1 Commitment to Privacy & Statutory Base
ReffersPay FinCorp Private Limited ("ReffersPay", "we", "our", or "us") respects the privacy rights of all merchants, business correspondents, customers, and website visitors. We are steadfast in our commitment to upholding the highest standards of data protection and digital trust.
This Privacy Policy outlines our procedures for gathering, processing, storing, and safeguarding personal and transactional information in compliance with the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000 (including Section 43A and the Information Technology Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011), Reserve Bank of India (RBI) Payment System Data Storage Directives, and National Payments Corporation of India (NPCI) security frameworks.
2 Categories of Information Collected
To provide certified FinTech services, we collect and process only the minimum necessary categories of information:
3 Biometric Data & UIDAI Non-Retention Policy
Absolute Statutory Non-Retention Mandate:
Under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and UIDAI Security Directives, REFFERSPAY NEVER STORES, COPIES, LOGS, OR TRANSMITS UNENCRYPTED BIOMETRIC DATA (FINGERPRINTS OR IRIS SCANS) IN ANY MANNER OR ON ANY LOCAL OR CLOUD SERVER.
When an AePS customer provides a biometric scan, the biometric impression is immediately encrypted at the hardware level within the certified UIDAI L0/L1 Registered Device (RD) Service using UIDAI’s public key. The encrypted block (PID block) passes securely through ReffersPay strictly as an end-to-end encrypted passthrough payload to the NPCI and UIDAI Central Identities Data Repository (CIDR) for biometric match verification.
4 100% In-Country RBI Data Localization Mandate
In strict adherence to the Reserve Bank of India directive on Storage of Payment System Data (DPSS.CO.OD.No.2785/06.08.005/2017-18):
- All end-to-end payment transaction logs, user identifiers, account data, settlement ledgers, and system telemetry reside exclusively on MeitY-empanelled Tier-IV datacenters located within the sovereign borders of India (Mumbai and Hyderabad regions).
- No cross-border transmission, cloud mirroring, or foreign storage of Indian financial customer data is permitted or practiced.
- All database backups and disaster recovery clusters are maintained strictly within the Republic of India.
5 Purpose of Data Processing & Legal Grounds
We process data only under recognized legal grounds under the DPDP Act 2023, including user consent and compliance with statutory mandates:
6 Information Sharing & Statutory Disclosures
ReffersPay will never sell, rent, or lease your personal data to third parties for marketing purposes. Disclosures are strictly limited to authorized ecosystem partners:
- Sponsor & Settlement Partner Banks: (e.g., ICICI Bank, State Bank of India, Axis Bank, Yes Bank) for clearing, settlements, and nodal escrow management.
- Clearing Houses & Networks: National Payments Corporation of India (NPCI) for AePS, UPI, and Bharat BillPay (BBPS).
- Regulatory & Judicial Bodies: Reserve Bank of India (RBI), law enforcement agencies, cyber cells, and courts upon receipt of lawful summons or statutory orders.
7 Cryptographic Standards & PCI-DSS Level 1
ReffersPay maintains bank-grade cybersecurity defenses audited by CERT-In empanelled auditors:
8 Data Retention & Statutory PMLA Obligations
In accordance with Section 12 of the Prevention of Money Laundering Act (PMLA), 2002 and RBI KYC Master Directions, financial transaction logs and merchant identification records must be retained for a mandatory statutory period of ten (10) years from the date of cessation of the business relationship. Non-financial temporary logs are purged after 180 days.
9 Your Rights Under DPDP Act, 2023
As a Data Principal under the Digital Personal Data Protection Act, you possess clear statutory rights:
- Right to Access Information: Request an itemized summary of personal data being processed.
- Right to Correction & Erasure: Request updating of inaccurate data or deletion of data no longer required for statutory compliance.
- Right of Grievance Redressal: Direct complaints to our appointed Data Protection Officer and Grievance Officer.
- Right to Nominate: Designate a legal nominee to manage personal data rights in the event of death or incapacity.
10 Cookies & Telemetry
We utilize secure session cookies and telemetry strictly to authenticate merchant dashboard sessions, preserve your light/dark theme preference, and detect malicious brute-force attempts. We do not deploy third-party advertising cookies or cross-site tracking pixels.
11 Data Protection Officer (DPO) & Redressal
For inquiries, privacy grievances, or requests concerning your rights under the DPDP Act 2023, you may reach out directly to our appointed Data Protection Officer:
Designation: Data Protection Officer (DPO)
Office: ReffersPay FinCorp Private Limited, DLF Cyber City, Phase 2, Gurugram, HR 122002
Direct Privacy Email: dpo@refferspay.world
Direct Phone: +91 11 4982 9100 (Mon–Fri, 10:00 AM – 6:00 PM IST)
Review Related Financial Policies
Explore our transaction failure turnaround times & return policies.