Last Updated: January 1, 2026 | Effective Date: Immediately
At CSA Smart Pay Technologies Pvt Ltd ("we", "us", "our", or "the Company"), we are deeply committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you visit our website, use our services, or interact with us.
By accessing or using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our services.
1. Information We Collect
We collect information to provide better services to all our users. The types of information we collect include:
1.1 Personal Information
- Identity Data: Name, username, date of birth, and government-issued identification (if required for verification).
- Contact Data: Billing address, delivery address, email address, and telephone numbers.
- Financial Data: Bank account details, payment card details, and transaction history (processed securely via PCI-DSS compliant payment gateways).
1.2 Technical and Usage Data
- Device Information: IP address, browser type and version, time zone setting, operating system, and platform.
- Usage Data: Information about how you use our website, products, and services, including clickstream data, page response times, and download errors.
1.3 Communication Data
- Records of your correspondence with us (via email, chat, or support tickets) and your preferences for receiving marketing communications.
2. How We Use Your Information
We use your personal data only when legally permitted. The primary purposes for which we use your data include:
- Service Delivery: To register you as a new customer, process your orders, and manage our relationship with you.
- Billing and Payments: To collect and recover money owed to us and prevent fraudulent transactions.
- Support and Maintenance: To provide technical support, respond to your inquiries, and resolve disputes.
- Improvement: To administer and protect our business and website (including troubleshooting, data analysis, testing, and system maintenance).
- Marketing: To deliver relevant website content and advertisements to you (only with your explicit consent, where required by law).
- Legal Compliance: To comply with legal and regulatory obligations, including the Information Technology Act, 2000 (India) and the EU Digital Services Act (DSA).
3. Legal Basis for Processing (GDPR & Global Compliance)
If you are located in the European Economic Area (EEA) or other regions with comprehensive data protection laws, we rely on the following legal bases to process your data:
- Contractual Necessity: Processing is necessary to perform the contract governing our services.
- Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., network security, fraud prevention), provided your fundamental rights do not override those interests.
- Consent: You have given clear consent for us to process your personal data for a specific purpose (e.g., marketing emails).
- Legal Obligation: Processing is necessary to comply with a legal or regulatory obligation.
4. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our website and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.
- Essential Cookies: Required for the website to function properly (e.g., session management, security).
- Analytics Cookies: Help us understand how visitors interact with our website (e.g., Google Analytics).
- Marketing Cookies: Used to track visitors across websites to display relevant advertisements.
For more details, please refer to our dedicated Cookie Policy.
5. Data Sharing and Third Parties
We do not sell, trade, or rent your personal data to third parties.
We may share your data with trusted third parties only under the following circumstances:
- Service Providers: Third-party vendors who perform services on our behalf (e.g., payment processors, cloud hosting providers, email delivery services). They are bound by strict confidentiality agreements.
- Legal Requirements: If required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
- Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company.
6. Data Security
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. These measures include:
- End-to-end encryption for data in transit (TLS/SSL) and at rest.
- Strict access controls and role-based permissions for our employees.
- Regular security audits, vulnerability assessments, and penetration testing.
- Secure, ISO 27001-certified data centers for physical server protection.
However, please remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.
7. Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including satisfying any legal, accounting, or reporting requirements. Typically, we retain customer data for the duration of the active service relationship plus a statutory period (e.g., 5–7 years for financial records) thereafter.
8. Your Data Protection Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal exceptions.
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Data Portability: Request transfer of your data to another organization in a structured, machine-readable format.
- Right to Object: Object to our processing of your data for direct marketing or legitimate interest purposes.
To exercise any of these rights, please contact us at privacy@csasmartpay.com. We will respond to your request within 30 days.
9. International Data Transfers
Your information, including personal data, may be transferred to—and maintained on—computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. If you are located outside India and choose to provide information to us, please note that we transfer the data to India and process it there, ensuring adequate safeguards are in place.
10. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personally identifiable information from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately so we can take necessary actions to delete such information.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer (DPO) or Privacy Team:
Privacy & Data Protection Team
Monday - Saturday, 9:00 AM - 6:00 PM IST
Mathabhanga, Coochbehar,
West Bengal, India – 736146
This Privacy Policy is an integral part of our Terms and Conditions. Capitalized terms used but not defined herein shall have the meaning assigned to them in the Terms and Conditions.