Paylio Logo
Legal & Policy Documents

Privacy Policy

Paylio – Privacy Policy. Learn how we collect, secure, and protect your personal information on our platform.

Welcome to Paylio, a financial management platform operated by Ignivox Tech Private Limited ("Paylio", "we", "our", or "us"). Paylio is designed to help freelancers and content creators in India manage invoices, wallets, bank accounts, fixed deposits, expense tracking, and creator tools — all from a single mobile application available on Android and iOS. This Privacy Policy explains how we collect, use, store, share, and protect your personal data in accordance with: • The Digital Personal Data Protection Act, 2023 ("DPDP Act") • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") • The Information Technology Act, 2000 • Other applicable Indian laws and RBI guidelines By downloading, installing, or using the Paylio mobile application ("App"), you consent to the collection and use of your personal data as described in this Policy. If you do not agree, please do not use the App.
Under the DPDP Act, 2023, Ignivox Tech Private Limited is the Data Fiduciary responsible for determining the purposes and means of processing your personal data. Registered Office: Ignivox Tech Private Limited Plumeria, 17 CPR Layout Road, Haralur Main Road Opp. Ozone Evergreens, PWD Quarters Apartment HSR Layout, Bengaluru, Karnataka 560102, India Grievance Officer (as required under the DPDP Act, 2023 and IT Rules): Name: Grievance Officer, Ignivox Tech Private Limited Email: grievance@paylioapp.in Postal Address: As above Availability: Monday to Friday, 10:00 AM – 6:00 PM IST (excluding public holidays) The Grievance Officer will acknowledge your complaint within 24 hours and resolve it within 30 days of receipt.
We collect only the data necessary to provide Paylio services. The categories below reflect what our App actually collects, based on its current features. 3.1 Account Information • Full name (as it appears on your PAN card) • Date of birth • Mobile phone number (OTP-verified) • Email address (if provided) • User type: Freelancer or Creator • GST Identification Number — GSTIN (optional, provided during registration) 3.2 KYC and Identity Verification Information Required to access wallet, payment, and withdrawal features: • Permanent Account Number (PAN) • Photograph of the front side of your PAN card • Name as returned by the PAN verification service KYC information constitutes Sensitive Personal Data or Information ("SPDI") under the SPDI Rules, 2011, and is handled with the highest level of care. 3.3 Financial Information • Bank account number, IFSC code, and bank name • UPI IDs • Wallet balance and transaction history • Invoice details: client names, service descriptions, amounts, payment terms, and conditions • Expense records Financial information is treated as SPDI under applicable Indian law. 3.4 Tax Information • GSTIN (if voluntarily provided during registration) 3.5 Creator-Specific Information Applicable to Creator accounts only: • Social media account statistics and analytics • Media Kit content (profile, audience demographics, brand collaboration details) • Content Planner schedules and posts 3.6 Device and Technical Information • Device type, model, and operating system version • App version (currently 1.0.0+1) • Network connectivity status (checked via connectivity_plus for stable transaction processing) • Secure authentication tokens (access token, refresh token, temporary signup token) — stored using Flutter Secure Storage (Android Keystore / iOS Keychain) Note: We do not use third-party advertising SDKs or behavioural analytics trackers. The App does not use browser cookies. 3.7 User-Generated Content • Invoice templates and service descriptions • Payment terms and conditions • Complaint submissions • Profile information
Under the DPDP Act, 2023, we process your personal data on the following lawful bases: • Consent: Collected at account creation (for personal data) and before KYC (for SPDI). You will be presented with a clear, standalone consent notice before any SPDI is collected. • Contractual necessity: To deliver the Paylio services you have requested, including invoice creation, wallet operations, fund withdrawals, and Fixed Deposit facilitation. • Legal obligation: To comply with the Income Tax Act, GST legislation, Prevention of Money Laundering Act (PMLA), and applicable RBI guidelines. • Legitimate interests: For platform security, fraud prevention, and service improvement, where our interests do not override your fundamental data protection rights. Right to Withdraw Consent: You may withdraw consent at any time by contacting grievance@paylioapp.in. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. However, certain features (including wallet, withdrawals, and KYC-gated functionality) may become unavailable upon withdrawal.
We use your information strictly for the purposes for which it was collected: • Creating and managing your Paylio account; authenticating your identity via OTP • Completing KYC verification as required by Indian financial regulations • Processing invoices, payment requests, and wallet transactions • Enabling bank account linking and fund withdrawals to your designated bank account • Facilitating Fixed Deposit plan browsing, FD calculator use, and FD portfolio management • Providing Creator tools: Media Kit builder and Content Planner • Generating financial analytics, expense reports, and transaction summaries • Processing and responding to complaints and support requests • Sending OTPs, transaction confirmations, and critical account notifications • Applying promotional coupons and offers to your account • Detecting, preventing, and investigating fraud or unauthorised access • Complying with legal and regulatory obligations We will not use your personal data for marketing communications without your explicit, separate consent. We do not engage in automated decision-making that produces legal or similarly significant effects without your explicit consent, except where required by law.
We implement technical and organisational measures proportionate to the sensitivity of your data: • Authentication tokens are stored using Flutter Secure Storage, which leverages the device's native secure enclave (Android Keystore on Android; Keychain on iOS) • All API communications are conducted over HTTPS/TLS encrypted connections • PAN card images are transmitted securely and are not stored locally on your device after upload • Sensitive financial data (including bank account numbers) is not stored in plain text • Role-based access controls limit employee access to personal data • Regular security assessments and vulnerability monitoring • Incident response procedures for data breaches Data Breach Notification: In the event of a personal data breach likely to result in risk to your rights or interests, we will notify the Data Protection Board of India and affected users within the timeframes prescribed under the DPDP Act, 2023 and applicable rules. While we implement industry-standard safeguards, no method of electronic transmission or storage is completely secure. Please notify us immediately at grievance@paylioapp.in if you suspect unauthorised access to your account.
Invoice payments and wallet transactions processed through Paylio are handled by authorised third-party payment service providers operating under RBI authorisation (including, but not limited to, Razorpay and other authorised payment aggregators). Paylio does not store complete card numbers, CVV, or UPI PINs on its own servers. Payment credentials are transmitted securely to the relevant payment processor. By using payment features, you acknowledge that your payment data will also be processed subject to the privacy policy of the applicable payment processor.
When you browse, calculate, or invest in Fixed Deposit products via Paylio, your data (including KYC details and bank information) may be shared with the relevant banking partners offering those FD products. Paylio acts as a facilitator and is not the deposit-holding institution. FD products are subject to the respective bank's terms, conditions, and privacy practices.
We do not sell, rent, or trade your personal data. We may share your information only in the following circumstances: • Banking partners: For bank account verification, fund withdrawals, and Fixed Deposit services • Payment processors: For executing invoice payments and wallet transactions (e.g., Razorpay and authorised partners) • KYC verification providers: For PAN card verification as mandated by Indian financial regulations • Cloud infrastructure providers: For application hosting and data storage (data may be stored on servers within or outside India — see Section 13) • Government and regulatory authorities: Where required by law, court order, regulatory direction, or the PMLA • Professional advisors: Auditors, legal counsel, and accountants, under binding confidentiality obligations • With your explicit consent: When you choose to share invoices, media kits, or other documents using the share functionality within the App • Business transfers: In the event of a merger, acquisition, or asset sale, subject to the incoming party assuming equivalent data protection obligations and providing advance notice to you All third-party service providers are contractually required to process your data only for specified purposes and to implement appropriate security measures.
We retain your personal data only for as long as necessary for the purposes described in this Policy or as required by applicable law: • Account data: Retained for the duration of your account and for 3 years following account closure, unless a longer period is required by law. • Financial records and invoice data: Retained for a minimum of 8 years as required under the Income Tax Act, 1961 and GST legislation. • KYC records (PAN data): Retained in accordance with PMLA and RBI guidelines — currently a minimum of 5 years from the date of the last transaction. • Non-essential data: Deleted within 90 days of account deletion. • Technical and security logs: Retained for up to 90 days, then securely deleted. Upon expiry of the applicable retention period, data will be securely deleted or irreversibly anonymised.
As a Data Principal under the DPDP Act, 2023, you have the following rights: • Right to Access: Request a summary of the personal data we hold about you and information on how it has been processed. You can view your profile, transaction history, and bank accounts at any time through the App. • Right to Correction: Update your profile details through the Profile screen in the App, or contact us for corrections not possible in-app. • Right to Erasure: Request deletion of your account and associated data. Certain data must be retained as required by law (see Section 10). • Right to Data Portability: Export and share your invoices and financial documents directly from the App. • Right to Withdraw Consent: Withdraw consent at any time (see Section 4). • Right to Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity, in accordance with the DPDP Act, 2023. • Right to Grievance Redressal: Lodge a complaint with our Grievance Officer (Section 2). If unresolved within 30 days, escalate to the Data Protection Board of India. To exercise these rights, submit your request through the Help and Support section in the App, or email grievance@paylioapp.in. We will acknowledge within 24 hours and respond within 30 days. Identity verification may be required before acting on your request.
Paylio is intended only for individuals aged 18 years or older. During sign-up, users must provide a valid date of birth, and accounts will be restricted if the user is determined to be under 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a person under 18, we will take prompt steps to delete that data. If you believe a minor has registered on Paylio, please contact grievance@paylioapp.in immediately.
Your data may be processed or stored on servers located outside India in connection with our cloud infrastructure and third-party service providers. Where such transfers occur, we ensure appropriate contractual safeguards are in place consistent with the requirements of the DPDP Act, 2023 and any rules notified by the Central Government regarding permissible cross-border data transfers. We will update this section as the DPDP Rules and the Data Protection Board's framework are further operationalised.
We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make material changes, we will: • Notify you via in-app notification or your registered mobile number at least 14 days before the changes take effect • Display a prominent notice within the App • Update the version number and 'Last Updated' date at the top of this Policy Your continued use of Paylio after the effective date constitutes acceptance of the updated Policy. If you do not agree, you may close your account and request deletion of your data.
For general support: Help and Support section in the App, or raise a complaint via the built-in complaint form. Email: support@paylioapp.in For privacy and data protection matters: Email: grievance@paylioapp.in Postal: Ignivox Tech Private Limited, Plumeria, 17 CPR Layout Road, Haralur Main Road, HSR Layout, Bengaluru, Karnataka 560102, India We aim to respond to all queries within 48 business hours. This document has been prepared for production use. Paylio recommends periodic review by a data protection practitioner experienced in Indian fintech law as DPDP Rules are operationalised.

Have questions or concerns about our Privacy Policy?

Our support team is here to assist you with any questions.

Contact: support@paylioapp.in