1. Data we collect
- Account data: name, email address, mobile number, referral details.
- Identity verification data: the type of ID, name and date of birth as printed, the last 4 characters of the ID number, images of your ID (front and back), a selfie and short live camera frames used for the face and liveness check, and the verification result. We do not collect full Aadhaar numbers; if you upload Aadhaar, it must be masked.
- Payment data: UPI IDs and bank account details you save (account numbers are encrypted), payment references and proofs you upload.
- Transaction data: orders, deposits, withdrawals, wallet addresses, blockchain transaction hashes and ledger entries.
- Security and device data: IP address, device and browser type, sign-in events, 2FA events and session information.
- Support data: tickets, messages, dispute evidence and call or chat notes.
2. Why we use it
- To open and run your account and process orders, payments and withdrawals.
- To verify your identity, including automated document, face-match and liveness checks with human review, and to prevent fraud, account takeover and money laundering.
- To meet legal and regulatory obligations such as record keeping, suspicious transaction reporting and responding to lawful requests.
- To resolve disputes and support requests, and to keep the service secure and reliable.
- To send service messages. We send marketing only with your consent, and you can opt out at any time.
3. Automated decisions
Identity checks may use automated systems that produce an initial approve, reject or review result. Any result can be reviewed and changed by a trained staff member, and you can ask for a human review by contacting support.
4. How long we keep it
We keep identity, transaction and related records for at least five (5) years after our relationship ends, or longer where required by applicable law (for example anti-money-laundering rules) or while a dispute, investigation or legal claim is ongoing. Other data is kept only as long as needed for the purposes above, then deleted or anonymised.
5. Who we share it with
- Service providers acting for us under contract: cloud hosting and storage, email delivery, identity verification, sanctions screening, malware scanning and custody or blockchain infrastructure.
- Your order counterparty, only what is needed to complete the order (for example your display name and payment details for that order).
- Law enforcement, regulators, the Financial Intelligence Unit–India, courts and other authorities when we are legally required to, including in response to cyber-crime complaints.
- Professional advisers, and a successor business if the service is transferred, under confidentiality obligations.
6. Security
Identity images and sensitive fields are encrypted at rest. Access is limited to authorised staff by role, sensitive actions need two-factor authentication, and staff views of identity documents are logged. No system is perfectly secure; tell us immediately if you suspect unauthorised access.
7. Your rights
Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you can ask to access, correct or update your data, withdraw consent (which may mean we can no longer provide the service), and ask us to erase data we are not required to keep. You can also nominate another person to exercise your rights in case of death or incapacity.
8. Grievance officer
For privacy questions or complaints, contact our Grievance Officer: To be appointed, grievance@example.com. We acknowledge and resolve complaints within the timelines required by law. If you are not satisfied, you may approach the Data Protection Board of India once it is operational.