Where the Stayvora Technologies platform connects to government API infrastructure (such as APIs made available through API Setu) to facilitate a Center's submission of a government service application, we follow the principles below to ensure that access is consent-based, purpose-limited, and secure.
Government API calls are made only after the end customer has given explicit, informed consent for the specific service being requested (see our Customer Consent Policy). No government data lookup or submission is made without a specific, active customer request behind it.
Data retrieved via a government API is used solely to complete the specific service the customer requested (e.g. verifying details for a PAN application) and is never repurposed for an unrelated use, such as marketing or profiling.
We request and process only the specific data fields a government API requires to complete the requested service — never broader access than the transaction genuinely needs, and never speculative data collection "in case it's useful later."
Government API calls are made only through authorized platform functions, by authenticated Center staff acting on a specific, consented customer request. Access to government API credentials and response data is limited to the systems and personnel that need it, consistent with our Security Policy.
Requests made through a government-facing API are logged (requesting Center, timestamp, and the service invoked) to support accountability and investigation, without logging more of the underlying government data than is operationally necessary for that audit trail.
Data obtained through a government API integration is not shared with any party beyond the Center that initiated the request and the systems strictly necessary to complete it, without the customer's further consent.
Government API response data is retained only for as long as necessary to complete and record the requested service, per our Data Retention Policy, and can be deleted on request per our Data Deletion Policy, subject to any legal retention requirement.
Customers may ask the Center they applied through what government data was accessed on their behalf and why, and may request deletion of that data subject to the exceptions in our Data Retention/Data Deletion Policies.
Our use of any government-facing API is subject to the terms, rate limits, and usage conditions set by the API provider (e.g. API Setu, UIDAI, or a specific department), in addition to this policy — see our API Usage Policy.