What we collect
The data we collect depends on how you interact with PayBridgeNP. Merchants provide account, business, project, API, and provider credential information. Customers may provide payment references, contact details, and addresses where the merchant's checkout flow requests them.
- Account data - name, email, optional contact phone number, password hash, authentication settings, team-member roles, support history.
- Business and project data - merchant name, environment (live or sandbox), webhook endpoints, API keys, branding settings (logo, colour, footer text), provider configuration.
- Transaction data - amount, currency, provider, payment status, session IDs, reference numbers, metadata, and callback / webhook delivery logs.
- Customer contact data - when collected by the merchant's checkout: customer name, email, phone number, billing and shipping addresses. Used to render the receipt, complete the payment, and send transactional notifications. PayBridgeNP does not market to customers.
- SMS log data - recipient phone, template name, message body, send status, provider reference, error reason. Visible to the merchant in their /sms history page and used by support to debug delivery issues.
- Email log data - recipient email, template name, send status, provider reference. Used by support to debug delivery issues.
- Website and analytics data - IP address, browser details, device information, pages visited, and Google Analytics-derived aggregates. On the marketing site the Meta Pixel additionally records page visits for advertising measurement (see Sub-processors below).
- At merchant sign-up, sign-in, and API use, we record a hashed form of the IP address and browser used to help prevent abuse.
- How you found us - if you arrive from a link carrying campaign tags or an ad click identifier (Google's gclid, wbraid or gbraid), we store those alongside the referring site and landing page on your merchant record, so we can tell which campaigns bring merchants in. It is stored once, at signup. We do not use it to profile you, we do not sell it, and signing up without ever clicking an ad simply leaves it empty.
How we use data
We use data to operate the platform, secure accounts, confirm payment outcomes, deliver webhooks, send transactional notifications, troubleshoot merchant issues, and improve reliability of the product.
- To create and manage merchant accounts, authenticate users, and protect access with security controls such as email verification and optional 2FA.
- To create checkout sessions, route customers to supported providers, verify provider callbacks, and keep payment state in sync.
- To deliver dashboards, public payment-tracking pages, refund records, webhook logs, SMS history, and operational reporting.
- To send customer-facing transactional notifications (payment receipts, refund confirmations, payment reminders) on behalf of the merchant.
- To detect abuse, enforce rate limits, investigate fraud or suspicious behaviour, and comply with legal obligations.
Sub-processors
PayBridgeNP relies on the following third-party providers to operate the platform. Each is bound by their own data-processing terms; we work only with vendors who provide reasonable security and privacy guarantees.
- Neon - managed Postgres database hosting. Stores all merchant, project, transaction, and notification log data.
- Railway - application hosting for the API and Shopify integration services.
- Vercel - application hosting for the marketing site, the merchant dashboard, and PayBridgeNP ID.
- Cloudflare - DNS, WAF, CDN, R2 object storage (merchant-uploaded brand and receipt logos at
cdn.paybridgenp.com), and Cloudflare for SaaS (custom checkout hostnames for Pro-plan and Enterprise merchants). - Upstash - managed Redis used for sliding-window rate limits.
- MailerSend - our primary transactional email delivery (verification, password reset, payment receipts, refund notifications, invoice reminders).
- Resend - backup transactional email delivery, used automatically when MailerSend is unavailable.
- bulk.bedbyaspokhrel.com.np - SMS gateway used to deliver transactional SMS to customer phones in Nepal, and account notices to a merchant's own contact number.
- Google (OAuth + Analytics) - Google Sign-In on the merchant dashboard exchanges your Google account email and basic profile fields with us when you choose "Continue with Google". Google Analytics also performs aggregate website-traffic measurement on the marketing site, and Google Ads measures whether our ads lead to signups. When you reach us from a Google ad, the click identifier Google adds to the link is stored on your merchant record so a signup can be matched to the campaign that produced it. Use of Google Sign-In is optional; merchants can sign up with email + password instead. Google Fonts serves the typefaces on the hosted checkout, so Google receives that request (including the IP address) when a checkout page loads; it sets no cookies there.
- Meta Platforms - the Meta (Facebook) Pixel on the marketing site (paybridgenp.com only) measures how our Facebook and Instagram ads perform and builds advertising audiences of site visitors, so we can reach people who already know PayBridgeNP with relevant ads. It records pages visited, browser details, and Meta's own cookie identifiers. Not used on the merchant dashboard, the hosted checkout, or any payment flow - it never sees transaction or customer data.
- PostHog - product analytics and error monitoring for the merchant dashboard and the API. Records dashboard page views, feature usage, and exception details (including IP address and a device identifier) so we can keep the product reliable. The hosted checkout sends a small number of server-side product events keyed by the checkout session ID, with no buyer contact data and no PostHog script or cookie on the page. Not used on the marketing site.
- Intercom - the support messenger inside the merchant dashboard. Receives your name, email, account ID, plan, and role so we can answer your support conversations. Not used on the hosted checkout.
- BetterStack - uptime monitoring for
status.paybridgenp.comand application log management. The API forwards error and warning logs to BetterStack for reliability monitoring; these can incidentally include identifiers such as a request ID, merchant ID, or IP address.
Two further services sit outside the payment flow. Mintlify hosts the documentation at docs.paybridgenp.com and receives ordinary web-request data from readers. Discord delivers our internal operational alerts; an alert can include a merchant's account name and contact email alongside operational identifiers, and never a buyer's contact details.
We will update this list when we add or remove a sub-processor that processes personal data. Material changes will be reflected in the "Last updated" date above.
Legal basis and cross-border transfer
PayBridgeNP is operated from Kathmandu, Nepal, and processes personal data under Nepal's Individual Privacy Act, 2075 (2018): we collect it with notice and, where the law requires, your consent; we use it only for the purposes described on this page; and we do not sell it. PayBridgeNP decides how merchant-account, website, support, and PayBridgeNP ID data is used. For the customer data a merchant collects through their checkout, the merchant decides the purpose and PayBridgeNP processes it to provide the service.
Some of the sub-processors listed above operate outside Nepal, so providing the service involves transferring your data across borders. We share only what each provider needs for its stated purpose, under that provider's own data-processing terms, and we do not transfer your data to anyone for their own independent use. By using PayBridgeNP you consent to this processing and transfer.
SMS and email notifications
PayBridgeNP sends transactional SMS and email on behalf of merchants - for example a "payment received" receipt to the customer who just paid, or a "complete your payment" reminder for an abandoned Shopify checkout. We never send marketing messages.
- What goes out - payment receipts, refund confirmations, abandoned-checkout reminders, invoice notifications, security alerts, and platform-level account emails (verification, password reset). If a merchant has a contact phone number on file, we may also text that number about their own PayBridgeNP account, for example a reminder that a plan invoice is due or overdue.
- SMS log - every dispatch (whether sent or suppressed) is recorded with recipient phone, template, body, status, and provider reference. Merchants can view this in their dashboard at /sms.
- Per-template controls - merchants can disable any template (payment success, payment failed, refund, invoice reminders) from /settings/emails and /sms settings.
- Sandbox mode - when a merchant is in sandbox, SMS dispatches are logged but never reach the provider, so no real messages go out during testing. (Payment-wise, sandbox eSewa and Khalti use provider test environments; sandbox Fonepay uses the merchant's own credentials and moves real money within tight caps.)
- Free plan: SMS dispatch is suppressed but logged so merchants can preview what would have gone out before upgrading.
- Growth and Pro plans: live SMS is included up to the plan's monthly allowance. Dispatches beyond the allowance are suppressed and logged, the same way Free-plan dispatches are, until the allowance resets the next calendar month.
MCP and AI agents
PayBridgeNP publishes an official Model Context Protocol (MCP) server so merchants can connect AI assistants (Claude, ChatGPT, Cursor, and others) to their merchant data. Agents authenticate with a scoped token issued by the merchant from their dashboard.
- Read access - agents can list and inspect payments, refunds, customers, invoices, webhooks, and KPIs the merchant could see in the dashboard.
- Write access (Pro plan and higher): issuing refunds, creating payment links, modifying subscriptions. Confirmation prompts are surfaced for money-moving actions.
- Audit trail - every MCP-driven action is logged to the dashboard activity log with the agent identifier, so merchants can see exactly what the agent did.
- Merchant responsibility - the merchant is responsible for the AI assistant they connect, the prompts they issue, and the data they share with that assistant. Disconnect a token from /mcp at any time.
Uploaded files
Merchants can upload brand and receipt logos from the dashboard (/settings and /settings/emails). These files are stored in Cloudflare R2 and served from cdn.paybridgenp.com using unguessable random filenames.
- Public reads - receipt logos must be embeddable in customer emails, so the URL is public. Filenames are random and carry no merchant identifier.
- Replacement - uploading a new logo replaces the previous one and best-effort deletes the older object from R2.
- Removal - clicking "Remove logo" in the dashboard nulls the URL on your account and best-effort deletes the R2 object.
PayBridgeNP ID - Insights imports
PayBridgeNP ID (id.paybridgenp.com) is a consumer identity layer that lets buyers view their spending history across eSewa, Khalti, Fonepay, and their bank accounts. The Insights feature allows users to upload wallet exports and bank account statements to build a unified transaction view. This section explains exactly what happens to uploaded files.
- What you upload - eSewa or Khalti transaction exports (CSV or XLS), or bank account statement files (PDF or Excel) from any Nepali bank.
- How the file is handled - the file is parsed to extract transaction rows, is held in server memory only for the duration of parsing, and is never written to disk or object storage. Only the extracted rows and the import record are kept.
- What is stored - for the import: the source (eSewa, Khalti, or bank) and its label, the file name, a fingerprint of the file used to detect duplicates, upload and parse times, status and any parse error, and the row count. For each extracted transaction: date, amount, direction (debit or credit), currency, the counterparty and narration text as your bank or wallet wrote it (which can itself contain a name or reference number), the reference, channel, and wallet transaction identifiers the export carried, a spending category, and a fingerprint used to avoid duplicates. Bank statement account numbers and balances are not stored.
- Duplicate detection - a file that has already been imported is recognised and is not imported twice.
- Retention and deletion - imported transactions are retained for as long as your PayBridgeNP ID account is active. You can delete any individual import (and all its transactions) from the Insights import page. Deleting your account removes all Insights data.
- Access - imported transaction data is private to your PayBridgeNP ID account. PayBridgeNP staff can access de-identified aggregate statistics for reliability monitoring, but do not routinely read individual transaction narrations.
Retention and security
We keep information for as long as it is needed to provide the service, maintain reliable payment records, resolve disputes, meet compliance obligations, and enforce our agreements. The plan windows below limit what the API and dashboard show; they are not deletion schedules.
- Free plan: list endpoints (payments, refunds, sessions, webhooks, SMS log) are clamped to the most recent 30 days. Older records are retained as described above but are not surfaced in the API or dashboard.
- Growth plan: list endpoints clamped to the most recent 90 days.
- Pro and Enterprise plans: full historical retention with no list-endpoint cap.
- Sensitive credentials - provider API keys and signing secrets are encrypted at rest with AES-GCM using a key not stored in source control.
- Passwords - hashed with Argon2id; never stored in plaintext or sent to third parties.
- Sandbox data - retained while your account is active, for your reference; sandbox SMS and emails are never delivered to recipients.
Your choices
Merchants can request updates or deletion of account information, subject to records we need to retain for legitimate business or legal reasons. Customers should generally contact the merchant first for questions about a specific purchase, because the merchant controls the underlying transaction purpose.
You can also manage cookie preferences through your browser settings. For privacy requests, contact support@paybridgenp.com and include enough detail for us to verify the request safely.
Shopify integration
When a merchant installs PayBridgeNP for Shopify on their Shopify store, the app processes a limited set of customer data to facilitate payment collection. This section explains what is collected, why, and how long it is retained.
- Customer email and phone number - read from the Shopify orders/create webhook payload. Used exclusively for transactional payment-link delivery: SMS and email messages that contain a secure link to the PayBridgeNP hosted checkout. Not used for marketing, profiling, or automated decision-making.
- Customer name - read from the order payload to personalise the payment notification message (e.g. "Hi Aarav, complete your payment..."). Stored only within the checkout session metadata.
- Retention - customer email and phone number are stored on the pending-order record while the order is active (awaiting payment, reminders in progress). Once the order reaches a terminal state (paid, cancelled, or expired), these fields are automatically nulled out after 90 days by a daily retention scrub. This follows Shopify's data-minimisation requirements.
- GDPR compliance - the app implements Shopify's mandatory data-request, customer-redact, and shop-redact webhooks: a data request is answered without echoing personal data, a customer redaction removes that customer's email and phone, and a shop redaction removes everything held for the shop.
- Address fields - the app reads the customer's shipping name for the greeting. When the merchant has the Protected Customer Data Access scope granted by Shopify, address fields may also be passed through to PayBridgeNP for tax and fulfilment context. Address data is never persisted by the Shopify app outside the order's checkout session.
- Cross-app routing - customer SMS is dispatched via PayBridgeNP's central messaging service (subject to merchant plan, sandbox mode, per-template toggles, and rate limits). The Shopify app does not call the SMS provider directly.
WooCommerce integration
PayBridgeNP for WooCommerce acts as a standard WooCommerce payment gateway plugin. It redirects customers to the PayBridgeNP hosted checkout page and receives payment confirmation via signed webhooks. The plugin does not store any additional customer data beyond what WooCommerce itself stores.
- Order metadata - the plugin attaches the WooCommerce order ID and order key to the PayBridgeNP checkout session as metadata. This is used to match the incoming payment webhook to the correct order. The metadata is stored on the PayBridgeNP API alongside the checkout session record.
- No PII stored by the plugin - customer name, email, phone, and address are managed entirely by WooCommerce's own order storage. The PayBridgeNP plugin reads the order total and key but never independently copies or persists personal data.
- Webhook payloads - signed webhook deliveries from PayBridgeNP to WooCommerce contain payment status, provider reference, and amount. They do not contain customer PII. The signing secret is stored in wp_options by WooCommerce's built-in settings API.
WHMCS integration
PayBridgeNP for WHMCS is a standard WHMCS payment gateway module, available on the WHMCS Marketplace. It works the same way as the WooCommerce plugin: customers are redirected to the PayBridgeNP hosted checkout, and the invoice flips to Paid via signed webhook callback.
- Invoice metadata only - the module passes the WHMCS invoice ID and amount to PayBridgeNP. Customer details remain managed by WHMCS's built-in client database.
- No additional PII storage - the module does not extract or copy WHMCS client records.
Data subject rights
If you are a customer whose data has been processed through a PayBridgeNP-powered checkout:
- Right to access - you can request a copy of the personal data PayBridgeNP holds about you by emailing support@paybridgenp.com with enough identifying information for us to locate your records (e.g. the order reference, your email, or the merchant's store name).
- Right to deletion - you can request deletion of your personal data. For Shopify integrations, email and phone are automatically deleted after 90 days; a manual deletion request accelerates this. Transaction records (amounts, dates, provider references) may be retained for legal, audit, fraud-prevention, dispute, or accounting needs, and are not deleted on request.
- Right to rectification - if any personal data PayBridgeNP holds about you is inaccurate, you can request correction by contacting support@paybridgenp.com.
- Merchant responsibility - because PayBridgeNP processes customer data on behalf of the merchant, data subject requests should first be directed to the merchant whose store you purchased from. The merchant may then work with PayBridgeNP to fulfil the request.
- Response timeline - we respond to data subject requests within 30 days. If we cannot complete your request within that period, we will notify you of the reason for the delay and the expected completion date.