From 4 September 2026, the person you pay through UPI no longer sees your full mobile number. NPCI circular NPCI/UPI/OC-234/2026-27, issued on 5 June 2026 with a 4 September compliance deadline, requires every UPI member bank and app to mask sensitive user details — UPI IDs, mobile numbers and account numbers — across all customer-facing screens and communications, showing counterparties only the last four digits, and to let users create a UPI ID that is not their phone number and set it as the default. QR code payments must not reveal the full number even after the payment completes. Nothing changes about limits, charges or tax: UPI transfers remain free of GST, the standard per-transaction limits stand, and the higher ₹5 lakh limit for hospitals and educational institutions is unchanged. What changes is who can harvest your phone number from a payment.
What the circular requires
NPCI's directive rests on the Payment and Settlement Systems Act, 2007 and the 2008 Regulations, and it lands alongside India's Digital Personal Data Protection Act, which puts obligations on how entities collect, store and share personal data. The circular is short. Its operative requirements are three.
First, masking. Any UPI ID, mobile number or account number shown to a counterparty, in transaction screens, confirmations, receipts or notifications, must be masked. In practice the last four digits of a mobile number are visible; the rest are hidden. Second, QR flows. When you scan a merchant or personal QR and pay, the full mobile number behind that QR is not displayed to you, and yours is not displayed to them, before or after the transaction. Third, alternative identifiers. Apps must let users create a UPI ID that does not embed a mobile number — a username-style handle — and must allow it to be set as the default ID that other people see and that gets shared when you generate a QR or request money.
Banks and apps carry the accountability. If your app still shows a full number to the other party after 4 September, that is a compliance failure on the app's side, not a setting you missed.
Why this matters more than it sounds
For years a UPI payment was also a phone-number exchange. Pay a stranger for a second-hand item and they had your number; a delivery agent who took a UPI transfer had it; every small merchant's payment history was a list of customer numbers. That data fed spam calls and, at the sharp end, targeted fraud where a caller already knows your number, your bank and the exact amount of a recent payment. Masking removes the cheapest source of that triple. It does not stop fraud that starts with a link you tap, but it removes the credibility a scammer buys by quoting your own transaction back to you.
What changes for you as a payer
Open your UPI app and look at your profile. You will see either a prompt to create a username UPI ID or an option under UPI IDs to add one. Choose something you are happy to share publicly — it will appear on QR codes and payment requests — and set it as default. Your mobile-number-based ID keeps working for anyone who already has it; the default controls what gets shared from now on.
Your transaction history still shows full details of your own accounts to you. Masking applies to what the other side sees. If you regularly pay people who need to identify you — a landlord matching rent to a tenant, for example — the visible last four digits plus your display name are usually enough; if not, share the reference number, not your phone number.
What changes for merchants and freelancers
Three practical moves. One: regenerate your static QR from a username UPI ID rather than the mobile-number one, so the QR on your counter or your invoice does not leak your personal number. If you produce invoices with an embedded UPI QR, the GST invoice generator and the QR code generator both accept any valid UPI ID as the payee address. Two: update payment links. A UPI deep link carries the payee address in the pa= parameter; links you built with your mobile number still work but now expose it to anyone who reads the URL. Rebuild them with the new handle using the UPI payment link maker. Three: reconciliation. If your bookkeeping matched customers by the phone number visible in the UPI app, that field is now truncated. Match on the UPI transaction reference (the 12-digit RRN) instead — it was always the reliable key.
For businesses that collect customer numbers separately for delivery or support, nothing in this circular stops that. It only stops the payment rail itself from being the collection mechanism.
What is not changing
A cluster of forwarded messages claimed new limits and new taxes from 1 September. None are real. UPI transaction limits did not change on 1 September 2026; the increase to ₹5 lakh per transaction for hospitals and educational institutions was an earlier, separate change. Transferring money by UPI is not a taxable service and attracts no GST. Income-tax slabs and GST rates did not change on 1 September either. The only 1 September tax item that mattered was the end of the non-audit ITR-3 and ITR-4 window on 31 August, after which those returns are belated filings with late fee and interest.
A developer's note on the masking rule
If you run a product that displays UPI transaction data pulled from a PSP or bank feed — a reconciliation dashboard, a rent-collection tool, a marketplace — the circular's masking requirement applies to your customer-facing interfaces too, because your users are seeing counterparty details through your screens. Mask at render time, keep the full value server-side for matching, and log who unmasked what. A simple rule: the last four digits of a mobile number and the RRN are enough for any support workflow we have seen.
Worked example: a freelancer's invoice flow after 4 September
Take a designer who invoices eight clients a month and gets paid by UPI. Before the circular, every invoice carried a QR generated from her mobile-number UPI ID, so every client — and everyone a client forwarded the PDF to — had her personal number. Here is the same flow rebuilt in an afternoon.
Step one, in the UPI app: create a username ID (something like a studio name) and set it as default. Step two: regenerate the invoice QR from that ID and drop it into the invoice template, so the PDF no longer contains a phone number anywhere. Step three: rebuild the payment link she pastes into WhatsApp and email with the new ID in the payee field; old links keep working, but each one she sends after today should carry the new handle. Step four, and the one people forget: change how she reconciles. Her spreadsheet used to match incoming payments by the payer's phone number as shown in the app. That field is now the last four digits. The 12-digit UPI transaction reference is unique, appears on both sides and in the bank statement, and is the correct key. Add a column for it and ask clients to quote it if there is ever a dispute.
Step five is communication. A one-line note on the next invoice — "we now use a username UPI ID; your payment screen will show our studio handle, not a phone number" — removes the "is this really you?" call that otherwise arrives the first time a long-standing client sees an unfamiliar ID.
Nothing in this flow changes what she owes or when. The 15 September advance-tax instalment and the belated-return rules for anyone who missed 31 August are unaffected — see our missed ITR deadline and advance tax guide — and if she sells to overseas clients the payment-rail question is different again, which we covered in why UPI is missing from some rupee checkouts.
Quick answers
From what date do UPI apps hide my number?
4 September 2026, the compliance deadline in NPCI circular NPCI/UPI/OC-234/2026-27 dated 5 June 2026.
Will the person I pay see anything?
Your display name, your default UPI ID (which can now be a username, not a number) and at most the last four digits of your mobile number.
Do I have to create a new UPI ID?
No, but apps must offer one and let you set it as default. Doing so is the only way to stop your number appearing on QR codes and requests you generate.
Did UPI limits or charges change on 1 September?
No. Limits are unchanged and UPI transfers carry no GST.
Does this apply to QR payments?
Yes. Full mobile numbers are not shown in QR flows, including after the transaction completes.
Set a username UPI ID as your default this week, regenerate any QR or payment link that carries your number, and switch reconciliation to the RRN. For the wider set of India money tasks — filing, regime choice, checklists — the Income Tax Filing Checklist 2026-27 and the ITR Form Selection Flowchart are the two references we hand to every freelancer client. Every product mentioned is available at wowhow.cloud — pay once, ship forever.
Disclaimer: This article is for informational purposes only and does not constitute financial, tax, or legal advice. Consult a qualified professional for guidance specific to your situation.
Originally published at wowhow.cloud
Top comments (0)