Privacy Policy

Last updated: 18 September 2026

Introduction

PalmNode Infratech Pvt. Ltd. ("PalmNode", "the Company", "we", "us", or "our") operates the website niev.in and provides palm-vein biometric checkout terminals and merchant software for physical retail. This Privacy Policy explains what information we collect from merchants, their customers, and website visitors, how we use and protect that information, and the choices available to you. This policy is intended to be read together with our applicable obligations under the Information Technology Act, 2000 and rules made thereunder, and the Digital Personal Data Protection Act, 2023, to the extent these laws apply to our processing of personal data in India.

Information we collect

We collect two broad categories of information in connection with our services.

First, we collect basic contact information such as a phone number, and, where provided, a name and email address. This is used to create and manage merchant and user accounts, communicate with you about our services, and provide support.

Second, when a customer or merchant enrols with a palm-vein terminal, we collect encrypted biometric hashes generated from a palm-vein scan. These hashes are used solely for terminal login and authentication at the point of sale, allowing a customer to be recognised and a transaction to proceed without a phone, card, or PIN.

We do not collect, store, or process any raw banking details, UPI PINs, or card data. All financial routing is handled securely via our payment gateway partner, and no such data passes through or is retained on PalmNode systems.

We also want to be clear about what we do not store: we never store raw palm images. Only irreversible, encrypted hashes derived from a palm-vein scan are retained on our systems, and these hashes cannot be used to reconstruct the original image of a palm.

How we use information

We use the information described above to create and manage accounts, authenticate customers at palm-vein terminals, operate and improve our hardware and software, provide customer support, communicate service updates, and comply with applicable legal obligations. We do not use biometric hashes for any purpose beyond identity verification at the point of sale.

Biometric data safeguards

Biometric hashes are encrypted both at rest on our servers and in transit between terminals and our systems. Because the hashes are generated through a one-way, irreversible process, they cannot be reverse-engineered into an image of a palm or any other identifiable representation. Access to biometric data within PalmNode is restricted to personnel and systems that require it to operate the authentication service, and is governed by internal access controls.

Sharing and disclosure

We share information only where necessary to operate our services. This includes our payment gateway partner, who processes financial transactions on behalf of merchants and customers, and other service providers who support functions such as hosting, technical infrastructure, and customer support, and who are bound to handle information only for the purposes we specify. We may also disclose information where required by law, regulation, court order, or a valid request from a government authority. We do not sell personal information or biometric data to third parties.

Data retention

Biometric hashes are retained for as long as an account remains active and are deleted upon account closure or upon a verified request from the individual concerned. Basic contact information may be retained for a longer period where required to meet our legal, accounting, or regulatory obligations, after which it is deleted or anonymised.

Your rights

Subject to applicable law, you have the right to access the personal information we hold about you, request correction of inaccurate information, withdraw consent for further processing, and request deletion of your information, including biometric hashes. To exercise any of these rights, please write to us at support@niev.in and we will respond to your request in accordance with applicable law.

Cookies

Our website, niev.in, uses minimal to no tracking cookies. We do not use cookies for behavioural advertising or third-party tracking.

Children

Our services are not directed to, and are not intended for use by, individuals under the age of 18. We do not knowingly collect personal or biometric information from anyone under 18.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page indicates when this policy was last revised. We encourage you to review this page periodically.

Grievance Officer / Contact

In accordance with applicable Indian law, any questions, concerns, or grievances regarding this Privacy Policy or our handling of personal information may be directed to our Grievance Officer, PalmNode Infratech Pvt. Ltd., who can be reached at support@niev.in or +91 9324 892 469, at our registered address:

PALMNODE INFRATECH PRIVATE LIMITED
Gala No. 19, Bldg No 3, Samruddhi Sagar Plaza,
Vasai East IE, Vasai, Thane- 401208, Maharashtra