Reference

Open 2factor Privacy Policy

This Privacy Policy explains how we handle the account details, device data and transaction trail linked to 2factor.

Account dataDevice logsCookie useTransaction trail
2factor Open 2factor Privacy Policy
CONTACT PATHS

Switch to privacy contact paths

If you want to change your contact details, ask for a copy of your data, or raise a privacy concern, we route the request to the…

Email request Send the address linked to your account, the change you want, and any supporting…
In-app message Use the contact path inside your account if you need access to stored data…
Written request If you prefer a written trail, send a dated request from the details on…
DATA HANDLING

Browse our record safeguards

We handle privacy work in layers: data collection is limited to what the account needs, cookie use is kept to session and preference support, and access to records…

Data minimisation

We collect only what we need to open, service and protect your account, including contact details, login records and payment…

Cookie control

Cookies help us keep you signed in, remember language and session settings, and measure basic site stability.

Account security

Your sign-in data is protected with access controls and login checks.

Retention limits

We keep records only as long as needed for account service, dispute handling and legal duties.

Change requests

If you want a copy, correction, restriction or deletion where the law allows it, send the request through support.

Contact route

For anything that does not fit the forms, use the support paths in the section above.

Check privacy questions for your account

Use the questions below to see how our privacy handling works in practice. They cover what we collect, why certain records stay on file, how cookies support session use, and how you can ask for a copy or correction. If a request depends on local law, we follow that rule and ask for verification before changing account records or sending copies.

It covers the personal data tied to your account, device and payment trail, plus the way we use it for access control, support, record keeping and the handling of lawful requests.

We may collect the details you submit, login activity, device signals, support messages and the transaction references linked to UPI, Paytm or PhonePe when you use those rails through your account.

Cookies and device signals help us keep sessions stable, remember your settings and detect unusual access. We do not use them to pull in more detail than the account and page flow need.

We keep records for as long as the account, dispute handling or local law requires. After that, we remove or anonymise the pieces we no longer need to keep on file.

Yes. Send the request through support and we will check the account, verify the person making the request and apply the change where local law and our record rules allow it.

A privacy-trained support path handles them. That team reviews the case file, asks for proof when needed and keeps the request separate from general account messages so the right record is updated.

Yes. If the law in your location changes what we can share or when we can delete, we follow that rule and explain the limit in our reply.