Last updated: 13 September 2026
This Privacy Policy explains how 1NR, operated by 1NR ("we", "us", "our"), collects, uses, shares, stores and protects your personal data when you use our website, our Android application and the related digital-payment services we provide (collectively, the "Services").
The Services are intended for our registered business partners — retailers, distributors and their authorised team members — who use them to serve their customers with recharge, bill payment, Aadhaar-enabled payment (AePS), money transfer, wallet and reporting features. By creating an account or using the Services, you agree to this Policy. We handle personal data in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP) and other applicable laws, and — for Aadhaar-based services — the regulations of the UIDAI and NPCI.
Depending on how you use the Services, we collect the following categories of personal data:
Aadhaar-enabled Payment System (AePS) services require a fingerprint scan to authenticate a customer. This is handled with care:
We process personal data on the basis of your consent, the performance of the contract under which we provide the Services to you, our compliance with legal and regulatory obligations, and our legitimate interest in keeping the Services secure and preventing fraud. You may withdraw consent as described in Section 9; withdrawing consent may mean we can no longer provide some or all of the Services.
We share personal data only as needed to run the Services, and never sell it. Recipients include:
We do not sell your personal data and do not share it with third parties for their own advertising.
The app requests device permissions only for specific features, and only when needed:
You can review or revoke these at any time in your device settings; some features may then stop working.
We use first-party cookies that are strictly necessary to operate the Services (sign-in sessions, CSRF protection, remember-me and interface preferences). We do not run third-party advertising or cross-site tracking cookies.
Passwords and MPINs are stored only as salted one-way hashes — we never see the plaintext. Sensitive values such as OTPs and API credentials are encrypted (AES-256-GCM). All traffic is served over TLS/HTTPS. Sessions are bound to your device fingerprint and user-agent, repeated bad-MPIN attempts trigger automatic lock-outs, and access to systems is restricted and logged. No method of transmission or storage is completely secure, but we work to protect your data using measures appropriate to its sensitivity.
We keep personal data only as long as needed for the purposes above or as required by law. Transaction records are retained for the period mandated by RBI (currently up to 10 years from the transaction date); KYC records are retained for the period required after account closure; and audit and security logs are retained for as long as needed for compliance and fraud prevention. When data is no longer required, we delete or anonymise it.
Subject to applicable law, you may:
The Services are for business use by adults and are not directed at children. We do not knowingly create partner accounts for, or knowingly collect personal data from, anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
The Services may link to or route you to third-party sites and apps (for example a bank page or a UPI app). Their privacy practices are governed by their own policies, and we are not responsible for them. Please review those policies before providing your data.
Your data is processed and stored on servers located in India. Where any processing occurs outside India, we take steps to ensure it receives protection consistent with this Policy and applicable law.
For any privacy question, request to exercise your rights, or complaint, contact our Grievance Officer at contact@workingninjas.in, or through our contact form. We will acknowledge and address your request within the timelines required by law.
We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, where changes are material, provide a more prominent notice. Your continued use of the Services after an update means you accept the revised Policy.