This policy explains how customer consent is obtained before a Center operator collects, uses, or submits an end customer's personal information through the Stayvora Technologies platform.
Each Center is responsible for informing its customers, at the point of service, what information is being collected and why, and for obtaining the customer's consent before submitting that information for a government or third-party service application. The platform provides the tools (consent checkboxes, recorded confirmations) Centers use to capture this consent.
Where a service involves Aadhaar-based authentication (e.g. eKYC), the platform displays and requires acknowledgement of the applicant's explicit consent statement before proceeding — for example: "I have no objection in authenticating myself and fully understand that information provided by me shall be used for authenticating my identity through Aadhaar Authentication System for the purpose stated above and no other purpose." This consent is specific to the stated purpose and is never reused for an unrelated purpose.
A customer may withdraw consent before an application has been submitted to the relevant authority by informing the Center they are working with. Once an application has already been submitted to a government authority or provider, withdrawal may not be possible for that specific submission, consistent with how the underlying government process itself works.
Records of consent (e.g. a timestamped consent checkbox confirmation) are retained as part of the application record, per our Data Retention Policy, so that a Center can demonstrate consent was obtained if ever required.