What you get
A white-label build is the Payonclick platform, rebranded and deployed for your business. Three parts share one backend, one database and one wallet ledger.
| Part | Who uses it | What it covers |
|---|---|---|
| Admin web panel | You and your staff | Users and roles, services, commission, KYC approvals, settlements, disputes, provider settings and reports |
| User web portal | Your master distributors, distributors, retailers and staff | Services, wallets, history, fund requests, network management and support tickets, installable as a PWA |
| Native Android app | Your retailers and distributors | Services with biometric and card-reader integrations, wallets, receipts, network and support, under your own app ID and signing key |
Each client gets a separate deployment with its own database, not an account on a shared multi-tenant system. Your users and your ledger stay in your platform.
Modules in the platform
Network hierarchy
Master distributor, distributor and retailer levels. Each level creates only the level below it, checked on the server, with a daily cap per creator. Relationship managers and staff roles sit alongside.
Wallets and ledger
A main wallet and an AEPS wallet per user, on a ledger with unique references and row locks, plus wallet reconciliation, TPIN-protected transfers and fund requests with UTR de-duplication.
Commission and charges
Package, service and amount slabs, flat or percentage, with TDS on commission, GST on charges and shares for up to five upline levels. Slabs import and export by Excel.
Service control
Hide, disable, lock or open each service per role or per user, with paid activation, validity and renewal. The app's menu and home tiles are driven from the server.
KYC and agreements
KYC review with approve, reject and re-KYC, DigiLocker document fetch and Aadhaar eSign agreements with versioned templates.
Service modules
Bharat Connect bill payments, mobile and DTH recharge, AEPS, Micro ATM, UPI cash withdrawal, money transfer and settlement, connected to your own provider contracts.
Partner API module
API keys with permissions, IP whitelists, rate limits, HMAC request signing and an audit trail, so you can offer APIs to your own partners.
Support and disputes
Tickets with attachments on web and app, and a dispute console that can refund a transaction and reverse its commission.
Reports
A live dashboard, active-user and onboarding reports, a single-user 360 view, wallet drill-downs and exports.
Each service module is described in detail on its own page: bill payments, mobile recharge, DTH, AEPS, Micro ATM, UPI cash withdrawal, money transfer and payouts.
Security built into the platform
- Passwords are hashed with bcrypt, and TPINs with a salted key-derivation function, with a lockout after wrong attempts.
- Login uses an SMS OTP, with optional Google Authenticator, one active session per user and trusted devices.
- An account locks after three wrong passwords in 24 hours, and blocking a user ends their sessions and freezes their wallets.
- Sensitive admin pages and user deletion need a step-up OTP.
- Login, OTP and TPIN attempts are throttled, and abusive IP addresses are blocked.
- Personal data is masked in one central place before it reaches screens and logs.
As with any codebase you take over, have the source reviewed by a security professional before go-live, including a check that no development or test routes remain.
How a white-label build runs
Requirement freeze and branding
Your brand name, logo, colours, domain and the services you will launch.
Backend branding and setup
The platform is rebranded and configured for your services and roles.
Portal customisation
The admin panel and the user portal take on your brand.
Android app build
Your app is built under your app ID and signed with your keystore.
Provider integration and testing
Your provider credentials are connected, and each service is tested.
Acceptance testing
Your team tests the whole platform before launch.
Go-live and training
Launch, an online training session for your admin team and help with your first Play Store upload.
The timeline depends on how quickly sign-offs happen, when your provider credentials arrive and how long Play Store and partner approvals take. We share a dated plan once your requirements are frozen.
What's included, and what isn't
| Included | Not included |
|---|---|
| Your brand name, logo, colour theme and domain on every part | Provider onboarding costs, deposits and transaction charges, paid to the providers |
| All the standard modules above | Domain registration and any paid SSL certificate |
| An Android app signed with your keystore, and help with one Play Store upload | The Google Play developer account fee |
| One online training session for your admin team | SMS gateway credits |
| Deployment scripts, API documentation, and admin and retailer guides | New modules beyond the agreed scope |
| Support for the first 30 days after go-live, then a hosting and maintenance plan | An iOS app |
| Ownership of the source code once the final payment is made |
Who holds the licence
Software doesn't carry a licence. Each regulated service needs a regulated partner, and your contracts with those partners decide what your network may do.
| Service | Regulated party | Your role, typically |
|---|---|---|
| AEPS, Micro ATM, UPI cash withdrawal, money transfer | A sponsor or acquiring bank | A BC, sub-agent or distributor under a bank or aggregator contract |
| Bharat Connect bill payments, including prepaid recharge on Bharat Connect | An operating unit, or an agent institution certified by NBBL | An agent under that operating unit or agent institution |
| Pooled payouts and QR collection for merchants | A bank, or a payment aggregator authorised by RBI | A merchant, or the aggregator's technology partner |
| Operator recharge outside Bharat Connect | The operator's distribution arrangements | A distributor or reseller |
| A wallet usable beyond your own services | A prepaid payment instrument issuer authorised by RBI | Needs authorisation, or a closed-system design |
This table is general information from our research, not legal advice. Once your platform is live, operating it within RBI, NPCI and Bharat Connect rules is your responsibility, so have your model reviewed by a legal adviser.
Our white-label buyer's checklist lists the questions to ask any vendor, including us.
Honest limits
- One deployment per client. This isn't a shared multi-tenant SaaS account, which also means your data isn't mixed with another brand's.
- Android, not iOS. The native app is Android. The web portal works in modern mobile browsers and can be installed as a PWA. An iOS app can be quoted separately.
- SMS and push notifications. The platform sends SMS OTPs and push notifications. Email and WhatsApp notifications aren't built in.
- Your provider contracts. We don't supply provider accounts. You sign with the providers, and we integrate them.