PRIVACY POLICY

This Privacy Policy (“Privacy Policy”) governs how Hiveloop E-Commerce Private limited (“HEPL” or “us” or “our”) through udaan pay mobile application (“Mobile Application”) processes, uses, collects, discloses, transfers, stores, and retains User’s (“Merchant”, “you” or “your”) information. HEPL recognizes the importance of privacy as well as the importance of maintaining the confidentiality of Personal Data (defined hereunder).

The Mobile Application enables the extension of certain services to the Users as specified in the Terms of Use. By downloading, and using the Mobile Application, and/or, providing your information for availing our services, you expressly agree to be bound by this Privacy Policy and the applicable Terms of Use. We value the trust you place in us and respect your privacy, maintaining the highest standards for secure transactions and protection of Personal Data (defined hereunder).

All capitalized terms not defined in this document shall have the meanings ascribed to them in the Terms of Use of the Mobile Application, which can be found here.

1. PERSONAL DATA AND PURPOSE OF COLLECTION

Personal data is information that enables us to identify any natural person (including you) or relates to an identified or identifiable natural person (“Personal Data”). We collect personal and financial data from you when you register, use, transact, or attempt to transact, and access links available on our Mobile Application, or interact with us through the Mobile Application. The Personal Data that may be collected at various stages of your usage of the Mobile Application are as follows:

Information Type Data Collected Purpose and Use

Personal Information

We will collect your full name, age, email address (optional), phone-number, and geographical location.

We will also collect details of your place of business which includes name, category, and address of the place of business.

For processing User’s registration as a user, providing User(s) with a log-in ID for the Mobile Application and maintaining and managing User’s registration;

For verifying User’s identity;

For providing User(s) with customer service and responding to User(s) queries, feedback, claims or disputes;

Subject to Applicable Laws, HEPL (including our affiliated companies and their designated Service Providers (defined hereunder) may use User’s name, phone number, address, email address, and other data (“Marketing Data”) to provide notices, surveys, product alerts, communications and other marketing materials to User(s) relating to products and services offered by HEPL or HEPL’s affiliated companies; and

Making such disclosures as may be required for any of the purposes mentioned herein or as required by law, regulations, and guidelines or in respect of any investigations, claims or potential claims brought on or against us or against third parties.

KYC Related Information

PAN, your business-related information, online/ offline verification documents.

Furthermore, we may also collect Aadhaar information including Aadhaar number or Virtual ID for the purposes of e-KYC authentication with the Unique Identification Authority of India (UIDAI).

Please note here that submission of Aadhaar information is not mandatory and there are alternatives to submission of identity information (e.g., Voter ID, Driving License, or any other Officially Valid Document as per RBI Guidelines.)

For verification as mandated by relevant regulatory authorities.

Financial Information

We will collect transaction history and value, bank account details, transaction related communication, and service fulfilment details.

We may share your information/information submitted by you to financial institutions and service providers such as payment processors, card issuers, collection service provider, NBFC partners and banking partners to facilitate transactions.

To help in tracking your payment;

Access to SMS

We will collect your Short Messaging Service (SMS (es)) that are stored on your device for the purposes of, including but not limited to, registering you and your device for payments services, and One Time Passwords (OTPs) for logins and payments, this also includes OTP sent to you by HEPL.

To help us give our services, verifying your phone number, enhancing your security, and/ or any other legitimate uses with your explicit consent.

Device Information

We will collect device details such as device identifier, SIM details, IP address, internet bandwidth, mobile device model, and cookies or similar technologies that may identify your Mobile Application, IP address and location.

To analyze device’s interaction with our services and to send promotional information. This information is used for purposes such as serving and rendering advertisements, personalizing advertisements, analysing our Mobile Application’s flow, measuring our promotional effectiveness and improves your experience of the Mobile Application as it allows us to enhance our products and services provided to you via the Mobile Application.

Demographic Information

We will collect IP Address, location and geolocation information from your device.

Please note that if you do not consent to collection of this information, certain services will not function properly, and you will not be able to use those services.

For processing of payment and verification of payment.

Log & Usage Information

We may collect data about how you interact with the services offered by Mobile Application. This includes data such as access dates and times, crashes and other system activity, and names of relevant third-party services used pursuant to interacting with our services.

To enable better functioning of the Mobile Application, for research and development, and prevent technical glitches etc.

Information collected for Third Party Analytics services

We may use third-party analytics services to collect information about how you use and interact with our Mobile Application. These services may use cookies to gather information about your usage. We use these analytics to understand how people use our app, to improve it, and to customize the content and features based on user interests. However, no personally identifiable information or payment-sensitive information is shared or used for such analytical purposes.

For performing research or statistical analysis in order to improve the content and layout of the Mobile Application, to improve HEPL’s product offerings and services and for marketing and promotional purposes.

In addition to the purposes outlined above, you may also voluntarily provide Personal Data to us (for instance, feedback). This is completely optional, and we will use this Personal Data in connection with the purpose for which it was collected, or to improve our products and services.

Moreover, to the extent that Personal Data you share with us is not your own (i.e., for example, you are a representative of an User of the Mobile Application, or are sharing information on behalf of an employer, representative, or family member), you warrant that you have the right to provide such Personal Data, and you and the business with which you are associated shall be fully responsible for any liability arising from any such use of Personal Data, including indemnifying HEPL for any loss.

If you share Personal Data with us that is not your own, you agree to inform such persons which may include your agents, employer, or any authorized personnel (e.g., contractors, partners, or authorized third parties): (i) that their Personal Data may be processed by us; and (ii) of their rights regarding the processing of their Personal Data in accordance with this Privacy Policy and the Applicable Laws.

To the extent possible, we provide you the option of not divulging any specific information that you wish for us not to collect, store or use. You may choose to opt out of any non-essential communications from HEPL by communicating the same to our Grievance Officer as per Paragraph 11. Depending on the particular product and/or service, some of the information we ask you to provide is identified as mandatory and some is identified as voluntary. If you do not provide the mandatory information for a particular product and/or service that requires it, you will not be permitted to avail such product and/or service.

Further, we may collect data that is not identifiable to you or otherwise associated with you, such as aggregated data, which is not Personal Data. We will not attempt to identify you from this data. To the extent this data is not identifiable or associated with any person it is not subject to this Privacy Policy.

2. LEGAL BASIS FOR PROCESSING PERSONAL DATA

We process your Personal Data for, or based on, one or more of the following legal bases:

  • Your Consent: We may process your Personal Data on the basis of your express consent. For instance, when you opt-in to receive our marketing and promotional materials, we process Personal Data to send messages to you about us and the products and services we offer. You can withdraw your consent at any time.
  • Legitimate Uses: We may use your Personal Data for certain legitimate uses, such as when you voluntarily provide us with Personal Data, or to ensure compliance with the law and other legal obligations, as well as to protect you and other individuals from certain harms.
3. DISCLOSURE OF USER DATA

We may share or disclose User Data only as permissible under Applicable Laws and as per terms of this Privacy Policy. We may share your personal information in the course of providing services and processing your transactions and other instructions with different persons and entities such as financial institutions, merchants, service providers, other entities participating in a payment system, business associates, government and regulatory authorities, consultants and internal departments. This sharing of User Data is on a need-to-know basis, such that:

  • User(s) further agrees that HEPL may disclose and transfer User(s) Data to third party service providers (including but not limited to data entry, database management, promotions, products and services alerts, delivery services, payment extension services, authentication and verification services) (“Service Providers”). These Service Providers are under a duty of confidentiality to HEPL and are only permitted to use User(s) Data in connection with the purposes specified in paragraph 1 herein above.
  • User(s) agree that HEPL may disclose and transfer User(s) Data to HEPL’s affiliated companies and/or their designated Service Providers.
  • When needed, HEPL may disclose User Data if required or permitted to do so by law, in the good faith belief that such action is reasonably necessary to comply with Applicable Law or to protect our rights, property, or safety of our employees, customers, or the public, or where the disclosure is otherwise appropriate due to safety or similar concerns. This includes sharing data with law enforcement officials, other government authorities, insurance companies, or other third parties as necessary.
  • When necessary HEPL may also disclose and transfer User(s) Data to our professional advisers.
  • Any User(s) Data supplied by User(s) will be accessible by our employees, Service Providers, and third parties, including without limitation, banks, financial institutions, credit agencies, or vendors to enable such third parties to offer their products or services to such Users.
  • HEPL may establish relationships with other parties and websites to offer User the benefit of products and services which HEPL does not offer. HEPL may offer you access to these other parties and/or their applications. This Privacy Policy does not apply to the products and services enabled or facilitated by such third-parties. The privacy policies of those other parties may differ from HEPL, and HEPL has no control over the information that User may submit to those third-parties. User should read the relevant privacy policy for those third parties before responding to and availing any offers, products or services advertised or provided by those third-parties.
  • We may also share your data other than as described where you consent to such sharing.
4. COOKIES

HEPL uses “cookies” to store specific information about User(s) and track User(s) visits to the Mobile Application. A “cookie is a small amount of data that is stored on User’s device. If User does not deactivate or erase the cookie, each time User uses the same device to access the Mobile Application, our services will be notified of User visit to the Mobile Application and in turn HEPL may have knowledge of User(s) visit and the pattern of User’s usage.

Generally, HEPL use cookies to identify User(s) and enable HEPL to:

  • access User’s registration information or account information so User(s) do not have to re-enter it;
  • gather statistical information about usage by Users(s);
  • research visiting patterns and help target advertisements based on User(s) interests;
  • assist HEPL’s partners to track User(s) visits to the Mobile Application; and
  • track progress and participation on the Mobile Application.

Please know, though, that if you choose to delete or block your cookies, you will lose the ability to save certain preferences, such as your username and password. If you delete or block your cookies, you will, for example, need to re-enter your log-in credentials to gain access to certain services under Mobile Application upon each visit.

5. MINORS

We do not knowingly collect, process, or store Personal Data of individuals under the age of 18 years. Our services are intended for use only by individuals who have attained the age of majority and are legally permitted to engage in financial transactions under Applicable Laws.

If we become aware that Personal Data of a minor has been collected without verifiable parental consent, we will take appropriate steps to delete such data.

Parents or legal guardians who believe that a minor has provided their Personal Data may contact us at details provided in Paragraph 11 to request deletion or exercise any other rights under Applicable Law.

Minors are advised not to use Mobile Application or provide any personal information. By accessing and using our services, you confirm that you are at least 18 years of age or have obtained parental/legal guardian consent where required.

6. USER RIGHTS

In accordance with Applicable Laws, you may be entitled to a variety of legal rights regarding the collection and processing of your Personal Data. You may exercise these rights, either directly through the functionalities provided on the Mobile Application or by contacting us as outlined in the section ‘Communication with Us and Grievance Officer’ at the end of this Privacy Policy. We may request certain additional information (that may include Personal Data) that may be reasonably required to authenticate your identity, your request, and/or to clarify or understand the scope of such requests. The rights available to Users include:

  • the right to know if we process your Personal Data and the purposes of processing;
  • the right to be informed about the Personal Data we collect and/or process about you;
  • the right to know the details of the persons with whom we have shared your Personal Data, including the Personal Data shared and the purposes of sharing your Personal Data;
  • the right to access, modify, update, complete, correct Personal Data about you;
  • the right to request for erasure of Personal Data;
  • in certain circumstances, the right to erasure and/or the right to be forgotten, which means that you can request deletion or removal of certain Personal Data we process about you;
  • where processing of Personal Data is based on consent, the right to withdraw your consent to such processing; and
  • right to nominate a person to exercise your rights hereunder in case of death or incapacity.
7. WITHDRAWAL OF CONSENT

HEPL takes all reasonable steps to ensure that User’s personal information is processed ‘as is’. You have an option to withdraw your consent that you have already provided by writing to us at the contact information provided under Paragraph 11. Please mention “for withdrawal of consent” in the subject line of your communication. HEPL will verify such requests before acting upon your request.

Please note, however, that withdrawal of consent will not be retroactive and will be in accordance with the terms of this Privacy Policy, related terms of use, and Applicable Laws. In the event you withdraw the consent given to us under this Privacy Policy, such withdrawal may hamper your access to the Mobile Application or restrict the provision of our services to you for which HEPL consider that information to be necessary.

8. RETENTION OF DATA

HEPL retains your personal information in accordance with Applicable Laws, for a period no longer than is required for the purpose for which it was collected or as required under any Applicable Law. However, HEPL may retain data related to you if it believes it may be necessary for the following reasons:

  • To prevent fraud or future abuse;
  • To respond to a question or complaint, or to show whether we gave you fair treatment;
  • To establish, exercise or defend our legal claims rights and/or defend against legal claims or if required by law or for other legitimate purposes;
  • To comply with legal rules that apply to us about keeping records or information in which case we will retain your data for a minimum of 3 (three) years after your account has been terminated or longer depending on Applicable Laws; and
  • HEPL may continue to retain your data in anonymised form for analytical and research purposes.
9. SECURITY MEASURES

HEPL employs commercially reasonable security methods to prevent unauthorized access to the Mobile Application, to maintain data accuracy and to ensure the correct use of the information HEPL holds. No data transmission over the internet or any wireless network can be guaranteed to be perfectly secure. As a result, while HEPL tries to protect the information HEPL holds, HEPL cannot guarantee the security of any information the User transmits to HEPL and User(s) do so at their own risk.

Our servers are located within the territory of India, where your data is stored securely.

The Mobile Application intends to protect your Personal Data to maintain its accuracy as confirmed by you. We implement reasonable physical, administrative, and technical safeguards to help us protect your personal information from unauthorized access, use and disclosure.

Please note that we will not ask you to share any sensitive data or information such as account / login / passwords / financial information (bank details, OTPs etc.) and other sensitive personal information via email / telephone / SMS / link. Please do not share such information with any person.

HEPL endeavours to safeguard the confidentiality of your Personal Data, however, transmissions made by means of the internet cannot be made absolutely secure. HEPL will have no liability for disclosure of your information due to errors in transmission and / or unauthorized acts of third-parties.

10. CHANGES TO THIS PRIVACY POLICY

Any changes to this Privacy Policy will be communicated by us posting an amended and restated Privacy Policy on the Mobile Application. Once posted on the Mobile Application the new Privacy Policy will be effective immediately. Your continued use of the Mobile Application shall be deemed to be your acceptance to the provisions of the Privacy Policy. User(s) agrees that any information HEPL hold about User (as described in this Privacy Policy and whether or not collected prior to or after the new Privacy Policy became effective) will be governed by the latest version of the Privacy Policy.

11. COMMUNICATION WITH COMPANY AND GRIEVANCE OFFICER

If you wish to correct or update any information you have provided you may contact us to correct or update such information by raising a request through support channel available in the Mobile Application.

In the event of loss of access to the Mobile Application, you may contact us by sending an e-mail to: udaanpay-support@udaan.com

In the event you wish to report a breach of the Privacy Policy, you may contact the designated Grievance Officer of the Company at:

Grievance Officer,

Hiveloop E-Commerce Private Limited, 1st Floor of South Wing “TWA - SJR - The Hub” situated at Survey Number 8, 2 & 9, Sarjapur Main Road, Sarjapur - Marathahalli Road, Bellandur, Bengaluru, Karnataka PIN- 560102, India

Email: grievance-officer@udaan.com

Working Hours: Monday to Saturday (From 09:00 AM to 06:00 PM)

Email: udaanpay-support@udaan.com