1. Information We Collect
We collect the following categories of information:
- Identity & KYC data: full name, date of birth, gender, Aadhaar number (masked / hashed), PAN, photograph, biometric authentication response (fingerprint / IRIS — used only for on-the-spot authentication and not stored), signature, and video-KYC recording where applicable.
- Contact & business data: mobile number, email, residential and shop address, GSTIN, Udyam / shop-act number, cancelled cheque / bank details.
- Transaction data: beneficiary account details, transaction amount, timestamp, geo-location of the retailer terminal, device ID, IP address, RRN / UTR numbers, bill and utility account numbers.
- Device & usage data: browser type, OS, mobile handset, application version, log files, cookies and similar tracking technologies used to secure and improve the Platform.
2. Aadhaar and Biometric Information
For AEPS, Aadhaar-Pay, e-KYC and Micro-ATM services, we act as a Sub-AUA / Sub-KUA of our banking partners under contract with the Unique Identification Authority of India (UIDAI). Aadhaar numbers are collected only in a masked form for display and are stored in encrypted / hashed form as required by UIDAI regulations. Biometric data (fingerprint / IRIS) is captured on a UIDAI-registered device, encrypted at the device level, transmitted directly to the UIDAI / NPCI switch for authentication and never stored by us in any form.
3. How We Use Your Information
- To register, verify and on-board Channel Partners and end-customers.
- To process financial transactions and provide services such as AEPS, DMT, Micro-ATM, BBPS, PAN, insurance, lending, travel and digital commerce.
- To comply with KYC, AML and record-keeping obligations under the RBI, NPCI, IRDAI, UIDAI, PMLA and Income-Tax Act.
- To detect, investigate and prevent fraud, money-laundering and cyber attacks.
- To send transactional alerts (SMS, email, push, WhatsApp), service updates and, where consented, marketing communications.
- To generate anonymised, aggregated analytics that help us improve the Platform.
4. Sharing of Information
We share information only in the following limited circumstances:
- With our regulated banking and non-banking aggregator partners to execute transactions and settle funds.
- With NPCI, UIDAI, NSDL, UTIITSL, insurers and lenders to the extent required to provide the service you requested.
- With service providers such as cloud hosting, SMS / email gateways, analytics and customer-support tools, under strict confidentiality and data-protection contracts.
- With law-enforcement, regulators and courts when required by law, subpoena or a valid legal request.
We do not sell your personal or financial information to any third party for advertising or profiling purposes.
5. Data Retention
KYC and transaction records are retained for a minimum of ten (10) years from the date of the transaction, as mandated under the Prevention of Money Laundering Act, 2002. Records may be retained for longer periods where required for regulatory, audit, tax or dispute-resolution purposes.
6. Security
We implement industry-standard technical and organisational measures to protect your data, including TLS 1.2+ encryption in transit, AES-256 encryption at rest, tokenisation of sensitive identifiers, role-based access, secure key management, periodic VAPT, ISO / SOC-aligned processes and 24×7 fraud-monitoring. Despite our efforts, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Cookies
The Platform uses cookies and similar technologies for session management, security, preference storage and analytics. You may disable cookies through your browser settings, but some features of the Platform may not function correctly.
8. Your Rights
Subject to applicable law, you may access, correct, update or request erasure of your personal information, withdraw a consent previously given, or opt out of marketing communications, by writing to our Grievance Officer at the address below. Erasure requests will be honoured except where retention is required by law or for legitimate business purposes.
9. Children
The Platform is not intended for use by persons under the age of 18. We do not knowingly collect personal information from minors.
10. Changes to this Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised "Last updated" date.
11. Grievance Officer
In accordance with the Information Technology Act, 2000 and Rules made thereunder, the name and contact details of the Grievance Officer are:
Grievance Officer
JSS Global
Office-107, First Floor, Plot No-6, T.C. Jaina Tower-II, Janakpuri A-3, West Delhi, Delhi 110058
Email: admin@jssglobal.co.in
Response time: within 15 (fifteen) working days of receipt of a complaint.