Reference

How rockbook9 Handles Your Personal Data

Your privacy matters to us, and this page sets out exactly what data we collect when you open and use your rockbook9 account, how we store it, who…

Data collected with your consentStored on secured serversNo sale of personal dataRight to access your recordsContact us to request changes
rockbook9 How rockbook9 Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Us About Your Privacy Rights

If you want to access, correct or delete the personal data we hold on your account, our privacy support team is reachable through the channels below.

Email Privacy Desk Send your data access, correction or deletion request to our dedicated privacy email address.
Live Chat Support Open the live chat widget inside your account dashboard and select the Privacy category.
In-App Help Centre Navigate to Account Settings, then Help, then Privacy in the rockbook9 app or mobile…
HOW WE PROTECT YOUR ACCOUNT

Data Handling, Cookies and Account Security

We apply a layered approach to keeping your data safe — from the moment you enter your UPI details at checkout to the point your withdrawal is confirmed.

Encryption in Transit and at Rest

All data you send to us — including your Paytm reference numbers and PhonePe transaction IDs — travels over TLS-encrypted connections. At rest, account records are stored with AES-256 encryption on infrastructure hosted in secured data centres.

Cookie Use and Your Choices

We use session cookies to keep you logged in, analytics cookies to understand which lobby sections see most engagement, and preference cookies to remember your language and display settings. You can adjust cookie preferences from your account settings at any time.

Account Security Practices

Every login attempt is checked against your registered device fingerprint. Unrecognised devices trigger a verification step sent to your registered mobile number, reducing the risk of unauthorised access even if your password is compromised elsewhere.

Data Retention Periods

We keep your account data for as long as your account remains active and for a defined period after closure, as required by applicable financial and anti-fraud regulations. Transaction records linked to UPI and Paytm payments are retained for the period mandated by law.

Who We Share Data With

We share your data only with payment processors needed to complete your UPI or PhonePe transactions, identity verification providers required by applicable law, and our fraud-prevention partners. We do not share data with advertising networks or data brokers.

Requesting Changes to Your Data

You can request a copy of all data we hold on your account, ask us to correct inaccurate entries, or request deletion where no legal retention obligation applies. Submit requests via email, live chat or the in-app privacy form described in the section above.

Your Privacy Questions, Clearly Answered

The questions below cover the topics account holders in India ask us about most when it comes to their personal data. If your question is not here, reach out through any of the contact paths listed above and we will respond within two business days.

We collect your name, email address, phone number and, where required for identity verification, a copy of a government-issued ID. When you make deposits via UPI or Paytm, we also receive the transaction reference returned by the payment processor.

No. We do not sell, lease or share your personal data with third-party marketers or advertising networks. Data is shared only with processors needed to run your transactions, such as UPI gateway partners and PhonePe settlement services, and with compliance-mandated verification providers.

Retention periods depend on the type of data. Transaction records are kept for the period required under applicable financial regulations. Profile data not subject to a legal retention obligation is deleted within 90 days of a confirmed account closure request.

Yes. Submit a data access request via the in-app privacy form, live chat or email. We will compile your account data — including login history, transaction records and profile fields — and deliver it to your registered email within 30 days of the request.

Use the privacy form in Account Settings or contact our support team via live chat. Specify which data you want corrected or removed. We will action correction requests within 14 days and deletion requests within 30 days, subject to any legal retention obligations.

We use three categories: session cookies for login continuity, analytics cookies to track lobby usage patterns, and preference cookies for display settings. You can view and adjust active cookie categories in Account Settings under Privacy Preferences at any time.

Payment data travels over TLS-encrypted connections and is never stored in full on our servers. UPI handles and PhonePe references are tokenised after the transaction is confirmed, meaning no readable payment credential is held in your account record.