GhostVault creates a server-controlled payment link instead of putting your raw UPI ID inside the QR. Timed sessions can really expire or be revoked, while Smart QR lets you update the destination later without reprinting the physical code.
Your UPI destination is stored behind GhostVault. The QR itself contains only a random GhostVault payment token.
Every scan checks status and expiry on the server, then shows merchant, amount and purpose before UPI is opened.
Use Direct Merchant Pay for direct UPI settlement, or GhostPay Balance for a provider/acquirer-backed merchant balance with withdrawals.
A saved QR contains only a GhostVault token. After server expiry or revoke, that saved token no longer hands off to UPI.
CONTROLLEDForwarded GhostVault links are checked server-side on every scan and can be revoked by the merchant.
REVOCABLEThe GhostVault QR/page shows a GhostPay alias and ID instead of embedding the raw UPI ID. The final UPI app can still show the bank-resolved beneficiary identity.
MINIMIZEDTimed links stop handing off to UPI after their server TTL. Smart QR links remain active until the merchant revokes them.
ENFORCEDGhostPay Balance uses unique payment intents and provider-confirmed ledger credits. Direct UPI app-open is not treated as payment success.
TRACKEDNo web app can detect when an attacker physically replaces your sticker with a different QR. Customers should verify the GhostVault domain and final UPI recipient before paying.
USER CHECK