Privacy & Security

Privacy Policy

Learn how DadaPay collects, uses, stores, and protects your information while providing financial services.

Last Updated: May 07, 2025

Introduction

DadaPay ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our financial services platform, mobile application, and related services (collectively, the "Services").

By accessing or using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our Services.

This Privacy Policy applies to all users of DadaPay's Services, including individuals who register accounts, conduct transactions, or otherwise interact with our platform. We encourage you to read this policy carefully and contact us if you have any questions.

Information Provided by You

We collect information that you voluntarily provide to us when you register for an account, use our Services, or communicate with us. This includes:

  • Identity Information: Full name, date of birth, government-issued identification numbers (Aadhaar, PAN card), and passport or driver's license details.
  • Contact Information: Email address, phone number, and mailing address.
  • Financial Information: Bank account details, credit/debit card numbers, UPI IDs, transaction history, and income details required for KYC compliance.
  • Profile Information: Username, password, profile picture, and personal preferences.
  • Communication Data: Messages, support requests, feedback, and survey responses you send to us.
  • Business Information: For business account holders – company name, registration number, GST details, and authorized representative information.

You are responsible for ensuring that all information you provide is accurate, complete, and up to date. Inaccurate information may result in service interruptions or account suspension.

Information Obtained from Credit Information Companies

As a financial services provider, DadaPay may obtain information about you from Credit Information Companies (CICs) such as CIBIL, Experian, Equifax, and CRIF High Mark, in accordance with applicable laws and regulations. This information includes:

  • Credit score and credit history.
  • Existing loan and credit card details.
  • Payment history and defaults, if any.
  • Enquiry records and credit utilization patterns.

We use this information solely for the purpose of evaluating your creditworthiness, processing loan applications, setting credit limits, and managing financial risk. By using our lending or credit services, you authorize DadaPay to access your credit information from authorized CICs.

All access to credit information is conducted in strict compliance with the Credit Information Companies (Regulation) Act, 2005, and the Reserve Bank of India's guidelines.

Information Automatically Collected

When you use our Services, we automatically collect certain information through technical means, including:

  • Device Information: Device type, operating system, unique device identifiers, hardware model, and mobile network information.
  • Usage Data: Pages visited, features used, time spent on the platform, click patterns, and navigation paths.
  • Location Data: GPS coordinates, IP address-based location, and network-based location (with your permission).
  • Transaction Metadata: Transaction timestamps, IP addresses, device fingerprints, and geolocation at the time of transactions.
  • Performance Data: App crashes, system activity, error reports, and diagnostic information.

This automatically collected information helps us improve our Services, detect fraudulent activities, ensure security, and personalize your experience. You can control certain types of automatic data collection through your device settings.

Use of Personal Information

DadaPay uses the personal information we collect for the following purposes:

  1. Service Delivery: To create and manage your account, process transactions, and provide customer support.
  2. Compliance & Verification: To comply with KYC/AML regulations, verify your identity, and fulfill legal obligations.
  3. Security & Fraud Prevention: To detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal activities.
  4. Personalization: To tailor our Services, content, and offers based on your preferences and usage patterns.
  5. Communication: To send you transaction alerts, account updates, promotional offers, and important notices.
  6. Analytics & Improvement: To analyze usage trends, conduct research, and improve the functionality and user experience of our Services.
  7. Legal Compliance: To meet our obligations under applicable laws, regulations, and court orders.
  8. Business Operations: For internal purposes such as auditing, data analysis, and administration.

Information Sharing

We do not sell your personal information to third parties. We may share your information in the following limited circumstances:

  • Financial Partners: Banks, payment networks, card issuers, and other financial institutions involved in processing your transactions.
  • Regulatory Authorities: Reserve Bank of India (RBI), Financial Intelligence Unit (FIU), SEBI, and other government agencies as required by law.
  • Service Providers: Technology partners, cloud service providers, KYC verification agencies, and analytics vendors who assist in operating our Services under strict confidentiality obligations.
  • Credit Bureaus: Reporting of credit-related information to authorized Credit Information Companies as mandated by law.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction, subject to equivalent privacy protections.
  • Legal Requirements: When required to comply with applicable law, legal process, court orders, or to protect the rights, property, or safety of DadaPay, our users, or the public.

Any third parties with whom we share your information are contractually obligated to maintain the confidentiality and security of your data and are prohibited from using it for any other purpose.

Information Security

DadaPay employs robust security measures to protect your personal and financial information from unauthorized access, disclosure, alteration, or destruction:

  • Encryption: All data transmitted between your device and our servers is protected using industry-standard TLS/SSL encryption. Sensitive data at rest is encrypted using AES-256 encryption.
  • Access Controls: Strict role-based access controls ensure that only authorized personnel can access your data, on a need-to-know basis.
  • Security Audits: Regular third-party security audits, penetration testing, and vulnerability assessments are conducted to identify and remediate risks.
  • Multi-Factor Authentication: We use multi-factor authentication (MFA) to prevent unauthorized access to accounts.
  • Incident Response: We maintain a comprehensive incident response plan to address security breaches swiftly and notify affected users as required by law.

While we strive to protect your information, no method of transmission over the Internet or method of electronic storage is 100% secure. We encourage you to use strong passwords, enable biometric authentication, and keep your device software updated.

Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law:

  • Account Data: Retained for the duration of your account and for 5 years after account closure, as required by RBI and PMLA regulations.
  • Transaction Records: Maintained for a minimum of 10 years in compliance with anti-money laundering and financial recordkeeping laws.
  • KYC Documents: Stored for a minimum of 5 years after the business relationship ends, as mandated by the Prevention of Money Laundering Act (PMLA).
  • Communication Records: Customer support interactions and communications are retained for 3 years.
  • Log Data: System and access logs are retained for up to 1 year for security and operational purposes.

After the applicable retention period, your data is securely deleted or anonymized in accordance with our data disposal procedures.

Log Files

Like many digital services, DadaPay uses log files to track activity on our platform. Log files record the following types of information:

  • Internet Protocol (IP) addresses.
  • Browser type and version.
  • Internet Service Provider (ISP).
  • Referring and exit pages.
  • Date and time stamps of user activity.
  • Number of clicks and navigation paths.
  • Device and operating system information.

This information is not linked to personally identifiable information and is used for administering the platform, analyzing trends, tracking user movements, and gathering aggregate demographic information. Log data helps us identify technical issues, improve performance, and detect potential security threats.

Log files are stored securely and access is restricted to authorized technical personnel only. Log data is retained for a period of 12 months, after which it is securely deleted.

Confidentiality of Your Account

You are responsible for maintaining the confidentiality of your DadaPay account credentials, including your username, password, PIN, and OTPs (One-Time Passwords).

Important security guidelines to protect your account:

  • Never share your password, PIN, or OTP with anyone, including DadaPay representatives. DadaPay will never ask for your password or OTP via phone, email, or SMS.
  • Use a strong, unique password that is not used for other online accounts.
  • Enable biometric authentication (fingerprint/face recognition) for additional security.
  • Log out of your account when using shared or public devices.
  • Regularly review your transaction history and report any unauthorized activity immediately.
  • Keep your registered mobile number and email address up to date for receiving security alerts.

DadaPay shall not be liable for any loss or damage arising from your failure to maintain the confidentiality of your account credentials. If you suspect your account has been compromised, contact our support team immediately at info@dadapay.in.

Cookies and Tracking Technologies

DadaPay uses cookies and similar tracking technologies to enhance your experience, analyze usage patterns, and deliver personalized content. The types of cookies we use include:

  • Essential Cookies: Necessary for the platform to function properly, enabling core features like secure login, session management, and fraud prevention.
  • Performance Cookies: Help us understand how users interact with our platform by collecting anonymized usage data and performance metrics.
  • Functionality Cookies: Remember your preferences, settings, and choices to provide a personalized experience.
  • Analytics Cookies: Used to analyze user behavior, track conversion rates, and improve our Services through tools like Google Analytics.

You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of our Services. By continuing to use DadaPay, you consent to our use of cookies as described in this policy.

Grievance Redressal Policy

DadaPay is committed to addressing your privacy concerns promptly and effectively. If you have any grievances regarding the collection, use, or processing of your personal information, you may contact our Grievance Officer:

  • Name: Grievance Officer, DadaPay
  • Email: info@dadapay.in
  • Response Time: We will acknowledge your complaint within 48 hours and resolve it within 30 days.

If your complaint is not resolved to your satisfaction, you may escalate it to the relevant regulatory authorities, including the Reserve Bank of India's Banking Ombudsman Scheme or the Ombudsman for Digital Transactions.

You also have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of your personal information (subject to legal retention requirements).
  • Withdraw consent for processing activities where consent is the legal basis.
  • Lodge a complaint with the relevant data protection authority.

Changes to this Privacy Policy

DadaPay reserves the right to update or modify this Privacy Policy at any time. We will notify you of any material changes through the following means:

  • A prominent notice on the DadaPay app or website.
  • An email notification to your registered email address.
  • An in-app notification or push message.

The updated Privacy Policy will take effect on the date specified in the notice. Your continued use of our Services after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. If you do not agree with any changes, you should discontinue use of our Services and may request deletion of your account.

For historical versions of this Privacy Policy, please contact us at info@dadapay.in.