Legal · Privacy
What we collect,
and what we refuse to.
A short policy, because we handle deliberately little. This page summarises the position in plain terms; the executed agreement with your acquiring partner governs the commercial relationship.
Cardholder data
We hold none of it
Card number, track data, expiry
Encrypted inside the certified kernel on the device, to a key your acquirer holds. It crosses our systems as an opaque blob and is never decrypted, parsed or logged.
Never
PIN
Not captured today. When PIN on glass ships it will be handled entirely within the certified kernel and will still never reach us in the clear.
Never
Masked tail and scheme
Last four digits and card scheme, for receipts and reconciliation only.
Retained

Plainly
A short policy, because we handle deliberately little
Operational data
What we do hold, and why
Operator identity
Who was authorised to take the payment. This is the core of the evidence record and the reason customers buy the product.
Retained
Device signals
Model, OS version, security patch level, integrity verdicts, and every allow or deny decision. Required by the payment security standards we operate under.
Retained
Location and time
Captured at the moment of the transaction, where your configuration enables it, to evidence presence.
Retained
Transaction metadata
Amount, rail, outcome, retrieval reference number and authorisation code.
Retained
End-customer KYC documents
Merchant onboarding runs through your acquiring partner’s process. We receive the verification outcome, not the documents.
Never
The short version
We are a poor target
There is no card number to steal from us, no PIN, no settlement balance and no KYC document store. The blast radius of a breach here is operational metadata.

Around, never through
Handling
Where it lives and how long
Location
All payment data is stored and processed on Indian infrastructure, and we can evidence that on request.
India only
Logging
A Luhn-checked redaction pass runs on every log line before any transport sees it, removing card numbers, track patterns and any field named pin, cvv or payload.
Scrubbed
Retention
Evidence records are kept for the period your sector and your acquiring partner require, and are deleted on schedule thereafter.
By agreement
Sub-processors
Your acquiring partner, cloud infrastructure inside India, and communications providers for notifications. Named in full in the executed agreement.
Disclosed
Your rights
Access, correction and erasure requests reach us at privacy@tapproof.in. Where we process on your instruction we will route the request to you.
Exercisable
This page is a summary written to be understood, not a substitute for the executed agreement. Where the two differ, the agreement governs. Questions to privacy@tapproof.in.