Privacy Policy
What we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it.
01Scope of this policy
This policy explains how Rupeeco Fintech Private Limited (“Rupeeco”, “we”) handles personal data when you visit this website, contact us, or use our APIs and dashboard.
Where we process personal data on behalf of a business customer — for example, verifying that customer's end users — we act as a data processor under that customer's instructions, and their own privacy notice governs the relationship with the individual.
02Information we collect
- Contact details you submit — name, work email, company, phone number, enquiry type and message content submitted through forms on this site.
- Account and integration data — API keys, webhook endpoints, dashboard user records, roles and configuration settings.
- Transaction and verification data — payment, collection, settlement, mandate and verification records processed through our APIs on behalf of our customers.
- Technical data — IP address, device and browser information, request logs, timestamps and error traces.
We do not knowingly collect data from children, and we do not ask you to send full card numbers, CVVs, OTPs or Aadhaar numbers over email.
03How we use information
- To respond to your enquiry and route it to the correct internal team.
- To provide, operate, secure and improve the Rupeeco platform and its APIs.
- To perform KYC, KYB, fraud prevention, AML screening and risk decisioning.
- To meet legal, regulatory, audit and tax obligations.
- To send service, security and status communications relating to your account.
04Consent and lawful basis
Where required, we process personal data on the basis of consent — for example, verification checks that require an explicit consent flag in the API request. We also rely on the performance of a contract, compliance with a legal obligation, and our legitimate interest in operating a secure platform. You may withdraw consent at any time by writing to support@rupeeco.in, though this may prevent us from providing certain services.
06Data security
We apply AES-256 encryption at rest, TLS 1.3 in transit, HSM-backed key custody, role-based access control, network segmentation, immutable audit logging and regular penetration testing. No system is perfectly secure, so we also maintain an incident response process and will notify affected parties and authorities as required by applicable law.
07Data retention and residency
Customer and transaction data is stored and processed within India. We retain records for as long as your relationship with us continues and thereafter for the period required by applicable financial, tax and anti-money-laundering law, after which data is deleted or irreversibly anonymised.
08Your rights
Subject to applicable law, you may request:
- Access to a summary of the personal data we hold about you.
- Correction or completion of inaccurate or incomplete data.
- Erasure of data we no longer have a lawful basis to retain.
- Withdrawal of consent, and nomination of another person to exercise your rights.
- Grievance redressal, as described on our grievance page.
Send requests to support@rupeeco.in. We may need to verify your identity before acting.
10Changes to this policy
We may update this policy as our services, partners or legal obligations change. Material changes will be announced on this page with a revised effective date, and where required we will notify you directly.
Questions about this policy?
Write to support@rupeeco.in or use the contact form. For unresolved matters, escalate to director@rupeeco.in.
