Your Shopify and courier files are processed and immediately discarded. We never store full order rows or customer details. Orders flagged as discrepancies keep a minimal record (AWB, flag type, shortfall amount) so you can track them later.
All data moving between your browser and our servers is encrypted with TLS, and the Shopify and courier credentials you connect are stored encrypted (AES-256-GCM).
We keep your account details (email, verified mobile number, subscription status), a per-run audit summary, and a minimal record for each flagged order (AWB or order reference, flag type, shortfall amount). Full file rows, customer names, addresses, and customer contact details are never stored.
PayTrace is a COD remittance reconciliation service built for D2C brands operating in India. We exist to solve one specific and costly problem: the consistent, often invisible loss of revenue that occurs when courier partners short-pay, delay, or fail to remit COD collections to the businesses they serve. Our product allows brands to upload their Shopify order exports and courier remittance reports, automatically identifies every discrepancy between those two files, and produces a clear, exportable audit showing the exact amounts in dispute, broken down by shortfall type, AWB reference, and courier.
PayTrace operates at paytrace.in (with the Enterprise application at app.paytrace.in) and processes reconciliation requests at api.paytrace.in. When this policy refers to "PayTrace", "we", "us", or "our", it refers to the PayTrace service and its operators. This privacy policy governs all data you provide to us or that we collect in the course of your use of the service: during sign-up, during a free trial, during an active subscription, and at any point of contact with our product or support.
We take privacy seriously, not as a legal formality, but because the files you upload to PayTrace contain sensitive financial and operational data about your business. The product is built around a core principle: your business data belongs to you and only to you. We do not benefit from retaining your files, we have no reason to store them, and our system is designed from the ground up to ensure that we never do. If you have any questions or concerns about this policy or how we handle your data, you can reach us directly at help@paytrace.in. We will respond within 48 hours.
When you use PayTrace, you give us two sets of data: a Shopify order export and a courier remittance report. Most customers upload these as CSV files. Enterprise customers can instead connect their Shopify store and courier accounts so the same data is pulled in automatically (see Section 8). Either way, the data is handled the same way: processed in memory, with only the minimal records described below kept. These files typically contain a significant volume of business-sensitive information. A Shopify export will include order IDs, customer names, delivery addresses, contact numbers, product details, COD amounts, payment terms, fulfillment status, and tracking numbers. A courier remittance report will include AWB numbers, delivery dates, remittance amounts, UTR references, bank details, and shipment status codes. Together, these two files represent a detailed record of your brand's financial transactions with its logistics partner: information that is central to your business operations and not something to be handled carelessly.
It is important to be precise about what "processing" means in this context. PayTrace does not read your files the way a person reads a document, and no human at PayTrace sees the contents of your files. The files are transmitted from your browser to our reconciliation engine, a piece of software running on Cloudflare's edge infrastructure, which parses the CSV structure, identifies the relevant columns for reconciliation, matches AWB numbers across both files, calculates any shortfall or anomaly figures, and returns a structured result set to your browser. This entire process is automated, takes place in memory, and produces no persistent record of the input data.
Separately from the file data processed during reconciliation, we collect a small amount of account data when you create a PayTrace account: your email address, the Indian mobile number you verify to start a trial, and, if you sign in via Google, your display name. Enterprise accounts also hold the names, email addresses and roles of the teammates the account owner invites. This account data is stored in our database and is used solely to manage your access to the service. The distinction between file data that is processed and immediately discarded, and account data that is stored for the life of your account, is fundamental to how PayTrace is designed and is described in full detail in the sections that follow.
Understanding the exact technical flow of how your files move through our system is the most reliable way to evaluate the privacy commitments we make. The following is an accurate, step-by-step account of what happens from the moment you initiate an audit to the moment your results appear on screen.
When you select your files and click Run Audit, both files are read by your browser and transmitted over an encrypted HTTPS connection to our reconciliation API at api.paytrace.in. This connection uses TLS encryption, which means that the contents of your files are protected against interception or eavesdropping during transit. The files travel from your device directly to a Cloudflare Worker, a serverless compute environment that operates at the network edge, typically in a data centre geographically close to your location, without passing through any intermediate PayTrace-operated server.
The Cloudflare Worker receives your files and processes them entirely in memory. There is no step in this process where file contents are written to a database, a file system, a logging service, a cache, or any other form of persistent or semi-persistent storage. The Worker parses both CSV files, identifies the relevant columns using a header detection system that handles different courier and Shopify export formats, matches AWB numbers between the two files, compares collected COD amounts against remitted amounts, and classifies each order as reconciled, short-paid, overdue, or flagged as an RTO anomaly. The entire process runs within a single isolated Worker instance that is created specifically for your request and exists only for the duration of that request.
Once processing is complete, the Worker returns only the reconciliation output to your browser: a structured result set containing AWB references, flag types, shortfall amounts, and order identifiers. The raw contents of your files are not included in this output and are not transmitted back at any point. When the Worker instance terminates at the conclusion of your request, all raw file data held in its memory is cleared by the platform. There is no residual copy of your file contents anywhere in PayTrace's infrastructure after this point.
A run-level summary is stored to your account record at the conclusion of each run, containing the total number of orders processed, the count of each flag type, the aggregate shortfall amount, the courier name, and the brand label you provided. Alongside it, each order that reconciliation flags as a discrepancy has a minimal record retained: its AWB (or Shopify order ID, when no AWB is present), the flag type, and the shortfall amount, so flagged orders stay visible and trackable after the run. Neither record contains customer names, addresses, contact numbers, or any other data from your files. This is what populates your Audit History, your run count, and the recovery status of orders you choose to track.
When you choose to export your audit as an Excel report, or to generate a formal dispute letter, this process happens entirely within your browser. The export is built from the reconciliation results already displayed on your screen and does not involve any additional data being sent to PayTrace's servers. The resulting file is constructed on your device and downloaded directly to your machine. No additional network requests to PayTrace are made during the export process.
Because PayTrace's reconciliation engine runs on Cloudflare Workers, your files pass through Cloudflare's infrastructure during processing. Cloudflare is one of the world's leading network infrastructure providers and operates its Workers platform as a serverless compute environment where request data is processed in memory and not stored beyond the life of the request. Cloudflare's own privacy policy governs how they handle infrastructure-level metadata such as request logs, and is available at cloudflare.com/privacypolicy. PayTrace does not share any additional information with Cloudflare beyond what is inherent in routing a network request through their platform, and Cloudflare does not have access to your account data or any data about your PayTrace subscription.
The account data we collect, limited to your email address, subscription status, and where applicable your display name and sign-in provider, is used exclusively to operate and maintain your access to the PayTrace service. We do not use your data for any purpose beyond what is described in this section, and we do not share it with any party for purposes beyond the direct operation of the service.
Your email address is the primary identifier for your PayTrace account. It is used to authenticate you when you sign in, to retrieve your account record from our database on each visit, and to verify whether you are within an active trial period or hold a current subscription. This check happens automatically every time you load the PayTrace application and is what determines whether you have access to the reconciliation feature or whether your account is in a trial or expired state. Without this data, we cannot provide the service.
When you choose to subscribe to PayTrace, your email address is passed to Razorpay, our payment processing partner, to pre-fill the payment form and associate your transaction with your account. Upon successful payment or mandate set-up, Razorpay returns a payment and subscription reference to our system, which we store alongside your account record as confirmation that your subscription is active. We never receive, handle, or store your card number, CVV, UPI ID, bank account details, or any other payment credentials. All sensitive payment data is handled exclusively by Razorpay, who are certified to the highest industry standards for payment security. Razorpay's privacy policy is available at razorpay.com/privacy.
If you choose to sign in using your Google account, Google's authentication service provides your name and email address to PayTrace as part of the sign-in process. We use your email to create and manage your account in exactly the same way as accounts registered directly with an email address, and your display name to personalise the dashboard interface. We do not request access to any other part of your Google account: no Drive, no Gmail, no Calendar, no Contacts. The data Google shares with PayTrace is limited strictly to the basic profile information required to complete authentication, and we do not use that information for any purpose other than creating and maintaining your account.
To keep the free trial fair, we ask you to verify an Indian mobile number with a one-time code before your trial starts. The code is sent and checked through Google's Firebase Authentication service. We store the number and the fact that it has been verified, so that one trial is not started repeatedly with different email addresses. We use it for nothing else, and we do not send you marketing messages on it.
We may use your email address to contact you about your account, for example to confirm a payment, to respond to a support request you have submitted, or to inform you of a change to the service that materially affects your ability to use it. We do not send marketing emails or promotional newsletters. Beyond these account messages, the only other emails you may receive are ones you or your account owner switch on inside the product, such as Enterprise alert emails, scheduled reports and teammate invitations. These are sent through our email provider, Resend. If we ever introduce optional marketing communications, participation will be opt-in and easy to withdraw.
We have implemented a layered set of technical measures to protect both the file data you upload during reconciliation and the account data we store. The following describes each of these measures and the rationale behind them.
All communication between your browser and PayTrace, including file uploads to the reconciliation API, authentication requests, and the return of reconciliation results, is transmitted over HTTPS using TLS encryption. This applies to the main application at paytrace.in and to the reconciliation API at api.paytrace.in. TLS encryption ensures that your data cannot be intercepted, read, or tampered with by any party positioned between your device and our servers. This is the same encryption standard used by banking, financial services, and healthcare applications worldwide.
The most significant security measure PayTrace employs is architectural rather than procedural. Because the raw contents of your files, full order rows, customer records, addresses, and contact details, are not written to any database, file system or cache that PayTrace operates, there is no bulk file data for anyone to breach. A security incident affecting PayTrace's infrastructure would mainly concern the account details and the minimal records described in this policy: run summaries, and for flagged orders an AWB or order ID, a flag type and a shortfall amount. It could not expose the full contents of your files or your customers' personal details, because those do not exist in our systems once your reconciliation completes. Connected credentials are stored encrypted.
What is stored is a run-level audit summary (total orders, flag counts, total shortfall, brand label, and courier name) plus a minimal per-order record for each flagged discrepancy (AWB or order ID, flag type, and shortfall amount), so you can track and resolve flagged orders later. Neither contains customer data, addresses, or contact details. We consider the architectural exclusion of full file data and customer information from persistent storage the most meaningful privacy guarantee we can offer for your business information.
Account data is stored in Supabase, a database platform that supports fine-grained access control policies. Access to account data is protected in layers: every request is authenticated, our servers check what each signed-in user and team role is allowed to do, and we use database-level access policies (Row Level Security) so that the database itself enforces boundaries between accounts. Enterprise teams have role-based access, so a view-only teammate cannot change settings or credentials.
File processing runs on Cloudflare's Workers platform, which runs each request in a sandboxed environment that is isolated from other customers' requests. PayTrace does not write your file contents to any storage, and request data is held in memory only for as long as the request takes. This is designed so that your file data stays within the lifecycle of a single request and cannot carry over to another session or another customer.
If you connect a Shopify store or courier account, the access token or API key is encrypted before it is saved, is used only to fetch the data you asked us to reconcile, and is never shown back to you or your teammates in full. You can disconnect at any time, which removes the stored credential. We recommend using read-only or reporting-scoped keys where your courier or Shopify allows it.
If you discover a security vulnerability in PayTrace, whether in the application, the reconciliation API, the database layer, or any other component of our infrastructure, we ask that you report it to us responsibly at help@paytrace.in before making it public. We take all security reports seriously, regardless of the severity or complexity of the issue reported. We will acknowledge your report within 48 hours, investigate it thoroughly, and work to resolve any confirmed vulnerabilities promptly. We are genuinely grateful to anyone who invests the time to identify and report security issues, and we will handle all such reports with the seriousness and discretion they deserve.
PayTrace handles two distinct categories of data with two very different retention approaches. Understanding the difference between these categories is important, and we want to be unambiguous about each.
The contents of the files you upload, your Shopify order export and your courier remittance report, are retained for precisely zero seconds beyond what is required to complete the reconciliation process. As described in detail in Section 3, file data is processed in memory within a Cloudflare Worker instance and is discarded the moment that instance terminates at the conclusion of your request. There is no copy of your file data in any database, backup, transaction log, audit trail, or archive. This is not a data retention period: it is the complete and intentional absence of retention, built into the architecture of the system.
The full reconciliation results shown on your screen after an audit, the complete list of every reconciled row including orders that matched cleanly, exist only in your browser's session memory. This complete view is cleared automatically when you close the tab or browser window, does not persist between sessions, and exporting a report generates the file entirely within your browser without any server-side operation. Separately, and unlike this full on-screen view, a minimal record for each flagged order is retained server-side, as described next, so you don't lose track of discrepancies between sessions.
After each completed run, PayTrace stores a run-level summary to your account record: the date and time of the run, the total number of orders processed, the count of each flag type, the aggregate shortfall amount, the courier name, and the brand label you supplied. For each order that run flags as a discrepancy, we additionally retain a minimal record: its AWB (or Shopify order ID, when no AWB exists), the flag type, and the shortfall amount. This is what lets you open a past run in Audit History, see which specific orders need attention, and mark individual orders as disputed, recovered, or written off. Neither the run summary nor the per-order record contains customer names, delivery addresses, contact numbers, or any other data from your uploaded files. If you mark a flagged order's recovery status, we also store that status against its AWB, together with the shortfall amount, brand, and courier, so the status is still there next time you check; enterprise accounts associate this record with your organisation so teammates see the same status. All of it is retained for the lifetime of your account and deleted when you request account deletion.
For Enterprise accounts, we also keep the brand configuration you set up, your connected-credential records (stored encrypted), your alert and report settings, client portal links, and your team member list, for as long as the account is active. Disconnecting a Shopify store or courier removes its stored credential. Portal links can be revoked at any time by an account admin.
Account data, comprising your email address, verified mobile number, subscription status and sign-in provider, is retained for as long as your account remains active with PayTrace. This data is the minimum necessary to provide the service: without an email address and subscription status, we cannot authenticate you or enforce access controls. We do not create secondary copies of account data for analytical or commercial purposes, and we do not aggregate account data across users for any purpose.
You have the right to request permanent deletion of your account and all associated data at any time, regardless of whether you are within a trial, an active subscription, or an expired subscription. To request deletion, send an email to help@paytrace.in with the subject line "Account Deletion Request" from the email address associated with your PayTrace account. We will permanently remove your account data from our database within 30 days of receiving your request and will confirm completion to you by email. Records we are legally required to keep, such as invoices and payment records held with our payment provider, may be retained for the period the law requires. Please note that once your account is deleted, the associated access history cannot be restored and a new registration would be treated as a first-time sign-up.
PayTrace uses the absolute minimum browser storage necessary to operate the service. We do not use advertising cookies, third-party tracking pixels, behavioural analytics platforms, heatmap tools, session recording software, or any other technology designed to monitor, profile, or target users based on their activity within or outside of the product. This is a deliberate product decision, not a regulatory concession.
When you sign in to PayTrace, your sign-in session (a secure session token issued by our authentication provider, Supabase), your email address, display name and sign-in provider are saved in your browser's localStorage. This allows the application to recognise you as signed in across page refreshes and return visits without requiring you to authenticate again each time. This data is stored locally on your own device and is not accessible to any other website or service. The session token is sent to PayTrace's servers with your requests so we can confirm who you are and what your plan allows. You can clear this data at any time by signing out of PayTrace, which removes it from localStorage, or by clearing your browser's local storage manually.
Reconciliation results are held in your browser's session memory for the duration of your active session. This is what makes it possible for you to view your audit results, switch between the summary view and the detailed breakdown, and generate an export without having to re-upload your files. This data lives only in your browser, is not transmitted to PayTrace servers after the initial reconciliation response is received, and is cleared automatically when you close the tab or browser window. Nothing from a previous session carries over into a new one.
PayTrace does not use Google Analytics, Meta Pixel, Mixpanel, Amplitude, Hotjar, FullStory, Clarity, or any equivalent analytics or behavioural tracking platform. We do not record which pages you visit, how long you spend on any part of the site, what actions you take within the product, or any usage behaviour of any kind. We do not use browser fingerprinting, device identification, cross-site tracking, or any technology designed to identify or track you across the web. There are no advertising cookies set by PayTrace or by any advertising network operating through the PayTrace platform. The only storage PayTrace writes to in your browser is your sign-in session and a few interface preferences (such as whether the sidebar is collapsed) in localStorage, plus the session results in session memory. All of it is within your control.
Most customers use PayTrace by uploading files. Enterprise customers can also use optional features that save time. This section explains what each one involves, so you can decide which to switch on. Everything here is off until an account admin turns it on.
An account admin can connect a Shopify store and courier accounts using an access token or API key. With Autopilot switched on, PayTrace runs a check every hour: it fetches the last seven days of Shopify orders and the matching courier remittance data, reconciles them in memory exactly as it would for uploaded files, and then discards the fetched data. Only the same minimal records are kept: the run summary, and for flagged orders the AWB or order reference, flag type and shortfall amount. Credentials are stored encrypted and can be disconnected at any time.
If you choose, PayTrace can email an alert or a scheduled report to addresses you specify, or send a summary of each run to a webhook URL you provide. Webhook messages are signed so your system can confirm they came from us. These messages contain run-level figures and flagged-order references, not customer names or addresses. You decide where they go, so please only enter addresses and URLs you control or trust.
Agencies can create read-only portals so their own clients can see audit summaries for their brand. A portal is reached through a private link and access key created by your admin, shows the same minimal summary data described above, and can be revoked or have its key regenerated at any time. You are responsible for who you share a portal link with.
Enterprise account admins can invite teammates and assign a role (admin, ops, finance or view-only). We store each teammate's email address and role, and we send them an invitation email. Admins can change a role or remove a teammate at any time.
We use a small number of trusted providers to run PayTrace. Each receives only what it needs for its job:
These providers operate globally, so some processing may take place outside India. We choose providers that maintain recognised security standards, and we do not sell your data or share it for advertising. We may also disclose information where the law requires it.
We handle personal data in line with applicable Indian law, including the Digital Personal Data Protection Act, 2023. In practice this means you can ask us to:
You can also nominate someone to exercise these rights on your behalf. We use your data only for the purposes described in this policy, and we will tell you if that changes.
Much of the data in your uploaded files relates to your own customers. You stay responsible for having a lawful basis to use that data for reconciliation, and for the choices you make about who receives alerts, reports or portal access. PayTrace processes that data only on your instructions and only to provide the service.
For any privacy question, request or complaint, contact our grievance contact at help@paytrace.in. We will acknowledge your message within 48 hours and aim to resolve it within 30 days. If we have not resolved your concern, you may approach the Data Protection Board of India once it is operational.
We update this policy when our product or the law changes, and we change the "Last updated" date above whenever we do. If a change materially affects how we use your data, we will let you know by email before it takes effect.