BharatOne logo

Privacy Policy

Privacy Policy – BharatOne Services and Affiliates Pvt. Ltd.

Last Updated: May 2026

BharatOne Services and Affiliates Private Limited ("BharatOne", "Company", "we", "our", or "us") values the privacy and security of personal and business information entrusted to us.

This Privacy Policy ("Policy") explains how BharatOne collects, uses, stores, processes, protects, and shares information through its websites, applications, APIs, merchant platforms, software systems, communication channels, and associated services (collectively, the "Services").

This Policy applies to customers, merchants, retailers, agents, distributors, API users, business partners, franchisees, website visitors, and other users interacting with the Services ("Users"). By accessing or using the Services, you acknowledge and consent to the practices described in this Policy.

1. Purpose of this Policy

This Policy is intended to ensure transparency in data handling practices, support responsible and lawful use of information, protect personal and operational information, and explain user rights and responsibilities relating to information shared with BharatOne.

BharatOne's privacy and operational practices are designed to align with applicable Indian legal and regulatory expectations including the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, applicable payment ecosystem requirements, and operational security standards.

2. Information We Collect

Depending on the Services used, BharatOne may collect information including:

Personal Information

  • Name
  • Mobile number
  • Email address
  • Residential or business address
  • Date of birth
  • Profile information
  • Business, merchant, retailer, or franchise information

Verification Information

  • PAN details
  • GST information
  • Government-issued identification details where required
  • Business registration information
  • Bank account information

Transaction and Operational Information

  • Payment and transaction records
  • Recharge and bill payment history
  • Settlement information
  • Support requests and communication records
  • Merchant and retailer operational activity

Technical and Usage Information

  • Device information
  • IP address
  • Browser and operating system details
  • Login and session information
  • Application usage activity
  • API usage logs
  • Device and network identifiers

Certain information may be collected directly from Users, partner integrations, verification providers, government departments, banking partners, payment service providers, or operational systems connected to the Services.

3. How Information is Used

Information collected by BharatOne may be used for purposes including:

  • Account registration and onboarding;
  • Service delivery and transaction processing;
  • Customer support and grievance handling;
  • Fraud prevention and platform security;
  • Operational monitoring and analytics;
  • Verification and authentication;
  • Settlement and reconciliation;
  • Communication and service notifications;
  • Compliance with legal, regulatory, audit, and operational requirements;
  • Improving platform functionality, security, and user experience.

4. Consent and Authorization

By accessing or using the Services, Users consent to:

  • Collection and processing of information reasonably required for providing Services;
  • Verification and authentication procedures where applicable;
  • Operational communication and transaction-related notifications; and
  • Sharing of information with authorized service providers, banking partners, government departments, or ecosystem partners where necessary for service delivery.

Consent may be collected through registration forms, onboarding processes, OTP validation, digital acceptance, electronic confirmations, online applications, or other legally recognized methods.

Users may withdraw certain consent permissions where permitted under applicable laws, subject to operational, contractual, regulatory, or legal limitations.

5. Information Sharing

BharatOne may share information with authorized entities including:

  • Banking and payment partners;
  • Government departments and public authorities;
  • Infrastructure and technology providers;
  • Verification and onboarding partners;
  • Telecom or utility service providers;
  • Fraud prevention and cybersecurity service providers;
  • Legal, audit, taxation, and compliance advisors; and
  • Government agencies or lawful authorities where required under applicable law.

Information is shared only on a lawful, operationally necessary, and need-to-know basis.

BharatOne does not sell personal information to unauthorized third parties.

6. Data Localization

BharatOne stores and processes regulated customer, operational, and payment-related information within India.

The Company follows applicable Indian operational and data localization requirements relevant to digital governance, financial services, payment systems, and digital commerce.

Technology and infrastructure providers engaged by BharatOne are expected to maintain appropriate confidentiality, security, and operational safeguards.

7. Data Retention

BharatOne may retain information for periods reasonably necessary to:

  • Provide Services;
  • Maintain operational and transaction records;
  • Support customer service and grievance resolution;
  • Comply with applicable legal and regulatory obligations;
  • Prevent fraud and misuse; and
  • Maintain audit, compliance, and security records.

Information that is no longer required may be securely deleted, anonymized, or archived in accordance with internal policies and applicable legal requirements.

8. Security Practices

BharatOne implements reasonable administrative, technical, and organizational safeguards intended to protect information against unauthorized access, misuse, alteration, disclosure, or destruction.

Security measures may include:

  • Access controls;
  • Secure authentication mechanisms;
  • Encryption and secure communication protocols;
  • Monitoring and logging systems;
  • API security controls;
  • Network security measures; and
  • Periodic review and testing of systems and operational processes.

Users are responsible for maintaining the confidentiality of passwords, PINs, OTPs, API credentials, and login information, using secure devices and networks, and promptly reporting suspicious activity or unauthorized access.

9. Communication and Notifications

Users may receive:

  • Transaction alerts;
  • OTPs;
  • Onboarding notifications;
  • Service updates;
  • Support responses;
  • Operational or security notifications; and
  • Promotional communications where permitted by law.

Communications may be delivered through SMS, email, telephone calls, WhatsApp, push notifications, or in-application messaging.

Users may opt out of promotional communications where applicable.

10. Cookies and Analytics

BharatOne may use cookies, analytics tools, software development kits (SDKs), session identifiers, and similar technologies to support platform functionality, analytics, fraud prevention, security, and enhancement of user experience.

Users may manage certain cookie preferences through their browser or device settings.

11. Third-Party Services

The Services may integrate with third-party systems, APIs, applications, government platforms, banking systems, or partner infrastructure.

BharatOne is not responsible for the privacy practices of third-party websites, applications, or systems outside BharatOne's operational control.

Users are encouraged to review applicable third-party privacy policies where relevant.

12. User Rights

Subject to applicable laws and operational limitations, Users may request:

  • Access to certain personal information;
  • Correction of inaccurate or incomplete information;
  • Withdrawal of consent where legally permissible;
  • Deletion of personal data where applicable; and
  • Grievance redressal relating to privacy concerns.

Certain requests may be restricted where legal obligations require retention or where fraud prevention, security, or regulatory requirements apply.

13. Grievance Officer

For privacy-related concerns, complaints, or requests, Users may contact:

BharatOne will make reasonable efforts to review and address grievances within applicable legal timelines.

14. Changes to this Policy

BharatOne may update this Privacy Policy periodically to reflect operational changes, technological developments, legal amendments, regulatory requirements, partner obligations, or modifications to the Services.

Updated versions will be published on the official BharatOne website.

Continued use of the Services following publication of changes constitutes acceptance of the revised Policy.

15. Governing Law

This Privacy Policy shall be governed by the laws of India.

Any disputes relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Hassan, Karnataka, India, unless otherwise required by applicable law.

16. Contact Information

For privacy, security, or data-related concerns, please contact: