1. Introduction
PayPocket ("PayPocket", "we", "us", "our") operates a multi-service fintech platform offering
mobile/DTH recharge, Bharat Connect (BBPS) bill payments, Aadhaar Enabled Payment System (AEPS)
banking services, flight booking, wallet, and a referral commission program, accessible through
our website (agent.paypocket.in and related domains) and our Android application (together, the
"Services").
This Privacy Policy explains what personal information we collect, why we collect it, how we
use and protect it, and the choices you have. By creating an account or using the Services, you
agree to the collection and use of information in accordance with this policy.
This policy applies to all users of the Services, including individual account holders
("Users"), staff accounts created by us, and businesses that integrate with our platform via
API ("API Partners").
2. Information We Collect
2.1 Account & Identity Information
- Full name, mobile number, email address, and password (stored as a salted, irreversible hash — we never store or can retrieve your plaintext password).
- A unique referral code and, if applicable, who referred you.
- Profile and account status information (role, verification status, activation status).
2.2 KYC & Identity Verification
- Government-issued identity documents required for KYC (Know Your Customer) verification,
which may include Aadhaar number, PAN number, and scanned copies/photographs of these
documents, submitted through the Camera or file upload.
- KYC is required by regulation for financial services such as AEPS and is used solely to
verify your identity and to comply with Reserve Bank of India (RBI) and Prevention of Money
Laundering Act (PMLA) requirements.
2.3 Biometric Information (AEPS only)
- If you use AEPS (Aadhaar-linked banking transactions such as balance inquiry, cash
withdrawal, or 2-factor authentication), a connected NPCI-certified biometric capture device
(fingerprint, iris, or face) is used to capture your biometric data at the time of each
transaction.
- This biometric data is captured only for the specific transaction being performed, is
transmitted in encrypted form directly to the Unique Identification Authority of India (UIDAI)
/ National Payments Corporation of India (NPCI) banking network through our licensed AEPS
technology partner for one-time authentication, and is not stored by
PayPocket after the transaction completes.
2.4 Financial & Transaction Information
- Wallet balance, transaction history, recharge/bill-payment/flight-booking records, commission
and referral earnings.
- Bank account details linked to your Aadhaar number for AEPS transactions (processed by our
banking/AEPS partner; PayPocket does not store your bank account number or IFSC).
- UPI transaction references for wallet top-ups, processed through our payment gateway
partner.
2.5 Device, Location & Usage Information
- Device identifiers, device model, operating system, browser type, IP address, and a device
fingerprint used to detect fraudulent or unauthorized login attempts and to let you view and
manage devices logged into your account.
- Best-effort geolocation (derived from IP address, or from GPS where you grant location
permission) used for fraud prevention, AEPS merchant-location capture, and to show relevant
service availability.
- App usage data such as pages/screens visited, features used, and crash/error logs, used to
maintain and improve the Services.
2.6 Communications
- One-Time Passwords (OTPs) sent to your registered mobile number for login and
verification, and any support communications you send us.
3. App Permissions
Our Android application requests only the permissions it needs to provide the Services:
| Permission | Why we need it |
| Camera | Capturing KYC documents (Aadhaar/PAN) and, where applicable, QR codes for web login and bill payments. |
| Location | Fraud prevention, device fingerprinting, and recording merchant location for AEPS transactions as required by our banking partner. |
| Biometric / USB / Bluetooth device access | Connecting an NPCI-certified fingerprint/iris/face capture device for AEPS transactions. |
| SMS (read-only, on supported devices) | Auto-reading OTP codes sent to your device to speed up login — never used to read or send any other message. |
| Storage / Media | Saving transaction receipts and uploading KYC documents. |
| Internet & Network State | Core connectivity to our servers — required for the app to function at all. |
You can review and revoke permissions at any time from your device's Settings. Some features
(e.g. AEPS or KYC upload) will not function without the corresponding permission.
4. How We Use Information
- To create and maintain your account, and authenticate your logins (password + OTP).
- To process recharges, bill payments, AEPS banking transactions, flight bookings, wallet
top-ups, and referral commission payouts you request.
- To verify your identity as required for regulated financial services (KYC/AML).
- To detect, investigate, and prevent fraud, unauthorized access, and abuse.
- To provide customer support and respond to your requests.
- To comply with legal, regulatory, and tax obligations (including TDS deduction where
applicable and record-keeping required under RBI/PMLA rules).
- To send transactional notifications (OTPs, transaction confirmations, account alerts). We do
not send marketing messages without your consent.
We do not sell your personal information to third parties.
5. Services Covered
This policy covers all services offered on the platform, including:
- Recharge: mobile, DTH, and utility recharges through our network of recharge
providers.
- BBPS (Bharat Connect): bill payments for electricity, water, gas, and other
billers under the Bharat Bill Payment System.
- AEPS: Aadhaar-linked banking services (balance inquiry, cash withdrawal,
mini statement) via our licensed banking technology partner.
- Flight Booking: domestic/international flight search and booking via our
travel supplier partner.
- Wallet & Referral Program: an internal wallet used to fund transactions,
and a two-level referral commission program.
6. Third-Party Service Providers
To provide the Services, we share the minimum necessary information with the following
categories of trusted service providers, each bound by their own confidentiality and data
protection obligations:
- AEPS / biometric banking partner — to process Aadhaar-based banking
transactions with UIDAI/NPCI on your behalf.
- Bharat Connect (BBPS) aggregator — to fetch bills and process bill
payments.
- Recharge API providers — to fulfil mobile/DTH recharge requests.
- Flight supplier — to search and confirm flight bookings.
- SMS gateway provider — to deliver OTP messages to your mobile number.
- Payment gateway — to process UPI wallet top-ups.
- Cloud hosting infrastructure — to securely store and process data described
in this policy.
We do not permit these providers to use your information for their own marketing purposes.
7. Data Sharing & Disclosure
Beyond the service providers listed above, we may disclose your information:
- When required by law, court order, or governmental/regulatory request (including RBI,
UIDAI, income tax, and law-enforcement authorities).
- To protect the rights, property, or safety of PayPocket, our users, or the public, including
to investigate fraud or security incidents.
- In connection with a merger, acquisition, or sale of assets, subject to this policy
continuing to apply to your information.
- With your explicit consent, for any other purpose we disclose to you at the time.
8. Data Security
- Passwords are stored using one-way, salted cryptographic hashing — never in plaintext.
- Sensitive credentials and API secrets are stored using strong encryption (AES-256).
- All data in transit between the app and our servers is encrypted using HTTPS/TLS.
- Biometric data captured for AEPS is never persisted on our servers (see Section 2.3).
- Access to production systems and personal data is restricted to authorized personnel on a
need-to-know basis.
While we take reasonable and industry-standard measures to protect your information, no method
of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Data Retention
- KYC records are retained for at least 5 years after the account is closed, and transaction
records for at least 10 years, in line with RBI and PMLA record-keeping requirements for
regulated financial services.
- Account information is retained for as long as your account is active, and thereafter for as
long as needed to comply with our legal and regulatory obligations, resolve disputes, and
enforce our agreements.
- Biometric data collected for AEPS transactions is not retained (see Section 2.3).
10. Your Rights & Choices
Subject to applicable law, you have the right to:
- Access and review the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Withdraw consent for optional processing (e.g. location-based features), where this does not
conflict with a regulatory obligation.
- Request deletion of your account and associated data, subject to the retention requirements
described in Section 9.
- Lodge a complaint with your local data protection authority.
You can exercise these rights by contacting us using the details in Section 15.
11. Account & Data Deletion
You may request deletion of your PayPocket account and associated personal data at any time by:
- Emailing our support team (see Section 15) from your registered email address with the
subject "Account Deletion Request", including your registered mobile number; or
- Asking your platform administrator to submit the request on your behalf.
We will process your request within 30 days. Please note that, as described in Section 9, we
are legally required to retain certain KYC and transaction records for a minimum period even
after account deletion, in accordance with RBI/PMLA regulations. Wallet balances and referral
earnings must be withdrawn or resolved before an account can be fully closed.
12. Children's Privacy
The Services involve regulated financial transactions and are not directed at, or intended for
use by, anyone under the age of 18. We do not knowingly collect personal information from
children. If we become aware that we have inadvertently collected information from a minor, we
will take steps to delete it promptly.
13. Regulatory Compliance
We process personal data in accordance with applicable Indian law, including the
Digital Personal Data Protection Act, 2023 (DPDP Act), the Information
Technology Act, 2000 and its rules, guidelines issued by the
Reserve Bank of India (RBI) for payment system operators and AEPS, and the
Prevention of Money Laundering Act (PMLA) for KYC/AML obligations.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for
legal, operational, or regulatory reasons. We will post the revised policy on this page with an
updated "Last updated" date, and, for material changes, provide additional notice (such as an
in-app notification) where required by law.
If you have questions, requests, or concerns about this Privacy Policy or how we handle your
information, please contact us: