Last updated: 26 July 2026
Privacy Policy
Paizy (“Paizy”, “we”, “us”) is a technology platform for a flexible digital credit line. This policy explains what personal data we collect, why we collect it, how we protect it, and the choices you have. It applies to paizy.in, the Paizy mobile app, and related services, and is published in accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
What we collect
- Contact details — your name, mobile number, and email address, when you join the waitlist or create an account.
- KYC information — details required by law before credit can be extended, such as your PAN and date of birth. PAN numbers are encrypted at rest and are never displayed back in full.
- Transaction data — draws, repayments, and statements on your credit line, kept as an auditable ledger.
- Device data — device model, operating system, and a push-notification token, so we can secure your account and deliver alerts you enable.
Our website analytics are cookieless and aggregate — we do not use advertising trackers, and we do not sell personal data. Ever.
Why we collect it
- To provide and service your credit line and process payments.
- To verify your identity as required by RBI KYC regulations.
- To send you service notifications (transactions, repayment reminders, account alerts).
- To prevent fraud, secure accounts, and meet legal obligations.
Who we share it with
We share personal data only where it is necessary to run the service:
- Our regulated lending partner — credit on Paizy is provided by an RBI-regulated entity, which requires borrower information to underwrite and hold the loan.
- Service providers — payment processing (Razorpay), authentication and data hosting (Supabase), push delivery (Google Firebase), and error monitoring (Sentry, configured to exclude personal data). Each receives only what its function requires.
- Authorities — where disclosure is required by law or a valid legal process.
Where your data lives
Our application infrastructure and primary database are hosted in Mumbai, India (AWS ap-south-1 region).
How we protect it
- All traffic is encrypted in transit (HTTPS/TLS).
- Sensitive identifiers such as PAN are encrypted at rest with AES-256-GCM.
- Access to production data is restricted, role-based, and logged in an audit trail.
How long we keep it
Waitlist details are kept until launch outreach completes or you ask us to remove them. Account, KYC, and transaction records are retained for as long as your account is active and thereafter for the periods required by RBI and tax regulations, after which they are deleted or anonymised.
Your rights
Under the DPDP Act you may request access to, correction of, or erasure of your personal data, withdraw consent, and nominate another person to exercise these rights. Write to hello@paizy.in — we respond within the statutory timelines. Erasure of records we must retain by law (e.g. loan records) takes effect once the retention period ends.
Grievances
If you have a complaint about how your data is handled, contact our grievance team at hello@paizy.in with “Grievance” in the subject line. We acknowledge within 48 hours and aim to resolve within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India.
Changes to this policy
We will post any changes on this page and update the date above. Material changes will be notified in the app or by email.