Skip to content
upınow

Connect your Gmail alerts

Why UPINOW reads your bank's payment alert emails, and how to connect Gmail.

On this page

Why we need this

Your bank's payment alert email is the proof a payment happened. UPINOW reads it, matches it to the right order, and stamps the order PAID. Nothing else confirms a payment.

Gmail only, for now

UPINOW connects to Gmail over IMAP with an App Password. Other mailbox providers are not supported yet.

What we read, and what we never read

We only read your bank's payment alert emails. Nothing else. Disconnect any time.

  • We read: your bank or UPI app's payment alert emails, only from senders you approve.
  • We never read: the rest of your mail, contacts, drafts or attachments.
  • Disconnect any time from Settings. The saved App Password is deleted that same second.

UPINOW will never ask for your UPI PIN, OTP or bank password.

Create a Gmail App Password

An App Password is a 16-letter code that lets UPINOW read this one mailbox, without your real Gmail password.

  1. Open your Google Account (myaccount.google.com), then Security.
Screenshot to add
Google Account, Security tab
  1. Turn ON 2-Step Verification, if it isn't already.
Screenshot to add
2-Step Verification toggle turned on
  1. Type "App passwords" in the search box and open it.
Screenshot to add
Google Account search box with "App passwords" typed in
  1. Name the app "UPINOW", then hit Create.
Screenshot to add
App passwords screen with the name "UPINOW" entered
  1. Copy the 16-letter password and paste it below. Spaces don't matter.
Screenshot to add
The generated 16-letter App Password ready to copy

Connecting

On Settings, UPI accounts, open the account and enter its Gmail address and the App Password, then select "Connect Gmail". A few checks run before it saves:

  • "Enter a valid Gmail address." if the address is not valid.
  • "Paste the 16-letter App Password." if the password is under 8 characters once spaces are removed.
  • "Gmail login failed. Your App Password changed or IMAP is off in Gmail. Enter a new App Password to reconnect Gmail." if Gmail refuses the App Password.
  • "This Gmail is already linked to another UPINOW account. Use a different Gmail, or disconnect it from that account first." if that Gmail address is already connected to a different UPINOW business. One mailbox can only ever feed one business.

What the status shows

Once connected, a pill reads "Gmail alerts: Connected" next to your Gmail address, with the last check and last alert times. If a scan fails, the pill instead reads "Gmail trouble", and the top bar's health pill switches from "Payments live" to "Fix Gmail" (or shows "Connect Gmail" if you have never connected). Use "Test connection" any time to check the connection by hand. "Disconnect" deletes UPINOW's own saved copy of the App Password right away, not just marks it inactive. The App Password itself still works at Google until you remove it there: open your Google Account (myaccount.google.com), then Security, then App passwords, and delete the UPINOW one.

The saved App Password is encrypted with AES-256-GCM using a server key, and only decrypted in memory to read your alerts.

Alert senders

UPINOW only trusts alerts from senders you list, and checks the DKIM signature on every alert, so a fake email can't trigger a PAID stamp.

  • PhonePe Business fills in noreply@phonepe.com by default.
  • Paytm Business fills in no-reply@paytm.com by default.
  • Google Pay Business fills in payments-noreply@google.com by default.
  • Bank UPI ID and Other have no default: type the "From" address your bank's alert email actually uses.

You can list up to 5 sender addresses, one per line.

Extra alert emails

A payment only counts as confirmed when the bank's alert reaches your connected Gmail or an extra alert email added here. If the bank's alerts go to another address that then forwards into your connected Gmail, add that address here. You can add up to 5 extra alert emails. Add only your own address, never one a customer asks for.

Use Gmail's own forwarding to bring alerts in from another mailbox. Do not use Gmail's "Check mail from other accounts" feature: UPINOW cannot verify the sender of mail pulled in that way, so it treats it as unverified and does not count it.

If you change your Google password

Google's rule is that changing your account password may stop an existing App Password working. If your Gmail alerts stop arriving after you change your Google password, create a new App Password and reconnect.

One Gmail per UPI account

Each UPI account connects its own Gmail; one Gmail cannot feed two UPI accounts, even two of your own. This is not a limit we could relax safely: nothing in a bank's alert email reliably names which UPI ID was paid, so if two accounts shared one inbox, both would accept every alert and a single payment could end up stamping two orders paid. Connecting a Gmail already linked elsewhere is refused with the same message either way, whether that other account belongs to you or to someone else.

Two things follow from this:

  • Do not forward one account's payment alerts into another account's connected Gmail. Once they land there, UPINOW cannot tell them apart from that account's own alerts.
  • Do not list another of your accounts' connected Gmail address as an extra alert email. Extra alert emails are for addresses that forward into this account, not for another live account's own mailbox.

If you try either, UPINOW refuses the change and tells you which account the address already belongs to.