Updated 9th February 2024
This policy applies to PhonePe Private Limited a company incorporated under the Companies Act, 1956 with its registered office at Office-2, Floor 5, Wing A, Block A, Salarpuria Softzone, Bellandur Village, Varthur Hobli, Outer Ring Road, Bangalore South, Bangalore, Karnataka, India, 560103, and its Entities/Subsidiaries including but not limited to PhonePe Private Limited, PhonePe Insurance Broking Services Private Limited, PhonePe Wealth Broking Private Limited, PhonePe Lending Services Private Limited (Formerly known as “PhonePe Credit Services Private Limited” and “Explorium Innovative Technologies Private Limited”), PhonePe Technology Services Private Limited (“PhonePe AA”), Pincode Shopping Solutions Private Limited (Formerly known as “PhonePe Shopping Solutions Private Limited” and “PhonePe Payment Technology Services Private Limited”), Wealth Technology & Services Private Limited (collectively “PhonePe”, “we”, “our”, or “us” as the context may require).
We may collect your Personal Information when you use our services or Platform or otherwise interact with us during the course of our relationship. We collect Personal Information which is relevant and absolutely necessary for providing the services requested by you and to continually improve the PhonePe Platform.
Personal and Sensitive Personal Information collected, as applicable, includes, but are not limited to:
- name, age, gender, photo, address, phone number, e-mail id, your contacts, nominee details
- KYC-related information such as PAN, income details, your business-related information, videos or other online/ offline verification documents as mandated by relevant regulatory authorities.
- Aadhaar information including Aadhaar number or Virtual ID for the purposes of e-KYC authentication with the Unique Identification Authority of India (UIDAI). Note that submission of Aadhaar information is not mandatory and there are alternatives to submission of identity information (e.g., Voter ID, DL)
- OTP sent to you by your bank, NSDL or PhonePe
- balance including broker ledger balance or margins, transaction history and value, bank account details, wallet balance, investment details and transactions, income range, expense range, investment goals, service or transaction related communication, order details, service fulfilment details, part of your card details for smooth transaction using PhonePe or any of the services
- your device details such as device identifier, internet bandwidth, mobile device model, browser plug-ins, and cookies or similar technologies that may identify your browser/PhonePe Applications and plug-ins, and time spent, IP address and location
- your Short Messaging Service (SMS(es)) that are stored on your device for the purposes of, including but not limited to, registering you and your device for payments or investment services, OTPs for logins and payments, enhancing your security, bill payments and recharge reminders, and any other legitimate uses with your explicit consent
Information may be collected at various stages of your usage of the PhonePe Platform such as:
- visiting PhonePe Platform
- registering on PhonePe Platform as an “user” or “merchant” or any other relationship that may be governed by terms and conditions listed on PhonePe Platform
- transacting or attempting to transact on PhonePe Platform
- accessing links, e-mails, chat conversations, feedbacks, notifications sent or owned by PhonePe Platform and if you opt to participate in our occasional surveys
- otherwise dealing with any of the PhonePe Entities/Subsidiaries
- while applying for career opportunities with PhonePe
We and our service providers or business partners may also collect your Personal Information from third parties or information made publicly available, as applicable, including but not limited to:
- financial history and other information for the purpose of providing you PhonePe services, verifying and authenticating an investment transaction request you place with us to prevent suspicious transactions, or to comply with court judgements and bankruptcies, from credit reference and fraud prevention agencies.
- vehicle-related information when you opt for vehicle insurance
- your resume, your past employment and educational qualification for background checks and verifications, through online or offline databases that are otherwise legitimately obtained in case you apply for employment opportunities with PhonePe
- your demographic and photo information including but not limited to Aadhaar number, address, gender, and date of birth as a response received from UIDAI upon successful Aadhaar e-KYC
Purpose and Use of Information
PhonePe may process your Personal Information for the following purposes:
- creation of your account and verification of your identity and access privileges
- provide you access to the products and services being offered by us, merchants, registered investment advisors, research analysts, entities, subsidiaries, sellers, logistic partners, or business partners
- fulfill your service request
- to conduct the KYC compliance process as a mandatory prerequisite as per the requirements of various regulatory bodies, including UIDAI under the Aadhaar Act and its Regulations
- to validate, process and/or share your KYC information, nominee details with other intermediaries, Regulated Entities (REs) or AMCs or financial institutions or with any other service providers as may be required
- to process payments on your behalf and on your instructions; communicate with you for your queries, transactions, and/or any other regulatory requirement, etc.
- to facilitate the offer of services and enable communications to you by WealthBasket curators for purchase and sale transactions of Wealthbaskets by you
- to authenticate a transaction request; validate a standing instruction for a Systematic Investment Plan or confirm a payment made via the services
- enhancing your user experience in various processes/submission of applications/availment of product/service offerings by analysing user behaviour on an aggregated basis
- to monitor and review products/services from time to time; customize the services to make your experience safer and easier, and conducting audits
- to allow third parties to contact you for products and services availed/requested by you on PhonePe Platform or third-party links
- to carry out credit checks, screenings or due diligence checks as lawfully required by us and detect and protect us against error, fraud, money laundering and other criminal activity
- enforce our terms and conditions
- to inform you about online and offline offers, products, services, and updates; customizing and improving your experience by marketing, presenting advertising, and offering tailored products and offers
- to resolve disputes; troubleshoot problems; technical support and fixing bugs; help promote a safe service
- to identify security breaches and attacks; investigating, preventing, and taking action on illegal or suspected fraud or money laundering activities and conducting forensic audits as part of internal or external audit or investigation by PhonePe or government agencies located within India or outside the Indian jurisdiction
- to meet legal obligations
While we may also process your Personal Information for other legitimate business cases, we ensure to take appropriate steps to minimize the processing to the extent possible, making it less intrusive to your privacy.
Please note that when providing you with account aggregator services, we do not store, use, process, or have access to any financial information that you choose to transmit under our services.
Information Sharing and Disclosures
Your Personal Information is shared as allowed under applicable laws, after following due diligence and in line with the purposes set out in this Policy.
We may share your Personal Information with different categories of recipients such as business partners, service providers, sellers, logistic partners, merchants, Wealthbasket curators, entities, subsidiaries, legally recognized authorities, regulatory bodies, governmental authorities, financial institutions, internal teams such as marketing, security, investigation team, etc.
Personal Information will be shared, as applicable, on need-to-know basis, for the following purposes, including but not limited to:
- for enabling the provision of the products/services availed by you and facilitating the services between you and the service provider, registered investment advisors, research analysts, sellers, logistic partners, as requested
- for the Aadhaar authentication process by submitting Aadhaar information to Central Identities Data Repository (CIDR) and National Securities Depository Limited (NSDL)
- for complying with applicable laws as well as meeting the Know Your Customer (KYC) requirements as mandated by various regulatory bodies, whose regulated service/product you opt through our services/Platforms
- for completing a payment transaction initiated by you on a merchant site, where based on your instructions, the merchant requests to fetch your Personal Information from us
- for the purpose of processing your financial product subscription requests placed with us and ensuring that these requests reach the relevant financial institution whose service/product you have opted for
- for enabling your lending journey by sharing information with authorized financial institutions with whom we partner to offer you credit-related products and services. We may also share your information with third parties under contract who assist us with our business operations, including enabling your KYC process, eligibility checks, collection services, and storage of such information, as required by our lending partners
- if it is required by financial institutions to verify, mitigate, or prevent fraud or to manage risk or recover funds in accordance with applicable laws/regulations
- for services related to communication, marketing, data and information storage, transmission, security, analytics, fraud detection, risk assessment and research
- respond to claims that an advertisement, posting, or other content violates the rights of a third party; or protect the rights, property or personal safety of our users or the general public
- if required to do so by law or in good faith we believe that such disclosure is reasonably necessary to respond to subpoenas, court orders, or other legal process
- if requested by government authorities for government initiatives and benefits
- for grievance redressal and resolution of disputes
- with the internal investigation department within PhonePe or agencies appointed by PhonePe for investigation purposes located within or outside the Indian jurisdiction
- should we (or our assets) plan to merge with, or be acquired by any business entity, or re-organization, amalgamation, restructuring of our business then with such other business entity
While the information is shared with third parties as per purposes set out in this Policy, processing of your Personal Information is governed by their policies. PhonePe ensures stricter or no less stringent privacy protection obligations are cast on these third-parties, wherever applicable and to the extent possible. However, PhonePe may share Personal Information with third-parties such as legally recognized authorities, regulatory bodies, governmental authorities, and financial institutions as per purposes set out in this Policy or as per applicable laws. We do not accept any responsibility or liability for usage of your Personal Information by these third parties or their policies.
Storage and Retention
To the extent applicable, we store Personal Information within India and retain it in accordance with applicable laws and for a period no longer than it is required for the purpose for which it was collected. However, we may retain Personal Information related to you if we believe it may be necessary to prevent fraud or future abuse or if required by law such as in the event of the pendency of any legal/regulatory proceeding or receipt of any legal and/or regulatory direction to that effect or for other legitimate purposes.
Once the Personal Information has reached its retention period, it shall be deleted in compliance with applicable laws.
Reasonable Security Practices
PhonePe has deployed administrative, technical, and physical security measures to safeguard user’s Personal Information and Sensitive Personal Information. Specifically, in order to safeguard your Aadhaar information, we have implemented applicable security controls as given under and required by the Aadhaar Regulations. We understand that as effective as our security measures are, no security system is impenetrable. Hence, as part of our reasonable security practices, we undergo strict internal and external reviews to ensure appropriate information security encryption or controls are placed for both data in motion and data at rest within our network and servers respectively. The database is stored on servers secured behind a firewall; access to the servers is password-protected and is strictly limited.
Further, you are responsible for maintaining the confidentiality and security of your login id and password. Please do not share your PhonePe login, password, and OTP details with anybody. It shall be your responsibility to intimate us in case of any actual or suspected compromise to your Personal Information.
We have provided multiple levels of security to safeguard the PhonePe Application by login/logout option and PhonePe Application lock feature (“Enable Screen Lock”) that can be enabled by you. We have preventive controls implemented to ensure you use PhonePe Application on your device and the same login credentials cannot be used on different device without any additional authentication/OTP.
Third-Party Products, Services, or Websites
We provide all users with the opportunity to opt-out of receiving any of our services or non-essential (promotional, marketing-related) communications from us, after setting up an account. If you want to remove your contact information from all our lists and newsletters or discontinue any our services, please click on the unsubscribe button on the emailers.
In case you receive a call for any specific PhonePe product/service you may opt-out from such calls by informing PhonePe’s representative during the call.
Personal Information Access/Rectification and Consent
You can access and review your Personal Information shared by you by placing a request with us. In addition, you may at any time revoke consent given to us to store your e-KYC information, collected as part of the Aadhaar-based e-KYC process. Upon such revocation, you may lose access to services that were availed on the basis of the consent provided. In some cases, we may continue to retain your information as per the ‘Storage and Retention’ section of this Policy. To raise any of the above requests, you may write to us using the contact information provided under the ‘Contact Us’ section of this Policy.
In case you wish to delete your account or Personal Information, please use the ‘Help’ section of the PhonePe Platform. However, retention of your Personal Information will be subject to applicable laws.
For the above requests, PhonePe may need to request specific information from you to confirm your identity and ensure authentication. This is a security measure to ensure that Personal Information is not disclosed to any person who does not have a right to receive it or is not incorrectly modified or deleted.
In cases where you need any further information specific to the product/ services that you are availing, we request you to read through the Terms and Conditions specific to the product/service which is easily accessible through the PhonePe Platform. For seeking any further information on the same, you can write to us at the details mentioned in the ‘Contact Us’ section of this Policy.
We do not knowingly solicit or collect Personal Information from children under the age of 18 and use of our Platform is available only to persons who can form a legally binding contract under the Indian Contract Act, 1872. If you are under the age of 18 years then you must use the Platform or services under the supervision of your parent, legal guardian, or any responsible adult.
Changes to Policy