Legalv1.1.0

Privacy Policy

Effective date: 9 September 2026 · Last updated: 9 September 2026 · Published by USR Enterprises Private Limited

Privacy Policy

Last updated: 9 September 2026 · Version: 1.1.0 · Effective date: 9 September 2026

1. Introduction

ZulePay ("ZulePay", "we", "us", "our") is a digital wallet and payments platform that lets users load money into a wallet, send and receive payments, pay merchants online and offline, and pay bills and recharges. We are committed to being transparent about how we collect, use, share, store and protect your personal data, and about the choices you have.

This Privacy Policy explains your rights as a Data Principal under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), read with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and any other applicable laws of India.

This Privacy Policy is published on our website at https://zulepay.com/privacy-policy and is available within the ZulePay mobile applications. It is maintained in versioned form; every material change results in a new version number and a new effective date, and we keep a record of the versions you have accepted.

2. Who We Are (Data Fiduciary)

USR Enterprises Private Limited ("Company", "we", "us"), a company incorporated under the Companies Act, 2013, having its registered office at:

USR Enterprises Private Limited CIN: U62011KA2026PTC224718 VO-843, WeWork 10th Floor, RMZ Latitude, No. 69/458/69, Hebbal Kempapura, Bengaluru – 560024, Karnataka, India Email: support@zulepay.com · Phone: +91 95381 07745

The Company is the Data Fiduciary under the DPDP Act — the entity that, alone or jointly with others, determines the purpose and means of processing your personal data in connection with the ZulePay platform. Where a partner bank, payment aggregator or biller processes data on our instructions, they act as Data Processors or independent Data Fiduciaries for their own services, as described in Section 11.

Grievance Officer (under the DPDP Act and the Consumer Protection (E-Commerce) Rules, 2020):

Chethan Kumar TP — Grievance Officer USR Enterprises Private Limited VO-843, WeWork 10th Floor, RMZ Latitude, No. 69/458/69, Hebbal Kempapura, Bengaluru – 560024, Karnataka, India Email: support@zulepay.com · Phone: +91 95381 07745

3. Scope of This Policy

This Privacy Policy applies to:

  1. The ZulePay website at https://zulepay.com and all its pages;
  2. The ZulePay consumer mobile application ("Customer App");
  3. The ZulePay merchant mobile application ("Merchant App"); and
  4. Any related services, features, tools, communications and support offered by us (together, the "Services").

It applies to all visitors, users and merchants who interact with the Services, including users located outside India. If you do not agree with this Privacy Policy, please do not access or use the Services. Your use of the Services after the effective date of a new version constitutes acceptance of that version.

4. Definitions

In this Privacy Policy, unless the context requires otherwise:

TermMeaning
Personal DataAny data about an individual who is identifiable by or in relation to such data, in digital form or in non-digital form that is digitised subsequently
Data FiduciaryA person who, alone or jointly with others, determines the purpose and means of processing personal data
Data ProcessorA person who processes personal data on behalf of a Data Fiduciary
Data PrincipalThe individual to whom the personal data relates — here, you
Consent ManagerA person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform
ProcessingA wholly or partially automated operation performed on digital personal data, such as collection, storage, use, sharing, disclosure, alignment, combination, adaptation, erasure or destruction
ISUTImmutable Single-Use Token — an end-to-end encrypted, single-use cryptographic token used to make offline payments on ZulePay
Offline PocketThe segregated portion of your wallet (capped by regulatory limits) from which offline ISUT payments are made

5. Categories of Personal Data We Collect

We collect the following categories of personal data, depending on the Services you use and your KYC tier:

CategoryExamples
Identity and KYC dataFull name, date of birth, gender, photograph, PAN / Officially Valid Documents (passport, driving licence, Voter ID, NREGA job card, National Population Register letter), Aadhaar-based e-KYC data (where you choose Aadhaar authentication), self-declarations
Contact dataMobile phone number, email address, mailing address
Financial and transaction dataWallet identifier (ZulePay ID), UPI virtual payment address (where issued), wallet balance, load and withdrawal records, payment and transfer records, bill payment records, refunds, transaction PIN metadata (never the PIN itself), bank account details for withdrawals and settlements (account number, IFSC, verified name), escrow-related references
Merchant business data (for merchants)Business name, business category, proof of business (GSTIN, shop licence, etc.), settlement bank account details, rate-plan information
Device and technical dataDevice model, operating system and version, app version, device identifiers, IP address, Bluetooth identifiers used for offline transfers, crash and log data
Device key metadataPublic keys of your device's cryptographic key pair (ECDSA P-256), key registration and revocation status. Your private keys are generated on and never leave your device's secure storage.
Contacts metadataIf you expressly permit contact access, hashed or encrypted forms of contact identifiers used to match ZulePay users and display names for P2P transfers. We do not upload or store your full address book
Location dataCoarse location inferred from IP address for fraud prevention. Precise GPS location is requested only where needed for a specific feature (with your permission), and is used for fraud monitoring and regulatory reporting
Communications dataOTP requests and delivery status, support tickets, grievance communications, notification preferences
Usage dataPages and features used, session timing, and analytics events

We do not collect or store: your transaction PIN in readable form (only a salted hash), your card numbers or CVV (these are handled entirely by our payment gateway partner), your device private keys, your UPI PIN, or your biometric data (biometric authentication is performed locally on your device and never transmitted to us).

6. Data Collected Through Device Permissions

The ZulePay apps may request the following device permissions, each tied to a specific purpose. You may decline any permission; some features may then be unavailable:

PermissionPurpose
CameraScanning merchant QR codes and payment-request codes
BluetoothTransmitting and receiving ISUTs for offline payments without internet
ContactsFinding friends who use ZulePay and pre-filling payment details
NotificationsTransaction alerts, payment requests, security notices
BiometricsLocal unlocking of payments (processed on-device only)
Location (optional)Fraud monitoring and regulatory compliance reporting

7. How We Collect Personal Data

We collect personal data:

  1. Directly from you — when you register, complete KYC, load or withdraw money, make payments, contact support, or use app features;
  2. Automatically — from your device, browser, and your use of the Services (device data, IP address, log data, usage events);
  3. From third parties — from our banking, escrow and payment partners (e.g., payment confirmations, failsafe confirmations), KYC/verification vendors, telecom partners (OTP delivery confirmation), and billers/BBPS participants (bill fetch results); and
  4. From offline payment counterparties — when you send or receive an ISUT, the counterparty's device shares the minimum data necessary to settle the payment (amount, token reference, sender/receiver public keys, and display identifiers such as your ZulePay ID).

8. Purposes of Processing

We process your personal data for the following purposes:

  1. Onboarding you as a user or merchant, and authenticating you (OTP, sessions, device binding);
  2. Carrying out KYC / CDD required under the RBI Master Direction on KYC and the Prevention of Money-Laundering Act, 2002 ("PMLA"), and applicable sanctions screening;
  3. Operating your wallet: loading money, maintaining balances, executing transfers and payments, processing withdrawals and settlements;
  4. Enabling offline payments: provisioning your Offline Pocket, generating, transmitting, verifying and settling ISUTs, enforcing their single-use and validity properties, and returning expired tokens;
  5. Paying bills and processing recharges through the Bharat Bill Payment System ("BBPS");
  6. Detecting, preventing and investigating fraud, money laundering, and other prohibited conduct; securing the platform;
  7. Meeting legal, regulatory, supervisory and audit obligations (record-keeping, reporting to authorities, responding to lawful requests);
  8. Providing customer support and handling complaints and grievances;
  9. Sending transactional communications (OTP, alerts, receipts, security notices) which are essential for the Service;
  10. With your consent: sending product updates, offers and marketing; and
  11. Improving the Services (analytics, aggregated statistics) in a de-identified form wherever practicable.

Under the DPDP Act, we process your personal data either with your consent (given through the app's consent notices and your acceptance of these terms) or for certain legitimate uses recognised by law, principally:

  1. compliance with any law, regulation, or order of a court or tribunal, or any order of a regulator (including RBI directions on PPIs, KYC, record-keeping and reporting);
  2. responding to a medical emergency or disaster threatening life;
  3. employment-related or public-function obligations where applicable; and
  4. fraud monitoring and prevention, and recovery of dues, which are essential to a payment system.

Where processing is based on consent, that consent is free, specific, informed, unconditional and unambiguous, is sought through a clear notice before or at the time of collection, and is limited to the specified purpose. Where processing is based on a legitimate use, we may still limit the data to what is strictly necessary.

10. Contacts Matching and Minimisation

If you enable contact access, matching is performed using one-way hashed identifiers; we do not retain a copy of your address book on our servers. You can revoke contacts permission at any time in your device settings.

11. How We Share Personal Data

We do not sell your personal data. We share it only as described below, to the extent necessary:

RecipientWhat is sharedWhy
Escrow / partner bank(s)Wallet holder records, transaction records, settlement instructions, KYC statusYour wallet operates as a prepaid payment instrument whose underlying funds are held in escrow; the bank maintains and reconciles these funds and performs statutory reporting
Payment gateway / aggregator (e.g., Razorpay)Order references, amounts, masked payment instrument details for refundsEnabling wallet loads by UPI, cards and net-banking, and processing refunds
Bill payment ecosystem (BBPS / BillDesk and billers)Consumer numbers, bill details, payment confirmationBill fetch, presentment and payment
KYC and verification vendorsIdentity documents and identifiers you submitVerifying your identity as required by law
OTP / telecom partners (e.g., msg91)Mobile number, message content (OTP), delivery statusAuthentication
Cloud and infrastructure providersEncrypted account and transaction dataHosting the Services
Law enforcement, regulators, courtsRequested records, statutory reports (e.g., suspicious transaction reports)Legal and regulatory obligations, including under PMLA
Professional advisers, auditorsRelevant records under confidentialityAudit, legal and regulatory compliance
Payment counterpartiesDisplay identifiers (e.g., ZulePay ID, name), amount, token referenceCompleting transfers you initiate

We may also share data in connection with a merger, acquisition, financing or sale of assets, under confidentiality, and only as permitted by law.

Before sharing personal data, we take reasonable steps to satisfy ourselves that the recipient is appropriate for the purpose. Data Processors are engaged subject to due diligence and are bound by contract to process personal data only on our instructions, for the stated purposes, with comparable protection, and to assist us in honouring your rights under the DPDP Act. Where a recipient acts as an independent Data Fiduciary for its own services (for example your bank, a card network or a biller), its own privacy policy governs its processing of your data.

12. Cross-Border Data Transfers

Our primary infrastructure is located in India. The ZulePay application is operated worldwide; if you access the Services from outside India, your data will be transferred to and processed in India. Certain vendors (for example, cloud infrastructure, analytics or communications providers) may process data outside India. Any such transfer is made only to countries and under safeguards permitted under the DPDP Act and the DPDP Rules (including any government-notified restrictions), under contractual protections with the recipient, and limited to the extent necessary to provide you the Services.

13. Data Retention

We retain your personal data only as long as necessary for the purposes set out in this Policy, and thereafter as required by law:

  1. Transaction, KYC and PMLA records: retained for at least 5 (five) years from the date of the transaction, the end of the business relationship, or the date of satisfaction of a threshold, as required under the PMLA and RBI's record-keeping directions;
  2. Regulatory order books and audit trails: for periods stipulated by the RBI and applicable law;
  3. Terms acceptance records: retained for the duration of your account and for at least 5 years thereafter, as evidence of the contractual terms applicable to your use;
  4. Grievance records: for at least the periods required under consumer-protection norms; and
  5. Marketing consents: until you withdraw consent, plus a minimal record of withdrawal for accountability.

When data is no longer required, it is erased or irreversibly de-identified, except where retention is required to comply with a legal obligation, defend legal claims, or for establishment/exercise/defence of legal claims.

14. How We Protect Personal Data

We maintain reasonable security safeguards, including:

  1. End-to-end encryption of offline payments — each ISUT is encrypted to the recipient's public key and is single-use ("destroy-on-generate"), so it cannot be reused, altered or intercepted;
  2. Hardware-backed device cryptography — payment keys are ECDSA P-256 key pairs generated and held in your device's secure enclave/keystore; private keys never leave the device;
  3. Encryption in transit (TLS) and encryption of data at rest;
  4. Hashed transaction PINs and no storage of card data, UPI PINs or biometrics on our systems;
  5. Role-based access control, least-privilege administration, audit logging of privileged actions, and immutable double-entry ledger records for all value movements;
  6. Segregated escrow backing — wallet funds are held with our partner bank and reconciled continuously; and
  7. Periodic security review, monitoring and vendor assessments.

No method of transmission or storage is completely secure; while we strive to protect your data, we cannot guarantee absolute security. If you suspect any vulnerability or unauthorised access, contact us immediately at support@zulepay.com.

15. Your Rights as a Data Principal

Under the DPDP Act, you have the right to:

  1. Access a summary of the personal data we process about you, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom your data has been shared;
  2. Correction and completion of inaccurate, incomplete or out-of-date personal data — including the right to correct your own data conveniently, and to have corrections shared with downstream recipients;
  3. Erasure of your personal data, subject to our obligation to retain data under applicable law (see Section 13);
  4. Nominate another individual to exercise your rights in the event of your death or incapacity;
  5. Grievance redressal — the right to readily available means of grievance redressal and to have your grievance addressed within the timelines in Section 16; and
  6. Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

Data of children and persons with disabilities: we do not process the personal data of children (persons under 18) — see Section 18. Parents and lawful guardians may contact our Grievance Officer to have any data concerning a child erased and to stop tracking, behavioural monitoring or targeted advertising directed at children.

16. Exercising Your Rights and Response Timelines

To exercise any right, use the in-app profile tools where available, or write to our Grievance Officer (Section 2). We will:

  1. Acknowledge your request within 48 (forty-eight) hours;
  2. Resolve rights requests and grievances within the shorter of the period specified in applicable law or 30 (thirty) days of receipt, unless a valid extension is communicated to you with reasons; and
  3. Inform you of any action taken or, where we decline a request, the reason for refusal and your right to escalate to the Data Protection Board of India.

You may also escalate an unresolved grievance to the Data Protection Board of India through the mechanism notified by the Board under the DPDP Act and DPDP Rules.

Where processing is consent-based, you may withdraw consent at any time via app settings or by contacting us. Withdrawal does not affect the lawfulness of processing prior to withdrawal. Please note that certain processing is necessary for performance of the Services and compliance with legal obligations — for example KYC, transaction records and fraud monitoring — and withdrawal of consent for such processing may prevent you from using the affected Services and may require account closure in accordance with the Terms & Conditions.

18. Children's Data

The Services are not directed at, and we do not knowingly collect personal data from, persons under the age of 18. Opening a ZulePay account and making payments is restricted to adults. If we learn that we have collected personal data of a child, we will delete it promptly and disable the account, unless retention is required by law. Parents or guardians who believe their child's data has been provided to us may write to the Grievance Officer.

19. Cookies and Similar Technologies

The ZulePay website and apps use a minimal set of cookies and similar technologies (including browser local storage and comparable in-app identifiers). We group them as follows:

  1. Strictly necessary cookies — required for the website to function: security, authentication, session integrity and load balancing. These cannot be switched off.
  2. Functional cookies — remember your preferences, such as theme, language and cookie-consent state.
  3. Analytics and performance cookies — used only with your consent, to understand aggregate usage and improve the Services.

Your consent choices are set out in the cookie banner when you first visit, and can be changed at any time through the cookie settings. Refusing or deleting strictly necessary cookies may prevent parts of the website from working. In the apps, comparable identifiers (such as push-notification tokens) serve the corresponding purposes. For detailed information on the cookies we use and their purposes, see the cookie notice in the banner and in the app settings.

20. Third-Party Products, Services and Websites

  1. The Services may contain links to, or integrations with, third-party websites, applications, products and services — for example our partner bank's portal, biller websites, payment-gateway checkout pages, app stores and merchants' own websites. Such links are provided for your convenience.
  2. Except where we state otherwise, these third parties operate independently of us. Once you follow a link or leave our website or app, your activity there is governed by that third party's own terms of use and privacy policy, which we encourage you to read. We do not control those third parties and are not responsible for their content, products, services or data practices.
  3. Where you access a third-party service through the Services (for example, paying a biller through BBPS), data exchanged in that transaction is governed by this Policy so far as it is processed by us, and by the third party's own terms and privacy policy so far as it is processed by it as an independent Data Fiduciary.
  4. A link or integration does not imply our endorsement of the third party or of any content it publishes, and does not expand the purposes for which we process your personal data.

21. Your Choices and Opt-Out

You can control how we use your personal data in several ways:

  1. Marketing communications — you may opt out of receiving offers and product updates at any time, using the notification and communication settings in the app or the unsubscribe link in our emails. Transactional and security messages (OTP, payment receipts, alerts) are essential to the Services and are not marketing messages; they cannot be switched off while your account is active.
  2. Device permissions — you may enable or disable the permissions listed in Section 6 through your device settings at any time; the related features will stop working if you do.
  3. Cookies — you may withdraw or change your cookie consent at any time through the cookie settings on the website (Section 19).
  4. Consent-based processing — you may withdraw consent as described in Section 17; this may affect the availability of the affected Services.
  5. Your data rights — you may exercise your rights to access, correction, erasure and nomination at any time, as described in Sections 15 and 16.

22. Data Breach Notification

In the event of a personal data breach, we will without undue delay: assess its scope and impact; contain and remediate; notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines prescribed under the DPDP Act and the DPDP Rules, describing the nature of the breach, likely consequences and mitigating measures; and notify other regulators (such as the RBI and CERT-In) as required under applicable law and directions, including the CERT-In directions on reporting cyber incidents.

23. Changes to This Policy and Versioning

We may update this Privacy Policy from time to time to reflect changes in law, our Services or our practices. Every version carries a version number and effective date at the top of this document. The current version is always available at https://zulepay.com/privacy-policy.

  1. Material changes (for example, new purposes of processing, new categories of data, or materially different sharing) will be notified to you in the app and/or by other channels before they take effect, and — where your consent is required — we will seek fresh consent. Continued use after the effective date constitutes acceptance where consent is not separately required.
  2. We maintain a version history — each published version is archived, and the app records which version you accepted and when, so you can always establish which policy governed your use at any point in time.
  3. Protection floor — we will never change this Policy in a way that reduces the protection of the personal data you have already shared with us.

24. Grievance Redressal

If you have any concern, query or complaint about how we handle your personal data, please contact our Grievance Officer:

Chethan Kumar TP — Grievance Officer USR Enterprises Private Limited, VO-843, WeWork 10th Floor, RMZ Latitude, No. 69/458/69, Hebbal Kempapura, Bengaluru – 560024, Karnataka, India Email: support@zulepay.com · Phone: +91 95381 07745

We will acknowledge within 48 hours and endeavour to resolve within 30 days. If your grievance remains unresolved, or you are dissatisfied with the resolution, you may escalate to the Data Protection Board of India, and — for payment-related complaints — follow the escalation path set out in our Terms & Conditions, culminating in the Reserve Bank – Integrated Ombudsman Scheme, 2021.

25. Contact Us

Questions about this Privacy Policy may be directed to:

USR Enterprises Private Limited CIN: U62011KA2026PTC224718 VO-843, WeWork 10th Floor, RMZ Latitude, No. 69/458/69, Hebbal Kempapura, Bengaluru – 560024, Karnataka, India Email: support@zulepay.com · Phone: +91 95381 07745