What they may do · DPDP §6(4)

What PhonePe does with your data

PhonePe uses your behaviour in the app to market to you, advertise to you and tailor which products and offers you are shown. It also routes your KYC identity details and nominee details out to banks, NBFCs and fund houses, and its policy — as published — never says how long any of it is kept.

2 of 6 uses declared in their own policy
MEDIUM 4 Read on 2026-08-12 · their policy ↗

What the policy does not mention

These are uses PhonePe’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.

Who to write to at PhonePe

PhonePe publishes no Grievance Officer under the IT Rules and no privacy or DPO address at all — privacy requests are pushed to a web form. What it does publish is the RBI-style Nodal structure, and that is the only named human escalation route there is. Use it.

Nodal Officer
Ms Deepa Shetty
Principal Nodal Officer
Mr Aniket Baheti
Email
pno@phonepe.com
Phone
080-68727105 Monday to Friday, 10:00 am to 7:00 pm
Web form
nodalofficerdesk.phonepe.com
Privacy requests
support.phonepe.com The privacy policy routes you here rather than to an address — it says you may write to PhonePe’s Privacy Officer using this link.
Post
Office-2, Floor 4, 5, 6, 7, Wing A, Block A, Salarpuria Softzone, Service Road, Green Glen Layout, Bellandur, Bengaluru, Karnataka – 560103
Show me where they publish that
PhonePe’s grievance policy says“Nodal Officer: Ms. Deepa Shetty Principal Nodal Officer: Mr. Aniket Baheti Contact No.: 080-68727105 Email id: pno@phonepe.com Webform: nodalofficerdesk.phonepe.com”

Source phonepe.com/grievance-policy, read on 12 August 2026.

What you can withdraw, and what will outlive the request

PhonePe is a regulated payments company, and that shapes what a request can and cannot reach. The split is worth understanding before you write.

You can stop this now

  • Marketing, advertising and tailored-offer messaging.
  • The app permissions the policy names — camera, microphone and location — for features you do not use.
  • Commercial calls and SMS from registered senders, via 1909 / DND under TRAI’s TCCCPR. That lever is live right now.

This will survive it

  • KYC identity and nominee details already passed to banks, NBFCs and fund houses. Each of those has its own statutory retention duty, so withdrawing at PhonePe does not erase the downstream copies.
  • Your UPI transaction record, which the payment chain has to retain.

A fair question to put to them. PhonePe’s published policy states no retention period at all — not for any category. Asking them to state one is a reasonable and answerable request, and a good thing to include in your first letter.

The legal position, stated straight. The DPDP Act’s consent-withdrawal right in section 6(4) is not in force today — sections 3 to 17 are on a staged commencement running to 14 May 2027. A request sent now asks for voluntary compliance and puts the date on record, which is what any later escalation rests on. There is no 90-day statutory erasure deadline, and the ₹250 crore figure is the penalty for failing to secure data against a breach — not for ignoring your request.

PhonePe is one app. How many are on your phone?

Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.

Manage my data with Saaph.in →

Free to check · no account needed · built in India for the DPDP Act

Questions

What does PhonePe do with my personal data?

According to PhonePe's own privacy policy, read on 2026-08-12, it discloses 2 of the six uses we track: shares your data with partners, builds an advertising profile of you.

Can I withdraw my consent from PhonePe?

Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.

Does PhonePe track me for advertising?

Yes — PhonePe's published policy discloses this. The exact sentence it is based on is quoted on this page, with the date we read it and a link to the source.

Who do I contact at PhonePe about my data?

PhonePe publishes no Grievance Officer under the IT Rules and no privacy or DPO address. Its named escalation route is the Nodal structure: Nodal Officer Ms Deepa Shetty and Principal Nodal Officer Mr Aniket Baheti, pno@phonepe.com, 080-68727105. Privacy requests themselves are routed to a web form at support.phonepe.com.

Every use above is one PhonePe declared in its own published privacy policy, which we read on 2026-08-12. Quotes are verbatim; the summary beside each one is ours and is labelled as ours. Nothing here is inferred.

Saaph.in is a DPDP consent and request management platform operated by Ronin Works Private Limited. It is a communication facilitator, not your legal or authorised representative. The DPDP Act 2023 commences in stages up to May 2027, so a request made today asks for voluntary compliance and records the date you asked. Our privacy policy