What they may do · DPDP §6(4)
What BHIM does with your data
A payments app that shares data with banks, merchants, affiliates and regulators, markets to you via third parties, and keeps records after your relationship ends — but states it stores no biometric or health data.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
BHIM’s own policy says “We may share your personal information in the course of providing services and processing your transactions and other instructions with different persons and entities such as financial institutions, merchants, service providers, other entities participating in a payment system, business associates, government and regulatory authorities, consultants, our affiliates and internal departments.”
Our summary personal information is shared with financial institutions, merchants, service providers, other payment-system participants, business associates, government and regulatory authorities, consultants and the company's own affiliates.
-
Builds an advertising profile of you
They watch what you view, tap and buy, and use it to decide which ads you see.
What this costs you. Your attention gets priced. What you hesitate over becomes a bid — and a profile built to predict you is a profile built to persuade you.
Show me where they say that
BHIM’s own policy says “To send and allow third parties to send offers and promotional materials related to our App and/or products and/or services availed by you on the App;”
Our summary a stated purpose of processing is sending — and allowing third parties to send — offers and promotional materials tied to the products and services the user has availed on the App.
-
Keeps your records long-term
Held on after you stop using the service.
What this costs you. Years after you delete the app, the record is still sitting there — and every year it sits there is another year it can leak.
Show me where they say that
BHIM’s own policy says “We retain the personal information we collect about you on our systems for as long as required for the purposes set out above and based on our retention policies, which may include retention beyond the expiry of our transactional relationship with you for the following reasons: as required to comply with any legal and regulatory obligations to which we are subject; or for the establishment, exercise, or defense of legal claims to the extent permitted under applicable laws.”
Our summary personal information is kept for as long as required under internal retention policies, expressly including retention after the transactional relationship with the user has ended, for legal/regulatory obligations or legal claims.
What the policy does not mention
These are uses BHIM’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Follows you onto other websites and apps
- Processes your face or other biometrics
- Trains AI models on your content
BHIM is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does BHIM do with my personal data?
According to BHIM's own privacy policy, read on 2026-08-14, it discloses 3 of the six uses we track: shares your data with partners, builds an advertising profile of you, keeps your records long-term.
Can I withdraw my consent from BHIM?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Does BHIM track me for advertising?
Yes — BHIM's published policy discloses this. The exact sentence it is based on is quoted on this page, with the date we read it and a link to the source.
Every use above is one BHIM declared in its own published privacy policy, which we
read on 2026-08-14. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy