Where a Center service flow involves retrieving a document from DigiLocker (India's national digital document wallet), Stayvora Technologies follows the principles below.
A document is retrieved from a customer's DigiLocker account only after that customer has explicitly authorized the retrieval through DigiLocker's own consent flow at the time of the request — the platform never accesses a customer's DigiLocker documents without their direct, in-the-moment authorization.
The customer authenticates directly with DigiLocker's own sign-in and consent screen (not a Stayvora-controlled login) — the platform never sees or stores the customer's DigiLocker credentials, and authentication happens entirely within DigiLocker's own secure flow.
Retrieved documents are used solely to complete the specific service application the customer initiated (for example, using a DigiLocker-issued Aadhaar or educational certificate as supporting proof for an application), consistent with the purpose the customer consented to.
A retrieved document is processed only for the single service request it was fetched for. Where a document is only needed transiently (for example, to read a specific field for validation) rather than to be retained as part of the permanent application record, it is processed in memory and not separately persisted beyond that immediate use.
DigiLocker-sourced documents are not used for any purpose beyond the service application they were retrieved for, and are not shared with any party other than the Center processing that application and, where the service genuinely requires it, the relevant government authority.
Documents retained as part of an application record are stored securely, per our Data Retention Policy, and are subject to the same access controls as any other customer document on the platform — never copied or stored outside that authorized application record.
Documents retrieved directly from DigiLocker carry DigiLocker's own digital signature/verification, which the platform relies on as evidence of authenticity — we do not alter or reissue a DigiLocker document.
Access to a customer's DigiLocker account is never attempted or stored outside of the single, consented retrieval flow, and a retrieved document is never shared onward without the customer's further consent, consistent with our Customer Consent Policy.
Where a document was only used transiently and not retained as part of the application record (see Section 5), no separate deletion step is needed since nothing was stored. Where a document is retained as part of the record, it can be deleted on request per our Data Deletion Policy, subject to any legal retention requirement.