1. About this Privacy Policy
This Privacy Policy explains how DEEPFI SERVICES PRIVATE LIMITED (“Deepfi”, “we”, “us” or “our”), operating the consumer brand Setupay (“Setupay”, the “App”, the “Website” or the “Services”), collects, receives, uses, shares, stores, secures and deletes personal data in connection with the Services.
It applies to our consumer-facing activities, including:
- the Setupay mobile application and website;
- account creation, onboarding and identity verification;
- payment initiation, collection, transfer, settlement, refunds and chargebacks;
- customer support, complaints and fraud reporting;
- communications, surveys, product improvement and marketing; and
- related offline, telephone, email, chat, API and partner-assisted interactions.
For purposes of applicable Indian data-protection law, Deepfi is the Data Fiduciary for personal data for which Deepfi determines the purpose and means of processing. Banks, card issuers, UPI applications, payment networks, payment aggregators, merchants, KYC providers and other regulated partners may process some data independently. Their own privacy notices and terms may also apply.
By using Setupay, you acknowledge that you have read this Policy. Where consent is required, we will obtain it through a clear, specific and separate notice or consent request. You may refuse optional processing and withdraw consent as described below. Refusing or withdrawing consent may mean that we cannot provide a particular feature or Service.
2. Key terms
- Personal data means data about an individual who is identifiable by or in relation to that data.
- Processing includes collecting, recording, organising, storing, accessing, using, sharing, analysing, disclosing, restricting, deleting or destroying personal data.
- Data Principal means the individual to whom personal data relates.
- Data Processor means a service provider that processes personal data on Deepfi’s behalf under a contract.
- Payment data means information connected with a payment instruction or payment transaction, such as payer or beneficiary details, account or payment-instrument details, transaction reference, amount, status and time.
3. Personal data we collect
We collect only the data reasonably required for a specified purpose. The exact fields depend on the product, payment method, legal requirements and permissions you choose to grant.
3.1 Data you provide directly
| Category | Examples | When it may be collected |
|---|---|---|
| Registration and profile data | Name, mobile number, email address, date of birth, address, username, profile details, referral code and communication preferences | When you register, maintain an account or contact us |
| Identity and KYC data | PAN, government-ID details, masked Aadhaar or an authorised identity reference, address and date-of-birth information, proof-of-identity or proof-of-address documents, selfie or video-verification information, occupation or other information required for a permitted KYC process | When required for onboarding, KYC, anti-money-laundering, fraud prevention or a regulated payment service |
| Payment and bank data | Bank name, account number, IFSC, UPI ID/VPA, beneficiary details, payment-token details, card network, last four digits and expiry information where applicable | When you link a payment method, initiate a payment, receive funds or request a refund |
| Transaction data | Amount, currency, payer, beneficiary, merchant, biller, payment method, transaction reference, timestamp, status, failure reason, refund, chargeback and dispute information | When a transaction is attempted, processed or disputed |
| Authentication and security data | Login credentials, device-binding information, one-time verification results, security questions and records of account recovery | When you sign in, verify a device or recover an account |
| Support and communications | Messages, emails, chat transcripts, call recordings where permitted and disclosed, attachments, complaint details and feedback | When you contact us, respond to a survey or raise a dispute |
| Consents and preferences | Records of notices shown, consents given or withdrawn, marketing choices, cookie choices and language preference | When you manage permissions or interact with our notices |
| Information about another person | Beneficiary, recipient, emergency contact or other person’s name, mobile number, UPI ID or account details | When you choose to make a payment or use a feature involving another person |
You should provide only information that you are authorised to provide. If you provide another person’s data, you must have a lawful basis or authority to do so and should inform that person where appropriate.
3.2 Data collected automatically
When you use the App, Website or Services, we may collect:
- IP address, approximate location derived from IP, browser type, operating system, app version and language;
- device model, device identifiers, advertising identifier where permitted, SIM or network information where required for security, and device-binding signals;
- login, session, click, page-view, crash, diagnostic, performance and audit logs;
- information about how you use the App, Website and Services;
- security, fraud and risk indicators, including unusual device, login, transaction or behavioural patterns; and
- cookie, SDK and similar-technology data as described in Section 8.
We do not collect precise location, contacts, microphone, camera, files, SMS or other device permissions unless a feature needs them and you grant permission or the permission is otherwise permitted by law. You can manage device permissions through your device settings, although disabling a permission may prevent a feature from working.
3.3 Authentication information we do not ask you to share
Never share your UPI PIN, card PIN, CVV, password or one-time password with a Setupay employee, agent or anyone claiming to provide support. Where authentication is handled by your bank, card issuer, UPI application, payment network or payment processor, the credential may be entered directly into that provider’s secure interface. Setupay may receive only an authorisation result, token, masked information or other confirmation needed to complete the transaction.
3.4 Data received from other sources
We may receive personal data from:
- banks, payment-system participants, UPI applications, card networks, payment aggregators and payment gateways;
- KYC, identity-verification, e-sign, sanctions-screening and fraud-prevention providers;
- merchants, billers, beneficiaries, employers, referral partners or other users who initiate a transaction involving you;
- customer-support, communications, analytics, cloud and security providers;
- publicly available or legally accessible sources; and
- regulators, courts, law-enforcement agencies or government authorities where permitted or required by law.
4. How the complete consumer journey works
The following table describes the normal B2C data lifecycle. A particular product may not use every step.
| Stage | What happens | Typical data used | Main recipients |
|---|---|---|---|
| 1. Discovery and pre-sign-up | You visit a Setupay page, respond to an advertisement, scan a QR code, use a referral link or contact us | Device, log, cookie, campaign and contact data | Setupay, analytics and communications providers |
| 2. Registration | You create an account and verify your mobile number or email | Name, mobile, email, device and verification data | Setupay, OTP/SMS/email providers |
| 3. Eligibility and KYC | We check whether a Service is available to you and complete any legally required verification | Identity, age, address, PAN, government-ID reference, document and verification data | Setupay, authorised KYC providers, relevant regulated partners and authorities where required |
| 4. Linking a payment method | You link a bank account, UPI ID, card, wallet or other payment method | Account, IFSC, UPI, token, masked card and device-binding data | Relevant bank, issuer, UPI/payment participant, network, gateway or processor |
| 5. Payment initiation | You confirm a payment, transfer, collection or bill payment | Payment instruction, beneficiary/merchant, amount, timestamp, device, authentication result | Payment participants, bank, network, aggregator/gateway, merchant or biller |
| 6. Risk and authentication | We and our partners validate the instruction and identify suspicious or unauthorised activity | Transaction, device, account, IP, location and fraud signals | Setupay, fraud/security providers and relevant payment participants |
| 7. Processing and settlement | The transaction is authorised, declined, settled, reversed or held for review | Payment data, status, ledger, settlement and reconciliation data | Banks, payment-system participants, merchants/billers, processors and auditors |
| 8. Notifications | We send receipts, alerts, security messages, status updates or service notices | Mobile, email, device token, transaction and message data | Setupay and SMS, email, push or WhatsApp providers, where used |
| 9. Customer support and disputes | You ask a question, report fraud, request a refund or raise a chargeback | Account, transaction, communication, verification and complaint data | Setupay, relevant payment partner, merchant/biller, support provider and authorities where required |
| 10. Account closure and retention | You close the account or stop using the Service; we delete, anonymise or retain data according to this Policy and applicable law | Account, consent, transaction, KYC, legal, fraud and audit records | Setupay, processors and authorities where legally required |
5. Why we use personal data
We may process personal data for the following specified purposes:
- To provide the Services: create and administer your account; authenticate you; process payments; maintain a ledger; send receipts and alerts; provide refunds; resolve failures; and deliver other features you request.
- To complete KYC and legal checks: verify identity, age and eligibility; comply with applicable payment, anti-money-laundering, sanctions, tax, accounting, record-keeping and other legal or regulatory requirements; and respond to lawful requests.
- To protect accounts and transactions: detect, prevent and investigate fraud, money laundering, unauthorised access, cyberattacks, misuse, policy violations and other security incidents; secure our systems; and protect users, partners and the public.
- To provide support and grievance redressal: verify you, investigate complaints, manage disputes, record support interactions, communicate status and improve response quality.
- To maintain and improve the Services: troubleshoot, test, measure performance, conduct internal reporting, develop features, understand usage and create aggregated or de-identified insights. We do not use de-identified information to identify you again except where permitted for testing or security.
- To communicate with you: send service, security, legal and transaction messages. These messages are necessary for the account or transaction and may continue even if you opt out of marketing.
- To send optional marketing: send offers, product updates, surveys or partner communications where permitted and, where required, after obtaining your consent. You may opt out at any time.
- To exercise or defend legal rights: establish, exercise or defend claims; manage audits; enforce our agreements; preserve evidence; and comply with orders or proceedings.
- To manage business changes: conduct a merger, acquisition, restructuring, financing, sale of assets or transfer of a Service, subject to lawful safeguards and appropriate notice.
We will not use personal data for a new or incompatible purpose without giving an appropriate notice and obtaining consent where required. We do not sell your personal data.
5.1 Legal permission for processing
Depending on the purpose, we process personal data based on your consent, your voluntary request for a Service, performance of the requested transaction, compliance with law, protection of users and systems, prevention of fraud, legal claims, or another lawful basis permitted by applicable law. We will not make consent a condition for processing data that is not necessary for the relevant Service, and optional marketing consent will be separate from Service consent.
6. Sharing and disclosure
We share personal data only when necessary for a stated purpose, with your direction, with your consent where required, or as permitted or required by law. Recipients may include:
- Payment and financial participants: banks, account providers, UPI/payment-system participants, payment aggregators, payment gateways, card issuers, card networks, wallet issuers, merchants, billers and beneficiaries to authorise, route, settle, reconcile or refund a payment.
- Identity and compliance providers: KYC, identity, document, e-sign, sanctions, AML and fraud-screening providers.
- Technology and operations providers: cloud hosting, databases, security, authentication, device intelligence, analytics, customer support, call-centre, communications, notification, email, SMS, push and incident-response providers.
- Professional advisers and auditors: lawyers, accountants, auditors, insurers, consultants and other advisers who are bound by confidentiality or professional duties.
- Group companies and transaction counterparties: Deepfi group entities or parties involved in a corporate transaction, subject to confidentiality and security controls.
- Government and legal recipients: regulators, courts, law-enforcement, tax authorities, dispute-resolution bodies, payment-system authorities and other persons where disclosure is legally required, necessary to prevent or investigate fraud or crime, or needed to protect rights, safety or property.
- Recipients you choose: any merchant, biller, beneficiary or other person you direct us to pay or notify.
Our Data Processors may process personal data only for contracted purposes and on our instructions. Some banks, payment-system participants, merchants and regulated partners may be independent Data Fiduciaries and will process data under their own policies.
We do not allow third parties to use your personal data for their own direct marketing through Setupay unless you have been separately informed and have provided the consent required by law.
7. Consent, withdrawal and communication choices
7.1 Consent
Where we rely on consent, the consent request will be clear, specific, informed, limited to data necessary for the stated purpose and presented separately from unrelated terms. We will maintain records of the notice, consent, time, version and channel.
You may withdraw consent through the same or an equally easy method used to give it, including through Panel → Profile → Privacy & Data → Manage consent or by contacting privacy@setupay.co.in. Withdrawal does not affect processing lawfully completed before withdrawal. We will stop or arrange for our processors to stop the relevant processing within a reasonable time unless continued processing is required or authorised by law, required to complete a transaction, needed for security, or necessary for a legal claim.
If you withdraw consent that is necessary for a Service, we may be unable to provide or continue that Service. We will explain the consequence where reasonably practicable.
7.2 Marketing choices
You can opt out of marketing email, SMS, push, phone or WhatsApp messages by using the unsubscribe or opt-out instruction in the message, changing your App settings, or contacting us. We may retain a limited suppression record so that we do not send marketing after you opt out. You cannot opt out of essential account, security, legal or transaction messages.
8. Cookies, SDKs and similar technologies
We and our service providers may use cookies, mobile SDKs, pixels, local storage and similar technologies for:
- essential login, security, fraud prevention, session management and core functionality;
- remembering preferences and language;
- analytics, crash reporting and performance measurement; and
- advertising or campaign measurement, where permitted and after obtaining any consent required by law.
You can manage cookies through your browser and, where available, through our cookie banner or privacy settings. Mobile operating systems may provide controls for advertising identifiers, notifications and permissions. Disabling essential technologies may affect the availability or security of parts of the Services.
Cookie/SDK list: essential session and security cookies set by the Setupay website and Panel (session duration); optional analytics cookies (up to 13 months) that can be declined through the cookie banner; no third-party advertising cookies are set on the Setupay website.
9. Automated checks and profiling
To operate a secure payment service, we may use automated rules, device intelligence, transaction monitoring, sanctions screening, fraud models and risk scores. These tools may identify a transaction or account for additional verification, delay, decline, restrict or suspend an activity, or require human review.
These tools use signals such as transaction details, device and network information, account history, authentication results and information received from payment or fraud-prevention partners. They are used for security, compliance and service operations, not to sell your personal data. If you believe a decision is incorrect, contact Setupay Customer Support at support@setupay.co.in or +91 79866 29866 with the transaction or case reference. We will review the matter and respond under our applicable process and law. We will not use solely automated processing to make a decision where prohibited by applicable law.
10. Security safeguards
We maintain reasonable technical and organisational safeguards proportionate to the risk and nature of the personal data. Depending on the system and data involved, these may include:
- encryption in transit and at rest;
- tokenisation, masking and secure handling of payment and identity references;
- access controls based on role and need, authentication, privileged-access controls and personnel confidentiality obligations;
- monitoring, logging, alerting, vulnerability management, testing and incident response;
- secure development, backups, disaster recovery and business-continuity controls;
- vendor due diligence and contractual security obligations; and
- privacy, security and fraud-awareness training.
No method of transmission or storage is completely secure. You are responsible for protecting your device, password and authentication information and for notifying us immediately of suspected loss, compromise, unauthorised access or unauthorised transactions. Setupay support will never ask for your UPI PIN, card PIN, CVV or OTP.
11. Data storage and international transfers
We retain personal data on systems operated by Deepfi and its service providers. Unless a product notice says otherwise, our primary customer records are intended to be hosted in India.
Where RBI, NPCI, card-network, payment-system or other applicable requirements prescribe India-only storage or a particular handling method for payment-system data, we will follow those requirements. Payment data may include end-to-end transaction details, customer and beneficiary account information, payment credentials or tokens, and transaction information. If a permitted payment-processing activity occurs outside India, the data will be handled, returned, stored and deleted in accordance with applicable requirements.
Some non-payment technology or support providers may process limited data outside India. Before using such providers, we will apply the transfer restrictions, contractual safeguards, security controls and other requirements applicable to the relevant data and Service. We will not transfer personal data to a country or recipient where the transfer is prohibited by applicable Indian law or a binding regulatory direction.
12. Retention and deletion
We keep personal data only for as long as it is needed for the specified purpose, a lawful business or security purpose, or a period required by law, regulation, payment-system rules, tax/accounting requirements, dispute procedures or legal claims. When it is no longer required, we delete it, anonymise it or securely isolate it.
The following principles apply:
- Active account data: retained while your account or requested Service is active and for a reasonable period needed for account administration and support.
- KYC, AML, identity, payment, settlement and tax records: retained for the period required by applicable law, regulatory directions, audit, dispute, chargeback, fraud-prevention and record-keeping requirements. These records may remain after account closure.
- Support, complaint and dispute records: retained for as long as reasonably necessary to investigate, resolve, audit and defend the matter and to meet applicable legal requirements.
- Security, access, fraud and processing logs: retained for the period required for security monitoring, investigation, remediation, audit and applicable law.
- Consent and marketing records: retained to demonstrate your choices and to honour opt-outs; marketing data is not retained longer than necessary for the relevant campaign or relationship.
- Backups: deleted or overwritten under our backup and disaster-recovery cycle, subject to security and legal requirements. Backups are not used for ordinary marketing.
If you request erasure or close your account, we will delete or anonymise data that is no longer required. We may retain a limited record where necessary to comply with law, complete or reconcile a transaction, prevent fraud, resolve a dispute, enforce an agreement, maintain suppression lists or establish, exercise or defend a legal claim. We will restrict access to retained data and will not use it for unrelated purposes.
If a specified purpose ends and no legal retention exception applies, we will take reasonable steps to delete the relevant data and cause our processors to do the same.
13. Your rights and how to exercise them
Subject to applicable law and any lawful exceptions, you may:
- Request access: ask for a summary of personal data we process about you, the processing activities and the Data Fiduciaries and Data Processors with whom we have shared it, together with a description of the data shared where applicable.
- Request correction, completion or updating: ask us to correct inaccurate or misleading data, complete incomplete data or update changed data.
- Request erasure: ask us to erase personal data where retention is not necessary for the specified purpose or compliance with law.
- Withdraw consent: withdraw consent where consent is the basis of processing.
- Raise a grievance: complain about our processing of your personal data or our response to a rights request.
- Nominate another individual: nominate a person to exercise your rights in the event of death or incapacity, in the manner permitted by law.
13.1 Rights-request process
Submit a request using one of the following channels:
- Privacy and rights email: privacy@setupay.co.in
- In-App route: Panel → Profile → Privacy & Data → Raise a privacy request
- Postal address: Office no 3 Kundan complex railway road panipat haryana 132103
- Customer support: +91 79866 29866 | https://www.setupay.co.in/contact.html | Monday to Saturday, 7:00 AM – 10:00 PM IST
To protect your account, we may ask for reasonable information to verify your identity and locate your records, such as your registered mobile number, email address, customer ID, application/reference number or transaction reference. Do not send your full Aadhaar, UPI PIN, card PIN, CVV or OTP by email or chat. If identity evidence is necessary, we will tell you how to provide it securely.
We aim to acknowledge requests promptly and normally respond within 30 days. We will respond within the maximum period prescribed by applicable law, including any 90-day period that applies to a rights or grievance request under the Digital Personal Data Protection framework. If a request is refused or limited, we will explain the reason unless the law prevents us from doing so.
If you are not satisfied, escalate the matter to our Grievance Officer or authorised privacy contact at grievance@setupay.co.in. You may pursue any further remedy available under applicable law, including approaching the relevant regulator, payment-system grievance mechanism or the Data Protection Board of India after using our internal grievance process, where applicable.
14. Children and persons with disabilities
Unless a particular Setupay product expressly states otherwise, the Services are intended for individuals who have completed 18 years of age. Do not create an account or use an age-restricted Service if you are under 18.
If we offer a Service to a child, or if we process a child’s personal data, we will obtain verifiable consent from a parent or lawful guardian where required, will not knowingly undertake processing likely to harm the child, and will not undertake tracking, behavioural monitoring or targeted advertising directed at children except where permitted by applicable law.
Where a person with a disability has a lawful guardian and the law requires guardian involvement, we will use the required verification and consent process. If you believe a child’s data has been provided to us improperly, contact privacy@setupay.co.in.
15. Third-party websites, apps and payment pages
The Services may contain links, redirects, SDKs or integrations operated by third parties. A bank, UPI application, card issuer, wallet, merchant, biller, payment gateway or other third party may collect and process data under its own privacy policy. We are not responsible for the privacy, security or content practices of an independent third party. Review the applicable notice before submitting information to it.
16. Personal data breaches
If we become aware of a personal data breach affecting you, we will assess and respond in accordance with applicable law. Where notification is required, we will notify affected individuals without undue delay through a registered communication channel or user account, explain what happened and the likely impact to the extent known, describe the steps taken or proposed, tell you what you can do to protect yourself, and provide a contact for questions. We will notify the relevant authority or Board in the manner and time required by law.
17. Changes to this Policy
We may update this Policy when our Services, data practices, laws or regulatory requirements change. We will publish the updated version with a new “Last updated” date. If a change is material or consent is required, we will provide additional notice or obtain fresh consent as required by law. You should review this Policy periodically.
18. Contact us
DEEPFI SERVICES PRIVATE LIMITED — Setupay Privacy Team
- Privacy contact
- Data Protection & Privacy Team
- privacy@setupay.co.in
- Grievance contact
- Grievance Officer, DEEPFI SERVICES PRIVATE LIMITED
- grievance@setupay.co.in
- Customer support
- +91 79866 29866 | https://www.setupay.co.in/contact.html
- Registered office
- [Complete registered office address of DEEPFI SERVICES PRIVATE LIMITED]
- Website
- https://www.setupay.co.in
- Languages available
- English (Hindi translation available on request)
When writing to us, use the subject line “Setupay Privacy Request” or “Setupay Privacy Grievance” and include your registered mobile number or customer/reference ID. Do not include passwords, UPI PINs, card PINs, CVVs or OTPs.
