Privacy Policy
Last Updated: June 16, 2026
1. Operating Entity & Introduction
This Privacy Policy describes how HINDUSTAN MFG (operating under the trade name "PayCred", having GSTIN: 27BZWPK3501Q1ZM, hereinafter referred to as "we", "us", or "our") collects, uses, stores, and protects your information when you visit or use our payment utility platform.
We are committed to securing your personal and transactional details in compliance with the Information Technology Act, 2000, the Digital Personal Data Protection (DPDP) Act, 2023, and Reserve Bank of India (RBI) guidelines for online payment aggregators.
2. Information We Collect
To offer secure credit-card-to-bank settlement services (for fee and education payments), we collect the following sets of data:
- Identity Details: Full legal name and mobile number verified via OTP.
- KYC Documentation: Permanent Account Number (PAN) details and Aadhaar verification status to comply with anti-money laundering (AML) and RBI compliance thresholds.
- Beneficiary Details: Beneficiary or educational institution bank account numbers, IFSC codes, and resolved bank account holder names (validated via ₹1 Penny-Drop API simulation).
- Card & Payment Data: Credit card numbers, cardholder names, expiry dates, and card networks. Note: In compliance with RBI Card-on-File Tokenisation (CoFT) rules, we do NOT store raw card details or CVV codes. Cards are converted into secure network tokens for all future payments.
3. Usage & Processing of Information
We process your details based on corporate requirements and security checks, including:
- Verifying user identity (KYC check) to prevent credit-card cash outs, fraud, and circular payments.
- Routing settlements through our designated nodal/escrow current accounts at Bharat Co-op Bank directly to the beneficiary or institution.
- Generating digital HRA tax receipts for tax exemptions under Section 10(13A) of the Income Tax Act.
- Fulfilling legal obligations, audit logs, and reporting suspicious transaction alerts (STRs) to regulatory authorities.
4. Data Security and Standards
We enforce premium security protocols to defend your data:
All transactions are secured with 256-bit Secure Socket Layer (SSL) encryption. Card tokenization processes run in isolation using secure HSMs (Hardware Security Modules) certified by PCI-DSS. Information stored in our database (facilitated through Supabase) is encrypted at rest and in transit.
5. Data Disclosure & Sharing
We do not sell, fee, or trade your data with external advertisers. Data is shared strictly with:
- Licensed banking institutions (e.g., **Bharat Co-op Bank**) and card networks to authorize payments.
- Government bodies, income tax departments, and audit entities where required by law.
6. Grievance Redressal Officer
In compliance with the Reserve Bank of India (RBI) guidelines for online payment aggregators, PayCred has established a structured grievance redressal policy to address customer queries, failed payouts, and disputes:
Grievance Escalation Matrix:
- Level 1 (Support Desk): Contact our automated help panel or email support@paycred.tech for real-time tracking, standard NEFT checks, or initial queries.
- Level 2 (Compliance & Nodal Officer): If Level 1 support does not satisfy your query within 3 business days, you can escalate to our Nodal Officer:
Name: Compliance Officer, HINDUSTAN MFG
Email: support@paycred.tech
Phone: +91 83560 14390
Address: HINDUSTAN MFG, Devi Dayal Compound, Kanjurmarg East, Mumbai, Maharashtra - 400042
- Level 3 (RBI Ombudsman): If your query is not resolved or remains unaddressed after 30 days, you can register a complaint under the RBI Integrated Ombudsman Scheme.
Disposal Timelines:
- Complaint acknowledgement email/ticket: Within 24 to 48 hours.
- Complete resolution & dispute closure: Within 15 business days.
7. Data Retention & Deletion
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law:
- Transaction Records: Retained for a minimum of 10 years from the date of the transaction, as required under the Prevention of Money Laundering Act (PMLA) and Income Tax Act.
- KYC Documents (PAN, Aadhaar verification): Retained for 5 years after closure of the account or last transaction, whichever is later.
- Payment Card Tokens: Network tokens are retained until the user explicitly requests deletion or revokes card authorization. No raw card data is stored.
- Account Profile Data: Retained until the user requests account deletion. Upon deletion request, data is removed within 30 days, except where retention is legally mandated.
8. Your Rights Under DPDPA 2023
Under the Digital Personal Data Protection Act, 2023 (DPDPA), you have the following rights with respect to your personal data processed by PayCred:
- Right to Access: You may request a summary of your personal data being processed, including the categories of data and the purposes of processing.
- Right to Correction: You may request correction or completion of inaccurate or incomplete personal data held by us.
- Right to Erasure: You may request deletion of your personal data, subject to any legal obligations requiring us to retain certain records.
- Right to Grievance Redressal: You have the right to file a complaint with our Grievance Officer or escalate to the Data Protection Board of India if your request is not resolved.
- Right to Nominate: You may nominate another individual to exercise your rights under this policy in case of your death or incapacity.
To exercise any of these rights, please contact our Grievance Officer at support@paycred.tech with your registered mobile number and a description of your request. We will respond within 30 days of receiving your request.