Payya ("we", "our", "us") operates the Payya mobile application and the website at payya.me. This Privacy Policy explains how we collect, use, and protect your information when you use our services.
1. Information We Collect
Account Information
When you create an account, we may collect:
- Name and display name
- Email address
- Phone number (if provided)
- Profile photo (if uploaded)
- Authentication credentials via Apple Sign-In, Google Sign-In, or email/password
Payment Information
Payment processing is handled by Stripe. When you set up payouts or make payments, Stripe collects and processes your financial information directly. We do not store your full card numbers or bank account details on our servers. We store:
- Your PayID (email or phone) if you choose to save it
- Stripe Connect account identifiers
- Transaction records (amounts, dates, and status)
Event Registration Information
When you register for an event through Payya, we collect:
- Full name
- Phone number
- Email address
- Ticket purchase and payment status
- Check-in status at the event
This information is shared with the event organiser so they can manage their event and attendee list.
Usage Data
We collect information about how you use the app, including:
- Splits and payment requests you create
- Events you create or attend
- Friends and groups you manage
- Device type and operating system version
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Payya service
- Process payment requests and facilitate transfers
- Process event registrations and ticket purchases
- Send payment notifications, payout updates, and ticket confirmations via SMS, email, and push notifications
- Provide event organisers with attendee and check-in information
- Authenticate your identity and secure your account
- Respond to support requests
- Comply with legal obligations
3. Data Storage and Security
Your data is stored using Google Firebase (Cloud Firestore and Firebase Authentication), hosted in Australia. We implement appropriate technical and organisational measures to protect your personal information, including encryption in transit and at rest.
4. Third-Party Services
We use the following third-party services that may process your data:
- Firebase (Google) — authentication, database, and hosting
- Stripe — payment processing, ticket purchases, and payout management
- Twilio — SMS delivery for ticket confirmations and payment notifications
- Resend — transactional email delivery for ticket confirmations and account communications
- Apple — Sign in with Apple authentication
- Google — Google Sign-In authentication
Each of these providers has their own privacy policy governing the use of your data.
5. Data Sharing
We do not sell your personal information. We may share data in the following circumstances:
- With Stripe to process payments, ticket purchases, and payouts
- With other Payya users as part of split and request functionality (e.g., your name appears on requests you send)
- With event organisers when you register for or attend their event (including your name, phone, email, payment status, and check-in status)
- When required by law or to protect our legal rights
6. Camera and Device Access
Payya may request access to your device camera for:
- Scanning QR codes for event check-in
- Verifying identity documents during payout setup (handled by Stripe)
Camera access is only used when you actively initiate one of these actions. We do not record, store, or transmit camera footage.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Withdraw consent for optional data processing
To exercise any of these rights, contact us at support@payya.me.
8. Data Retention
We retain your account data for as long as your account is active. Transaction records may be retained for up to 7 years to comply with financial record-keeping requirements. You can request deletion of your account at any time by contacting support.
9. Children's Privacy
Payya is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page. Continued use of Payya after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy, contact us at: