Pay4done

Privacy Policy

How Pay4done collects, uses and protects your information.

Last updated: 24 July 2026

1. Scope and consent

This Privacy Policy applies to retailers and customers who access the Pay4done website, retailer dashboard, or mobile app. It should be read together with our Terms & Conditions.

By registering, completing KYC, or transacting on Pay4done, you consent to the collection, storage and use of your information as described below.

2. Information we collect

Identity and KYC information: name, address, mobile number, PAN, Aadhaar number and photograph submitted during retailer or customer onboarding.

Biometric and Aadhaar data: fingerprint or iris scans captured through your Micro ATM/biometric device for AEPS and Aadhaar Pay authentication. This data is transmitted to NPCI/UIDAI for verification and is not stored by Pay4done beyond the authentication request.

Financial and transaction data: linked bank account details, wallet balance, transaction amounts, beneficiary details and settlement records.

Device and usage data: IP address, device identifiers, app version, log-in timestamps and cookies used on the website and dashboard.

3. How we use your information

To verify your identity, process DMT, AEPS, Aadhaar Pay, recharge, bill payment, Micro ATM and insurance transactions, and settle commission to retailers.

To detect and prevent fraud, comply with RBI/NPCI/UIDAI regulatory requirements, and respond to lawful requests from authorities.

To provide retailer support, send transaction alerts and service updates, and — where you have not opted out — share product or commission-slab updates.

4. How we share your information

With partner banks, NPCI, UIDAI and authorized service providers strictly to complete the transaction you initiate — this sharing is required for DMT, AEPS and Aadhaar Pay to function and cannot be opted out of while using those services.

With regulators or law enforcement when required by law, court order, or RBI directive.

Pay4done does not sell customer or retailer data to third parties for marketing purposes.

5. Data storage and security

Financial and personal data is stored on encrypted, access-controlled servers located in India, in line with RBI data localization requirements.

Payment pages use SSL/TLS encryption. Access to sensitive data is restricted to personnel on a need-to-know basis and is logged and periodically reviewed.

Biometric data captured for AEPS/Aadhaar Pay is encrypted at the device level before transmission and is not retained by Pay4done after authentication.

6. Data retention

KYC and transaction records are retained for the period mandated by RBI and applicable law (typically a minimum of 10 years from the transaction date), after which they are securely deleted or anonymized.

Data collected for a specific purpose (e.g. a support request) is retained only as long as needed to fulfil that purpose, unless a longer retention is legally required.

7. Cookies

The Pay4done website and dashboard use cookies to keep you signed in, remember preferences, and understand aggregate usage patterns. You can disable cookies in your browser, though some dashboard features may not work correctly without them.

8. Your rights and choices

You may opt out of promotional communications from your dashboard settings at any time; transactional alerts (OTPs, settlement notices) cannot be opted out of as they are necessary for the service.

You may request access to or correction of your KYC information by contacting Retailer Support. Deletion requests are honored only where retention is not otherwise required by RBI or law.

9. Children's data

Pay4done's services are intended for use by adults (18+) who can complete KYC. We do not knowingly collect data from minors.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified via the dashboard, SMS or email, and continued use of the platform after such notice constitutes acceptance.

11. Grievance officer and contact

For privacy-related questions, complaints, or data requests, contact our Grievance Officer at trovinaglobalpvtltd@gmail.com. Complaints are acknowledged within 48 hours and resolved, where possible, within 30 days.

Registered office: OFFICE No.605, BEST SKY TOWER, F-5, NETAJI SUBHASH PLACE, PITAMPURA DELHI-110034