capital

Privacy Policy

Last Updated: 19th May 2026

This Privacy Policy sets out how airpay capital digital lending application ("App") operated by Airpay Payment Services Private Limited ("Company", "we", "us", or "our") uses and protects any information of a person who visit the site and provide information to the Company (the Visitor / You).

The Company endeavours to safeguard and protect the Visitor's privacy.

The information of customers and others who visit the Company website, we believe it is necessary to post a privacy statement. The information shared with the Company will be treated as private. We also desire to say explicitly that adequate precautions have been taken to protect information relating to customers and their information available with the Company.

Customer confidentiality and privacy are of utmost concern to the Company.

Who is covered by this Policy?

All persons who visit the website and provide information to the airpay online are covered under this Policy. This Policy does not cover the information provided through other modes of communication to the Company.

Consent Management

By using the Company website and services, you provide your consent for the collection and processing of your personal data as described in this Privacy Policy. You may withdraw or manage your consent at any time by contacting us at dpo@airpay.capital We will process your request in accordance with applicable laws.

Information We Collect

We may collect personal and financial information such as your name, address, email, mobile number, PAN, Aadhaar (where permitted), income details, bank account information, and demographic details.
By providing your contact details, you agree to be contacted by the Company through permitted communication channels.

Use of Information

The use/purpose for which any information collected from the Visitor, through the website of the Company, will vary depending upon the circumstances. Broadly, they may comprise all or any one or more of the following purposes (but shall not be restricted to):

  1. To use the information for internal record keeping.
  2. To use the information to improve our products and services.
  3. To use the information for normal business functioning.
  4. To send periodically promotional communication about new products, special offers or other information, which the Company thinks the visitor, may find interesting.
  5. To contact the visitor periodically for market research purposes. The Company may contact the visitor by email/post or by any other suitable mode of communication. We may use the information to customise the website according to the Visitors' interests.

We collect and retain information about you only for specific business purposes. 

We use information to 

  1. Open and administer your accounts and to protect your records and funds. 
  2. Comply with all applicable laws and regulations. 
  3. Understand your financial needs so that we can provide you with quality products and superior services. 
  4. To comply with laws, guidelines and regulations that govern the financial services in the country.
  5. To quote examples we need to obtain passport number for NRI account & PAN for deposit accounts in respect of resident customers for KYC (Know Your Customer Norms Set by Reserve Bank of India) 

Access to the collected information:

The access to the information provided through the Company website would only be given to authorised employees or other Group Companies or affiliates or authorised agents or service provider for normal business purposes, only on need-to-know basis.

The Company may be required, from time to time, to disclose the Visitor's information to Banks or Payment Services Providers or Governmental or judicial bodies or Regulators or any person to whom the Company is under an obligation to make disclosure under the requirements of any law or terms of service agreement between you and the Company .

The Company does not release customer information except as directed by law or as per your mandate. We do not share specific information about customer accounts or other personally identifiable data with non-affiliated third parties for their independent use unless:

  1. The information is provided to help complete a transaction initiated by you.
  2. You request or authorise it.
  3. The disclosure is required by/or directed by law.
  4. You have been informed about the possibility of such disclosure for marketing or similar purposes through a prior communication and have been given the opportunity to decline.

Data Retention and Deletion

The Company retains your personal data only for as long as necessary to fulfil the purposes for which it was collected, including service fulfilment, legal compliance, regulatory obligations, accounting, or reporting requirements. The specific retention period may vary depending on the nature of the information and applicable laws. Once the data is no longer required, we securely delete or anonymize it in accordance with industry best practices. You may also request the deletion of your personal data, subject to any legal or contractual obligations that may require us to retain it for a longer period.

Our security procedures to protect customer information

The Company follows best security practices to help prevent unauthorised access to confidential information about visitors. Company endeavour is to ensure that information is secure. In order to prevent unauthorised access or disclosure, the Company has put in place suitable systems and procedures to safeguard and secure the information that it collects online. The Company may also work with third parties for Web traffic analysis to research certain usage and activities on parts of the Company’s website. The Web analysis software is used to find out more about the Visitor, including the Visitor demographics, behaviour and usage patterns, for more accurate reporting and to improve the effectiveness of Company’s marketing.

Data Breach Notification

In the event of a data breach involving your personal information, Company will notify you and relevant authorities in accordance with applicable laws. Notification will be made without undue delay and will include details of the breach, the data involved, potential consequences, and the steps being taken to mitigate any harm.

Data Security and Protection Measures

The Company is committed to protecting your personal data through robust security controls and best practices. We implement strict access restrictions, ensuring only authorized personnel can access sensitive information on a need-to-know basis. To maintain data integrity, we use validation mechanisms to detect unauthorised alterations. Our systems are protected through firewalls, intrusion detection tools, and regular security audits. We also conduct periodic reviews and assessments to strengthen our security posture and ensure compliance with applicable laws.

Links to other websites:

Company’s website may contain links to other websites of your interest. Please note that once the Visitor opts to link to other websites, Company shall not be responsible for protection of further disclosure of information and this Privacy Policy / statement cease to be applicable for such disclosure of information. The Visitor may therefore, like to exercise caution and look at the privacy statement applicable to those websites.

Similarly, link of Company’s website may be available on various other third-party websites. However, Company shall not be responsible to the contents and material of such other websites. If any person provides its information on other websites, where link of Company’s website or Company’s logo is available, Company shall not be responsible to any acts or omissions committed by third-party websites including but not limited to data theft, misuse of information of such person.

Cross-Border Data Transfers

The Company may transfer your personal data to countries outside of India where our affiliates, service providers, or partners are located. These transfers are carried out in compliance with applicable data protection laws, and we ensure that appropriate contractual, technical, and organisational safeguards are in place to protect your information. Where required, we use standard contractual clauses or rely on regulatory approvals to legitimize such transfers. By using our services and providing your information, you consent to such cross-border transfers of your data, including to jurisdictions that may not have equivalent data protection standards.

However, in compliance with RBI Digital Lending requirements, all customer data shall be stored primarily on servers located within India.

Use of AI and Automated Processing

The Company may deploy artificial intelligence (AI), machine learning models, and automated processing systems to enhance customer experience, perform risk assessment, detect fraud, improve service offerings, and support credit evaluation processes.

Such processing shall be conducted in a fair, transparent, and lawful manner, and shall not result in any unlawful discrimination or adverse impact without appropriate safeguards. Where required under applicable law, explicit user consent shall be obtained prior to such processing.

Use of MCP (Model Control & Processing Frameworks)

The Company may utilize Model Control Policies (MCP) and governed data-processing frameworks to ensure responsible use, monitoring, validation, and auditability of automated systems and data processing activities. These frameworks are designed to ensure compliance with regulatory standards, data protection laws, and internal risk management policies.

Rights of Data Principals

As a Data Principal, you have the following rights regarding your personal data processed by Company , subject to applicable laws:

  • The right to request correction or update of inaccurate or incomplete data.
  • The right to withdraw consent at any time, where processing is based on consent.
  • The right to object to or restrict certain types of processing.
  • The right to request erasure of your personal data (“right to be forgotten”), subject to legal obligations.

To exercise any of these rights, please contact our data protection officer at dpo@airpay.capital.

User Rights and Grievance Redressal

You have the right to access, correct, update, or delete your personal information held by the Company. You may also withdraw consent or object to certain types of data processing, subject to legal and contractual limitations. To exercise any of these rights, please contact our Data Protection Officer (DPO) with details of your request. We will process your request in accordance with applicable laws.

Data Protection Officer

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at dpo@airpay.capital.

IMPORTANT: Company reserves its right to amend the present Privacy Policy at any time and will place such amended Privacy Policy, if any, on its website with a revised “Last Updated” date. We encourage you to review this policy periodically to stay informed about how we protect your information. This Privacy Policy is neither intended to and nor does it create any contractual rights whatsoever or any other legal rights, nor does it create any obligations on the Company in respect of any other party or on behalf of any party. Your continued use of our website or services after any such updates constitutes your acceptance of the revised Privacy Policy.