Plain-language summary: We collect only what we need to operate our B2B payment infrastructure, process your transactions, and comply with RBI and NPCI regulations. We do not sell your data. Ever.
Overview
GujaratPe Private Limited ("GujaratPe", "we", "us", or "our") operates India's B2B fintech infrastructure, providing BBPS,Credit Card and related payment services to registered retailers, distributors, and partner organisations (collectively, "Business Partners").
This Privacy Policy explains how we collect, use, store, share, and protect personal data when you access our platform, APIs, dashboard, or website at GujaratPe.in. It applies to Business Partners, their authorised agents, end users served through our infrastructure, and visitors to our website.
We operate under the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and applicable RBI circulars governing payment system operators. By using GujaratPe services, you consent to the practices described here.
Data We Collect
2.1 Business Partner Data
When you register as a distributor, retailer, or API partner, we collect:
- Business name, registered address, and GSTIN
- Authorised signatory name, PAN, Aadhaar number (last 4 digits for verification), and photograph
- Bank account details for settlement and commission payouts
- Contact information: email, phone number, and correspondence address
- Device fingerprint, IP address, and browser metadata used during onboarding
2.2 Transaction Data
For every transaction processed through our infrastructure, we log:
- Transaction ID, amount, timestamp, and settlement status
- Service type ( BBPS, Credit Card, etc.)
- Beneficiary bank account or biller reference (masked in storage)
- Device and location metadata at the point of transaction
- API request and response payloads (sensitive fields encrypted at rest)
2.3 KYC Data
To comply with RBI's KYC norms, we collect and verify:
- Aadhaar-based eKYC data returned by UIDAI (demographic fields only; no biometrics stored)
- PAN card details validated via NSDL
- Shop/premises proof documents (utility bills, rental agreements)
- Liveness photographs captured during onboarding
2.4 Technical & Usage Data
- API call logs, endpoint access, and error codes
- Dashboard session data, page views, and feature usage
- Device type, OS, browser, and SDK version
- Cookies and similar tracking — see our Cookie Policy
How We Use It
We process personal data only for the following lawful purposes:
- Service delivery: Processing BBPS bill payments and all other financial transactions
- Regulatory compliance: Fulfilling RBI KYC norms, NPCI reporting obligations, PMLA/AML requirements, and UIDAI usage policies
- Account management: Onboarding, commission calculation, wallet management, and dispute resolution
- Security & fraud prevention: Detecting suspicious transactions, preventing identity fraud, and protecting the payment ecosystem
- Platform improvement: Analysing API performance, uptime monitoring, and product development (using aggregated, anonymised data)
- Communications: Transaction alerts, policy updates, downtime notices, and support responses
- Legal obligations: Responding to court orders, regulatory audits, and law enforcement requests
We never use your data for targeted advertising. We do not build behavioural profiles for marketing, sell data to third-party advertisers, or share your information with data brokers.
Sharing & Disclosure
We share data only in the circumstances below. In all cases, recipients are contractually bound to handle data in accordance with applicable law.
4.1 Payment Rails & Regulators
- NPCI — for BBPS, and IMPS transaction routing
- UIDAI — for Aadhaar-based authentication (biometric data never stored by us)
- NSDL — for PAN card verification
- Partner banks — for account credit, settlement, and beneficiary validation
- RBI and other regulators — on lawful requisition
4.2 Technology Sub-Processors
We engage vetted cloud and technology vendors who process data strictly on our documented instructions. A current list of sub-processors is available on request at support.gujaratpay@gmail.com.
4.3 Legal Disclosure
We may disclose data to law enforcement, courts, or government authorities when required by binding legal process, provided we give reasonable notice to affected parties where permitted by law.
4.4 Corporate Transactions
In the event of a merger, acquisition, or asset sale, data may be transferred to the successor entity, which will be bound by terms at least as protective as this Policy.
Retention
We retain data for the minimum period necessary to fulfil the purpose for which it was collected, subject to regulatory minimums:
- KYC documents: 5 years after account closure (PMLA requirement)
- Transaction records: 5 years from transaction date (RBI PSS Act)
- API logs: 90 days in hot storage, then archived for 1 year
- Marketing communications opt-outs: Indefinitely, to honour your preference
- Account data for active partners: Duration of the business relationship
On account termination, we anonymise or delete data that is not required to be retained under applicable law within 60 days of a verified deletion request.
Your Rights
Under the DPDP Act 2023 and applicable Indian law, you have the following rights with respect to your personal data:
- Right to access: Request a copy of the personal data we hold about you
- Right to correction: Ask us to correct inaccurate or incomplete data
- Right to erasure: Request deletion of data we no longer have a legal basis to hold
- Right to grievance redressal: Lodge a complaint with our Grievance Officer
- Right to nominate: Nominate another person to exercise rights on your behalf in the event of death or incapacity
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing
To exercise any right, write to support.gujaratpay@gmail.com. We will respond within 30 days. Identity verification may be required before we action certain requests.
Security
GujaratPe employs industry-standard technical and organisational safeguards:
- AES-256 encryption at rest for all sensitive data fields
- TLS 1.3 in transit across all API endpoints and dashboard connections
- Tokenisation of card and account numbers; raw PANs never stored
- Role-based access controls and audit logging for all internal data access
- Annual penetration testing and continuous vulnerability scanning
- ISO/IEC 27001-aligned information security management practices
In the event of a data breach that is likely to result in harm to you, we will notify affected parties and the relevant authority within the timelines prescribed by the DPDP Act.
Cross-Border Transfers
All payment transaction data and KYC data is stored exclusively on servers located within India, in compliance with RBI data localisation requirements under the Payment and Settlement Systems Act, 2007.
Certain operational data (analytics, support tooling) may be processed by sub-processors in jurisdictions approved by the Central Government under the DPDP Act. Such transfers are governed by standard contractual clauses or equivalent safeguards ensuring an equivalent level of protection.
Children
GujaratPe's services are directed exclusively at business entities and individuals aged 18 or above. We do not knowingly collect personal data from children under 18. If we become aware that data of a minor has been collected without appropriate consent, we will delete it promptly.
If you believe we have inadvertently collected information from a minor, please contact support.gujaratpay@gmail.com immediately.
Contact & DPO
For privacy questions, data requests, or to raise a complaint, contact our Data Protection Officer:
Data Protection Officer
GujaratPe Private Limited
Grievance & DPO Office
Email: support.gujaratpay@gmail.com
Response time: within 30 days of receipt
Regulatory Authority
If you are not satisfied with our response, you may escalate to the Data Protection Board of India once it is constituted under the DPDP Act 2023, or approach the appropriate consumer forum.
We reserve the right to update this Policy. Material changes will be communicated via registered email to active Business Partners at least 14 days before they take effect.