For adults 18 and over. Editorial guide only, no real-money play is offered on this publication. Responsible play guidance.
Editorial guide ·

Wallet and KYC, what the page asks for, what it stores

A wallet-and-KYC page combines two screens: the verification document upload and the wallet access. This page explains what each screen asks for and what a serious answer looks like.

A calm arrangement on pale linen: a single slim identity-document placeholder with photo area obscured, a smartphone showing a generic wallet screen and a small lined notepad with one pencil tick.

KYC, verification document

The KYC (Know Your Customer) screen asks for an identity document, typically a PAN card for Indian residents and an address proof (Aadhaar, passport, utility bill) in addition. The document is stored for the period required by the platform's KYC vendor and the regulator's retention rule.

The privacy page is the authoritative source for retention. A reader who wants to verify the retention window should look for the phrase "verification" or "KYC" on the privacy page; the page should name a duration and a vendor.

A blank card-sized placeholder resting in an open kraft-paper folder on pale linen with a brass paperclip and a pencil alongside.
The wallet-and-KYC screen is a small still life: a document, a phone, a notepad. Each object has a purpose and a retention rule.

Wallet, access and limits

The wallet screen typically shows the current balance, the deposit history, the withdrawal history and the deposit cap. A serious wallet screen also shows the deposit cap as a numeric value the reader can edit; a marketing wallet screen shows the cap only on request.

A reader who wants to evaluate a wallet should look for four controls: deposit cap, withdrawal history, deposit history and a clear pause action. The presence of all four is information about the platform; the absence of any one is also information.

Limit controls on the wallet

Limit controls belong in the account menu or on the wallet screen itself, not in a support inbox. A reader who cannot find the deposit cap in three taps is using a platform that makes limits harder to use. The responsible-play guide explains how to set each limit.

After the wallet review

The wallet review is part of the broader safety checklist. A reader who has run the four-step checklist and confirmed the limit controls can return to the change log for any documented updates.

Set your limits

Limit controls are the single most useful set of controls a reader can set on day one. The responsible-play guide explains how to use them.

Read the responsible-play guide

KYC shape

What a wallet + KYC flow actually asks for, line by line

A wallet + KYC flow on a skill-game platform is short, typically a single screen, but every line of it has a purpose. The notes below walk through the flow in the order a first-time reader encounters it, including the question each line is meant to satisfy.

Step 01

Identity document

The first KYC ask is a government-issued identity document: usually an Aadhaar card, a PAN card, a passport, or a driving licence. The platform's automated reader needs to extract the document number, the name, the date of birth, and (for some documents) the address. Most platforms now accept a clear photo of the original document rather than a scan; the important constraint is that all four corners of the document are in the frame and the photo has no glare on the photo zone.

Step 02

Address verification

The second KYC ask is address verification. Some platforms accept the address embedded in the identity document; others require a separate proof of address (a utility bill, a bank statement, or a rent agreement). The reader's response depends on whether the address on the identity document matches the current mailing address; if it does, the upload is one document; if not, the reader provides both the identity document and the proof of address.

Step 03

Selfie / liveness check

The third KYC ask is a selfie, sometimes paired with a short liveness check (turn your head left, blink, smile). The selfie is matched against the photo on the identity document; the liveness check is a separate defence against a stolen identity being used to open an account. Readers often find this step slightly awkward and skip it; the right reader response is to do it on the same session as the document upload, while both halves of the review are queued together.

Step 04

PAN / tax identity

The fourth KYC ask is the PAN card, on most Indian platforms regardless of which identity document was submitted first. The PAN is used for tax reporting (TDS on net winnings, where applicable) and for verifying that the reader is the registered holder of the bank account the reader will eventually withdraw to. The PAN may be the same as the identity document; on Aadhaar-driven flows, it usually isn't, and the platform asks for both.

Step 05

Bank account verification

The fifth KYC ask is bank account verification: account number, IFSC, and account-holder name. The name must match the name on the identity document and PAN exactly; the platform rejects the verification if the names diverge by more than a small amount (which can happen with regional name variations or transliteration differences). If the names diverge, the reader has to either correct the account or escalate to customer care before the verification is complete.

Step 06

Source of funds

The sixth KYC ask, on some platforms, is source-of-funds confirmation. This is most often triggered on large deposits or on withdrawals that exceed a regulatory threshold. The reader is asked to provide a payslip, a tax return, or a bank statement covering the past three to six months. The step is regulatory rather than operational; the platform is documenting its compliance with anti-money-laundering rules, and the documents are stored securely for the regulator's later inspection.

iWhy the document-matching rules are strict

The reason platforms reject KYC submissions on small name differences (a missing middle initial, a transliteration from Devanagari to Latin, a punctuation variant) is that the platform's regulator does. A reader who notices a mismatch should not assume the platform is being pedantic; the regulator tends to flag any platform whose KYC match-rate is significantly above the regulatory baseline. The strictness is downstream of the regulator, not the platform; the platform is carrying the regulator's rules into the reader's onboarding flow.

Document storage

What platforms do with KYC documents, and what they should do

Once a reader has submitted identity, address, PAN, and bank-account documents, the question of how the platform stores them is what differentiates a well-run KYC operation from a careless one. The four checks below capture the storage conventions the editorial review looks for.

Check 01

Encryption at rest

KYC documents should be encrypted at rest on the platform's storage. The encryption is straightforward (the documents live in a database, not in a publicly addressable directory), and a reader should be able to confirm it by checking the URL of any document preview. A preview that resolves over plain HTTP, or that resolves to a URL with the document number in it, is a sign that the storage is not encrypted to the standard the regulator expects. Boomerang's editorial review flags platforms that store documents unencrypted.

Check 02

Retention window

The retention window is the period the platform keeps KYC documents after the reader's account is closed. Most platforms retain documents for between 5 and 10 years after closure, in line with anti-money-laundering rules. A reader who wants to know the exact window should ask the platform's data-protection officer via the contact form; the answer is usually printed in the platform's privacy policy, and a platform that does not know its own retention window is a flag for the editorial review.

Check 03

Data minimisation

Data minimisation is the principle that the platform should ask for, and store, only the documents the regulator requires. A platform that asks for an Aadhaar number when PAN is sufficient, or that asks for a payslip on every reader regardless of deposit size, fails this check. The editorial review looks for KYC flows that scale the document set to the deposit size and the regulatory threshold, not flows that ask for the maximum document set regardless of context.

Check 04

Deletion on request

After the regulatory retention window expires, the reader has a right to ask the platform to delete the documents. Not all platforms will honour this request, and a few will refuse; the editorial review notes the platform's response and updates the privacy-policy summary accordingly. A reader who wants to confirm a platform's deletion behaviour before depositing should ask the platform's data-protection officer a single question: "After the retention window, will you delete on request?"

Frequently asked questions

Wallet + KYC questions readers actually send

Phrasing paraphrased from real correspondence; the underlying answers are the ones the editorial team has heard back from compliance officers in the same exchange.

The platform rejected my PAN because the name didn't match. What now?

The two usual reasons. First, the name on the PAN may differ from the name on the bank account by a punctuation variant or a transliteration difference; the platform may accept the verification if the reader submits a small clarifying note via email. Second, the bank account may be held in a different name than the reader's primary ID; this is the more common cause and the one the platform is right to reject. Add the holder's name as it appears on the bank statement, or switch to an account in the reader's own name.

Why is the platform asking for source-of-funds on a small deposit?

Most platforms only ask for source-of-funds on deposits above a regulatory threshold (typically ₹10,000 or ₹50,000 cumulative per month). If the platform is asking for source-of-funds below that threshold, the reader's right move is to ask customer care for the regulatory basis of the request. A platform that cannot cite the regulatory basis may be over-collecting, which is itself a finding the editorial review will record.

Can I close my account and delete my KYC documents?

The reader can close the account at any time via the account-settings flow. The KYC documents, however, are retained for the regulatory window (typically 5 to 10 years after closure) and are not deleted on the reader's request during that window. After the window expires, the reader can submit a deletion request via the data-protection officer's email; most platforms will honour it, though some will refuse on the basis of regulatory record-keeping.

The platform stored my Aadhaar number in plain text. Is this normal?

No. Aadhaar numbers should be tokenised or encrypted at rest, and only the last four digits should be visible in any operator-facing screen. A reader who notices a full Aadhaar number in a cashier screen or in an email confirmation should escalate the issue via the platform's data-protection officer and to the UIDAI's grievance cell. Boomerang's editorial review treats this kind of storage as a serious finding and updates the review score accordingly.

Play now