Skip to content
Nexdha
How it works What you can pay For business Fees Questions Get the app
Get the app
Back to Nexdha

Privacy policy

Effective 26 August 2026 Last updated 26 August 2026 Version 1.0

This policy explains what Nexdha collects when you use the Nexdha app, why we collect it, who else sees it, how long we keep it and what you can ask us to do with it. It is written to be read rather than to be survived, so if something here is unclear, write to us and we will explain it in plain terms.

Nexdha is operated by Nexdha AI Fintech Private Limited, a company incorporated in India with its registered office at 3rd Floor, Plot No. C-15/1, Secretariat Colony, Thiruvalluvar Nagar, Alandur, Chennai, Tamil Nadu 600016. In this policy, "Nexdha", "we", "us" and "our" mean that company, and "you" means the person using the app. For the purposes of the Digital Personal Data Protection Act, 2023, Nexdha is the data fiduciary for the personal data described below.

This policy applies to the Nexdha Android app published on Google Play as Nexdha: Bills & Payments, to this website, and to any email or in-app support conversation you have with us.

What this policy covers

  • 1. What we collect
  • 2. Device permissions
  • 3. Contacts
  • 4. Why we collect it
  • 5. The basis on which we use it
  • 6. Who we share it with
  • 7. How it is protected
  • 8. How long we keep it
  • 9. Deleting your account and data
  • 10. Your rights
  • 11. Children
  • 12. Changes to this policy
  • 13. Contacting us

1. What we collect

We collect the following categories of information. Some of it you give us directly, some is generated when you make a payment, and some is collected automatically by the app.

Account and profile information

Your name, date of birth, gender if you choose to provide it, the city or address you enter, your profile photo if you upload one, your preferred language, and the username and password or PIN that secure your account. For business accounts we also collect the entity name, constitution, GST number and the details of the authorised person operating the account.

Mobile number and email address

Your mobile number and email address, which we use to create and verify your account, to send one-time passwords, to send payment receipts and to reach you about a transaction. We verify your mobile number by sending a code to it. Verification of your mobile number is necessary to hold an account.

Bank and payment information

The payment instruments you use and the accounts you pay from. For cards, this means the card network, the issuing bank, the card type, the expiry month and year and the last four digits, together with a reference held by our payment gateway that lets a saved card be charged again with your approval. For UPI, this means your UPI handle and the app you approve the payment in. For bank transfers, this means the account number and IFSC you provide.

We do not receive or store your full card number, your CVV or your card PIN, and we do not receive your UPI PIN or your net banking password. Card details are entered on the payment gateway's own page, and those fields never pass through a Nexdha server. Nobody at Nexdha can see them, and no Nexdha employee will ever ask you for them.

Transaction information

For every payment you make: the amount, the date and time, the category, the payment method used, the convenience fee and the tax on it, the status of the payment, the bank reference number such as the UTR, the receipt we issue, and the reason for failure if it fails. We also keep the record of refunds, reversals, chargebacks and any dispute you raise.

Credit-card bill-payment information

Where you use Nexdha to pay a credit card bill, we collect the details needed to route that payment: the card network and issuing bank, the last four digits of the card being paid, the cardholder name as it appears on the statement, the amount due or the amount you choose to pay, and the due date if you enter it or we are able to retrieve it. We use these details to make the payment and to send you reminders you have asked for. We do not use them to assess your creditworthiness, and we do not sell or share them for anybody's marketing.

Receiver and beneficiary information

To pay a bill or an invoice we need to know who is being paid. This means, depending on the category: the biller and your consumer, customer or account number with them; or a beneficiary's name, bank account number and IFSC, or UPI handle; or a landlord's or vendor's name and contact details; or an educational institution and a student identifier. Where the amount is large, or the category calls for it, we may also collect a supporting document such as a rent agreement, fee notice or invoice.

If you give us another person's details so that we can pay them, you confirm that you are entitled to share those details with us for that purpose. We use them only to make and evidence the payment you asked for.

KYC information

To meet identity verification obligations we collect your PAN, and depending on the checks that apply to your account, an officially valid document such as your Aadhaar, passport, driving licence or voter identity card, along with a photograph or selfie for liveness verification. Business accounts also provide their certificate of incorporation or registration, GST registration and the identity documents of the authorised signatory.

Where we collect an Aadhaar number, we hold it in redacted form, so that only the last four digits are visible, and we do not store your Aadhaar biometrics. KYC records are handled as confidential, are available only to staff performing verification and compliance work, and are retained for the period the law requires even after your account is closed.

Device information

The make and model of your device, the operating system and its version, the app version, the device language and region, the screen size, the mobile network operator, whether the device appears to be rooted or emulated, and a device identifier generated for your installation. We use this to make the app work correctly on your device, to diagnose crashes, and to detect fraud, such as one device being used to run many unrelated accounts.

IP address and log information

Each time the app or the website contacts our servers we record the IP address, the date and time, the request made, the response returned, the approximate location derived from the IP address, and the app or browser version. We keep logs of sign-ins, sign-in failures, password and PIN changes, payment attempts, and changes to beneficiaries and account settings. These records are how a disputed transaction gets investigated and how account takeovers get caught.

Location

The app asks for permission to access your device location. We use it to check that a payment is being made from a plausible place, which is one of the stronger signals of fraud available to us; to meet the requirement that we know the location from which financial transactions originate; and to show you billers and services relevant to where you are.

You can refuse the location permission, or withdraw it later in your device settings, and the app will continue to work. If you refuse it, we may fall back on the coarse location derived from your IP address, and a small number of higher-risk payments may need an extra verification step. We collect location only while you are using the app. We do not track your location in the background, and we do not build a location history for advertising.

Camera and photo gallery

The app asks for camera and photo access so that you can complete identity verification: taking a selfie for liveness checking, and photographing or selecting an image of a document such as your PAN card or an officially valid document. You may also use it to attach a copy of a bill or invoice to a payment.

We access only the specific image you capture or choose. We do not scan or index your photo library, and we do not read images you have not selected. If you refuse these permissions you can still use the app, but you will not be able to complete verification steps that require a document or a selfie, and those features will stay unavailable.

Notifications and device identifiers

If you allow notifications, we store the push token issued by Google's Firebase Cloud Messaging for your installation so that we can send you payment confirmations, failure alerts, bill due reminders and security notices such as a sign-in from a new device. We also hold an app-instance identifier and, where available, the Android advertising identifier, which we use for fraud prevention, for measuring whether our own app installs and features work, and for nothing else.

You can turn notifications off in your device settings at any time. We will still send you transaction receipts and important security or legal notices by email or SMS, because those are records of a payment rather than marketing. Marketing messages, where we send them, always carry a way to opt out, and opting out does not affect your account.

2. Device permissions, in one place

These are all the permissions the app asks for, what each is for, and what happens if you say no.

Location
Fraud checks, transaction-origin records and locally relevant billers. Optional. Refusing it leaves the app usable; some higher-risk payments may need an extra verification step.
Camera
Taking a selfie for liveness verification and photographing KYC documents. Optional. Refusing it means verification steps needing a live capture cannot be completed.
Photos and media
Selecting an existing image of a KYC document, a bill or an invoice, and setting a profile photo. Optional, and limited to the file you pick.
Notifications
Payment confirmations, failure alerts, bill reminders and security notices. Optional, and revocable in device settings.
Internet and network state
Required for the app to reach our servers and to tell you when you are offline.

Android asks you for each of these at the moment the feature needs it, and you can review or withdraw any of them later under Settings, Apps, Nexdha, Permissions on your device.

3. Contacts

The Nexdha app does not request access to your contacts and does not read your address book. When you add a beneficiary, you type or paste the details yourself, or select from beneficiaries you have previously saved inside Nexdha. We do not upload your phone's contact list to our servers, we do not use it to find other Nexdha users, and we do not use it for referrals.

If this ever changes we will ask for the permission explicitly, explain what it is used for before you grant it, and update this policy before the feature ships.

4. Why we collect it

We use the information described above for these purposes and no others.

  • To create your account, verify who you are and let you sign in securely.
  • To carry out the payments you instruct, and to settle them to the right beneficiary.
  • To calculate and show the convenience fee and applicable tax before you confirm.
  • To issue receipts, statements and bank references, and to let you export them.
  • To send transaction confirmations, failure notices and bill reminders.
  • To investigate and resolve failed payments, refunds, reversals, chargebacks and disputes.
  • To detect, prevent and investigate fraud, money laundering, account takeover and misuse of the platform.
  • To meet our obligations under Indian law, including identity verification, record keeping, tax and reporting requirements, and to respond to lawful requests from authorities.
  • To provide customer support, and to keep a record of what was asked and answered.
  • To keep the app working: fixing crashes, measuring whether features are used, and improving reliability.
  • To tell you about Nexdha features and offers, where you have not opted out.

We do not sell your personal data. We do not rent or trade it. We do not share it with data brokers, and we do not allow third parties to use it to target advertising at you elsewhere.

5. The basis on which we use it

Most of what we do with your information is done because you have consented to it, by creating an account and by granting the specific permissions described above. Consent is asked for in plain language, is specific to a purpose, and can be withdrawn.

Some of it we are required to do regardless of consent: verifying your identity, keeping transaction records, reporting where the law requires reporting, and retaining what financial and tax law says must be retained. Where a legal obligation applies, withdrawing consent does not remove the obligation, and we will tell you when that is the case.

If you withdraw consent for something that is necessary to run your account, such as verification of your mobile number, we may not be able to keep providing the service, and we will say so rather than quietly degrading it.

6. Who we share it with

We share information only with parties who need it to deliver a payment or to run the service, and only to the extent they need. Every such party is bound by a written agreement that limits them to processing on our instructions, requires them to keep the information confidential and secure, and forbids them from using it for their own purposes.

Payment gateways and card networks
To authorise and capture the payment you make. They receive the card or UPI details you enter on their page, the amount and the transaction reference. Your card details are collected by them, not by us.
Banks and payment partners
To move the money to the beneficiary. They receive the beneficiary details, the amount, the reference and, where required, your name as remitter.
Billers and beneficiaries
The party being paid receives the payment details they need to credit the right account, which normally means your consumer or account number with them, the amount and the reference.
Identity verification providers
To check your PAN or an officially valid document against the issuing source, and to perform liveness checks. They receive the document details and image needed for that check.
Cloud hosting and infrastructure
Our application, databases and backups run on infrastructure operated by cloud providers whose data centres for this service are in India. They store data on our behalf and do not access its contents.
Communication providers
SMS, email and push notification providers, who receive your mobile number, email address or push token and the message to be delivered.
Analytics and crash reporting
To tell us that a screen is failing or a feature is unused. They receive device and usage information and an app-instance identifier, not your card, bank or KYC details.
Professional advisers and auditors
Lawyers, auditors and accountants, where they need access to perform an audit or advise us, under a duty of confidentiality.
Authorities and courts
Where we are compelled by a valid legal process, or where disclosure is necessary to investigate fraud or to protect somebody's safety or rights. We disclose the minimum required.
A future acquirer
If the business is merged, acquired or reorganised, information may transfer as part of it. The acquirer stays bound by this policy until you are told otherwise and given a choice.

Your information is stored and processed in India. If we ever need to transfer it outside India, we will do so only to a country not restricted by the Government of India for that purpose, only with protections at least equal to those described here, and we will update this policy first.

7. How it is protected

No system is perfectly secure and we would rather describe what we actually do than make claims that sound absolute.

  • In transit. All traffic between the app or website and our servers is encrypted using TLS version 1.2 or higher. Unencrypted connections are refused.
  • At rest. Databases and backups are encrypted on disk. Particularly sensitive fields, including KYC document references and identity numbers, are encrypted separately so that access to storage alone does not reveal them.
  • Card data. Full card numbers, CVV and PINs are never stored by us in any form. Card entry happens on the payment gateway's own page, and we hold only a reference and the last four digits.
  • Access control. Access to production data is limited to the small number of staff whose work requires it, is granted by role rather than by person, requires multi-factor authentication and is logged.
  • Authentication of payments. Every payment is approved by you with your bank or in your UPI app. We cannot initiate a payment without that approval.
  • Monitoring. We keep audit logs of sign-ins, permission changes and payment activity, and we monitor for patterns that suggest fraud or account takeover.
  • People. Staff are bound by confidentiality obligations, are trained on handling customer data, and lose access when they change role or leave.

If a breach occurs that affects your personal data, we will notify the Data Protection Board of India and affected users as required by law, describe what happened and what data was involved, and tell you what to do about it. We will not wait until we have a complete picture before telling you something has happened.

Your part matters too. Keep your device locked and its software updated, keep your Nexdha password or PIN to yourself, and never share an OTP with anybody, including anyone claiming to be from Nexdha. We will never ask you for your OTP, your full card number, your CVV or any PIN, whether by call, message or email.

8. How long we keep it

We keep information for as long as your account is open, and after that only for as long as we are required or genuinely need to.

Transaction records
Eight years from the end of the financial year in which the transaction took place, to meet financial record-keeping and tax requirements under Indian law.
KYC records
Five years from the closure of your account, or from the date of the transaction, whichever is later, as required by anti-money laundering rules. Longer if a matter is under investigation.
Account and profile data
While your account is open. Deleted or anonymised within 30 days of account deletion, except what must be retained under the rows above.
Access and server logs
At least 180 days, as required of intermediaries under Indian information technology rules, and up to 12 months for security investigation.
KYC document images
Retained for the KYC period above, then deleted. Held encrypted and accessible only to compliance staff.
Support conversations
Three years from the close of the conversation, so that a recurring problem or a reopened dispute has a history.
Marketing preferences
Kept indefinitely in minimal form, so that an opt-out stays honoured and we do not start messaging you again later.
Disputed or investigated matters
Until the dispute, chargeback, investigation or legal proceeding is concluded, and then for the applicable period above.

When a retention period ends, the data is deleted or irreversibly anonymised. Anonymised and aggregated figures, which cannot be traced back to you, may be kept for reporting and analysis.

9. Deleting your account and data

You can close your Nexdha account and ask us to delete your data at any time, and you do not have to give a reason.

From the app

Open the app, go to Profile, then Settings, then Delete account, and confirm. We will ask you to verify the request with an OTP so that nobody else can close your account.

By email

Write to support@nexdha.com from the email address on your account, or from any address if you include your registered mobile number, with the subject "Delete my account". We will verify that the request is really from you before acting on it.

What happens next

  • We acknowledge the request within 48 hours and confirm what will be deleted and what must be retained.
  • Your account is closed and access is stopped straight away. Any payment already in flight will complete or be reversed, because it cannot be left half done.
  • Your profile, saved beneficiaries, saved payment instruments, uploaded images and marketing preferences are deleted or anonymised within 30 days.
  • Transaction and KYC records are retained for the statutory periods in section 8, in restricted storage used only for legal and regulatory purposes, and are then deleted.
  • Backups are overwritten on their normal cycle, which completes within 90 days of deletion.
  • We confirm in writing when the deletion is done.

Deleting your account does not reverse payments already made, and does not cancel any amount you owe your card issuer or bank for a payment Nexdha has already settled.

If you want your data removed but not your account closed, tell us which parts. We will delete anything not needed to run the account or required by law.

10. Your rights

Under the Digital Personal Data Protection Act, 2023 and Indian information technology rules, you have the following rights. Exercising any of them is free, and we will not treat your account differently for it.

To know what we hold
Ask for a summary of the personal data we hold about you, what we are doing with it and who we have shared it with.
To get a copy
Ask for your data in a portable, machine-readable format. Transaction statements can also be exported from the app at any time.
To correct it
Have inaccurate or incomplete data corrected or completed. Most profile fields you can edit yourself in the app.
To erase it
Have data deleted where it is no longer needed for the purpose it was collected for and no law requires us to keep it. See section 9.
To withdraw consent
Withdraw consent for any processing based on it, including permissions and marketing, as easily as you gave it.
To opt out of marketing
Refuse promotional messages while continuing to receive transaction and security notices.
To nominate
Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
To complain
Raise a concern with us and, if we do not resolve it, take it to the Data Protection Board of India.

To exercise any of these, write to support@nexdha.com. We will acknowledge within 48 hours and respond substantively within 30 days. If a request would take longer, we will tell you why and give you a date. If we cannot do what you have asked, we will explain the reason rather than simply declining.

We may need to verify your identity before acting on a request, because acting on an impersonated request would be the worse outcome. We will ask only for what is needed to be sure it is you.

Please give accurate information and do not impersonate anybody else when making a request. Under the Act, a knowingly false or frivolous complaint can attract a penalty imposed by the Board.

11. Children

Nexdha is for people aged 18 and over. We do not knowingly collect personal data from children, we do not offer accounts to them, and we do not direct any advertising at them. If you believe a child has created an account or that we hold a child's data, write to support@nexdha.com and we will delete it and close the account.

Paying a school or college fee for a child is a payment made by you, the adult account holder. Where a student identifier or name is needed to route the fee, we use it only for that payment and treat it as beneficiary information under section 1.

12. Changes to this policy

We will update this policy when what we do changes. The effective date and version at the top always tell you which version you are reading.

For a material change, such as collecting a new category of data, asking for a new permission, using data for a new purpose or sharing it with a new kind of recipient, we will notify you in the app or by email at least 14 days before it takes effect, so that you can read it and decide. Where the change requires your consent, we will ask for it rather than assume it. Minor corrections and clarifications take effect when published.

Continuing to use Nexdha after a change takes effect means you accept the updated policy. If you do not, you can withdraw the relevant consent or close your account under section 9.

13. Contacting us

For anything about this policy, about your data, or to exercise any of the rights in section 10, write to us. Email reaches us fastest and gives us a record we can act on.

Nexdha AI Fintech Private Limited
Email support@nexdha.com
3rd Floor, Plot No. C-15/1
Secretariat Colony, Thiruvalluvar Nagar
Alandur, Chennai
Tamil Nadu 600016, India

Please mark your email "Privacy" so it reaches the right people quickly. We acknowledge within 48 hours and reply substantively within 30 days.

If you are not satisfied with how we have handled your concern, you may complain to the Data Protection Board of India, established under the Digital Personal Data Protection Act, 2023.

Nexdha

Payments for bills, rent and invoices that a card could not reach on its own.

Pay

Electricity Broadband and mobile Rent and maintenance Education fees Vendor invoices

Company

About Nexdha For business Fees Questions Get the app

Legal and support

Privacy policy Terms of use Refunds and cancellation support@nexdha.com

Registered office

Nexdha AI Fintech Private Limited
3rd Floor, Plot No. C-15/1
Secretariat Colony, Thiruvalluvar Nagar
Alandur, Chennai
Tamil Nadu 600016, India

© 2026 Nexdha AI Fintech Private Limited. All rights reserved.

Nexdha and the Nexdha mark are trademarks of Nexdha AI Fintech Private Limited. Nexdha is a technology platform and not a bank. Settlements are carried out through regulated banking and payment partners.