Privacy Policy

This Privacy Policy explains how Digiway Payment Pvt Ltd collects, uses, shares, and protects information when you use our website, dashboard, APIs, and connected services. We've written it in plain language wherever the law allows. Where it doesn't, we've added explanatory notes alongside the formal text.

1. Introduction

Digiway Payment Pvt Ltd (“Digiway”, “we”, “us”, or “our”) is an India-based private limited company headquartered at 123, D Block, Hisar, Haryana – 125001. We provide payment gateway services, payout APIs, and banking infrastructure to businesses across India.

This Privacy Policy applies to website visitors, merchants using Digiway services, customers making payments through Digiway, payout recipients, and developers using our tools.

We process personal data only for defined purposes, only as long as necessary, and with strict security standards. We do not sell personal data to advertisers or third parties.

By using our services, you agree to this policy.

2. Information We Collect

We collect data in three main contexts: merchants, customers, and website visitors.

Merchant Information

We collect business details such as name, PAN, GST number, registered address, and KYC documents. We also collect bank account details, contact information of team members, and usage data like login activity, API usage, and device information.

Customer Information

When a customer makes a payment, we collect transaction data, payment method details, device and browser information, and fraud-detection signals. Card details are never stored directly; only secure tokens are used.

Website Visitor Data

We collect basic analytics such as pages visited, time spent, and referral sources using privacy-friendly tracking tools.

3. How We Use Information

We use personal data only for legitimate purposes such as processing payments, settling funds, verifying identity, complying with RBI regulations, preventing fraud, improving services, and communicating with users.

We maintain logs and audit trails for compliance and accountability.

We do not use data for advertising, do not sell personal data, and do not allow unauthorized access by employees.

4. Sharing & Disclosure

We may share data only in limited cases:

With banking partners and payment networks to process transactions;
With service providers like cloud hosting and verification vendors under strict agreements;
With regulatory authorities such as RBI, FIU, or law enforcement when legally required;
With auditors for compliance certifications;
In case of mergers or acquisitions, with the new entity under the same protections.

We do not share data for marketing or advertising purposes.

5. Data Security

We follow strong security practices including encryption (TLS 1.3 and AES-256), tokenization of card data, strict access controls, multi-factor authentication, continuous monitoring, and regular security testing.

We maintain PCI-DSS compliance and follow RBI security standards.

6. Data Retention

We retain data only as long as required:

Transaction data is retained for up to 10 years as per RBI rules.
KYC documents are stored for 10 years after account closure.
Activity logs are kept for 7 years.
Webhook logs are retained for 90 days.
Marketing data is kept until you unsubscribe.
Cookies are stored for up to 13 months.

After this period, data is deleted or anonymized.

7. Your Rights

Under Indian data protection laws, you have the right to access your data, correct it, request deletion (subject to legal requirements), and raise complaints.

You can also nominate someone to act on your behalf.

To exercise your rights, email dpo@digiway.com. Requests are handled within 30 days.

Customers making payments should first contact the merchant for data-related queries.

8. Cookies & Tracking

We use cookies for essential functions like login and checkout, analytics, and user preferences.

Essential cookies cannot be disabled, but analytics and preference cookies can be managed through browser settings.

We do not use advertising trackers or cross-site tracking technologies.

9. International Transfers

All payment and KYC data is stored within India as per RBI data localization rules.

Some operational data may be processed outside India under strict legal safeguards such as standard contractual clauses.

10. Children’s Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect data from minors.

If such data is identified, it will be deleted immediately.

11. Policy Changes

We may update this Privacy Policy periodically.

Major changes will be notified at least 30 days in advance. Continued use of services means acceptance of the updated policy.

12. Contact & Data Protection Officer

For any privacy-related queries or complaints, contact:

Digiway Payment Pvt Ltd
Attn: Legal Department

26C, Ram Vihar Amardeep Colony
Kaimri Road, Hisar, India – 125001

Phone: 01662-433515
Mobile: +91-8814041140
Email: info@digiwaypayment.com
Website: www.digiwaypayment.com

© 2026 Digiway. All rights reserved.
  • Android store app
  • iPhone store app