Privacy Policy
We are committed to protecting your privacy and the privacy of your customers. This policy explains exactly what data we collect, why we collect it, and how we keep it safe.
Overview
Code Crafts Digisoft Pvt. Ltd. ("we", "our", or "us") operates a B2B financial technology platform that enables partners — retailers, distributors, and API integrators — to offer banking, payment, and remittance services across India.
This Privacy Policy applies to:
- Our registered partners and their authorised users who access the platform.
- End-customers whose transaction data is processed through our platform on behalf of partners.
- Visitors to our website at codecraftsdigisoft.com.
Under India's Digital Personal Data Protection Act 2023 (DPDPA), Code Crafts Digisoft acts as a "Data Fiduciary" for partner data and a "Data Processor" for end-customer data processed on behalf of partners. Partners remain the Data Fiduciary for their customers' data.
Data We Collect
We collect the following categories of personal and business data:
| Category | Examples | Source |
|---|---|---|
| Partner Identity | Business name, owner name, PAN, GSTIN, Aadhaar (masked) | Provided by partner during KYC |
| Contact Data | Email, mobile number, registered address, office address | Provided by partner |
| Financial Data | Bank account details, IFSC code, wallet balance, transaction history | Provided & generated through use |
| End-Customer Data | Mobile number, Aadhaar number (encrypted), account number, transaction amount | Transmitted via API during transaction |
| Device & Usage | IP address, device fingerprint, browser type, API endpoint calls, timestamps | Automatically collected |
| Communications | Support tickets, chat messages, emails, call recordings (with consent) | Generated during support interactions |
We do not collect full Aadhaar numbers. Only the last 4 digits are stored where required for transaction reference. Full biometric data (fingerprints) is never stored by us — it is processed in real-time by UIDAI's authentication servers.
How We Use Your Data
We use the data we collect for the following purposes:
- Platform Operations: Processing transactions, settlement of commissions, generating reports, and providing dashboard analytics.
- KYC & Compliance: Verifying partner identity, conducting due diligence, and fulfilling regulatory reporting obligations under RBI, NPCI, and UIDAI guidelines.
- Fraud Prevention: Detecting unusual patterns, flagging suspicious transactions, and preventing financial crime.
- Customer Support: Responding to queries, resolving disputes, and improving service quality.
- Security: Protecting platform integrity through authentication, access controls, and intrusion detection.
- Communications: Sending transaction alerts, settlement notifications, product updates, and promotional communications (with consent where required).
- Product Improvement: Analysing aggregated usage patterns to improve platform features and performance. This analysis is always performed on anonymised or pseudonymised data.
- Legal Obligations: Maintaining records as required by law and responding to lawful requests from regulatory authorities.
We do not use your data for automated decision-making that produces legal or similarly significant effects without human review.
Legal Basis for Processing
We process personal data on the following legal bases under applicable Indian and international data protection law:
- Contract Performance: Processing necessary to fulfill our obligations under the Partner Agreement, including transaction processing and settlement.
- Legal Obligation: Processing required to comply with applicable laws including PMLA, RBI directions, UIDAI regulations, and tax laws.
- Legitimate Interests: Fraud prevention, platform security, and improving our services — where these interests are not overridden by your rights.
- Consent: Marketing communications and optional analytics features. You may withdraw consent at any time without affecting prior processing.
Financial account data and transaction records are classified as sensitive personal data under IT (Reasonable Security Practices) Rules 2011. We apply enhanced security controls and access restrictions for such data.
Data Sharing & Disclosure
We share your data only in the following circumstances and with the following categories of recipients:
- Banking Partners: Data is shared with our empanelled banks and Business Correspondent networks strictly to process transactions you initiate. Banks are bound by RBI data protection guidelines.
- NPCI / UIDAI: Transaction data is transmitted to NPCI for IMPS, BBPS, and UPI processing, and to UIDAI for Aadhaar authentication. Both are statutory bodies with their own data protection obligations.
- Technology Sub-processors: We use cloud infrastructure providers, SMS gateways, and analytics tools that may process limited data on our behalf. All sub-processors are contractually bound to our data protection standards and process data only on our instructions.
- Regulatory Authorities: We will disclose data to the RBI, UIDAI, NPCI, income tax authorities, FIU-IND, or any other lawful authority upon receipt of a valid legal direction.
- Audit & Legal: Our statutory auditors and legal advisors may access data strictly under professional privilege obligations.
We do not sell, rent, or trade your personal data or your customers' data to any third party for commercial purposes. Ever. This is a core commitment of Code Crafts Digisoft.
Cross-border transfers: All data is stored and processed within India. We do not transfer personal data outside India unless required by applicable law and with appropriate safeguards in place.
Aadhaar & Biometric Data
Our AEPS, Aadhaar Pay, and cash deposit services use Aadhaar-based biometric authentication. We treat this data with the highest level of sensitivity:
- Biometric data (fingerprints) is captured at the Point of Sale device and transmitted directly to UIDAI's authentication servers over encrypted channels. We never store biometric data on our servers.
- Aadhaar numbers transmitted through our API are encrypted using AES-256 encryption at the source and are masked (showing only the last 4 digits) in all logs and records.
- Aadhaar authentication is performed solely for the purpose of the financial transaction requested and for no other purpose.
- We comply strictly with the Aadhaar Act 2016 and all UIDAI circulars governing AUA/KUA usage.
- Any attempt to use our platform to harvest, store, or misuse Aadhaar data will result in immediate termination and referral to UIDAI and law enforcement.
Unauthorised collection, storage, or use of Aadhaar data is a criminal offence punishable under Section 29 of the Aadhaar Act 2016, with imprisonment of up to 3 years and fines up to ₹10 lakh. Partners misusing Aadhaar data through our platform will face immediate legal action.
Cookies & Tracking Technologies
Our website and partner dashboard use cookies and similar technologies for the following purposes:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Session management, authentication, CSRF protection | Session / 24 hours |
| Functional | Remembering preferences, language settings, dashboard layout | 30 days |
| Analytics | Understanding which features are used (aggregated, anonymised) | 90 days |
| Marketing | Showing relevant content on our website (only with consent) | 90 days |
Essential cookies cannot be disabled as they are required for the platform to function. For all other cookies, you can manage your preferences through your browser settings or our cookie consent banner.
Our APIs do not use cookies. API authentication is handled exclusively through API keys and JWT tokens transmitted in request headers.
Data Security
We implement bank-grade security controls to protect your data:
- Encryption in Transit: All data transmitted between your systems and ours uses TLS 1.2 or higher. API endpoints enforce HTTPS exclusively.
- Encryption at Rest: Sensitive fields in our database are encrypted using AES-256. Database-level encryption is also applied.
- Access Control: Data access follows the principle of least privilege. Staff access to production data requires multi-factor authentication and is logged and audited.
- Vulnerability Management: We conduct regular penetration testing and vulnerability assessments. Critical vulnerabilities are patched within 24 hours of discovery.
- Data Segregation: Partner data is logically segregated. Your data is never accessible to other partners.
- Incident Response: We maintain a documented incident response plan. In case of a data breach affecting you, we will notify you within 72 hours of discovery as required by applicable law.
If you discover a security vulnerability in our platform, please report it responsibly to [email protected]. We commit to acknowledging all reports within 24 hours and working with you to resolve valid vulnerabilities promptly.
Data Retention
We retain data for the minimum period necessary to fulfill the purposes described in this policy, comply with legal obligations, and resolve disputes:
| Data Type | Retention Period | Basis |
|---|---|---|
| Transaction Records | 10 years from transaction date | PMLA 2002, RBI guidelines |
| KYC Documents | 5 years after account closure | PMLA 2002 |
| Partner Account Data | Duration of partnership + 5 years | Legal obligation & disputes |
| Support Communications | 3 years | Legitimate interests |
| API Access Logs | 2 years | Security & fraud investigation |
| Website Analytics | 90 days (aggregated) | Legitimate interests |
| Marketing Preferences | Until consent withdrawn + 30 days | Consent |
After the applicable retention period, data is securely deleted or anonymised using industry-standard methods. You may request early deletion of data not subject to mandatory retention obligations — see Your Rights below.
Your Data Rights
Under applicable Indian data protection law and where relevant, GDPR, you have the following rights with respect to your personal data:
- Right to Access: Request a copy of the personal data we hold about you and information about how it is used.
- Right to Correction: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to legal retention obligations.
- Right to Data Portability: Request your data in a machine-readable format where technically feasible.
- Right to Object: Object to processing of your data for marketing or where we rely on legitimate interests, subject to our overriding legitimate grounds.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time. Withdrawal does not affect prior processing.
- Right to Lodge a Complaint: File a complaint with the Data Protection Board of India once constituted, or with CERT-In for cybersecurity-related concerns.
To exercise any of these rights, email [email protected] with "Data Rights Request" in the subject line. We will respond within 30 days. We may need to verify your identity before processing your request.
Certain data cannot be deleted due to mandatory regulatory retention requirements (see Retention section). We will always tell you if a deletion request cannot be fully honoured and the reason why.
Children's Privacy
Our platform is a B2B service intended solely for registered business entities and their adult representatives. We do not knowingly collect personal data from individuals under the age of 18.
If you believe we have inadvertently collected data from a minor, please contact us immediately at [email protected] and we will delete it promptly.
Partners must not process transactions on behalf of minors and must ensure their agent networks comply with age verification requirements.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Send a notification to your registered email address for significant changes.
- Display a prominent notice on the partner dashboard for 30 days after a significant update.
Your continued use of the platform after changes take effect constitutes acceptance of the revised policy. If you disagree with a material change, you may terminate your partnership in accordance with the Terms & Conditions.
Contact & Grievance Officer
For any privacy-related queries, data rights requests, or concerns, please contact us:
- Privacy Email:[email protected]
- Address: 409, 4th floor, Shipra Path, Mansarovar, Jaipur Rajasthan, India - 302020
As mandated under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, we have appointed a Grievance Officer. Privacy complaints must be acknowledged within 24 hours and resolved within 15 days of receipt. Contact details are available on our Contact page.
We take every privacy concern seriously. Our goal is not just legal compliance but genuine respect for the trust you and your customers place in us.
Your privacy is our priority.
Have questions about how we handle your data? Our privacy team responds within 24 hours — always.