Effective date and last updated: 6 October 2026 · Applies to: NxtBanking (a product of Laraware Private Limited), its websites, APIs, dashboards and partner platforms.
1. About this policy
This policy applies to Aadhaar Enabled Payment System (AEPS) services offered through NxtBanking-powered platforms: cash withdrawal, balance enquiry, mini statement, cash deposit and Aadhaar Pay where enabled. AEPS is a bank-led model of NPCI that allows a customer to transact at a Business Correspondent or retailer using Aadhaar-linked authentication. It is governed by NPCI AEPS rules, RBI directions, the Aadhaar Act, 2016 and UIDAI guidelines.
NxtBanking is a software and API infrastructure provider. Where a service involves a regulated activity (for example BBPS bill payments, AEPS cash withdrawal, money transfer or prepaid recharge), that activity is carried out by the licensed or authorised entity concerned (such as a Bharat Bill Payment Operating Unit, a sponsor bank, a Payment Aggregator or a payment system operator) under its own licence and rules. NxtBanking does not hold customer funds as a bank, does not issue payment instruments and does not claim any licence or authorisation that it has not been granted.
2. Who can offer AEPS
AEPS can be offered only by merchants (retailers or Business Correspondent agents) who have been KYC-verified and onboarded by us and our partner bank, have a valid registered biometric device, and have accepted the agent terms. We may refuse, suspend or withdraw AEPS access at any time for risk and compliance reasons or at the direction of a partner bank or NPCI.
3. Customer consent and Aadhaar
- Every AEPS transaction needs the customer's informed consent and authentication by Aadhaar number (or virtual ID) and biometric.
- The merchant must tell the customer the nature of the transaction and the amount, and must obtain consent before the biometric is captured.
- Aadhaar numbers, biometric data and PINs are not stored by us. Only a masked reference is retained, as allowed under the Aadhaar Act and UIDAI rules. Biometric data is encrypted at the registered device and sent directly for authentication.
- The customer may ask for any Aadhaar-based transaction they did not authorise to be investigated. They can also lock their biometrics through the UIDAI portal or mAadhaar app for added safety.
4. Merchant duties
Merchants and agents must:
- Use only UIDAI-certified registered biometric devices that are in the merchant's name and location, and never share devices or credentials.
- Give the customer a receipt or SMS confirmation for every transaction, with the amount, date, time, reference number and the merchant's contact.
- Dispense the full cash amount for a successful withdrawal and never charge fees beyond those allowed. For cash withdrawal and similar services, fees must be as disclosed in the platform and not demanded in addition to the transaction amount where not permitted.
- Never capture, copy, store or reuse biometric data or Aadhaar numbers, and never carry out a transaction without the customer being present.
- Display the services, charges and complaint contact, and the grievance process, at the point of service.
- Maintain the cash and float needed to serve customers, and not refuse a valid transaction without reason.
- Follow cash-handling and AML requirements, and report suspicious behaviour immediately.
5. Transaction limits
Limits are set by NPCI, the issuing bank and our sponsor bank, and may be changed at any time. Typical limits apply per transaction, per day and per customer, and apply per Aadhaar and per bank account. The applicable limit is shown at the time of the transaction. We may impose lower limits for new, high-risk or flagged merchants.
6. Fees
Fees, commissions and interchange for AEPS are set out in the merchant's agreement or rate card, and are subject to NPCI and RBI rules. A customer is not charged for balance enquiry or for failed transactions. Any fee charged to the customer must be disclosed before the transaction and must not exceed what the rules permit.
7. Failed transactions and disputes
| Case | Handling |
|---|---|
| Customer account debited, cash not dispensed | Merchant reports immediately. The transaction is raised as a dispute through NPCI AEPS dispute management, and reversal is credited to the customer's bank account. Reversal normally takes up to T+5 working days |
| Transaction pending or timed out | Status is verified with the bank. Auto-reversal if failed |
| Biometric failure or technical decline | No debit. Customer may retry or use another authentication |
| Wrong amount paid out by merchant | Merchant must correct it on the spot, and where it cannot be resolved, a complaint can be filed with us |
| Unauthorised transaction claim | Customer is advised to report to us and to their bank at once, and to call 1930 for fraud. An investigation is started and the bank's decision under NPCI rules applies |
Chargebacks raised by banks or NPCI, penalties arising from the merchant's actions, and amounts wrongly paid out are recoverable from the merchant's wallet or settlement, as in the Terms and Conditions. Refund timelines and claim steps are in the Refund and Cancellation Policy.
8. Fraud prevention and controls
We use device binding, location and velocity checks, limits, and transaction monitoring to prevent misuse. Prohibited practices include use of cloned or silicone fingerprints, repeat transactions on the same customer without consent, splitting to evade limits, using customer biometrics for any other purpose, and collusion with others. Accounts involved may be frozen, reported to the bank, NPCI and law-enforcement agencies and prosecuted.
9. Customer safety tips
- Never give your Aadhaar number and fingerprint to anyone you do not trust, and never authenticate for a transaction you did not initiate.
- Check the amount on the device screen before giving your fingerprint.
- Always collect the receipt and check your SMS from the bank.
- Lock your biometrics when not in use, through the UIDAI portal or mAadhaar.
- Report problems immediately to the merchant, to us and to your bank.
10. Complaints
Customers and merchants can complain through the channels in the Grievance Redressal Policy. We register a complaint ID within 24 hours, and resolve within the timelines of the AEPS dispute scheme. Unresolved matters can go to the RBI Integrated Ombudsman as set out in that policy.
Contact us
| Purpose | Contact |
|---|---|
| General and customer support | support@laraware.com |
| Refund and failed transaction queries | refunds@laraware.com |
| Legal, compliance and grievance escalation | legalteam@laraware.com |
| Phone | 0731-4621515 |
| Registered and correspondence address | Laraware Private Limited, B-2/64, Vibhutikhand, Gomtinagar, Lucknow, Uttar Pradesh 226010, India |