Topic 04

Data protection — what the platform holds, how long, and how to have it removed.

Every licensed rummy platform operating in India is bound by the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules that have followed it. In practical terms, that means the platform acts as a Data Fiduciary for the personal information you hand it during sign-up, KYC and play, and it can only hold that information for as long as a defined purpose requires it. The first paragraph of this section is a quick reference of what is actually collected, because the most common surprise is finding out that the platform holds more than the player realised.

At sign-up the platform collects your name, mobile number, email address and the password hash (the password itself is never stored in plain text). At deposit it collects the payment instrument token — typically the last four digits of a card or a UPI handle reference — but never the full instrument number, because the actual money movement runs through a PCI-DSS compliant processor. At KYC it collects a government ID number (PAN for tax reporting above the threshold, Aadhaar for identity verification), the document image, a selfie or short video, and the device fingerprint used to take the selfie. At play it logs session timestamps, the table IDs you sat at, the hands you played, the deposits and withdrawals you made, and your IP address at the time of each session. None of this is unusual; what is unusual is a platform that does not tell you which of these categories it holds.

Retention is governed by purpose. Account credentials are kept for the life of the account and deleted within thirty days of account closure, except where a deletion request is contested or where a pending financial dispute requires preservation. KYC documents are kept for five years from the date of the last financial transaction, because anti-money-laundering rules require it — the platform does not get to choose a shorter window even if you ask. Transaction logs (deposits, withdrawals, hand outcomes, table IDs) are kept for seven years for the same reason. Gameplay telemetry that does not tie to a financial event — anonymous hand records, for example — can usually be deleted on request, but the platform will typically ask you to close the account first, because the data becomes orphaned once the account record is removed and is no longer useful for any purpose the law recognises.

To request deletion, write to the platform's grievance officer. Their name and email must be published on the platform's website, typically under a heading like "Grievance Officer", "Compliance" or "Contact" — a platform that does not name a grievance officer is in breach of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and you should treat that absence as a signal. Send a short email that includes your registered mobile number, your registered email address and the words "Request for erasure under DPDP Act, 2023 Section 12". The platform has thirty days to action the request; in practice the actioning happens in seven to fifteen days for a verified account. Once deletion is complete you should receive a confirmation email that lists the categories of data deleted and the categories retained (KYC documents and financial transaction logs, per the retention rules above, are typically the retained categories). If you do not receive confirmation within thirty days, escalate to the Data Protection Board of India through the portal on the MeitY website.

Editor's note

The thirty-day window is a legal maximum, not a target. Most well-run platforms close a deletion request in under two weeks. If a platform is still "reviewing" past day thirty, that is the moment to escalate — not because the platform is necessarily acting in bad faith, but because the law gives you a backstop and the backstop only works if you use it.