Privacy Policy
Last Updated: 13 August 2026
This Privacy Policy (“Policy”) describes how Mediwin Laboratories Next Private Limited, operating under the brand name “PayCR” (“PayCR”, “we”, “us” or “our”), collects, receives, uses, stores, processes, shares, protects and otherwise handles personal data and other information in connection with the PayCR website, web application and related services (“Services”).
This Policy should be read together with PayCR’s Terms & Conditions and Refund Policy.
This Privacy Policy is intended to be read and applied in accordance with applicable Indian data-protection, information-technology, payment and other laws, including, to the extent applicable, the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000, and applicable rules, regulations, directions and requirements made thereunder.
Where PayCR determines the purpose and means of processing personal data, PayCR may act as a Data Fiduciary for the purposes of applicable data-protection law.
Certain processing may be undertaken on the basis of consent, while other processing may be undertaken where permitted or required under applicable law.
1. Scope of this Policy
This Policy applies to personal data and other information collected or processed through:
- the PayCR website and web application;
- account registration and authentication;
- KYC/KYB and business verification;
- beneficiary or Payee onboarding and verification;
- payment initiation and transaction processing;
- payment links and payment requests;
- settlement, payout, refund and chargeback-related processes;
- customer support and grievance handling;
- communications with PayCR; and
- other PayCR Services made available from time to time.
Capitalised terms not defined in this Policy shall have the meaning given to them in PayCR’s Terms & Conditions.
2. Eligibility and Authorised Use
PayCR’s Transaction Services are intended for persons who are at least 18 years of age and competent to contract.
Where a User accesses PayCR on behalf of a company, proprietorship, partnership, firm, pharmacy, distributor, wholesaler, institution or other business entity, the User represents that the User is duly authorised to act on behalf of such entity.
PayCR is not intended for use by children.
3. Information We May Collect
Depending on the Services used, PayCR may collect the following categories of information.
A. Identity and Contact Information
This may include:
- name;
- mobile number;
- email address;
- date of birth where required;
- residential, postal or business address;
- authorised representative details; and
- other contact or identification information.
B. Business and KYC/KYB Information
PayCR may collect information required to identify and verify a User or business, including:
- Permanent Account Number (PAN);
- GSTIN;
- legal or trade name;
- business constitution;
- incorporation or registration information;
- authorised-person information;
- business address;
- bank-account information;
- identity or address proof;
- business licences or registrations;
- drug licence, trade licence or other sector-specific documentation where applicable; and
- additional documents required for KYC, KYB, AML/CFT, fraud prevention, risk review, banking or Service Provider requirements.
PayCR may request enhanced or additional information where required for verification, compliance or risk review.
4. Payee and Beneficiary Information
Where a User adds, verifies, pays or interacts with a supplier, vendor, beneficiary, customer or other business counterparty, PayCR may receive information including:
- Payee or beneficiary name;
- business name;
- mobile number;
- email address;
- bank-account number;
- IFSC;
- PAN or GSTIN where required;
- business identifiers;
- invoice or payment references; and
- other information reasonably required to identify, verify or make payment to the Payee.
Such information may be provided directly by the Payee or by another User interacting with that Payee through PayCR.
5. Information About Other Persons Provided by a User
A User may provide PayCR with information relating to another individual or business, including a Payee, supplier, vendor, customer, authorised representative or business counterparty.
By providing such information, the User represents that the User has lawful authority to provide such information for the relevant business-payment or verification purpose.
PayCR may use this information to:
- identify or verify the Payee;
- facilitate a requested Transaction;
- contact the Payee for verification or confirmation;
- invite the Payee to complete onboarding;
- obtain declarations, mandates or limited payment collection agency authorisations where required;
- prevent fraud or misuse;
- maintain transaction and audit records; or
- comply with applicable banking, Service Provider or legal requirements.
Where appropriate, PayCR may separately provide such person with a privacy notice or request consent, confirmation or authorisation.
6. Transaction and Payment Information
When a Transaction is initiated or processed through PayCR, we may collect or receive information including:
- Transaction Amount;
- Business Reference;
- invoice, bill, challan, order, supply, account or ledger reference;
- Payer and Payee details;
- payment-method type;
- transaction ID;
- payment-provider reference;
- payout or settlement reference;
- UTR or similar banking reference where available;
- transaction status;
- refund or chargeback status;
- timestamps;
- applicable fees and charges;
- issuer or payment-network information made available to PayCR; and
- other information reasonably necessary to process, reconcile, investigate or support the Transaction.
PayCR may also request or retain supporting transaction documentation where required for verification, audit, reconciliation, fraud prevention, risk review, dispute handling or compliance.
7. Card and Payment Instrument Information
Where card or other sensitive payment credentials are required, such information may be entered directly on the secure interface of the applicable bank, payment aggregator, payment gateway, acquiring institution or other authorised payment Service Provider.
PayCR does not intend to store sensitive card credentials such as the full card number, CVV or card-authentication credentials on its own systems.
PayCR may receive limited payment-related information made available by the applicable Service Provider, including:
- masked card details;
- card or payment-network type;
- issuer information;
- tokenised identifiers;
- payment-method category;
- transaction reference; and
- transaction status.
The processing of sensitive payment credentials by the relevant Service Provider is subject to that Service Provider’s own legal, regulatory, security and privacy obligations.
For avoidance of doubt, any reference in this Policy to PAN for KYC/KYB purposes means Permanent Account Number issued under Indian tax law and not the Primary Account Number of a payment card.
8. Device, Technical and Usage Information
When a User accesses PayCR, we may automatically collect or generate technical information including:
- IP address;
- browser type;
- device type;
- operating system;
- session information;
- login timestamps;
- browser or device identifiers;
- page and feature usage;
- referral information;
- diagnostic information;
- error logs; and
- other technical information reasonably required for security, analytics or operation of the Services.
Such information may be used for fraud detection, security monitoring, troubleshooting, audit, performance improvement and service optimisation.
9. Location Information
PayCR may collect or derive location information for purposes including security, fraud prevention, identity or transaction verification, transaction-risk assessment, audit and compliance.
Location information may include:
- approximate location, inferred from IP address, network or device information; and
- precise device location, where the User expressly grants location access through the browser or device.
Where precise location requires browser or device permission, PayCR will request permission through the applicable interface.
Users may generally withdraw precise-location permission through their browser or device settings. Certain verification, security or Transaction functionality may be restricted where required location information is unavailable.
10. Cookies and Similar Technologies
PayCR may use cookies, local storage, session storage, analytics technologies and similar tools to:
- maintain login sessions;
- authenticate Users;
- remember preferences;
- secure accounts;
- detect suspicious activity;
- understand website usage;
- improve functionality;
- measure performance; and
- support analytics.
Certain cookies and storage technologies may be necessary for the operation and security of the platform.
Where required under applicable law, PayCR may seek consent before using non-essential cookies or similar technologies.
Users may manage cookies through their browser settings, although disabling certain cookies may affect the functionality of PayCR.
11. How We Use Personal Data
PayCR may process information for purposes including:
- creating and administering User accounts;
- authenticating Users;
- conducting KYC/KYB and business verification;
- verifying PAN, GSTIN, bank-account and beneficiary information;
- processing and facilitating Transactions;
- generating or processing payment links and payment requests;
- coordinating settlement, payout, refund or chargeback processes through Service Providers;
- fraud prevention and transaction-risk monitoring;
- AML/CFT and compliance review;
- maintaining transaction, reconciliation and audit records;
- providing customer support;
- investigating complaints, disputes and suspicious activity;
- preventing misuse or prohibited Transactions;
- improving the PayCR platform;
- troubleshooting and analytics;
- sending service and Transaction communications;
- meeting banking and Service Provider requirements;
- complying with applicable law, regulation, court orders or regulatory directions;
- enforcing PayCR’s Terms & Conditions and other agreements; and
- protecting PayCR, Users, Service Providers and third parties against fraud, misuse or unlawful activity.
PayCR may also use anonymised or aggregated information that does not identify an individual for analytics, reporting, product improvement, research and business planning.
12. Notice, Consent and Permitted Processing
Where required, PayCR may provide Users with notice describing the personal data being collected and the purpose for which it is being processed.
Where PayCR relies on consent, such consent may be obtained through an appropriate affirmative mechanism, including:
- checkbox;
- clickwrap;
- OTP-authenticated flow;
- browser or device permission;
- account setting; or
- another legally permissible electronic method.
Consent, where applicable, may be withdrawn through the method made available by PayCR or by contacting PayCR.
Withdrawal of consent does not affect processing lawfully undertaken before such withdrawal.
Certain processing may continue after withdrawal where required or permitted under applicable law, including for:
- transaction completion;
- statutory record keeping;
- KYC/KYB or AML/CFT requirements;
- fraud prevention;
- dispute resolution;
- audit;
- regulatory compliance; or
- establishment, exercise or defence of legal claims.
Where personal data is necessary to provide a requested Service, refusal or withdrawal may prevent PayCR from providing that Service.
13. Sharing of Information
PayCR may share personal data, only to the extent reasonably necessary, with:
- banks;
- acquiring institutions;
- payment aggregators;
- payment gateways;
- card networks;
- payment processors;
- escrow providers;
- trustees;
- payout providers;
- settlement banks;
- KYC/KYB and identity-verification providers;
- PAN, GSTIN or business-verification providers;
- bank-account verification providers;
- fraud-prevention and risk-management providers;
- technology and infrastructure providers;
- hosting or cloud providers;
- communication providers;
- professional advisers;
- auditors and accountants;
- regulators;
- courts;
- law-enforcement authorities;
- government agencies; and
- other Service Providers involved in providing or supporting PayCR Services.
Information may be shared for transaction processing, verification, settlement, payout, refund, reconciliation, dispute handling, security, fraud prevention, compliance, audit or other service-related purposes.
PayCR does not sell personal data to advertisers.
14. Disclosure Required by Law
PayCR may disclose personal data, transaction records or other information where required or permitted under:
- applicable law;
- court order;
- regulatory direction;
- law-enforcement request;
- government requirement;
- banking or payment-system requirement;
- fraud investigation;
- cybercrime investigation; or
- other lawful process.
PayCR may also disclose information where reasonably necessary to protect the legal rights, security or legitimate interests of PayCR, Users, Service Providers or third parties.
15. Business Transfers
If PayCR or Mediwin Laboratories Next Private Limited undergoes or considers a merger, acquisition, restructuring, investment, financing, reorganisation, sale or transfer of business or assets, insolvency process or similar corporate transaction, relevant information may be disclosed to or transferred to the parties involved, subject to applicable law and appropriate confidentiality arrangements.
16. Storage, Processing and Data Localisation
PayCR may store or process information through its own systems or through third-party technology and infrastructure providers.
Payment and Transaction information may also be processed or stored by banks, payment aggregators, payment gateways, acquiring institutions, escrow providers, payout providers and other Service Providers in accordance with legal, regulatory and data-localisation requirements applicable to them.
PayCR will take reasonable steps to ensure that personal data under its control is processed in accordance with applicable Indian data-protection requirements.
Where personal data is processed outside India, such processing shall be subject to applicable Indian law and any restrictions or requirements prescribed by the Government of India from time to time.
17. Data Retention
PayCR may retain personal data for as long as reasonably necessary for purposes including:
- providing the Services;
- maintaining User and Transaction records;
- KYC/KYB and AML/CFT compliance;
- audit and reconciliation;
- fraud prevention;
- dispute and chargeback management;
- tax and accounting;
- statutory or regulatory record keeping;
- legal proceedings; and
- enforcement of contractual rights.
Where the purpose for processing has been completed and continued retention is not required or permitted under applicable law, PayCR may delete, anonymise or securely archive the relevant information.
Closing or deleting a PayCR account does not necessarily result in immediate deletion of all data where continued retention is legally, contractually or operationally required.
18. Security Safeguards
PayCR will take reasonable technical, organisational and operational measures designed to protect personal data against:
- unauthorised access;
- unlawful processing;
- accidental disclosure;
- alteration;
- loss;
- misuse; and
- destruction.
Such measures may include, where appropriate:
- encrypted transmission;
- authentication controls;
- access controls;
- secure infrastructure;
- system logging;
- monitoring;
- restricted administrative access;
- backup and recovery processes; and
- security requirements imposed on Service Providers.
However, no internet-based system can be guaranteed to be completely secure.
Users are responsible for maintaining the confidentiality of OTPs, passwords, authentication credentials and devices used to access PayCR and should promptly report suspected unauthorised access.
19. Personal Data Breach
Where PayCR becomes aware of a personal-data breach affecting personal data under its control, PayCR may take appropriate steps to:
- investigate the incident;
- contain the breach;
- mitigate potential harm;
- secure affected systems;
- coordinate with relevant Service Providers;
- preserve required records; and
- notify affected individuals and competent authorities where required under applicable law.
20. Rights of Users
Subject to applicable law, Users may have rights in relation to personal data processed by PayCR, including the right to:
- obtain information regarding personal data being processed;
- request correction of inaccurate or misleading personal data;
- request updating or completion of incomplete or outdated data;
- request erasure of personal data where legally permissible;
- withdraw consent where consent forms the basis of processing; and
- raise a grievance concerning processing of personal data.
PayCR may undertake reasonable identity or account verification before acting on a request.
A request may be declined or restricted where continued processing or retention is required or permitted by applicable law.
Nothing in this Policy limits any non-waivable right available to a User under applicable law.
21. Accuracy and Responsibilities of Users
Users are responsible for ensuring that personal, business, banking, beneficiary and Transaction information provided to PayCR is:
- accurate;
- complete;
- current;
- lawful; and
- not misleading.
Users should update information where relevant details change.
Where information concerning another person or business is provided to PayCR, the User is responsible for ensuring that such information is provided lawfully and for an appropriate business purpose.
22. Communications
PayCR may send communications necessary for:
- OTP and account verification;
- Transaction processing;
- payment or payout status;
- security and fraud alerts;
- refund or chargeback updates;
- KYC/KYB requirements;
- beneficiary verification;
- service announcements;
- support and grievance handling;
- changes to policies or contractual terms; and
- other administrative or legally required purposes.
Users generally cannot opt out of communications necessary for provision of the Services, security or legal compliance.
Marketing or promotional communications, if undertaken, will be subject to applicable consent and communications requirements.
Users may opt out of promotional communications through the method made available by PayCR.
23. Third-Party Websites, Interfaces and Services
PayCR may link to, integrate with or redirect Users to websites, payment interfaces or services operated by third parties.
Such third parties may independently collect and process personal data under their own privacy policies and terms.
This may include payment aggregators, payment gateways, banks, KYC providers and other Service Providers.
PayCR does not control the independent privacy practices of third-party websites or Service Providers.
Users should review the privacy policy of the relevant third party where appropriate.
24. Account Closure, Correction and Erasure Requests
Users may contact PayCR to request:
- correction or updating of account information;
- account closure;
- withdrawal of consent where applicable;
- erasure of personal data where legally permissible; or
- information concerning personal data processed by PayCR.
PayCR may continue to retain Transaction, KYC/KYB, audit, tax, accounting, fraud, grievance, chargeback, legal or regulatory records where retention is required or permitted by applicable law or Service Provider requirements.
25. Changes to this Privacy Policy
PayCR may update this Policy from time to time to reflect changes in:
- applicable law;
- data-protection requirements;
- PayCR Services;
- banking or payment arrangements;
- technology;
- Service Providers;
- security practices; or
- business operations.
The revised Policy will be published on the PayCR website or communicated through another reasonable electronic method.
Where required under applicable law, PayCR may provide additional notice or obtain fresh consent for materially different processing activities.
26. Governing Law
This Policy shall be governed by the laws of India.
Subject to applicable law, courts having competent jurisdiction at Ambala, Haryana shall have jurisdiction over matters arising in connection with this Policy.
27. Privacy, Support and Grievance Contact
PayCR is owned and operated by:
Mediwin Laboratories Next Private Limited
CIN: U21003HR2025PTC128495
Registered Office:
126, JD Farm, Kalarheri, Ambala Cantt, Haryana – 133001
Support Email: support@paycr.in
Phone: +91 79999 99577
Contact for Queries & Grievances:
Sanjay Kumar Sharma
Phone: +91 92556 66660
Email: grievance@paycr.in
Requests relating to personal-data access, correction, updating, erasure, withdrawal of consent or other privacy concerns may also be sent to the above grievance email.
Where applicable, a User may pursue any further grievance or remedy available under applicable Indian data-protection law after using PayCR’s grievance-redressal mechanism.
