What they may do · DPDP §6(4)
What PhonePe does with your data
PhonePe uses your behaviour in the app to market to you, advertise to you and tailor which products and offers you are shown. It also routes your KYC identity details and nominee details out to banks, NBFCs and fund houses, and its policy — as published — never says how long any of it is kept.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
PhonePe’s own policy says “to validate, process and/or share your KYC information, nominee details with other intermediaries, Regulated Entities (REs), non-banking financial companies, or AMCs, or financial institutions”
Our summary validates, processes and shares KYC and nominee details with other intermediaries, Regulated Entities, NBFCs, AMCs and financial institutions.
-
Builds an advertising profile of you
They watch what you view, tap and buy, and use it to decide which ads you see.
What this costs you. Your attention gets priced. What you hesitate over becomes a bid — and a profile built to predict you is a profile built to persuade you.
Show me where they say that
PhonePe’s own policy says “to inform you about online and offline offers, products, services, and updates; customizing and improving your experience by marketing, presenting advertising, and offering tailored products and offers”
Our summary uses your information to market, advertise and tailor which products and offers you are shown.
What the policy does not mention
These are uses PhonePe’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Follows you onto other websites and apps
- Keeps your records long-term
- Processes your face or other biometrics
- Trains AI models on your content
Who to write to at PhonePe
PhonePe publishes no Grievance Officer under the IT Rules and no privacy or DPO address at all — privacy requests are pushed to a web form. What it does publish is the RBI-style Nodal structure, and that is the only named human escalation route there is. Use it.
- Nodal Officer
- Ms Deepa Shetty
- Principal Nodal Officer
- Mr Aniket Baheti
- pno@phonepe.com
- Phone
- 080-68727105 Monday to Friday, 10:00 am to 7:00 pm
- Web form
- nodalofficerdesk.phonepe.com
- Privacy requests
- support.phonepe.com The privacy policy routes you here rather than to an address — it says you may write to PhonePe’s Privacy Officer using this link.
- Post
- Office-2, Floor 4, 5, 6, 7, Wing A, Block A, Salarpuria Softzone, Service Road, Green Glen Layout, Bellandur, Bengaluru, Karnataka – 560103
Show me where they publish that
PhonePe’s grievance policy says“Nodal Officer: Ms. Deepa Shetty Principal Nodal Officer: Mr. Aniket Baheti Contact No.: 080-68727105 Email id: pno@phonepe.com Webform: nodalofficerdesk.phonepe.com”
Source phonepe.com/grievance-policy, read on 12 August 2026.
What you can withdraw, and what will outlive the request
PhonePe is a regulated payments company, and that shapes what a request can and cannot reach. The split is worth understanding before you write.
You can stop this now
- Marketing, advertising and tailored-offer messaging.
- The app permissions the policy names — camera, microphone and location — for features you do not use.
- Commercial calls and SMS from registered senders, via 1909 / DND under TRAI’s TCCCPR. That lever is live right now.
This will survive it
- KYC identity and nominee details already passed to banks, NBFCs and fund houses. Each of those has its own statutory retention duty, so withdrawing at PhonePe does not erase the downstream copies.
- Your UPI transaction record, which the payment chain has to retain.
A fair question to put to them. PhonePe’s published policy states no retention period at all — not for any category. Asking them to state one is a reasonable and answerable request, and a good thing to include in your first letter.
The legal position, stated straight. The DPDP Act’s consent-withdrawal right in section 6(4) is not in force today — sections 3 to 17 are on a staged commencement running to 14 May 2027. A request sent now asks for voluntary compliance and puts the date on record, which is what any later escalation rests on. There is no 90-day statutory erasure deadline, and the ₹250 crore figure is the penalty for failing to secure data against a breach — not for ignoring your request.
PhonePe is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does PhonePe do with my personal data?
According to PhonePe's own privacy policy, read on 2026-08-12, it discloses 2 of the six uses we track: shares your data with partners, builds an advertising profile of you.
Can I withdraw my consent from PhonePe?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Does PhonePe track me for advertising?
Yes — PhonePe's published policy discloses this. The exact sentence it is based on is quoted on this page, with the date we read it and a link to the source.
Who do I contact at PhonePe about my data?
PhonePe publishes no Grievance Officer under the IT Rules and no privacy or DPO address. Its named escalation route is the Nodal structure: Nodal Officer Ms Deepa Shetty and Principal Nodal Officer Mr Aniket Baheti, pno@phonepe.com, 080-68727105. Privacy requests themselves are routed to a web form at support.phonepe.com.
Every use above is one PhonePe declared in its own published privacy policy, which we
read on 2026-08-12. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy