Privacy Policy

Privacy Policy — Magic Yantra

Privacy Policy

Last updated: 09 August 2025

1. Scope & Purpose

This Privacy Policy explains how Magic Yantra collects, uses, stores and shares personal and transactional data when you use our Services (AEPS, DTM, recharge, bookings, bill payments, M-ATM).

2. Information We Collect

  • Identity data: name, date of birth, gender (when required for KYC).
  • Contact data: mobile number, email, postal address.
  • Government IDs: Aadhaar, PAN and supporting docs where KYC is required.
  • Transaction data: transaction ids, amounts, operator responses, settlement info.
  • Device & network data: IP address, device fingerprint, browser, geolocation (if enabled).
  • Support logs: chat transcripts, call recordings (where consented) for dispute resolution.

3. How We Use Data

  • To process and reconcile transactions, provide receipts and settlements.
  • To perform KYC checks, fraud detection, AML screening and regulatory reporting.
  • To send service notifications and transactional alerts (SMS, email, app push — you can opt-out of marketing).
  • To improve product features, monitor uptime, and run analytics (aggregated & anonymized where possible).

We process data where necessary for contract performance, legal compliance (RBI, tax and KYC laws), legitimate interests (fraud prevention, service reliability), or with your consent (marketing, recordings).

5. Sharing & Disclosure

We may share data with:

  • Banks, PSPs and payment networks for settlement & reversals.
  • Operator aggregators, IRCTC, ticketing providers for bookings.
  • Regulatory bodies, law enforcement when legally required.
  • Service providers (cloud hosting, analytics, support), under contractual confidentiality obligations.

6. Data Retention

We retain data as long as necessary for the purposes described, including regulatory retention (varies by law — often 5–8 years for financial records), and to resolve disputes. When retention ends, we securely delete or anonymize data.

7. Data Security

We implement organizational and technical safeguards: TLS encryption in transit, encrypted databases at rest, access controls, regular security reviews and logging. Despite precautions, no system is 100% secure — in the unlikely event of a breach we will follow applicable regulatory notification requirements.