements, comply with telecom/provider requirements, and establish or defend legal claims.
Retention varies by category. Active account and integration information is generally kept while the account operates. OTP delivery, provider, audit, IP, transaction, and security logs may be retained after an account closes when required for reconciliation, fraud prevention, security, complaints, or law. Verification and payment records may be retained for the applicable statutory period.
When information is no longer required, we take reasonable steps to delete, aggregate, de-identify, or securely isolate it. Backup copies may remain until overwritten through ordinary backup cycles. A deletion request does not require us to erase records that must or may lawfully be retained.
8. Security
We use reasonable administrative, technical, and organisational measures designed for the nature of the Service, such as encrypted transport, account authentication, access controls, API credentials, IP allowlisting, monitoring, logging, backup, provider controls, and restricted administrative access.
No internet service or storage system is completely secure. You are responsible for using a unique password, securing your email and devices, keeping API keys server-side, limiting authorised users, rotating exposed secrets, validating your own inputs, and notifying us promptly of suspected compromise.
If we confirm a personal-data incident that requires notice, we will take steps to contain and investigate it and provide notifications as required by applicable law. Security concerns can be reported to security@meraotp.in with the subject “Security report”. Do not include live credentials, OTPs, or unnecessary personal data in the first email.
9. Your rights and choices
Subject to applicable law and appropriate identity verification, you may request to:
- access a summary of personal information we process about you;
- correct or complete inaccurate account information;
- delete personal information that is no longer necessary and need not be retained by law;
- withdraw consent where processing depends on consent, without affecting earlier lawful processing;
- close your account or change available email/browser-notification preferences; and
- raise a grievance about our processing.
Send a request from your registered email to support@meraotp.in with the subject “Privacy request”. Describe the account and request without sending a password, API key, or OTP. We may ask for proportionate verification and may deny or limit a request where the law permits, including to protect another person, preserve security, comply with retention duties, or prevent fraud.
If the information belongs to a user of one of our Customers, please contact that Customer first because it controls the user relationship and request context. We will assist the Customer where required and reasonably possible.
10. Children
MeraOTP accounts and platform access are intended for adults and organisations, not children. We do not knowingly permit a person under 18 to open an account. Customers whose products involve children are responsible for determining and satisfying parental-consent, notice, safety, and other legal obligations before submitting a child's mobile number or other data.
If you believe a child created a MeraOTP account or that information was submitted contrary to law, contact us so we can investigate.
11. Applicable data-protection law
We intend to handle personal information in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023, its commencement notifications, the Digital Personal Data Protection Rules, 2025, and the corrigendum, as each provision comes into force and applies to the processing. Some provisions are already in force while others have one-year or eighteen-month commencement periods from the November 2025 notification. Other sectoral, telecom, payment, contractual, or local requirements may also apply to a Customer or a particular use case.
Official source: MeitY — Digital Personal Data Protection Rules, 2025 and related notifications.
This policy is a transparency notice; it does not limit any non-waivable right available under applicable law.
12. Changes to this policy
We may update this Privacy Policy for legal, security, provider, or product changes. The effective date at the top shows the current version. If a change materially affects how we use personal information, we will provide notice through the Service, registered email, or another reasonable channel before the change takes effect where required.
13. Privacy contact and grievance channel
For a privacy question, rights request, or grievance, contact:
MeraOTP Privacy & Grievance Contact
Email: support@meraotp.in
Address: India
Please include your registered email, a concise description, and relevant non-secret transaction references. We will acknowledge and address valid requests within the period required by applicable law.