Privacy Policy
This Privacy Policy explains how Hwrs Paytech Private Limited collects, processes, stores, secures, uses, shares, and protects personal information when users access or use our fintech, payment, API, recharge, BBPS, merchant, retailer, distributor, master distributor, white label, and digital financial services.
Introduction
This Privacy Policy applies to all users, customers, merchants, retailers, distributors, master distributors, white label partners, API partners, business partners, website visitors, app users, and any person using or accessing HWRS PayTech platforms, APIs, dashboards, panels, or services.
Hwrs Paytech Private Limited (“Company”, “HWRS PayTech”, “we”, “our”, or “us”) is committed to maintaining the confidentiality, integrity, and security of personal and financial information belonging to users, merchants, partners, retailers, distributors, master distributors, API partners, white label partners, customers, and website visitors.
By accessing or using our platforms, applications, APIs, websites, payment systems, merchant panels, retailer panels, distributor panels, master distributor panels, white label panels, admin panels, or related services, you acknowledge and agree to the collection and processing of information in accordance with this Privacy Policy.
This Privacy Policy forms an integral part of the Company's Terms & Conditions. If you do not agree with this Privacy Policy, you must stop using HWRS PayTech services.
Information We Collect
HWRS PayTech may collect personal, business, technical, transaction, compliance, and usage-related information depending on the user type, service type, KYC requirement, transaction requirement, API integration, white label arrangement, and applicable law.
Personal Information
We may collect the following personal information:
- Full Name
- Mobile Number
- Email Address
- Date of Birth
- Gender, where required
- Residential Address
- Business Address
- PAN Details
- Aadhaar Details, where permitted by law
- KYC Documentation
- Photographs & Verification Data
- Signature
- Identity Proof
- Address Proof
- Bank Account Details
- Cancelled Cheque
- UPI ID
- Nominee or authorized person details, where required
- Login credentials in encrypted or protected form
- Support communication details
- Any other information required for onboarding, KYC, compliance, service delivery, or dispute resolution
Business Information
For merchants, retailers, distributors, master distributors, white label partners, API partners, and business entities, we may collect:
- Business Name
- Shop Name
- Firm Name
- Company Name
- Business Registration Certificates
- GST Information
- Trade Licenses
- PAN of business entity
- Proprietor / Partner / Director details
- Board resolution or authorization letter, where applicable
- Business address proof
- Merchant & Retailer Information
- Distributor and Master Distributor details
- White Label Partner details
- API Partner details
- Settlement & Billing Records
- Commission structure and payout records
- Agreement documents
- Service activation records
- Business verification data
- Support and ticket history
Technical Information
- IP Address
- Browser & Device Information
- Operating System
- Device ID
- Device type
- Mobile application version
- Browser version
- Login Activity
- Cookies & Usage Data
- Session data
- Location approximation based on IP or service usage
- Server logs
- API logs
- Error logs
- Security logs
- Webhook/callback logs
- Authentication logs
- Failed login attempts
- Access token and refresh token metadata
- API key usage metadata
- System activity records
Transaction Information
We may collect and process transaction-related information including:
- Recharge Transactions
- BBPS Payments
- Utility Bill Payments
- Wallet Transactions
- AEPS Transactions
- Micro ATM Transactions
- UPI Transactions
- UPI Cash Withdrawal Records
- PAN Service Records
- Insurance Service Records
- Travel Booking Records
- FASTag Recharge Records
- Digital Gold Service Records
- Gift Card Service Records
- Courier Service Records
- Cash and EMI Collection Records
- Refund & Settlement Details
- Commission Details
- Chargeback Details
- Dispute Details
- Transaction ID
- Reference Number
- Beneficiary Details
- Consumer Number
- Operator/Biller Details
- Transaction Status
- Time and date of transaction
- Service provider response
- API request and response logs
- Callback status
White Label Platform Information
Where HWRS PayTech provides white label services, we may collect and process information relating to:
- White Label Partner account
- White Label Admin user
- White Label branding details
- Domain or sub-domain details
- Logo, theme, and color preferences
- Master Distributor hierarchy
- Distributor hierarchy
- Retailer hierarchy
- Merchant network
- User network
- Role and permission settings
- Commission settings
- Service activation settings
- Transaction reports
- Wallet and settlement records
- Support tickets
- KYC status of network users
- Fraud and risk monitoring data
White Label Partners are responsible for informing their own users about the collection and processing of personal information through their branded platform where they operate customer-facing services.
API Partner Information
For API Partners, we may collect and process:
- API Partner business details
- Developer contact details
- API key and authentication metadata
- IP whitelist details
- Request payload metadata
- Response payload metadata
- Callback URL details
- Webhook logs
- Endpoint usage
- Transaction logs
- Error logs
- Integration status
- Technical support records
- Settlement and billing records
- Service usage analytics
- Fraud monitoring data
- Security event logs
API Partners are responsible for obtaining required consent from their own users and ensuring lawful processing of customer data submitted through HWRS PayTech APIs.
How We Use Information
We use information for the following purposes:
- To create and manage user accounts
- To onboard customers, retailers, distributors, master distributors, white label partners, API partners, and merchants
- To process transactions securely and efficiently
- To provide recharge, BBPS, AEPS, UPI, wallet, PAN, insurance, travel, and other services
- To verify KYC and business documents
- To comply with KYC, AML, RBI, NPCI, BBPS, banking partner, and legal obligations
- To prevent fraud, suspicious activity, unauthorized access, money laundering, and misuse of services
- To maintain wallet, settlement, commission, and payout records
- To provide API access and integration support
- To manage white label platform services
- To manage partner hierarchy and role-based access
- To improve customer support and platform performance
- To send transaction alerts, updates, OTPs, notifications, service messages, and security alerts
- To maintain business records and operational analytics
- To handle refunds, reversals, disputes, chargebacks, and grievances
- To conduct audits, risk review, compliance review, and reconciliation
- To personalize platform experience
- To improve services, security, reporting, and user experience
- To enforce Terms & Conditions and other policies
- To comply with court orders, law enforcement requests, regulatory directions, or legal obligations
Sharing of Information
User information may be shared only where necessary for operational, legal, security, regulatory, service delivery, settlement, support, fraud prevention, or business purposes.
Information may be shared with:
- Banking partners & payment processors
- NPCI, BBPS, and financial institutions
- Payment gateways
- Recharge operators
- Billers
- AEPS service providers
- Micro ATM service providers
- UPI service providers
- Insurance service providers
- Travel service providers
- PAN and government service providers
- API service providers
- White label technology partners, where applicable
- Government authorities and law enforcement agencies
- Regulatory authorities
- Technology vendors and infrastructure providers
- Cloud hosting providers
- Cybersecurity vendors
- SMS, email, WhatsApp, and notification service providers
- Customer support tools
- Compliance consultants, auditors, and legal advisors
- Collection, recovery, or dispute resolution agencies, where legally permitted
- Any other entity where sharing is required for service delivery or legal compliance
We do not sell, trade, or rent personal information to third parties for unauthorized commercial purposes.
Data Sharing in White Label Model
In the white label model, HWRS PayTech may provide technology, APIs, backend systems, admin panel, role hierarchy, transaction routing, wallet management, and operational tools to White Label Partners.
Data may be processed between HWRS PayTech and White Label Partner for:
- User onboarding
- KYC verification
- Partner hierarchy management
- Transaction processing
- Settlement
- Commission calculation
- Support handling
- Fraud monitoring
- Service activation
- Reporting
- Compliance and audit
White Label Partners must ensure that they use such information only for lawful business purposes and protect it from unauthorized access, misuse, leakage, or illegal sharing.
Data Sharing in API Model
Where an API Partner submits customer or transaction data through HWRS PayTech APIs, such data may be processed for:
- API authentication
- Transaction execution
- Status confirmation
- Callback response
- Settlement
- Refund or reversal
- Reconciliation
- Fraud monitoring
- Dispute resolution
- Audit and compliance
- Technical support
API Partners are responsible for the accuracy, legality, consent, and security of data submitted through their own systems.
Data Security
The Company maintains commercially reasonable technical and organizational safeguards designed to protect user information from unauthorized access, misuse, alteration, disclosure, or destruction.
Security measures may include:
- Secure Servers & Encryption
- Access Control Mechanisms
- Cybersecurity Monitoring
- Firewall & Threat Protection
- Role-based access control
- Password protection
- OTP-based authentication
- API key-based authentication
- IP whitelisting, where applicable
- Secure communication protocols
- Log monitoring
- Fraud detection systems
- Backup and recovery controls
- Internal access restrictions
- Employee confidentiality obligations
- Periodic security review
While we strive to protect all information, no electronic transmission, internet system, server, API system, mobile application, or storage system can guarantee absolute security. Users are responsible for protecting their own login credentials, OTP, password, MPIN, API keys, devices, SIM card, email access, and system access.
Data Retention
Personal and transaction-related information may be retained for as long as required under applicable laws, regulatory obligations, audit requirements, dispute resolution procedures, tax compliance, fraud prevention, legal claims, service provider requirements, and legitimate business purposes.
Data may be retained for:
- KYC compliance
- AML monitoring
- Transaction records
- Settlement records
- Wallet records
- Refund records
- Chargeback records
- Tax records
- Audit records
- Legal claims
- API logs
- Security logs
- Customer support history
- Regulatory reporting
- Fraud prevention
The Company may retain information even after account closure where required by law, regulation, contractual obligation, dispute resolution, fraud investigation, or legitimate business purpose.
User Rights
Subject to applicable law and verification, users may have the right to:
- Request access to personal information
- Request correction or updates to information
- Request deletion where legally permissible
- Withdraw consent for non-essential communications
- Raise complaints regarding misuse of information
- Request information about processing of personal data
- Nominate another individual to exercise rights, where applicable under law
- Contact the Company for privacy-related concerns
Certain requests may be refused or restricted where retention or processing is required for legal, regulatory, tax, audit, security, fraud prevention, transaction, dispute resolution, or contractual purposes. For example, transaction records, KYC records, settlement records, API logs, and dispute records may not be deleted immediately if required for compliance or legal reasons.
Consent
By accessing or using HWRS PayTech services, users consent to the collection, processing, storage, use, and sharing of information as described in this Privacy Policy.
Where consent is required for specific processing activities, the Company may collect consent through website, app, form, checkbox, OTP verification, agreement, API onboarding, KYC process, partner onboarding, or other lawful methods.
Users may withdraw consent for non-essential processing where legally permissible. However, withdrawal of consent may affect access to services where such information is necessary for providing services, compliance, security, KYC, transaction processing, or fraud prevention.
Children's Privacy
HWRS PayTech services are intended for users who are at least 18 years of age. We do not knowingly onboard minors as users, retailers, distributors, API partners, white label partners, or merchants.
If we become aware that personal information of a minor has been collected without lawful authorization, we may delete or restrict such information as required by applicable law.
Marketing and Communication
We may use contact information to send:
- Transaction alerts
- OTPs
- Security alerts
- Service updates
- Policy updates
- Support messages
- Settlement updates
- Refund updates
- API notifications
- Partner program communication
- Service promotion
- Offers or business opportunity communication, where permitted
Users may opt out of non-essential marketing communication where such option is available. However, transactional, security, compliance, and service-related communications may continue.
Third-Party Links and Services
HWRS PayTech platforms may contain links, integrations, APIs, redirects, or references to third-party websites, banks, payment gateways, operators, billers, government portals, service providers, or partner platforms.
The Company is not responsible for the privacy practices, content, security, or data handling of third-party websites or services. Users should review the privacy policies of such third-party providers before using their services.
Legal & Regulatory Compliance
The Company complies with applicable Indian laws and regulations including:
- Digital Personal Data Protection Act, 2023
- Information Technology Act, 2000
- Information Technology Rules, where applicable
- Applicable RBI Guidelines
- NPCI Regulations & Operational Standards
- BBPS Guidelines
- Applicable Financial & Taxation Laws
- Applicable KYC and AML requirements
- Banking partner and payment partner compliance requirements
- Any other applicable law, regulation, rule, order, or direction
The Company may disclose information where required by law, court order, government authority, regulator, law enforcement agency, banking partner, payment system operator, or competent authority.
Fraud Prevention and Risk Monitoring
HWRS PayTech may monitor accounts, transactions, devices, IP addresses, API usage, wallet activity, login attempts, and user behavior for fraud prevention and risk management.
The Company may process information to detect:
- Unauthorized access
- Suspicious transactions
- Fake KYC
- Money laundering risk
- Chargeback fraud
- API misuse
- Wallet misuse
- Duplicate accounts
- Network abuse
- Retailer or distributor misconduct
- White label partner network risk
- Cybersecurity threats
Where risk is detected, the Company may restrict account access, hold settlement, freeze wallet, request documents, suspend services, report to authorities, or take legal action.
Data Accuracy
Users must ensure that all personal, business, KYC, bank, contact, and transaction information provided to HWRS PayTech is accurate, complete, and updated.
The Company shall not be liable for loss, failed transaction, refund delay, settlement issue, KYC rejection, account suspension, or legal consequence caused by incorrect, outdated, incomplete, or false information submitted by user or partner.
Account Security
Users are responsible for maintaining security of:
- Login ID
- Password
- OTP
- MPIN
- API key
- Secret key
- Access token
- Device access
- Email account
- Mobile number
- SIM card
- Dashboard access
- White label admin access
- Partner panel access
Users must immediately report unauthorized access, suspicious login, lost device, compromised credentials, or fraudulent activity to HWRS PayTech.
The Company shall not be responsible for loss caused by user negligence, credential sharing, OTP sharing, malware, phishing, SIM swap, device compromise, or unauthorized third-party access.
International Data Transfer
Where technology vendors, cloud providers, API providers, or infrastructure partners are located outside India, data may be processed or stored outside India subject to applicable law, contractual safeguards, and operational requirements.
The Company will take reasonable steps to ensure that such processing is aligned with applicable legal requirements.
Updates to This Privacy Policy
HWRS PayTech may update this Privacy Policy from time to time due to changes in law, regulation, technology, services, business model, partner requirements, or operational practices.
Updated versions may be posted on the website, app, dashboard, or platform. Continued use of HWRS PayTech services after updates shall mean acceptance of the revised Privacy Policy.
Limitation of Liability
HWRS PayTech shall not be liable for:
- Unauthorized access due to user negligence
- OTP, password, MPIN, API key, or device sharing by user
- Third-party cyberattack beyond reasonable control
- Bank, operator, biller, API provider, payment gateway, or third-party data handling
- Malware, phishing, unsafe browser extensions, or compromised devices
- Incorrect information submitted by user or partner
- Independent data misuse by retailer, distributor, master distributor, API partner, or white label partner outside Company control
- Indirect, incidental, consequential, punitive, business, or reputational loss
Contact Information
Company
Hwrs Paytech Private Limited
Mobile
+91 98717 83739
Registered Address
B 1127 iThum, Sector 62, Noida, Uttar Pradesh - 201301, India
Privacy Concerns
privacy@hwrspay.comGrievance Concerns
grievance@hwrspay.comAcknowledgement & Consent
By accessing or using the services of Hwrs Paytech Private Limited, you acknowledge that you have read, understood, and agreed to this Privacy Policy and consent to the collection, processing, storage, sharing, and use of information as described herein.