PRIVACY
Privacy Policy
How personal, KYC, transaction and service data is intended to be handled.
1. Data We May Process
Depending on the requested service, data may include name, contact details, business details, tax identifiers, PAN, KYC/identity documents, bank/payment references, invoices, accounting records, service documents, device/security logs and transaction/request history.
2. Purpose
Data is processed to provide requested services, verify identity, prevent fraud, maintain audit trails, communicate status, meet legal/partner obligations, process authorised payments, improve security and provide customer support.
3. Consent and Notice
Where consent is the applicable basis, the user will receive a clear notice and an affirmative choice before information is submitted. Consent for one purpose is not treated as blanket permission for unrelated third-party sharing.
4. KYC and Sensitive Documents
KYC documents are collected only when necessary for the selected service or regulated partner. Aadhaar should be collected/used only where legally permitted and necessary; masked Aadhaar or alternative accepted Officially Valid Documents should be preferred where the applicable workflow permits. Public pages must not expose KYC documents.
5. Sharing
Information may be shared only with the relevant government authority, regulated entity, authorised service provider/payment partner or processor when required to deliver the selected service, comply with law or prevent fraud. Provider/API credentials are not shared with clients or agents.
6. Storage and Security
Production KYC and account records should be stored in access-controlled server storage with encryption in transit and appropriate encryption/protection at rest. Passwords must be stored as strong password hashes, not plaintext. Audit logs, role permissions, secure sessions and 2-factor authentication should protect privileged access.
7. Retention and Deletion
Records are retained only for the period needed for service delivery, statutory/regulatory obligations, dispute handling, fraud prevention and legitimate audit requirements. A deletion request may be limited where law or an authorised provider requires retention.
8. User Rights and Grievance
Users may request access/correction of applicable personal data, raise a grievance, or withdraw consent where legally available. Requests are subject to identity verification and applicable retention obligations. Use the Grievance page for privacy-related requests.
9. Children
The service is intended primarily for adults and businesses. Where data relating to a child is processed, the applicable legal requirements for verifiable parental/guardian consent and restrictions must be followed.
