Instant Booking Secure Payments 24×7 Support GST Invoice
Data Protection Standards

Privacy Policy

Last Updated: June 16, 2026

1. Operating Entity & Introduction

This Privacy Policy describes how HINDUSTAN MFG (operating under the trade name "PayCred", having GSTIN: 27BZWPK3501Q1ZM, hereinafter referred to as "we", "us", or "our") collects, uses, stores, and protects your information when you visit or use our payment utility platform.

We are committed to securing your personal and transactional details in compliance with the Information Technology Act, 2000, the Digital Personal Data Protection (DPDP) Act, 2023, and Reserve Bank of India (RBI) guidelines for online payment aggregators.

2. Information We Collect

To offer secure credit-card-to-bank settlement services (for fee and education payments), we collect the following sets of data:

  • Identity Details: Full legal name and mobile number verified via OTP.
  • KYC Documentation: Permanent Account Number (PAN) details and Aadhaar verification status to comply with anti-money laundering (AML) and RBI compliance thresholds.
  • Beneficiary Details: Beneficiary or educational institution bank account numbers, IFSC codes, and resolved bank account holder names (validated via ₹1 Penny-Drop API simulation).
  • Card & Payment Data: Credit card numbers, cardholder names, expiry dates, and card networks. Note: In compliance with RBI Card-on-File Tokenisation (CoFT) rules, we do NOT store raw card details or CVV codes. Cards are converted into secure network tokens for all future payments.

3. Usage & Processing of Information

We process your details based on corporate requirements and security checks, including:

  • Verifying user identity (KYC check) to prevent credit-card cash outs, fraud, and circular payments.
  • Routing settlements through our designated nodal/escrow current accounts at Bharat Co-op Bank directly to the beneficiary or institution.
  • Generating digital HRA tax receipts for tax exemptions under Section 10(13A) of the Income Tax Act.
  • Fulfilling legal obligations, audit logs, and reporting suspicious transaction alerts (STRs) to regulatory authorities.

4. Data Security and Standards

We enforce premium security protocols to defend your data:

All transactions are secured with 256-bit Secure Socket Layer (SSL) encryption. Card tokenization processes run in isolation using secure HSMs (Hardware Security Modules) certified by PCI-DSS. Information stored in our database (facilitated through Supabase) is encrypted at rest and in transit.

5. Data Disclosure & Sharing

We do not sell, fee, or trade your data with external advertisers. Data is shared strictly with:

  • Licensed banking institutions (e.g., **Bharat Co-op Bank**) and card networks to authorize payments.
  • Government bodies, income tax departments, and audit entities where required by law.

6. Grievance Redressal Officer

In compliance with the Reserve Bank of India (RBI) guidelines for online payment aggregators, PayCred has established a structured grievance redressal policy to address customer queries, failed payouts, and disputes:

Grievance Escalation Matrix:

  • Level 1 (Support Desk): Contact our automated help panel or email support@paycred.tech for real-time tracking, standard NEFT checks, or initial queries.
  • Level 2 (Compliance & Nodal Officer): If Level 1 support does not satisfy your query within 3 business days, you can escalate to our Nodal Officer:

    Name: Compliance Officer, HINDUSTAN MFG

    Email: support@paycred.tech

    Phone: +91 83560 14390

    Address: HINDUSTAN MFG, Devi Dayal Compound, Kanjurmarg East, Mumbai, Maharashtra - 400042

  • Level 3 (RBI Ombudsman): If your query is not resolved or remains unaddressed after 30 days, you can register a complaint under the RBI Integrated Ombudsman Scheme.

Disposal Timelines:

  • Complaint acknowledgement email/ticket: Within 24 to 48 hours.
  • Complete resolution & dispute closure: Within 15 business days.

7. Data Retention & Deletion

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law:

  • Transaction Records: Retained for a minimum of 10 years from the date of the transaction, as required under the Prevention of Money Laundering Act (PMLA) and Income Tax Act.
  • KYC Documents (PAN, Aadhaar verification): Retained for 5 years after closure of the account or last transaction, whichever is later.
  • Payment Card Tokens: Network tokens are retained until the user explicitly requests deletion or revokes card authorization. No raw card data is stored.
  • Account Profile Data: Retained until the user requests account deletion. Upon deletion request, data is removed within 30 days, except where retention is legally mandated.

8. Your Rights Under DPDPA 2023

Under the Digital Personal Data Protection Act, 2023 (DPDPA), you have the following rights with respect to your personal data processed by PayCred:

  • Right to Access: You may request a summary of your personal data being processed, including the categories of data and the purposes of processing.
  • Right to Correction: You may request correction or completion of inaccurate or incomplete personal data held by us.
  • Right to Erasure: You may request deletion of your personal data, subject to any legal obligations requiring us to retain certain records.
  • Right to Grievance Redressal: You have the right to file a complaint with our Grievance Officer or escalate to the Data Protection Board of India if your request is not resolved.
  • Right to Nominate: You may nominate another individual to exercise your rights under this policy in case of your death or incapacity.

To exercise any of these rights, please contact our Grievance Officer at support@paycred.tech with your registered mobile number and a description of your request. We will respond within 30 days of receiving your request.

© 2026 HINDUSTAN MFG (trading as PayCred). All rights reserved.