PRIVACY POLICY
SMILE MONEY PVT. LTD.
Registered Office: Office No. 16, Anand Plaza, Above Gangotry Dairy, Raiya Gam Road, Nr. Raiya Circle, 150 Ft. Ring Road, Rajkot – 360007, Gujarat, India
Email: smilemoney2025@gmail.com
Customer Care: +91 70703 73711
Website: https://smilemoney.in
1. INTRODUCTION
Smile Money Pvt. Ltd. (“Company”) provides fintech services including AEPS, DMT, PG, POS, recharge, and bill payments. This Privacy Policy is issued under the Information Technology Act, 2000; IT Rules 2011; RBI Directions; PMLA 2002; UIDAI Act; and all applicable laws to govern the processing of personal and sensitive personal data.
2. DEFINITIONS
‘Personal Data’ includes any data that identifies an individual.
‘Sensitive Personal Data’ includes Aadhaar, biometrics, financial details.
‘Processing’ includes collection, storage, use, transfer, or disclosure.
‘User’ refers to any individual or retailer using Company services.
3. INFORMATION COLLECTED
The Company may collect Personal Information, Sensitive Personal Information, financial information, KYC documents, device identifiers, IP address, and transactional metadata for compliance and service delivery.
4. LEGAL BASIS OF PROCESSING
Processing is conducted under:
- IT Act 2000 (Section 43A)
- IT (Reasonable Security Practices & Procedures) Rules 2011
- Aadhaar Act 2016 & UIDAI Regulations
- Prevention of Money Laundering Act 2002
- RBI Master Directions – KYC (2016)
- Payment & Settlement Systems Act 2007
- Indian Contract Act 1872
5. PURPOSE OF PROCESSING
Data is collected for regulatory compliance, identity verification, fraud prevention, AEPS authentication, DMT processing, payment settlement, retailer onboarding, and customer support.
6. DATA STORAGE & SECURITY
ISO 27001-level security controls, encryption, firewalls, secure APIs, and role-based access are implemented. Biometric data is never stored, as per Aadhaar Act regulations.
7. DATA SHARING & DISCLOSURE
Data may be shared with RBI, NPCI, UIDAI, FIU-IND, GST authorities, banks, payment partners, or law enforcement as legally required.
8. DATA RETENTION
KYC: 5 years (RBI)
Transactions: 10 years (Income Tax Act)
Logs: 90–180 days (CERT-In)
9. USER RIGHTS
Users may request access, correction, or portability of their data. Deletion requests may be declined for records maintained under statutory requirements.
10. COOKIES
Cookies are used for authentication, security, fraud monitoring, and performance analytics.
11. LIABILITY
The Company is not liable for unauthorized access caused by user negligence, malware, or credential sharing.
12. USER RESPONSIBILITIES
Users must safeguard login credentials, avoid public Wi-Fi, maintain updated devices, and report incidents within 24 hours.
13. CHILDREN’S PRIVACY
Services are not intended for persons under 18 years of age.
14. POLICY UPDATES
Updates may be made according to regulatory changes and will be posted publicly.
15. CONTACT INFORMATION
For any privacy-related queries, users may contact the Company via the registered office address or official email.