Privacy policy
Updated 16th April 2024
This policy applies to PhonePe Private Limited a company incorporated under the Companies Act, 1956 with its registered office at Office-2, Floor 5, Wing A, Block A, Salarpuria Softzone, Bellandur Village, Varthur Hobli, Outer Ring Road, Bangalore South, Bangalore, Karnataka, India, 560103, and its Entities/Subsidiaries including but not limited to PhonePe Private Limited, PhonePe Insurance Broking Services Private Limited, PhonePe Wealth Broking Private Limited, PhonePe Lending Services Private Limited (Formerly known as “PhonePe Credit Services Private Limited” and “Explorium Innovative Technologies Private Limited”), PhonePe Technology Services Private Limited (“PhonePe AA”), Pincode Shopping Solutions Private Limited (Formerly known as “PhonePe Shopping Solutions Private Limited” and “PhonePe Payment Technology Services Private Limited”), Wealth Technology & Services Private Limited (collectively “PhonePe”, “we”, “our”, or “us” as the context may require).
This policy describes how PhonePe collects, stores, uses and otherwise processes your Personal Information through PhonePe websites, PhonePe Applications, m-sites, chatbots, notifications or any other medium used by PhonePe to provide its services to you (hereinafter referred to as the “Platform”). By visiting, downloading, using PhonePe Platform, and/or, providing your information or availing our product/services, you expressly agree to be bound by this Privacy Policy (“Policy”) and the applicable service/product terms and conditions. We value the trust you place in us and respect your privacy, maintaining the highest standards for secure transactions and protection of your personal information.
This Privacy Policy is published and shall be construed in accordance with the provisions of Indian laws and regulations including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 under the Information Technology Act, 2000, the Aadhaar Act, 2016 and its Amendments, including the Aadhaar Regulations; that require publishing of the privacy policy for collection, use, storage, transfer, disclosure of Personal Information. Personal Information means and includes all information that can be linked to a specific individual and also includes Sensitive Personal Information (all Personal Information which requires heightened data protection measures due to its sensitive and personal nature), both, hereinafter referred to as “Personal Information”, excluding any information that is freely available or accessible in public domain. Please note, Our products/services are offered in India for Indian customers, and your Personal Information processing will be subject to Indian laws. If you do not agree with this Privacy Policy, please do not use or access our Platform.
Information Collection
We may collect your Personal Information when you use our services or Platform or otherwise interact with us during the course of our relationship. We collect Personal Information which is relevant and absolutely necessary for providing the services requested by you and to continually improve the PhonePe Platform.
Personal and Sensitive Personal Information collected, as applicable, includes, but are not limited to:
- name, age, gender, photo, address, phone number, e-mail id, your contacts, nominee details
- KYC-related information such as PAN, income details, your business-related information, videos or other online/ offline verification documents as mandated by relevant regulatory authorities.
- Aadhaar information including Aadhaar number or Virtual ID for the purposes of e-KYC authentication with the Unique Identification Authority of India (UIDAI). Note that submission of Aadhaar information is not mandatory and there are alternatives to submission of identity information (e.g., Voter ID, DL)
- OTP sent to you by your bank, NSDL or PhonePe
- balance including broker ledger balance or margins, transaction history and value, bank account details, wallet balance, investment details and transactions, income range, expense range, investment goals, service or transaction related communication, order details, service fulfilment details, part of your card details for smooth transaction using PhonePe or any of the services
- your device details such as device identifier, internet bandwidth, mobile device model, browser plug-ins, and cookies or similar technologies that may identify your browser/PhonePe Applications and plug-ins, and time spent, IP address and location
- your Short Messaging Service (SMS(es)) that are stored on your device for the purposes of, including but not limited to, registering you and your device for payments or investment services, OTPs for logins and payments, enhancing your security, bill payments and recharge reminders, and any other legitimate uses with your explicit consent
- your health and lifestyle-related information, including your physical activity, when you opt for health-tracking services
Information may be collected at various stages of your usage of the PhonePe Platform such as:
- visiting PhonePe Platform
- registering on PhonePe Platform as an “user” or “merchant” or any other relationship that may be governed by terms and conditions listed on PhonePe Platform
- transacting or attempting to transact on PhonePe Platform
- accessing links, e-mails, chat conversations, feedbacks, notifications sent or owned by PhonePe Platform and if you opt to participate in our occasional surveys
- otherwise dealing with any of the PhonePe Entities/Subsidiaries
- while applying for career opportunities with PhonePe
We and our service providers or business partners may also collect your Personal Information from third parties or information made publicly available, as applicable, including but not limited to:
- financial history and other information for the purpose of providing you PhonePe services, verifying and authenticating an investment transaction request you place with us to prevent suspicious transactions, or to comply with court judgements and bankruptcies, from credit reference and fraud prevention agencies.
- vehicle-related information
- your resume, your past employment and educational qualification for background checks and verifications, through online or offline databases that are otherwise legitimately obtained in case you apply for employment opportunities with PhonePe
- your demographic and photo information including but not limited to Aadhaar number, address, gender, and date of birth as a response received from UIDAI upon successful Aadhaar e-KYC
Purpose and Use of Information
PhonePe may process your Personal Information for the following purposes:
- creation of your account and verification of your identity and access privileges
- provide you access to the products and services being offered by us, merchants, registered investment advisors, research analysts, entities, subsidiaries, sellers, logistic partners, or business partners
- fulfill your service request
- to conduct the KYC compliance process as a mandatory prerequisite as per the requirements of various regulatory bodies, including UIDAI under the Aadhaar Act and its Regulations
- to validate, process and/or share your KYC information, nominee details with other intermediaries, Regulated Entities (REs) or AMCs or financial institutions or with any other service providers as may be required
- to process payments on your behalf and on your instructions; communicate with you for your queries, transactions, and/or any other regulatory requirement, etc.
- to facilitate the offer of services and enable communications to you by WealthBasket curators for purchase and sale transactions of Wealthbaskets by you
- to authenticate a transaction request; validate a standing instruction for a Systematic Investment Plan or confirm a payment made via the services
- enhancing your user experience in various processes/submission of applications/availment of product/service offerings by analysing user behaviour on an aggregated basis
- to monitor and review products/services from time to time; customize the services to make your experience safer and easier, and conducting audits
- to allow third parties to contact you for products and services availed/requested by you on PhonePe Platform or third-party links
- to carry out credit checks, screenings or due diligence checks as lawfully required by us and detect and protect us against error, fraud, money laundering and other criminal activity
- enforce our terms and conditions
- to inform you about online and offline offers, products, services, and updates; customizing and improving your experience by marketing, presenting advertising, and offering tailored products and offers
- to resolve disputes; troubleshoot problems; technical support and fixing bugs; help promote a safe service
- to identify security breaches and attacks; investigating, preventing, and taking action on illegal or suspected fraud or money laundering activities and conducting forensic audits as part of internal or external audit or investigation by PhonePe or government agencies located within India or outside the Indian jurisdiction
- to meet legal obligations
While we may also process your Personal Information for other legitimate business cases, we ensure to take appropriate steps to minimize the processing to the extent possible, making it less intrusive to your privacy.
Please note that when providing you with account aggregator services, we do not store, use, process, or have access to any financial information that you choose to transmit under our services.
Cookies or Similar Technologies
We use data collection devices such as “cookies” or similar technologies on certain pages of the Platform to help analyse our web page flow, measure promotional effectiveness, and promote trust and safety. “Cookies” are small files placed on your device hard-drive/storage that assist us in providing our services. Cookies do not contain any of your Personal Information. We offer certain features that are only available through the use of a “cookie” or similar technologies. We also use cookies to allow you to enter your password less frequently during a session. Cookies or similar technologies can also help us provide information that is targeted to your interests. Most cookies are “session cookies,” meaning that they are automatically deleted from your device hard-drive/storage at the end of a session. You are always free to decline/delete our cookies or similar technologies if your browser/device permits, although in that case you may not be able to use certain features on the Platform and you may be required to re-enter your password more frequently during a session. Additionally, you may encounter “cookies” or other similar technologies on certain pages of the Platform that are placed by third parties. We do not control the use of cookies by third parties.
Information Sharing and Disclosures
Your Personal Information is shared as allowed under applicable laws, after following due diligence and in line with the purposes set out in this Policy.
We may share your Personal Information with different categories of recipients such as business partners, service providers, sellers, logistic partners, merchants, Wealthbasket curators, entities, subsidiaries, legally recognized authorities, regulatory bodies, governmental authorities, financial institutions, internal teams such as marketing, security, investigation team, etc.
Personal Information will be shared, as applicable, on need-to-know basis, for the following purposes, including but not limited to:
- for enabling the provision of the products/services availed by you and facilitating the services between you and the service provider, registered investment advisors, research analysts, sellers, logistic partners, as requested
- for the Aadhaar authentication process by submitting Aadhaar information to Central Identities Data Repository (CIDR) and National Securities Depository Limited (NSDL)
- for complying with applicable laws as well as meeting the Know Your Customer (KYC) requirements as mandated by various regulatory bodies, whose regulated service/product you opt through our services/Platforms
- for completing a payment transaction initiated by you on a merchant site, where based on your instructions, the merchant requests to fetch your Personal Information from us
- for the purpose of processing your financial product subscription requests placed with us and ensuring that these requests reach the relevant financial institution whose service/product you have opted for
- for enabling your lending journey by sharing information with authorized financial institutions with whom we partner to offer you credit-related products and services. We may also share your information with third parties under contract who assist us with our business operations, including enabling your KYC process, eligibility checks, collection services, and storage of such information, as required by our lending partners
- if it is required by financial institutions to verify, mitigate, or prevent fraud or to manage risk or recover funds in accordance with applicable laws/regulations
- for services related to communication, marketing, data and information storage, transmission, security, analytics, fraud detection, risk assessment and research
- enforce our Terms or Privacy Policy;
- respond to claims that an advertisement, posting, or other content violates the rights of a third party; or protect the rights, property or personal safety of our users or the general public
- if required to do so by law or in good faith we believe that such disclosure is reasonably necessary to respond to subpoenas, court orders, or other legal process
- if requested by government authorities for government initiatives and benefits
- for grievance redressal and resolution of disputes
- with the internal investigation department within PhonePe or agencies appointed by PhonePe for investigation purposes located within or outside the Indian jurisdiction
- should we (or our assets) plan to merge with, or be acquired by any business entity, or re-organization, amalgamation, restructuring of our business then with such other business entity
While the information is shared with third parties as per purposes set out in this Policy, processing of your Personal Information is governed by their policies. PhonePe ensures stricter or no less stringent privacy protection obligations are cast on these third-parties, wherever applicable and to the extent possible. However, PhonePe may share Personal Information with third-parties such as legally recognized authorities, regulatory bodies, governmental authorities, and financial institutions as per purposes set out in this Policy or as per applicable laws. We do not accept any responsibility or liability for usage of your Personal Information by these third parties or their policies.
Storage and Retention
To the extent applicable, we store Personal Information within India and retain it in accordance with applicable laws and for a period no longer than it is required for the purpose for which it was collected. However, we may retain Personal Information related to you if we believe it may be necessary to prevent fraud or future abuse or if required by law such as in the event of the pendency of any legal/regulatory proceeding or receipt of any legal and/or regulatory direction to that effect or for other legitimate purposes.
Once the Personal Information has reached its retention period, it shall be deleted in compliance with applicable laws.
Reasonable Security Practices
PhonePe has deployed administrative, technical, and physical security measures to safeguard user’s Personal Information and Sensitive Personal Information. Specifically, in order to safeguard your Aadhaar information, we have implemented applicable security controls as given under and required by the Aadhaar Regulations. We understand that as effective as our security measures are, no security system is impenetrable. Hence, as part of our reasonable security practices, we undergo strict internal and external reviews to ensure appropriate information security encryption or controls are placed for both data in motion and data at rest within our network and servers respectively. The database is stored on servers secured behind a firewall; access to the servers is password-protected and is strictly limited.
Further, you are responsible for maintaining the confidentiality and security of your login id and password. Please do not share your PhonePe login, password, and OTP details with anybody. It shall be your responsibility to intimate us in case of any actual or suspected compromise to your Personal Information.
We have provided multiple levels of security to safeguard the PhonePe Application by login/logout option and PhonePe Application lock feature (“Enable Screen Lock”) that can be enabled by you. We have preventive controls implemented to ensure you use PhonePe Application on your device and the same login credentials cannot be used on different device without any additional authentication/OTP.
Third-Party Products, Services, or Websites
When you are availing products and services of service providers on PhonePe Platform, Personal Information may be collected by respective service providers and such Personal Information shall be governed by their privacy policy. You may refer to their privacy policy and terms of service to understand how your Personal Information will be handled by such service providers.
Our services may include links to other websites or applications when you visit our Platform. Such websites or applications are governed by their respective privacy policies, which are beyond our control. Once you leave our servers (you can tell where you are by checking the URL in the location bar on your browser or on the m-site you are redirected to), use of any Personal Information that you provide on these websites or applications is governed by the privacy policy of the operator of the application/website, you are visiting. That policy may differ from ours and you are requested to review those policies or seek access to the policies from the domain owner before proceeding to use those applications or websites. We do not accept any responsibility or liability for usage of your Personal Information by these third parties or their policies.
Your Consent
We process your Personal Information with consent. By using the PhonePe Platform or services and/or by providing your Personal Information, you consent to the processing of your Personal Information by PhonePe in accordance with this Privacy Policy. If you disclose to us any Personal Information relating to other people, you represent that you have the authority to do so and permit us to use the information in accordance with this Privacy Policy. Further, you agree and authorize PhonePe to communicate with you via channels like Phone calls and E-mail for the purposes set out in this policy, irrespective of your registration with any authorized DND registries.
Choice/Opt-out
We provide all users with the opportunity to opt-out of receiving any of our services or non-essential (promotional, marketing-related) communications from us, after setting up an account. If you want to remove your contact information from all our lists and newsletters or discontinue any our services, please click on the unsubscribe button on the emailers.
In case you receive a call for any specific PhonePe product/service you may opt-out from such calls by informing PhonePe’s representative during the call.
Personal Information Access/Rectification and Consent
You can access and review your Personal Information shared by you by placing a request with us. In addition, you may at any time revoke consent given to us to store your e-KYC information, collected as part of the Aadhaar-based e-KYC process. Upon such revocation, you may lose access to services that were availed on the basis of the consent provided. In some cases, we may continue to retain your information as per the ‘Storage and Retention’ section of this Policy. To raise any of the above requests, you may write to us using the contact information provided under the ‘Contact Us’ section of this Policy.
In case you wish to delete your account or Personal Information, please use the ‘Help’ section of the PhonePe Platform. However, retention of your Personal Information will be subject to applicable laws.
For the above requests, PhonePe may need to request specific information from you to confirm your identity and ensure authentication. This is a security measure to ensure that Personal Information is not disclosed to any person who does not have a right to receive it or is not incorrectly modified or deleted.
In cases where you need any further information specific to the product/ services that you are availing, we request you to read through the Terms and Conditions specific to the product/service which is easily accessible through the PhonePe Platform. For seeking any further information on the same, you can write to us at the details mentioned in the ‘Contact Us’ section of this Policy.
Children Information
We do not knowingly solicit or collect Personal Information from children under the age of 18 and use of our Platform is available only to persons who can form a legally binding contract under the Indian Contract Act, 1872. If you are under the age of 18 years then you must use the Platform or services under the supervision of your parent, legal guardian, or any responsible adult.
Changes to Policy
Since our business changes constantly, so will our policies. We reserve the right, at our sole discretion, to change, modify, add, or remove portions of this Privacy Policy at any time without any prior written notice to you. We may, however, reasonably endeavour to notify you of the changes, it is your responsibility to review the Privacy Policy periodically for updates/changes. Your continued use of our services/Platform, following the posting of changes will mean that you accept and agree to the revisions. We will never make changes to policies in order to make it less protective of Personal Information already shared by you.
Contact Us
In case you have any questions, concerns, or complaints regarding the processing of your Personal Information or this Privacy Policy you may write to PhonePe’s Privacy Officer using this link https://support.phonepe.com We are committed to answer your questions within the reasonable time limit. Any delay in the resolution time shall be proactively communicated to you.