Privacy Policy
1. Introduction
PayMyGST ("we", "our", or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our platform.
By using PayMyGST, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect the following types of information:
- Account information: Name, email address, mobile number, and firm/business name provided during registration
- Gmail data: Read-only access to your Gmail account, strictly limited to identifying and reading GST portal OTP emails from gstin.gov.in
- Usage data: Log data, IP addresses, browser type, pages visited, and timestamps
- GST data: GSTIN numbers and associated OTP activity for the purpose of filing assistance
3. How We Use Your Information
- To read OTP emails sent by the GST portal and display them to your authorised Chartered Accountant for timely GST return filing
- To verify that the Gmail account connected matches the GST-registered email on file for your business
- To create and manage your account on the PayMyGST platform
- To communicate with you about your account and our services
- To improve and expand our services
- To comply with legal obligations applicable in India
4. Gmail Data — Access, Use and Limitations
PayMyGST uses Google OAuth 2.0 to request read-only access to your Gmail account. This access is strictly scoped to identifying emails from the GST portal (gstin.gov.in) that contain OTP codes required for GST return filing.
What Gmail data we access:
- We access only emails from the GST portal that contain OTP codes
- We read the email subject, sender, and body solely to extract the OTP value
- We do not access, read, or store any other emails in your inbox
What we do not do:
- We do not read, store, or process any non-GST emails
- We do not send emails on your behalf
- We do not delete or modify any emails
- We do not use Gmail data for advertising, profiling, or any purpose unrelated to GST filing
- We do not sell, transfer, or share Gmail data with any third parties except your authorised CA
- We do not use Gmail data to train AI or machine learning models
- We do not transfer Gmail data to any third-party AI or ML services
You can revoke this access at any time via your Google Account settings.
Google API Limited Use Compliance Statement:
The use of information received from Gmail APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used solely to extract GST portal OTP codes for the purpose of facilitating GST return filing on behalf of the user's authorised Chartered Accountant. This data is not used for any other purpose.
5. Data Sharing and Transfer
We do not sell, trade, rent, or transfer your personal data or Gmail data to third parties. We may share data only in the following strictly limited circumstances:
- With your authorised CA who manages your GST filings through PayMyGST — only OTP values are shared, not your Gmail credentials or other email content
- With service providers who assist in operating our platform, under strict confidentiality agreements that prohibit them from using your data for any other purpose
- When required by law, court order, or governmental authority in India
We do not transfer Google user data to data brokers, advertisers, or any party for commercial purposes.
6. Data Protection and Security
We implement the following security measures to protect your data:
- All data is encrypted in transit using TLS 1.2 or higher
- Access to production systems is restricted to authorised personnel only
- Gmail OAuth tokens are stored securely and never exposed to unauthorised parties
- Regular security reviews are conducted on our infrastructure
- We use AWS infrastructure with industry-standard security configurations
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
7. Data Retention and Deletion
We retain your data as follows:
- OTP data: OTP values are displayed to your CA and are not permanently stored after use
- Gmail tokens: OAuth refresh tokens are retained only while your Gmail connection is active. Revoking access via Google Account settings immediately invalidates these tokens
- Account data: Retained for as long as your account is active
- Deletion requests: You may request full deletion of your account and all associated data by contacting us at karthik@vectra-pay.com. We will process deletion requests within 30 days
8. AI and Machine Learning
PayMyGST does not use any AI or machine learning models that interact with Gmail or Google Workspace data. Raw or derived user data received from Gmail APIs is never used to develop, improve, or train any AI or ML models, and is never transferred to third-party services for AI or ML training purposes.
9. Your Rights
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and all associated data
- Withdraw Gmail access at any time via myaccount.google.com/permissions
- Lodge a complaint with relevant data protection authorities in India
10. Children's Privacy
PayMyGST is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date above.
12. Contact Us
If you have any questions about this Privacy Policy, our data practices, or to submit a data deletion request, please contact us at:
Email: karthik@vectra-pay.com