1Overview
CashioPay Pvt. Ltd. ("CashioPay", "we", "us", "our") operates a B2B fintech platform that enables retail entrepreneurs to offer AEPS, BBPS, DMT, recharge, payout and travel booking services to their customers. This Privacy Policy explains what information we collect from partners, sub-agents and end customers, how we use it, and the choices available to you.
By registering as a CashioPay partner or using any service on our platform, you agree to the collection and use of information in accordance with this policy.
2Information we collect
Information you provide
- Name, mobile number, email address and residential/shop address during registration
- PAN, Aadhaar number and bank account details for KYC verification
- Business details such as shop name, GSTIN and trade licence, where applicable
- Customer transaction details entered while performing AEPS, BBPS, DMT, recharge, payout or travel bookings on behalf of your customers
Information collected automatically
- Device information (model, OS, unique device identifiers)
- IP address, approximate location and browser type
- App/dashboard usage logs, session duration and click events
- Transaction metadata (timestamps, amounts, service type, status)
3How we use your information
- To verify your identity and onboard you as a CashioPay retail partner
- To process AEPS, BBPS, DMT, recharge, payout and travel transactions and settle commissions
- To detect, investigate and prevent fraud, money laundering and unauthorised access
- To provide customer support and respond to service requests or complaints
- To comply with RBI, NPCI and other applicable regulatory reporting requirements
- To send transactional alerts, service updates and, where you've opted in, promotional communication
4Biometric & KYC data
Fingerprint or iris scans captured during AEPS cash-out are transmitted directly to NPCI/UIDAI-authorised systems for authentication and are not stored on CashioPay's servers beyond the duration required to complete the transaction. Aadhaar numbers used for e-KYC are masked and encrypted at rest, in line with UIDAI's Aadhaar Data Vault requirements.
7Data security
We use industry-standard measures including TLS encryption in transit, encryption at rest for sensitive fields, role-based access controls and periodic security audits. While we work to protect your information, no method of transmission or storage is 100% secure, and we encourage partners to safeguard their own login credentials and device access.
8Data retention
We retain transaction records and KYC information for the period mandated by RBI, NPCI and applicable Indian financial regulations (typically a minimum of 5–8 years from the date of transaction), after which the data is securely deleted or anonymised, unless a longer period is required for legal or dispute-resolution purposes.
9Your rights
Subject to applicable law, you may:
- Request a copy of the personal information we hold about you
- Ask us to correct inaccurate or outdated information
- Withdraw consent for optional/promotional communication at any time
- Request account closure, subject to completion of any pending settlements and regulatory record-keeping obligations
To exercise any of these rights, contact us using the details in Section 12.
10Children's privacy
CashioPay's services are intended for use by individuals aged 18 and above who are eligible to enter into a legally binding contract in India. We do not knowingly collect personal information from minors.
11Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be notified via email or an in-dashboard notice, and the "Last updated" date at the top of this page will be revised accordingly.