Legal

Privacy Policy

Last updated 2026-08-23 · Effective 2026-08-23

This Privacy Policy explains how MobileByteSensei Pvt Ltd (“PayCraft”, “we”, “us”, or “our”) handles personal data in connection with the PayCraft subscription-billing platform, dashboard, SDK, and the in-app paywalls it powers (together, the “Service”). It applies to two groups: Developers who build apps with PayCraft, and End Users who see a PayCraft-powered paywall or subscribe inside a Developer’s app.

For End Users: PayCraft provides the billing technology inside the app you are using. The app’s developer is the controller of your data and decides how it is used; PayCraft acts as their processor. If you have a request about your data, contact the app’s developer first — we will assist them in fulfilling it.

1. Information we collect

From Developers (our customers)

  • Account data — name, work email, hashed password, organization and app names.
  • Configuration — products, prices, paywall design, and provider connection metadata (never your raw provider secret keys, which are encrypted at rest and never returned to the browser).
  • Usage & audit — dashboard actions, API calls, and webhook events, recorded in your tenant audit trail.
  • Billing — the Stripe customer ID for your own PayCraft subscription (card data is held by Stripe, never by us).

From End Users (on a Developer’s behalf)

  • Subscription identity — an email or an anonymous app-scoped user ID used to link a purchase to an account and to restore it.
  • Entitlement state — which product was purchased, its status, renewal and expiry dates, and the originating store (Google Play, App Store, Stripe, or Razorpay).
  • Device signal — a device identifier and platform, used for cross-device restore and to enforce a fair per-account device limit.
  • Coarse location — country, derived from IP at request time, to show the correct currency and price. We do not store your IP address in the entitlement record.

PayCraft never receives or stores full payment-card numbers, CVCs, or bank credentials. All card processing happens on the payment provider’s systems.

2. How we use data

  • Operate the Service — authenticate accounts, route store and provider webhooks, render the SDK paywall, and grant or restore entitlements.
  • Bill our own plans — Stripe processes payment for the PayCraft subscription; we retain only your customer ID and invoice metadata.
  • Keep it working — detect webhook failures, abuse, and fraud, and notify Developers of account activity and usage limits.
  • Improve reliability — aggregated, non-identifying diagnostics on conversion and error rates.
  • Meet legal obligations — tax, accounting, and fraud-prevention records.

Where the GDPR applies, our legal bases are performance of a contract, our legitimate interests in operating and securing the Service, and compliance with legal obligations. We do not sell personal data and we do not use it for cross-context behavioral advertising.

3. How we share data

We share personal data only with the subprocessors below, only as needed to run the Service, and each under a data-processing agreement:

  • Supabase — database, authentication, and edge functions (US region).
  • Cloudflare — dashboard & marketing hosting (Cloudflare Pages), DNS, and edge security.
  • Stripe — payment processing for our own SaaS billing, and for Developer paywalls that connect Stripe.
  • Google Play & Apple App Store — store billing and receipt validation for in-app subscriptions.
  • Razorpay — payment processing where a Developer connects it.
  • Postmark — transactional email (account and system notices).

We may also disclose data to comply with law, enforce our Terms, or protect the rights and safety of users. If we are ever part of a merger or acquisition, we will notify affected accounts before their data becomes subject to a different policy.

4. Data retention

We keep personal data only as long as needed for the purposes above. Audit logs follow the Developer’s tier — 7 days (Free), 90 days (Pro), 365 days (Enterprise). Entitlements and registered devices live for the life of the tenant so that End Users can restore purchases. When a Developer closes their account we delete or anonymize their tenant data within 30 days, except records we must retain for legal or tax reasons.

5. Security

Data is encrypted in transit (TLS) and at rest. Provider secret keys are encrypted with authenticated symmetric encryption and are never returned to any browser or SDK. Access to production data is restricted, logged, and reviewed. No system is perfectly secure, but we work to protect your data using industry-standard safeguards.

6. International transfers

The Service is operated from, and data is primarily stored in, the United States. Where we transfer personal data out of the EEA, UK, or other regions, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7. Your rights

Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have the right to access, correct, delete, port, or restrict the use of your personal data, and to object to certain processing. You will not be discriminated against for exercising these rights.

  • Developers can export or delete tenant data from the dashboard, or email us.
  • End Users should contact the app’s developer, who controls your data; we will help them respond.

To reach us directly, email privacy@paycraft.mobilebytesensei.com. We respond to verifiable requests within 30 days.

8. Children

The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

9. Cookies

The PayCraft dashboard uses strictly necessary cookies for authentication and security. The SDK paywall does not set advertising or cross-site tracking cookies.

10. Changes to this policy

We may update this policy from time to time. Material changes will be announced in the dashboard or by email, and the “Last updated” date above will change. Continued use of the Service after an update means you accept the revised policy.

11. Contact

MobileByteSensei Pvt Ltd — Data Protection Officer: dpo@paycraft.mobilebytesensei.com. General privacy questions: privacy@paycraft.mobilebytesensei.com.

This document is provided for transparency and does not constitute legal advice. Developers remain responsible for their own privacy disclosures to their End Users.