01Introduction and scope
DESIPAY Payment Solutions Private Limited (“DESIPAY”, “we”, “us” or “our”) is an Indian payment technology company providing payment gateway services, e‑wallets, cash cards, prepaid and postpaid instruments, Aadhaar-enabled payments (AePS), interoperable QR acceptance, bank transfers and merchant acquiring services.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, and the choices and rights available to you. It is published in accordance with the Information Technology Act, 2000 and the rules made under it (including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011), the Digital Personal Data Protection Act, 2023, and applicable Reserve Bank of India (RBI) directions.
This policy applies to:
- visitors to our website and any DESIPAY microsite or landing page;
- merchants, sub‑merchants, agents, distributors and partners who onboard onto our platform;
- customers and end users who transact through a DESIPAY-powered checkout, wallet, card, QR code or AePS touchpoint;
- applicants, vendors and other individuals who interact with us in a business capacity.
Please read this carefully. By accessing our website, onboarding as a merchant, or using any DESIPAY service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use our services.
02Who is responsible for your data
For the personal data described in this policy, DESIPAY acts either as a data fiduciary (where we determine the purpose and means of processing — for example, merchant onboarding and KYC) or as a data processor on behalf of a merchant or a sponsor bank (for example, when we process a checkout transaction initiated on a merchant's website).
DESIPAY Payment Solutions Private Limited
Private Limited Company, incorporated under the Companies Act, 2013 and classified as a Small Company.
Delhi, India
Shop No 146, 1st Floor, Vardhman Premium Mall LSC, Saraswati Vihar, North West Delhi, Delhi.
Where we act as a processor for a merchant, that merchant's own privacy notice governs their collection and use of your data, and any request to access or delete data held for them should be addressed to the merchant in the first instance. We will support the merchant in responding.
03Information we collect
a. Information you provide to us
- Identity and contact details: full name, date of birth, gender, photograph, email address, mobile number, postal address.
- Business and onboarding information: legal and trade name, constitution, business category (MCC), certificate of incorporation or registration, PAN, GSTIN, shop and establishment licence, website and app details, expected transaction volumes.
- KYC and verification data: officially valid documents such as PAN, Aadhaar (masked or redacted where permitted), passport, voter ID or driving licence; authorised-signatory details, board resolutions, beneficial ownership declarations, and liveness or video-KYC recordings where applicable.
- Bank and settlement details: account number, IFSC, account holder name, cancelled cheque or bank statement, UPI handle.
- Communications: the content of enquiry forms, support tickets, emails, chat transcripts and recorded support calls.
b. Transaction and financial information
- Transaction amount, currency, date, time, reference and order identifiers, payment instrument type and the payment status.
- Payer and payee identifiers such as a UPI VPA, masked card number (first six and last four digits), card network, issuing bank and token reference.
- Settlement, refund, chargeback and dispute records, along with supporting evidence submitted by merchants.
c. Technical and usage information
- IP address, device identifier, device model and operating system, browser type and version, language, and time-zone settings.
- Log data including pages viewed, referring URL, API endpoints called, session duration, error events and diagnostic traces.
- Approximate location derived from IP address, and precise location only where you have granted permission in a DESIPAY mobile application.
d. Information from third parties
- Sponsor and partner banks, card networks, NPCI and other payment system operators.
- KYC and identity verification providers, credit information companies and regulatory or public databases (for example MCA, GSTN and UIDAI-authorised verification channels).
- Fraud, risk-scoring and sanctions-screening providers, including negative lists shared under industry practice.
- Referral partners, resellers and distributors who introduce you to our services.
04Card data, tokenisation and PCI-DSS
Payment card handling is governed by the Payment Card Industry Data Security Standard (PCI-DSS) and by RBI's directions on card storage and tokenisation.
- We do not store full card numbers, CVV/CVC codes, PINs, or magnetic-stripe data on our systems.
- Card credentials entered at checkout are transmitted over encrypted channels directly to the acquiring bank, card network or a PCI-DSS certified vault.
- Where card-on-file functionality is offered, the card is replaced by a network token issued by the card network. DESIPAY and the merchant hold only the token and permitted card metadata (issuer, network, card type, last four digits and expiry).
- Access to cardholder data environments is restricted, logged and reviewed, with segregation of duties and periodic vulnerability testing.
Never share your CVV, PIN, OTP or full card number with any person claiming to represent DESIPAY. Our staff will never ask you for these details over a call, email, SMS or chat.
05Aadhaar and biometric data (AePS)
Where you use an Aadhaar-enabled Payment System (AePS) touchpoint operated through DESIPAY or one of our business correspondents:
- Biometric data (fingerprint or iris) is captured only on a registered, STQC-certified device and is encrypted at the point of capture.
- The encrypted biometric packet is transmitted only for the purpose of authentication to UIDAI through the authorised channel, and is not stored, copied, shared or retained by DESIPAY after the authentication response is received.
- We do not use Aadhaar numbers for any purpose other than the transaction or verification you have consented to, and we store only permitted references such as a masked Aadhaar or a UID token where the law allows it.
- Your explicit, informed consent is obtained before every Aadhaar authentication, and the purpose is disclosed to you at the point of capture.
Aadhaar-related processing is carried out in accordance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, the regulations issued by UIDAI, and applicable RBI and NPCI circulars.
06How we use your information
We use personal data only for defined, lawful purposes:
| Purpose | What this involves | Basis |
|---|---|---|
| Providing the service | Processing payments, settlements, refunds, payouts, wallet balances and card issuance; operating your dashboard and APIs. | Performance of contract |
| Onboarding and KYC | Verifying identity, business standing, beneficial ownership and bank details before activation. | Legal obligation |
| Risk, fraud and AML | Transaction monitoring, velocity checks, device fingerprinting, sanctions and PEP screening, suspicious transaction reporting. | Legal obligation / legitimate use |
| Support and disputes | Responding to tickets, investigating failures, handling chargebacks and grievances. | Performance of contract |
| Regulatory reporting | Returns, audits and disclosures required by RBI, NPCI, FIU-IND, tax and law-enforcement authorities. | Legal obligation |
| Service improvement | Aggregated analytics, capacity planning, debugging, and testing on masked or synthetic data. | Legitimate use |
| Marketing and updates | Product announcements, offers and newsletters to business contacts. | Consent (withdrawable) |
We do not sell your personal data. We do not use your transaction data to build advertising profiles, and we do not carry out automated decision-making that produces legal effects without a route to human review.
08Storage location and cross-border transfers
In line with RBI's directive on storage of payment system data, all payment system data relating to transactions processed in India is stored on systems located in India. This includes end-to-end transaction details and the information collected, carried or processed as part of the message or payment instruction.
Where a transaction has a foreign leg, a copy of the foreign-leg data may also be stored abroad, as permitted. If we ever transfer personal data outside India for a limited processing purpose, we will do so only to jurisdictions permitted under applicable law, under contractual safeguards, and the data will be brought back to India within the timelines that regulation requires.
09How long we keep your data
- Transaction and settlement records: retained for a minimum of eight years from the date of the transaction, in line with record-keeping expectations for payment system participants and the Companies Act, 2013.
- KYC records and identification documents: retained for five years after the business relationship ends or the transaction is completed, as required under the Prevention of Money Laundering Act, 2002 and the rules made under it.
- Dispute, chargeback and grievance records: retained for the life of the case plus the applicable limitation period.
- Website and marketing data: retained until you withdraw consent or for 24 months of inactivity, whichever is earlier.
- System and access logs: retained for the period prescribed by our security policy and applicable cyber-security directions.
Where a longer period is required by law, a regulator's direction, or an ongoing investigation or legal proceeding, we retain the data for that longer period. After the retention period ends, data is securely deleted or irreversibly anonymised.
10How we protect your data
- Encryption: 256-bit encryption for data in transit (TLS) and encryption at rest for sensitive data stores.
- Tokenisation and masking: sensitive identifiers are tokenised or masked wherever the full value is not operationally required.
- Access control: role-based access on a least-privilege basis, multi-factor authentication for administrative access, and maker-checker controls on sensitive operations.
- Monitoring: continuous transaction and infrastructure monitoring, anomaly detection, centralised logging and tamper-evident audit trails.
- Assurance: periodic vulnerability assessments, penetration testing, secure development practices, and independent audits aligned to PCI-DSS and ISO 27001 practices.
- Resilience: encrypted backups, disaster-recovery arrangements and a tested business-continuity plan.
In the event of a personal data breach, we will notify the affected persons and the relevant authorities (including CERT-In and, where applicable, the RBI and the Data Protection Board) within the timelines prescribed by law, along with the nature of the breach and the steps we are taking.
No method of transmission or storage is completely secure. You are responsible for keeping your dashboard credentials, API keys and one-time passwords confidential, and for notifying us immediately at the contact address below if you suspect any unauthorised access.
11Your rights and choices
Subject to verification of your identity and to the limits set by law, you may:
- Access a summary of the personal data we hold about you and the identities of those with whom it has been shared.
- Correct or update data that is inaccurate, incomplete or out of date.
- Request erasure of data that is no longer needed for the purpose it was collected, unless retention is required by law.
- Withdraw consent that you previously gave, at any time. Withdrawal applies going forward, and may mean we can no longer provide certain services to you.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Opt out of marketing using the unsubscribe link in our emails or by writing to us. You will continue to receive transactional and service messages, which cannot be opted out of while your account is active.
- Complain to our Grievance Officer and, if unsatisfied, to the Data Protection Board of India or the relevant regulator.
To exercise any of these rights, write to us using the details in section 14. We will respond within 30 days of receiving a verifiable request. There is no fee for a first request; we may charge a reasonable fee for repetitive or manifestly excessive requests.
13Children's data
Our services are intended for businesses and for adults. We do not knowingly collect personal data of children below 18 years of age except where a payment is made from an account lawfully operated by or for a minor through a regulated instrument. Where processing of a child's data is required, it will be undertaken only with verifiable consent of the parent or lawful guardian, and we will not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child's data has been provided to us in error, contact us and we will delete it promptly.
14Third-party sites and services
Our website, dashboard and documentation may link to third-party websites, plugins and services that we do not control. This Privacy Policy does not apply to them. We encourage you to read the privacy notice of any third party before providing data to it. Similarly, when you complete a payment on a merchant's site, the merchant's own privacy notice governs the data it collects directly from you.
15Changes to this policy
We may update this Privacy Policy to reflect changes in our services, technology, or legal and regulatory requirements. The revised version will be posted on this page with an updated “last updated” date. Where a change is material — for example, a new category of data or a new purpose of processing — we will give notice by email or through your dashboard before it takes effect. Continued use of our services after the effective date constitutes acceptance of the revised policy.
16Grievance Officer and contact
If you have a question, a request relating to your rights, or a complaint about how we handle personal data, contact our Grievance Officer, appointed in accordance with the Information Technology Act, 2000 and the rules made under it.
Grievance Redressal Cell, DESIPAY
Email: grievance@desipay.website
Response commitment: acknowledgement within 48 hours, resolution within 30 days.
Privacy team
Email: privacy@desipay.website
General enquiries: contact@desipay.website
DESIPAY Payment Solutions Private Limited
Shop No 146, 1st Floor, Vardhman Premium Mall LSC, Saraswati Vihar, North West Delhi, Delhi, India.
Not satisfied with our response? You may escalate to the RBI Ombudsman under the Reserve Bank – Integrated Ombudsman Scheme, 2021 at cms.rbi.org.in, or to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.