Privacy Notice / India
Last Update: August 2026 Previous version
PRIVACY NOTICE
THIS IS THE PRIVACY NOTICE OF DLOCAL AND ITS INDIAN SUBSIDIARIES
Your privacy is very important to us. We are committed to the protection of your Personal Data, and the purpose of this Privacy Notice is to inform you about the way we process your Personal Data, including references to which data we process, how, why, and for how long, together with information about your rights in relation to your Personal Data.
This Privacy Notice (together with our Terms and Conditions available HERE, and any other documents referred to in it) sets out the basis on which any Personal Data we collect from you, or that you provide to us, will be processed by us. This Privacy Notice also sets out how you can instruct us if you prefer to limit the use of that Personal Data, as well as the procedures that we have in place to safeguard your privacy.
It is important that you read this Privacy Notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing Personal Data about you so that you are fully aware of how and why we are using your Personal Data. This Privacy Notice supplements the other notices and is not intended to override them.
1. IMPORTANT INFORMATION
In this Privacy Notice, “dLocal Group” means dLocal Limited and each entity that directly or indirectly controls, is controlled by, or is under common control with dLocal Limited. “dLocal” means the entities in the dLocal Group incorporated in India. References to “we”, “us” and “our” mean dLocal.
dLocal may process Personal Data as a Data Fiduciary or as a Data Processor. This Privacy Notice describes the processing activities for which dLocal acts as a Data Fiduciary. Where dLocal processes Personal Data on a Customer’s instructions, dLocal acts as a Data Processor.
Individuals whose Personal Data we process (each, a “Data Principal”)
In this Privacy Notice, “you” or “your” means an individual who is the subject of Personal Data we process as a Data Fiduciary, which would typically be: (i) the visitors of our website at www.dlocal.com (our “Website”); (ii) the representatives of merchants and other payment providers (our “Customers”) who interact with us and access our Merchant Dashboard to receive our payment processing services; (iii) representatives of third party service providers who interact with us to fulfil their contractual obligations with us; (iv) representatives of prospective Customers whose business contact details we obtain from third-party sources, such as business-contact databases, sales-intelligence or lead-generation platforms and (v) representatives of partners, vendors, counterparties and other organisations who interact with us in connection with our commercial, operational, contractual or vendor-management activities.
In addition, we also act as a Data Fiduciary in relation to Personal Data of buyers or beneficiaries of our Customers (“End-Users”) or business customers of our Customers who use our dLocal for Platforms solution (our “Platform product”) (“Sub-Merchants”) for limited purposes (as indicated in section 4 of this Privacy Notice). References to “Sub-Merchants” in this Privacy Notice should be understood in this sense.
For most End-User and Sub-Merchant data, we act as a Data Processor on behalf of the relevant Customer, except for the limited situations described in this Privacy Notice where we act as a Data Fiduciary, including for certain fraud-prevention, compliance and regulatory purposes.
Where an End-User chooses to save a payment method with a Customer that uses dLocal’s services, we may process the relevant payment credential or token, payment-method identifiers, transaction information, technical data and records of the End-User’s authorisation. We process this information to enable the Customer to initiate future subscription or other recurring payments in accordance with the terms agreed between the End-User and the Customer. The Customer is responsible for providing the End-User with its own privacy notice and, where required, obtaining the End-User’s consent or other valid authorisation for the saving and use of the payment method.
For the purpose of this Privacy Notice, “Data Protection Legislation” means applicable data-protection and privacy laws in India, including the Digital Personal Data Protection Act, 2023 and rules made under it, in each case to the extent applicable and in force.
Legal terms related to data protection used in this Privacy Notice follow the definition provided by the applicable legislations.
2. HOW WE COLLECT YOUR DATA
We collect your Personal Data in the following ways:
- Direct interactions. You may give us your Identity and Contact Data (as defined below) by filling in forms or by corresponding with us through available channels (for example, by email, through our online contact forms, or via our customer support tools such as Intercom), our CRM tools, our contract-management tools, our project-management tools, or other operational tools we use to manage our relationships and services. This includes Personal Data you provide as a representative of a Customer or a prospective Customer when you:
- apply for or enquire about our products or services;
- interact with us in connection with our services or our relationship with the Customer you represent;
- create a Customer user account on our payment processing service platform (“Merchant Dashboard”) to receive our services; or
- subscribe to our service or publications.
Where you interact with us through those systems, we may also collect or generate records of those interactions, including communications, notes, comments, workflow or status information, and related metadata.
Where we contact you as a representative of a prospective Customer and we have not obtained your Personal Data directly from you, we will usually do so using your business contact details that we have obtained from third‑party sources as described in section 2(e) below and will provide you with this Privacy Notice when we first contact you.
- Website and Merchant Dashboard usage. When you browse on our website or our Merchant Dashboard, we process Technical Data (defined below). We use strictly necessary Technical Data and cookies to operate, secure and troubleshoot the Website and Merchant Dashboard, including for debugging, DDoS mitigation, fraud prevention and service reliability. We may use analytics or similar technologies to understand and improve the Website and Merchant Dashboard in accordance with your choices through our Cookie Preference Centre. Please see our Cookies Policy HERE for further details.
- SmartFields, Mobile Checkout, Payment Links, Payout Links and Invoice Collection solutions, and our dLocal for Platforms solution (our Platform product). When you purchase goods or services from, or receive payments to or from, dLocal Customers using any of these solutions, you will most likely provide your Personal Data directly to dLocal, acting on behalf of those Customers.
In marketplace arrangements, we provide our services through our Platform product in combination with a Customer’s platform. Depending on our agreement with the Customer and the applicable data protection roles, Sub-Merchants and their End-Users may provide their Personal Data either directly to dLocal (for example, via dLocal-hosted onboarding and KYC/verification flows) or to the Customer’s platform (for example, via the Customer’s own user interfaces and onboarding tools). In the latter case, the Customer then shares that data with us so we can provide our services. - Due Diligence. When you apply to become a Customer of dLocal or you operate as a Sub-Merchant under a dLocal Customer, we require that you provide Personal Data including, but not limited to, the categories described in this paragraph. For regulatory reasons, we may request name, postal address, telephone number, and email address to fulfil our financial partner and regulatory requirements. We may also collect financial and Personal Data about you, such as your ownership interest in the company, your status of director or officer, your date of birth and government-issued identification numbers, tax identifiers and bank account information.
- Third parties or publicly available sources. We may receive Personal Data about you from various third parties and public sources, including:
- providers of businesscontact databases, salesintelligence and outreach tools that lawfully collect and provide business contact details for B2B prospecting and outreach purposes; and
- providers we use to carry out fraud prevention checks, ID checks and other “Know Your Customer” checks we need to perform on our Customers’ representatives, Sub-Merchants and End-users to comply with applicable financial services standards and requirements and to comply with applicable laws and regulations.
When we collect Personal Data directly from you, we will, before collection, inform you that the information is being collected, the purpose of collection, the intended recipients, and the name and address of the entity collecting and retaining the information. Where we collect Sensitive Personal Data or Information, we will obtain your prior written consent, including by electronic means, regarding the purpose of its use before collecting it. Before collection, you may choose not to provide the requested information. You may withdraw your consent in writing as described in Section 6. If you do not provide the information or withdraw your consent, we may not be able to provide the relevant products or services.
3. WHAT DATA WE COLLECT
We may collect, use, store and transfer different kinds of data about you, which we have grouped together as follows:
- Identity Data includes first name, last name, username, date of birth, government-issued identification numbers, tax identifiers and, where applicable, related identity-document details;
- Contact Data includes contact details, billing address, delivery address, email address and telephone numbers;
- Technical Data includes your internet protocol (IP) address, your login data, Google Analytics ID, internet browser and device type, time zone setting, location data and your use of our website, including which pages you visited, how you got to our Website, the time and length of your visit and your language preferences. This may include cookies and similar identifiers, browser user-agent information and device/online identifiers used to secure transactions and prevent fraud;
- Profile Data includes the username and password of Customer representatives using the Merchant Dashboard and, where applicable, account and interaction information relating to End-Users and Sub-Merchants, such as account-creation date, transaction history and risk or fraud indicators;
- Marketing and Communications Data includes your name, position and business details, your marketing and communication preferences, and records of communications with us, such as support requests or campaign responses;
- Relationship, Engagement and Operational Data includes information about your professional relationship with us and your interactions with our services and teams, such as account history, deal or ticket information, meeting, call and email records, notes, comments, support messages, contract or project status information, activity history, and related metadata; and
- Financial Data includes card data, bank account data, fiscal information, and other payment-instrument or payout information, including payment-method identifiers and related metadata, where relevant to the services.
We may collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your Personal Data, but will not be considered Personal Data in law, as this data will not directly or indirectly reveal your identity. Aggregated data collected include:
- Payment volumes and frequency
- Performance and risk metrics
- Merchant profitability and commercial analytics
- Aggregated views for external/merchant‑facing reports
- Compliance / AML & Data-Compliance metrics
We may also collect information about criminal convictions and offences but only in the context of fraud or security checks when this is necessary to comply with applicable laws or with any applicable financial services standards or requirements.
4. HOW WE USE PERSONAL DATA
We use Personal Data for the purposes set out below, in accordance with applicable law.
- provide the services you request from us;
- verify your identity or conduct appropriate checks for creditworthiness or fraud;
- understand your needs in order to provide you with the products and services you require;
- administer and manage our services, including billing for the services provided and debt collection;
- distribute information, newsletters, publications and other communication via various mediums to keep you informed including direct marketing communications about our services that we send to representatives of existing and prospective Customers (which may include contacting you using business contact details obtained from third‑party providers such as business‑contact databases, sales‑intelligence or lead‑generation tools);
You may opt out of direct marketing communications at any time by following the unsubscribe instructions in the relevant communication or by contacting us at [email protected]. Opting out of marketing communications will not affect service-related, transactional, security or other non-marketing communications. - research and develop new product offerings and services;
- analyse customer and support interactions (including, where relevant, via our customer support tools such as Intercom and AI-powered analytics tools, including large language models) to understand product and support performance, identify common issues and improve our services.
- analyse information contained in our CRM, support, contract-management, project-management and other operational systems, including communications, notes, tickets, comments, statuses and related metadata, including with the help of AI-powered analytics tools (including large language models), to generate summaries, identify trends, support reporting and forecasting, detect data-quality or operational issues, improve our services and operations, and support relationship management.
- manage and conduct our business and the services we provide to our Customers;
- draft or assist with drafting business communications, account briefings, follow-up notes and similar materials using information held in those systems, subject to appropriate human review and, where relevant, compliance with applicable direct-marketing, consent, opt-out and suppression-list requirements. We do not use these AI tools to make solely automated decisions that produce legal effects or similarly significant effects on you.
- make sure our website works properly, including debugging, to be able to deliver you its content, for DDOS mitigation on our website, and improving our website and performing statistical analyses;
- effectively communicate with third parties; and
- as required or authorised by applicable law.
End-Users and Sub-Merchants
As explained above in the section “Individuals whose Personal Data we process”, our relationship with End-Users and Sub-Merchants is indirect. In most cases, we process their Personal Data to provide the Services to our Customers and in accordance with our Customers’ instructions. In that context, dLocal acts as a Data Processor on behalf of the relevant Customer under a written contract, relying on the Customer’s authorisation to process End-User and Sub-Merchant Personal Data.
In selected arrangements, Sub‑Merchants agree to the terms and conditions of our Customer’s platform, which incorporate the payment‑processing terms that govern how we provide our services and how we process End‑User and Sub‑Merchant Personal Data on behalf of the Customer. Acceptance of those terms is collected through the Customer’s own onboarding and consent flows (for example, via the platform’s online terms or API‑based consent capture), rather than through a separate, dLocal‑hosted interface. Therefore, if you are an End-User or Sub-Merchant who has a relationship with one of our Customers, you should also refer to their privacy notice, as it is likely to be relevant to you and would contain information on how to contact them if you have queries about their use of your Personal Data or if you wish to exercise your data protection rights.
Notwithstanding our general role as a Data Processor for our Customers there are limited circumstances where dLocal determines the purposes and means of processing End-User or Sub-Merchant Personal Data for its own purposes. In those circumstances dLocal acts as a Data Fiduciary. These circumstances include the purposes listed below:
- to conduct, as needed, fraud and other risk management and prevention, and to comply with any mandatory reporting related to such activities;
- to comply with our statutory, regulatory and/or professional obligations, including any record-keeping obligations which we may have at law;
- to ensure the proper provision of the services for which you are a recipient or beneficiary through our Customer, and to establish, exercise, or defend legal claims; and
- to carry out identity-verification and due-diligence checks for Sub-Merchants, which may include document verification where required by law or where necessary to prevent fraud and financial crime.
In the context of those limited activities, we act as a Data Fiduciary and therefore parts of this Privacy Notice would be relevant to you as an End-User or Sub-Merchant. Information on contacting us for further information or exercising your legal rights in relation to your Personal Data is set out at the end of this Privacy Notice.
Due to changes in the law or to our business, from time to time, we may need to, as a Data Fiduciary, process your Personal Data for additional purposes beyond those set out above. In such a case, we will either update this Privacy Notice or issue a dedicated privacy notice covering the specific occasion, depending on what is most appropriate to do in the circumstances.
5. WHEN WE MAY DISCLOSE THE PERSONAL DATA
Your information may, for the purposes set out in this Privacy Notice, be disclosed for processing to:
- our employees, entities in the dLocal Group and their employees. For instance, dLocal will share your information with other entities in the dLocal Group for the purpose of the provision of our services or when such entities in the dLocal Group provide support services to dLocal;
- our third-party consultants, (sub-)contractors, suppliers and other service providers that may access your Personal Data when providing services to us (including, without limitation, IT support providers; KYC and identity-verification providers; customer-support and messaging platforms; AI analytics and automation tools (including tools that use machine learning or large language models to analyse customer interactions and help us provide and improve our services); payment-method, tokenisation or credential-vault providers; acquirers, payment networks and payment-method providers; recurring-payment and subscription-billing service providers; and providers of sales-intelligence, contact-enrichment and lead-generation tools);
- CRM, project-management, contract-management and other operational-tool providers; and providers of AI-enabled drafting, summarisation and analytics tools that process records, prompts, query metadata and generated outputs in connection with the services they provide to us;
- auditors or contractors, or other advisers auditing, assisting with or advising on any of our business purposes;
- analytics and search engine providers that assist us in the improvement and optimisation of our Website
- our successors in title, our prospective sellers or buyers of our business or to entities in the dLocal Group when we have a merger or reorganisation;
- government bodies and law enforcement agencies, and in response to other legal and regulatory requests;
- any third party where such disclosure is required to enforce or apply our Website Terms or other relevant agreements; and
- protect the rights, property, integrity or security of our company, our customers, or others (including, without limitation, you). This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
Where third parties process Personal Data on our behalf, we require them to use it only for the relevant purpose, protect it using appropriate security measures and comply with applicable legal requirements. Where we disclose Sensitive Personal Data or Information to a third party, we will obtain prior permission where required by the Data Protection Legislation, unless the disclosure is agreed in the applicable contract or is necessary to comply with a legal obligation.
6. WITHDRAWAL OF CONSENT
If you wish to withdraw consent that you have previously provided, please contact us at [email protected]. Withdrawal will not affect processing already carried out before we receive your request. We will assess your request and, where applicable, stop using the relevant Personal Data. We may retain Personal Data where necessary for a lawful purpose or where permitted or required by applicable law.
7. INTERNATIONAL TRANSFERS
dLocal serves Customers globally. We may share Personal Data with other entities in the dLocal Group and service providers located outside India where necessary for the purposes described in this Privacy Notice.
We take steps designed to protect Personal Data when it is shared internationally, including through contractual, technical and organisational measures, as appropriate. Any international sharing or transfer will be carried out subject to the Data Protection Legislation, including any applicable payment-data localisation or other sector-specific requirements.
8. WHAT HAPPENS IF YOU DON’T PROVIDE THE REQUESTED PERSONAL DATA
If we are unable to collect Personal Data from or about you, or if the Personal Data provided is incomplete or inaccurate, dLocal may not be able to assist you, including providing the products or services you are seeking or provide support or assist you with your queries.
9. SECURITY OF PERSONAL DATA
We have put in place a range of security procedures, as set out in this Privacy Notice. Where you have been allocated a profile in the Merchant Dashboard, this area is protected by your username and password, which you should never divulge to anyone else.
Please be aware that communications over the Internet, such as emails/webmails, are not secure unless they have been encrypted. Your communications may route through a number of countries before being delivered. This is the nature of the World Wide Web/Internet. We cannot accept responsibility for any unauthorised access or loss of Personal Data that is beyond our control.
We implement reasonable security practices and procedures designed to protect Personal Data under our control from unauthorised access, improper use or disclosure, unauthorised modification, unlawful destruction and accidental loss.
We will ensure that your information will not be disclosed to government institutions or authorities except if required by law (e.g., when requested by regulatory bodies or law enforcement organisations in accordance with applicable legislation).
10. COOKIES
dLocal uses cookies and similar technologies to store and collect information about your use of our Website and Merchant Dashboard. Cookies are small text files stored by the browser on your device. They send information stored on them back to our web server when you access our Website or Merchant Dashboard. We use certain cookies that are strictly necessary for the operation and security of our services, and we use other cookies (such as analytics or personalisation cookies) only where you have given your consent, as recorded through our cookie banner or preference centre. These cookies enable us, for example, to remember your settings and load your personal preferences to improve your experience. You can find out more about cookies at www.allaboutcookies.org, and more about the specific cookies we use and how to manage your choices in our Cookies Policy available on our Website HERE.
11. YOUR RIGHTS
We will take all reasonable steps to ensure that all information we collect, use, or disclose is accurate, complete and up to date. The rights available to you depend on the Data Protection Legislation and the nature of our relationship with you. Please contact us if your details change or if you believe the information we have about you is not accurate or complete.
In some instances, you may also have the right to:
- Request access to your Personal Data. This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.
- Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new information you provide to us.
- Request erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you.
- Withdraw consent at any time where we are relying on consent to process your Personal Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case.
How to exercise your rights.
Please click on this LINK and fill out the form to submit your request. This is the preferred channel to submit a request and exercise your rights. Requests submitted through other channels may require you to provide additional information to enable us to deal with the request.
If we process your Personal Data as a Data Processor on behalf of one of our Customers (for example, where you are an End-User or Sub-Merchant), we may ask you to contact the relevant Customer directly or we may forward your request to them, where this is required or appropriate under Data Protection Legislation.
What we may require from you.
We may need to request specific information from you to help us confirm your identity before starting to work on your request. We may also contact you to ask for further information in relation to your request.
Time limit to respond.
We try to respond to all legitimate requests within one month starting from the date your identity is deemed to be confirmed. Occasionally, it may take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.
No fee is usually required.
All communication and all actions taken by dLocal regarding your rights described above are provided free of charge. dLocal reserves the right, in the case of clearly unfounded or unreasonable requests, to either charge a reasonable fee covering the administrative costs of providing the information or taking the requested action or refusing to fulfil the requested action.
HOW LONG WE KEEP PERSONAL DATA
We retain your Personal Data only for as long as necessary to provide our services and fulfil the purposes for which it was collected, including to meet applicable legal, accounting, reporting, fraud-prevention and record-keeping requirements. To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
We will take reasonable steps to destroy or permanently de-identify Personal Data when it is no longer necessary for the purposes for which it was collected or where retention is not otherwise required by the Data Protection Legislation. Where destruction is not technically or legally possible, we will minimise the data, logically segregate it and restrict access to it.
Where we use AI-enabled analytics or drafting tools, we retain prompts, outputs, logs and related governance records only for as long as necessary for the relevant business, security, audit, legal and compliance purposes. Where appropriate, we seek to retain and share aggregated or pseudonymised outputs rather than raw identifiable content.
13. Contact Details
For questions, requests or grievances about this Notice or our handling of Personal Data, contact our Grievance Officer at [email protected]. The Grievance Officer will address grievances within one month of receipt.
Please contact the Grievance Officer first. Other remedies may be available to you under the Data Protection Legislation.
14. CHANGES TO THIS PRIVACY NOTICE
We reserve the right to amend or edit this Privacy Notice from time to time to reflect changes in dLocal’s business or practices, and we encourage you to review this Privacy Notice periodically. We may change the Privacy Notice at any time by posting the changed Privacy Notice on the dLocal website. If the changes are material, we will include a notice on the dLocal website homepage indicating that a change has been made.