Reference

How duiwin Handles Your Personal Data

Our Privacy Policy sets out exactly what data we collect when you open an account, how we store it, and the rights you hold over every detail tied…

Data Collected at Account OpeningEncrypted Storage StandardsYour Right to Access & CorrectIndia-Applicable Law CoverageRetention Period Disclosed
duiwin How duiwin Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Our Privacy Team Directly

If you wish to exercise any data right — access, correction, deletion or objection — our dedicated privacy team is reachable through three channels.

Email Our Data Officer Send your request to our Data Protection Officer at the privacy address listed in…
In-Account Support Chat Open the live chat widget from within your logged-in account and select the Privacy…
Formal Written Request For deletion or portability requests that require additional verification, submit a written request through…
DATA HANDLING PRACTICES

How We Protect and Manage Your Data

Every data-handling practice at duiwin is designed so you remain in control of what we hold, for how long, and what we do with it.

Data We Collect at Sign-Up

We collect your name, email address, mobile number and, where required by law, identity documents. Payment method details — such as your UPI VPA or Paytm-linked number — are handled by our payment processor and are never stored on our servers in full.

Cookies and Session Tracking

We use first-party cookies to keep your session active and remember your lobby preferences. Analytics cookies are pseudonymised and never sold to third parties. You can manage cookie preferences from the Privacy section of your account settings at any time.

Account Security Measures

Your account password is stored as a one-way hash that even our staff cannot read. Two-step verification is available and recommended. All traffic between your device and our servers travels over TLS 1.2 or higher, so data in transit is encrypted end-to-end.

Data Retention Schedule

Active account data is held for as long as your account is open plus the legally required period thereafter — typically five years for transaction records under Indian financial regulations. Once that period expires, personal identifiers are deleted or irreversibly anonymised.

Third-Party Data Sharing

We share data only with partners essential to operating the platform — payment processors for UPI, Paytm and PhonePe transactions, identity-verification services and cloud-hosting providers. We do not sell your personal data to advertisers or data brokers.

Requesting Changes to Your Data

You may request to view, correct or delete any personal data we hold by contacting our privacy team via any of the channels in the section above. We will confirm your identity, process the request and notify you of the outcome in writing.

Common Questions About Your Privacy Rights

The questions below address the privacy rights most often raised by people with accounts on our platform. If your question is not covered here, reach our privacy team directly through the contact paths listed above.

We collect your name, email address, mobile number and date of birth at account creation. If you make a payment via UPI, Paytm or PhonePe, the transaction reference is logged, but full payment credentials are held only by the respective payment processor.

Yes. Submit a Subject Access Request through our in-account chat or by emailing the Data Protection Officer. We will compile and send you a copy of your personal data within fifteen working days of verifying your identity.

Log in and visit the Account Details section to update your name, address or contact number directly. For identity documents already submitted for verification, contact our privacy team and we will guide you through the correction process.

You may request deletion of your personal data. We will erase or anonymise identifiers where no legal obligation requires us to keep them. Transaction records tied to financial compliance periods — typically five years — must be retained before deletion is complete.

Some infrastructure and identity-verification partners operate servers outside India. When that happens, we rely on contractual data-protection clauses to ensure your information receives a standard of protection consistent with Indian data-privacy requirements.

Open your Notification Preferences in account settings and toggle off the channels you no longer want — email, SMS or push. Changes take effect within twenty-four hours. Withdrawing consent for marketing does not affect your ability to use the platform.

After account closure, we retain transaction records for the period required by applicable Indian financial law, usually five years. Once that retention period ends, personal identifiers are permanently deleted or irreversibly anonymised from our systems.