Last updated: 1 August 2026

Privacy Policy

This policy explains what data we collect, why, how we protect it, and your rights under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Data we collect

Personal identifiers: full legal name, date of birth, PAN, Aadhaar number (masked except last 4), mobile number, email address. Government ID: front and back images, liveness video. Financial data: bank account number (masked), IFSC, UPI ID, TRC20 wallet addresses. Trade data: USDT amounts, INR amounts, UTR references, payment proofs. Device data: IP address, browser fingerprint, device type (for fraud prevention only).

2. Why we collect it

(a) Legal obligation: KYC and AML records are mandatory under PMLA Section 12 and FIU-IND guidelines. We cannot trade without them. (b) Contract performance: executing your trades, generating receipts, and resolving disputes. (c) Fraud prevention: device and IP data used only for fraud and AML detection, not for profiling or advertising.

3. How we protect your data

PAN and government ID images encrypted at rest using AES-256. Bank account numbers stored as masked values only. Private signing keys held in HSM — no plaintext key material in application code or databases. All storage on Indian cloud infrastructure. Payment proofs stored with private signed-URL access — never publicly accessible. Annual penetration tests conducted by CERT-In empanelled auditors.

4. Data sharing

We share data with: (a) KYC verification partners (DigiLocker, video KYC provider) — contractually bound; (b) FIU-IND and law enforcement when legally mandated under PMLA; (c) no data is sold, rented, or shared with advertisers ever.

5. Retention periods

KYC records: 5 years from account closure per PMLA. Trade records: 5 years from transaction date per PMLA. Payment proofs: 5 years. Device logs (IP, fingerprint): 2 years. Chat messages within trades: 5 years (part of audit trail). You cannot request deletion of PMLA-mandated records during the retention period.

6. Your rights (DPDP Act 2023)

(a) Right to access: request a copy of your personal data via privacy@escrowr.in. (b) Right to correction: request correction of inaccurate data. (c) Right to erasure: for data not subject to PMLA retention. (d) Right to grievance redressal: contact our Data Protection Officer at dpo@escrowr.in. We will respond within 30 days.

7. Cookies

We use essential cookies for session management and fraud prevention. Analytics cookies are only set with your explicit consent (per the banner at page load). We do not use advertising or tracking cookies.

8. Contact

Data Protection Officer: dpo@escrowr.in · Privacy queries: privacy@escrowr.in · Registered Office: Mumbai, Maharashtra — 400001.

This Privacy Policy is aligned with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and PMLA 2002 record-keeping obligations. DPO: dpo@escrowr.in