TOTP SEVA PRIVATE LIMITED

Brand: Panpe
Website: https://www.panpe.in
Effective Date: 01 January 2024
Last Updated: 05 January 2024
Version: 1.0.5

Registered Office and Corporate Details

Registered Office: 06, SHREE HARI NIWAS JDA COLONY BASSI, JAIPUR

CIN: U72900RJ2018PTC062608

GSTIN: 08AAGCT9741A1ZB

PRIVACY NOTICE

This privacy notice ("Notice") is being issued to you, in accordance with the provisions of the Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable rules, pursuant to your interaction with TOTP SEVA PRIVATE LIMITED (d/b/a Panpe) ("Company", "we", "us" or "our").

This Notice explains the personal data we process, the purpose of that processing, and the manner in which you may exercise your rights. Please read this Notice carefully.

This Privacy Notice applies only to the Panpe platform operated by TOTP SEVA PRIVATE LIMITED and does not apply to third-party platforms unless expressly stated.

TOTP SEVA PRIVATE LIMITED acts as a Data Fiduciary for the personal data processed through the Panpe platform. The Company is the Data Fiduciary responsible for personal data processed through the Panpe platform.

Contact Point: Nirmal Singh, Grievance Officer, support@panpe.in, +91 7976194272

If the Company is engaged by another entity to process personal data strictly on that entity's behalf and under its documented instructions, the Company may act as a data processor for that limited processing activity.

Important: Panpe does not collect, store, or process end-customer service data on its own website. Our platform is used for merchant onboarding, merchant verification, and redirection to an ITD-authorized website where customer-facing services and customer data are handled under that website's own terms and privacy policy.

1. Definitions

  • Personal Data: any data about an individual who is identifiable by or in relation to such data.
  • Merchant: a service partner, outlet owner, gig worker, or business associate onboarded on the Panpe platform.
  • Platform: the Panpe website, dashboards, and associated systems.
  • Authorized Website: the service platform officially authorized under the applicable programme or arrangement for delivery of PAN-related or other customer-facing services.
  • Processing: any operation performed on personal data, including collection, storage, use, sharing, or deletion.
  • Data Fiduciary: the entity that determines the purpose and means of processing personal data.
  • Consent: free, specific, informed, unconditional and unambiguous permission for processing, where required.

2. What Personal Data We May Collect

2.1. The Company may collect the following personal data from merchants / service partners / gig workers, as applicable, for the purposes detailed in paragraph #3 below:

  • identity related information / documents, such as full name, date of birth, gender, photograph, Proof of Identity (POI), Proof of Address (POA), Proof of Date of Birth (POD), or other Government identification documents;
  • contact information, such as address, telephone number, email address, and emergency contact details;
  • business / outlet information, such as shop name, shop address, branch location, service point details, and other information required to confirm the merchant's fixed place of business;
  • KYC and verification documents submitted by merchants for onboarding and verification;
  • bank account or payment details required for settlement, commission, or payout purposes;
  • communications exchanged with us through website, email, WhatsApp, phone, or any other support channel;
  • website and device usage data, such as access logs, IP address, browser type, pages visited, timestamps, referral information, device identifier, operating system, time zone, language preference, error logs, and crash reports; and
  • such other information as may be reasonably necessary for merchant onboarding, verification, compliance, support, security, or record-keeping.

2.2. We do not store customer service data on Panpe website. Any customer information relating to the service or transaction is handled on the ITD-authorized website to which the customer is redirected.

2.3. The Company generally does not intend its services for persons below 18 years of age.

3. What is the purpose for our collection of Personal Data?

3.1. Your personal data shall be processed in connection with:

  • verification of merchant identity and KYC documents;
  • merchant onboarding, registration, and activation on our platform;
  • confirming the merchant's fixed business location and branch eligibility;
  • assigning or approving the merchant for service delivery from a physical outlet of minimum 10 by 10 size, as required by our operating model;
  • facilitating redirection from Panpe website to the ITD-authorized website where customer-facing services are provided;
  • managing merchant support, settlement, payouts, and communication;
  • maintaining internal records, audit trails, fraud prevention, and compliance with applicable Indian law;
  • responding to queries, grievances, or verification requests;
  • protecting the safety, integrity, and security of our platform and users; and
  • complying with applicable Indian laws, regulations, government scheme documents, court orders, and requests from public authorities.

3.2. The Company may issue an authorization, onboarding approval, empanelment, certificate, or similar merchant credential to eligible Merchants for providing services under the Company's operational model. Such authorization may be suspended, withdrawn, or revoked in accordance with applicable Indian law, Company policy, fraud prevention requirements, regulatory directions, or contractual obligations.

4. Cookies and Similar Technologies

4.1. Panpe website may use cookies and similar technologies for essential functionality, session management, security, analytics, and performance monitoring.

  • Session Cookies
  • Authentication Cookies
  • Security Cookies
  • Analytics Cookies

You may manage or disable cookies through your browser settings; however, doing so may affect certain features of the website.

5. Log Files and Technical Data

5.1. We may collect log and technical data to operate and secure the platform, including:

  • IP address;
  • browser type;
  • device identifier;
  • operating system;
  • time zone;
  • language preference;
  • error logs; and
  • crash reports.

6. Security Measures

6.1. We use reasonable technical and organizational safeguards to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure.

  • Encryption in transit (HTTPS / TLS)
  • Encryption at rest, where applicable
  • Access Control
  • Firewall Protection
  • Secure Servers
  • Audit Logs
  • Need-to-know Access
  • Backups
  • Monitoring

While we implement reasonable security measures, no method of electronic transmission or storage is completely secure.

7. Till when do we retain your personal data?

7.1. Your personal data will be retained by the Company till the fulfilment of the purpose for which it was collected, unless you withdraw your consent or request erasure, subject to legal retention requirements.

7.2. However, irrespective of the above, we may retain personal data, associated logs, and transaction records for such period as may be required under the DPDP Act, applicable rules, tax laws, accounting laws, anti-fraud requirements, or other applicable legal obligations.

7.3. Merchant verification documents and onboarding records may be retained for compliance, audit, dispute resolution, and record-keeping purposes even after merchant disengagement, to the extent permitted by law.

Data TypeRetention
Merchant KYCAs per applicable Indian law and internal compliance requirements
Support TicketsAs required for support, dispute resolution, and audit
LogsAs required for security, troubleshooting, and compliance
PaymentsAs per accounting laws and financial record requirements

7.4. Personal data may be processed or stored outside India only where permitted under applicable Indian law.

8. Sharing of Personal Data

8.1. We may share data with the following categories of third parties, to the extent necessary and permitted by law:

8.2. We do not sell or rent your personal data to third parties.

  • Authorized Website
  • Payment Gateway
  • Cloud Hosting Providers
  • SMS Providers
  • Email Service Providers
  • WhatsApp / Messaging Providers
  • Government APIs
  • OTP Providers
  • Document Verification Vendors
  • Law Enforcement or statutory authorities, when required by law

9. Merchant Responsibility

9.1. Each merchant shall ensure that information submitted to us is accurate, complete, and updated.

9.2. Merchants shall not upload fake documents, forged credentials, or misleading information.

9.3. The Merchant confirms that all documents submitted are genuine and lawfully obtained.

9.4. Merchants shall be responsible for safeguarding their credentials and for any misuse arising from their own acts or omissions.

9.5. In order to maintain service quality, reduce processing errors, improve customer experience, and ensure proper compliance with operational requirements, the Company may periodically contact Merchants through telephone calls, WhatsApp, email, online meetings, training sessions, webinars, or other communication channels.

Such communications may include onboarding assistance, refresher training, policy updates, operational guidance, compliance instructions, customer service best practices, fraud prevention measures, and technical support.

Merchants may also communicate with the Company's authorized staff regarding account-related requests, policy clarification, grievance redressal, account closure, consent withdrawal, or any rights available under applicable Indian law.

9.6. Merchants must keep their login credentials confidential and immediately notify us of any suspected unauthorized access.

10. Breach Notification

10.1. In the event of a personal data breach or security incident, we will take reasonable steps to contain the incident, assess the impact, and notify affected users and authorities where required under applicable Indian law.

11. What are your rights and how can you exercise them?

11.1. Under the DPDP Act and applicable rules, you have the following rights, among others:

  • you have the right to withdraw your consent for processing of your personal data, subject to legal and contractual obligations;
  • you have the right to request a summary of the personal data processing and the identities of data processors with whom your personal data has been shared, where applicable;
  • you have the right to request correction, completion, updating, or erasure of your personal data, subject to applicable Indian law;
  • you have a right to nominate any other individual who shall exercise your rights in the event of your death or incapacity; and
  • you have the right to seek redressal of your grievances in connection with processing of your personal data by us.

11.2. If you wish to exercise any of the rights above, please write to the Company's grievance officer with your specific request (along with the reasons) at the following contact details:

We may verify your identity before processing any privacy-related request.

Name: Nirmal Singh

Designation: Grievance Officer

WhatsApp: +91 7976194272

Email: support@panpe.in

Website: https://www.panpe.in

Working Hours: 10:00 AM to 6:00 PM IST on working days, unless otherwise notified

11.3. Consent may be withdrawn by email, written request, merchant dashboard, support ticket, or WhatsApp.

11.4. We will make reasonable efforts to acknowledge and respond to grievances within the timelines prescribed under applicable Indian law.

11.5. If you are a customer and your data is processed on the Authorized Service Provider Website, your rights and complaints in relation to that customer data should be addressed under that website's privacy notice and grievance process.

11.6. While exercising any of your rights, please ensure that you do not impersonate another person, do not suppress any material information, do not register any false or frivolous grievance or complaint, and furnish only information that is verifiably authentic.

12. Account Suspension and Closure

12.1. We may suspend, restrict, or close a merchant account where required for KYC failure, fraud, duplicate merchant records, non-compliance, legal requirement, security risk, or misuse of the platform.

12.2. Upon merchant exit or closure of the merchant relationship, we will handle data in accordance with applicable retention requirements and deletion requests, subject to legal obligations.

12.3. Suspension or closure shall not affect the Company's right to retain information where required under applicable Indian law.

12.4. Where a Merchant requests closure of the Merchant Account or erasure of personal data under applicable Indian law, the Company shall process such request subject to applicable legal, regulatory, operational, and record-retention requirements.

If, at the time of such request, the Merchant has any pending customer application, pending service request, unresolved grievance, verification process, regulatory requirement, audit requirement, or any service which is under active processing, the Company may defer deletion of the relevant Merchant information until completion of such pending matters.

Upon completion of all pending obligations, and subject to applicable Indian law, the Company shall process the closure of the Merchant Account and deletion of eligible personal data.

12.5. If a Merchant has remained completely inactive for a continuous period of ninety (90) days, including no login activity, no customer request processing, no transaction, and no use of the Company's platform, the Company may, at its discretion, initiate the process of account closure and deletion or anonymization of personal data, subject to applicable legal retention requirements.

Where a Merchant voluntarily requests immediate closure of the Merchant Account and there are no pending customer requests, regulatory obligations, disputes, investigations, or legal retention requirements, the Company may immediately deactivate the Merchant Account and delete the Merchant's eligible personal data in accordance with applicable Indian law.

12.6. The Company may require reasonable identity verification before acting upon any request for account closure, consent withdrawal, or erasure of personal data.

12.7. Where the Company is subject to a legal hold, court order, regulatory investigation, audit, or law enforcement requirement, deletion of relevant personal data may be deferred until such obligation has been fulfilled.

13. Automated Decision Making

13.1. Panpe does not use automated decision making or profiling as a standalone basis for merchant verification or account handling.

14. Use of Authorized Website and Third-Party Processing

14.1. Panpe may redirect merchants or customers to an Authorized Service Provider Website for service delivery, transaction handling, or customer data management.

14.2. Any personal data collected on that authorized website is processed under the terms, notices, and policies applicable to that website. We do not control the privacy practices of that external website unless expressly stated otherwise.

14.3. On Panpe website, our role is limited to merchant onboarding, merchant verification, and facilitation of access to the Authorized Service Provider Website.

14.4. Our website may contain links to third-party websites. We are not responsible for their privacy practices.

15. Legal Basis for Processing

15.1. The processing of personal data by the Company may be based on consent, contractual necessity, legal obligation, and such other grounds as may be recognized under applicable Indian law.

16. Disclaimer

16.1. Panpe only facilitates merchant onboarding, merchant verification, and redirection to the authorized service website.

16.2. Actual customer service and customer-side information management are handled through the authorized service website and its applicable policies.

17. Updates to this Notice

17.1. This Notice may be updated from time to time on account of changes in our data processing practices or to ensure compliance with applicable Indian law. Any material changes shall be communicated to you through email, WhatsApp, text message, or other reasonable means.

18. Governing Law and Jurisdiction

18.1. This Notice shall be governed by the laws of India.

18.2. Courts having jurisdiction over the registered office of the Company shall have jurisdiction over disputes arising from this Notice, subject to applicable Indian law.

18.3. If the registered office is situated in Jaipur, Rajasthan, India, then the courts at Jaipur, Rajasthan, India shall have exclusive jurisdiction, subject to applicable Indian law.

Affirmative Consent

By checking the consent box and clicking "I Agree", you consent to this Privacy Notice.

I acknowledge and confirm that I have read and understood this Notice and I hereby provide my free, specific, informed, unconditional and unambiguous consent for the Company to process my personal data for the purposes stated in the Notice.

I understand I can withdraw my consent at any time by contacting the Company's grievance officer in accordance with this Notice, and that the Company may continue processing where required or permitted by law.