Control the QR.
Even After You Share It.

GhostVault creates a server-controlled payment link instead of putting your raw UPI ID inside the QR. Timed sessions can really expire or be revoked, while Smart QR lets you update the destination later without reprinting the physical code.

Tokenizedraw UPI not stored in public QR
Dynamicserver-controlled QR sessions
πŸ”’ MaskedUPI ID not embedded in QR
Server TTLsaved QR can truly expire
πŸ›‘οΈ Dynamic Payment Session Control
🎁 Free Trial
0 / 2 free QR codes used
1
2
3
πŸ”’ Stored server-side for payment handoff β€” never embedded in the QR
Optional compatibility hint. The final UPI app resolves the beneficiary from the UPI ID and may show the bank-registered name.
🎭 Customers see a GhostPay alias + generated GhostPay ID on the GhostVault page, not your raw UPI ID
Already have an account? Sign In
THE MECHANISM

How GhostVault Works

πŸͺ

Create a Server-Controlled Link

Your UPI destination is stored behind GhostVault. The QR itself contains only a random GhostVault payment token.

β†’
πŸ“²

GhostVault Validates the Scan

Every scan checks status and expiry on the server, then shows merchant, amount and purpose before UPI is opened.

β†’
βœ…

Choose Settlement

Use Direct Merchant Pay for direct UPI settlement, or GhostPay Balance for a provider/acquirer-backed merchant balance with withdrawals.

CONTROL LAYER

What GhostVault Actually Controls

πŸ“Έ

Saved QR Reuse

A saved QR contains only a GhostVault token. After server expiry or revoke, that saved token no longer hands off to UPI.

CONTROLLED
πŸ”—

Forwarded Payment Links

Forwarded GhostVault links are checked server-side on every scan and can be revoked by the merchant.

REVOCABLE
🎭

Public UPI Exposure

The GhostVault QR/page shows a GhostPay alias and ID instead of embedding the raw UPI ID. The final UPI app can still show the bank-resolved beneficiary identity.

MINIMIZED
⏱️

Timed Access

Timed links stop handing off to UPI after their server TTL. Smart QR links remain active until the merchant revokes them.

ENFORCED
πŸ’Έ

Balance Payment Idempotency

GhostPay Balance uses unique payment intents and provider-confirmed ledger credits. Direct UPI app-open is not treated as payment success.

TRACKED
⚠️

Physical QR Replacement

No web app can detect when an attacker physically replaces your sticker with a different QR. Customers should verify the GhostVault domain and final UPI recipient before paying.

USER CHECK