Terms of Service
These terms govern your use of DPay, a payment-verification and checkout service operated by DOWNLABS, Lahore, Pakistan. By creating an account you agree to them.
1. What DPay is, and is not
DPay is software. It gives you a hosted checkout, reads the transaction alerts your own bank or wallet emails to you, verifies that a customer's transfer arrived in your own account, and tells your systems. It also provides payment links, invoices, subscriptions, customer records, analytics, an API and webhooks.
DPay does not hold, receive, transmit, settle or store funds. Money moves directly from your customer's bank or wallet into the account you nominate. DPay is not a bank, an electronic money institution, a payment system operator or a money transmitter, and it does not offer accounts, wallets, balances or payouts. Your relationship with your bank or wallet provider is governed by their terms, not ours.
2. Your account
- You must be at least 18 and authorised to act for the business you register.
- You are responsible for everything done with your credentials, API keys and webhook secrets. Keep them confidential; rotate them if you suspect exposure. API keys are stored hashed and cannot be recovered, only replaced.
- Give accurate business and receiving-account details. A wrong account title or number means your payments cannot be verified, and DPay cannot recover money sent to the wrong place.
- One account per business. Do not share an account between unrelated businesses.
3. Connecting your inbox
To verify payments, DPay asks for read-only access to the Gmail inbox your bank alerts arrive in. DPay searches that inbox only for messages from known bank and wallet senders, only within the verification window of a pending payment, and reads only those messages. It cannot send mail, delete mail or move money. You may disconnect at any time from Integrations; DPay then deletes the stored access token. Our use of Google data is described in the Privacy Policy.
4. Verification and your responsibility
DPay marks a payment succeeded only when a single bank credit satisfies every required check: right account, incoming credit, right provider, exact amount, inside the time window, and not previously matched. Where two credits could match, DPay withholds approval and asks you to choose. DPay's verification is a strong signal, but you remain responsible for final reconciliation against your own bank records, for deciding whether to fulfil an order, and for the goods or services you sell.
Verification depends on your bank emailing alerts reliably and promptly. DPay is not responsible for alerts a bank delays, alters or fails to send, for changes to a bank's alert format, or for inboxes that filter those alerts.
5. Plans, fees and payment
- The Free plan and each paid plan are described on the pricing page, which forms part of these terms. Each paid plan runs for 30 days from activation.
- Plan fees are paid by bank transfer through a DPay checkout. A plan activates when that transfer is verified. Nothing is charged automatically, and DPay never stores a card.
- When a period ends unpaid, your limits continue for a 3-day grace period and then revert to Free. Renewing while a period is active extends it; renewals do not overlap.
- Reaching a plan's monthly limit blocks new payments until you upgrade or the month rolls over. In-progress payments complete normally.
- Fees are in Pakistani rupees and exclude any tax you are required to withhold or pay. Refunds of plan fees are governed by the Refund and Dispute Policy.
6. Acceptable use
You may not use DPay to sell anything unlawful in Pakistan or in your customer's jurisdiction, to launder money, to collect payments for someone who is not you, to defraud customers, or to interfere with the service or other merchants. You may not attempt to forge bank alerts, replay transactions, or manipulate verification. DPay may suspend or close an account for breach, for legal reasons, or where we reasonably believe an account is being used to harm others, and will tell you why where the law allows.
7. Your customers
You are the merchant of record. The checkout page shows your business name and your receiving account; the customer is paying you. You must honour what you sell, handle your customers' refunds and complaints, and comply with consumer law. DPay may contact a customer about a disputed payment as described in the Refund and Dispute Policy, but DPay cannot reverse a bank transfer.
8. API and webhooks
You may use the API and webhooks to build your own integration, subject to the rate limits and rules in the reference. Verify every webhook signature and treat unverified events as untrusted. Do not embed live API keys in client-side code, prompts you share, or public repositories. DPay may change the API with reasonable notice and will keep the reference current.
9. Data
DPay processes your business details, your customers' details as you supply them at checkout, and the bank alerts described above, to provide the service. The Privacy Policy explains what is collected, why, for how long, and your rights. You are responsible for having the right to give DPay your customers' details.
10. Availability and changes
DPay is provided as is. We work to keep it available and accurate, but we do not promise uninterrupted service, and verification speed is bounded by your bank. We may change features, plans or these terms; material changes will be announced in the dashboard or by email at least 14 days before they take effect, except where a change is required by law or security.
11. Liability
To the fullest extent permitted by law, DOWNLABS is not liable for indirect, incidental or consequential loss, lost profit, or lost business arising from use of DPay, including from a payment verified or not verified, an alert not delivered by a bank, or a transfer sent to the wrong account. Our total liability for any claim in a 12-month period is limited to the plan fees you paid DPay in that period. Nothing in these terms limits liability that cannot be limited by law.
12. Ending the relationship
You can close your account at any time; unused plan time is not refunded except as set out in the refund policy. On closure DPay disconnects your inbox and deletes its token, and retains transaction records for the period described in the Privacy Policy. Sections that by their nature should survive, such as liability, data and disputes, survive closure.
13. Governing law
These terms are governed by the laws of Pakistan. Courts in Lahore have exclusive jurisdiction, and both parties agree to try to resolve any dispute through info@dpay.com.pk first.
14. Contact
General: info@dpay.com.pk · Payment disputes: dispute@dpay.com.pk. Effective 9 September 2026.