Editorial helper · wallet and KYC

A reader-led wallet and KYC guide.

KYC is the platform-side identity proof before any first withdrawal. The desk’s editorial view: share only the documents a serious platform requires in the order it requires them. This page is the guide.

Editorial · safety deskUpdated 8 Apr 202611 min read
A verification scene: a desk with a printed KYC checklist and a passport-style photo card being reviewed
Editorial · Editorial helper · wallet and KYC
01
Documents

What KYC actually requires

On a serious Indian rummy platform, KYC requires three documents: PAN, a masked Aadhaar (first eight digits hidden), and a bank proof (cancelled cheque or bank statement). Some platforms also require a recent photograph. The documents are uploaded once at KYC; the platform re-asks when they expire.

PAN is the primary identity document. The PAN ties the account to the reader’s tax identity; the platform verifies PAN against the Income Tax database at upload. The verification usually completes in seconds; the platform stores the PAN hash, not the PAN number itself, and the PAN number is never displayed back to the reader in plain text on the platform’s UI.

Masked Aadhaar is the address document. The reader downloads a masked Aadhaar PDF from the UIDAI portal; the PDF has the first eight digits of the Aadhaar number replaced with x’s. The platform sees only the last four digits and the QR code; the platform does not see the full Aadhaar number. The desk recommends masking every Aadhaar copy by default; UIDAI’s portal makes the masked PDF the default download.

Bank proof is the financial document. The reader uploads a cancelled cheque or a recent bank statement; the document confirms the UPI handle (where the reader has set one up) and the bank account number. The platform stores the bank account number against the reader’s KYC record; the reader’s withdrawals route to this account.

The photograph is the optional fourth document. Some platforms ask for a recent selfie to confirm the PAN-holder is the person uploading the documents. The photograph is usually deleted after the KYC review; the platform does not store the photograph against the reader’s profile.

02
Order

The actual KYC order

The desk’s safety criteria rank KYC ordering as the third-most-important single signal. A serious platform asks for PAN before the deposit form, masked Aadhaar second, bank proof third. The deposit form opens only after PAN is verified.

PAN first

PAN confirms identity at the primary level. Most platforms verify PAN against the Income Tax database.

Aadhaar masked

The masked Aadhaar (first eight digits hidden) confirms address. The platform does not see the full Aadhaar.

Bank proof

The cancelled cheque or bank statement confirms the UPI handle and bank account number.

Deposit form

The deposit form opens only after KYC is verified. The deposit goes to the verified bank account.

The order matters because the order is what tells the reader whether the platform is reading the regulations or working around them. The IT Act 2000 and the PMLA 2002 rules require KYC before the deposit form; a platform that opens the deposit form before KYC is not compliant on the platform’s own terms.

Step one (PAN first) is the most important. The PAN is the primary identity; the PAN is what the platform returns on a Section 50 PMLA notice. A platform that asks for the deposit first and the PAN second is silently building a transaction profile before it has the identity trail. The desk flags this as a higher-risk pattern.

Step two (masked Aadhaar) is the address layer. The masked Aadhaar confirms the reader’s address at the UIDAI level; the bank proof confirms the same address at the bank level. Where the two addresses disagree (e.g. the Aadhaar address is a different city from the bank proof), the platform usually asks for an additional document. The desk finds that mismatched addresses are the most common KYC re-trigger pattern.

Step three (bank proof) is the financial layer. The bank proof ties the platform’s withdrawal route to the reader’s verified bank account. The desk recommends uploading a cancelled cheque rather than a bank statement where the platform accepts either; the cancelled cheque carries the MICR code, the IFSC code, and the account holder’s name on a single page.

Step four (deposit form) is the verification gate. The deposit form opens only after KYC is verified; the deposit goes to the verified bank account. The desk finds that platforms that open the deposit form before KYC verification usually route the first deposit to a holding account and re-route to the verified account after KYC clears, a pattern that complicates refund disputes. A platform that holds the deposit until KYC clears is the cleaner pattern.

03
UPI

UPI handles and withdrawal time

UPI handles are the most common withdrawal route on India-facing rummy platforms. A UPI handle is tied to a bank account, not a card, withdrawals are PSP-validated against the bank account number. The desk’s safety criteria flags withdrawals that route through a different PSP from the deposit PSP.

UPI handles have the format name@bank, e.g. 9876543210@paytm or rummyreader@okhdfcbank. The handle is tied to a bank account; the bank account is what the PSP uses to validate the withdrawal. The reader’s UPI handle is set up at the bank or at a UPI app (Google Pay, PhonePe, Paytm); the reader does not need a card.

The PSP-PSP match rule is the second-most-important withdrawal signal. Most platforms route deposits and withdrawals through the same PSP; the deposit lands on the PSP’s settlement account, the withdrawal leaves from the same settlement account. A platform that routes the withdrawal through a different PSP is exposing the reader to a new PSP’s fraud and dispute policy. The desk finds that PSP-PSP mismatches correlate with delayed withdrawals and rejected refunds.

Withdrawal time on UPI is the third signal. The published window is usually within 4 hours; the desk’s reader survey shows the median is closer to 30 minutes. Where a platform publishes a window longer than 24 hours for UPI withdrawals, the platform is usually batching withdrawals through a slower rail, and the desk flags this as a higher-risk pattern. UPI is real-time; a UPI withdrawal that takes longer than 4 hours is a flag.

The withdrawal limit per UPI transaction is set by the bank, not the platform. Most banks cap UPI transfers at Rs. 1 lakh per transaction; some banks cap at Rs. 50,000. The reader who wants to withdraw more than the bank cap must split the withdrawal into multiple transactions or route through IMPS. The desk recommends confirming the bank’s UPI cap before requesting a large withdrawal.

04
Closings

Reading a wallet page

Open the wallet page once before you share any document. Read the withdrawal language, plain hours, named payment rail, processing schedule. Then share the documents only when the language is human.

The wallet page is the platform’s first test of whether the platform is writing for the reader or writing for the marketing team. The desk finds that platforms writing for the reader publish withdrawal windows in plain hours (“within 4 hours”), name the payment rail (UPI, IMPS, NEFT), and publish the processing schedule (business hours, weekend handling, bank holiday handling). Platforms writing for marketing publish vague language (“instant withdrawals”) and route the reader to the FAQ for the details.

The three pieces of language to look for are: a plain-hours window, a named rail, and a processing schedule. Where all three are present, the wallet page is on the reader’s side; the platform has done the work of writing the language a reader can verify against the published deposit-and-withdrawal policy. Where any of the three is missing, the wallet page is on the marketing side; the reader should treat the missing piece as a flag and read the FAQ before sharing KYC.

The fourth piece of language the desk recommends looking for is the bonus terms link. A serious wallet page exposes the bonus terms from the wallet page itself, not from a separate “promotions” tab. The desk finds that platforms that hide the bonus terms behind a separate tab are usually the same platforms that publish incomplete bonus terms in the welcome banner.

L
FAQ

Reader questions

What documents does KYC require?
PAN, masked Aadhaar, bank proof. Some platforms also require a photograph.
What is masked Aadhaar?
A copy of Aadhaar with the first eight digits hidden. Standard for KYC on rummy platforms.
Why is the KYC order important?
It signals who is reading the regulations. A platform that asks for KYC after deposit is a flag.
Can I use a relative's bank account?
No. KYC is tied to your identity and your bank account.
What if my KYC is rejected?
Contact customer-care. Common reasons include blurry uploads and PAN-Aadhaar name mismatch.
R1
Documents

Reading your KYC documents before upload

Before uploading any KYC document, open the platform’s upload screen and read the file-format constraints. Most platforms accept PDF or image; some accept only image; some reject single-page documents longer than 4 MB. Read the constraints once; you will not need to re-read.

The file-format constraint is the most common cause of a KYC rejection. A reader who uploads a 6 MB Aadhaar PDF on a platform that rejects documents larger than 4 MB gets a generic rejection email; the reader then has to compress the PDF and re-upload. The desk recommends checking the file size on the source document before any upload, and using a free PDF compressor to bring the document under the published limit.

The image-resolution constraint is the second-most-common cause. A masked Aadhaar scanned at 600 DPI produces a 12 MB TIFF that most platforms reject. The desk recommends scanning at 200 DPI for KYC documents; the resolution is enough for the OCR the platform runs at upload and the file size stays under most platform limits.

The crop constraint is the third-most-common cause. Some platforms ask for a specific crop (e.g. PAN card front only, no border; Aadhaar PDF first page only). A reader who uploads a full Aadhaar PDF when the platform expects the first page only gets a rejection. The desk recommends reading the crop constraint once and using a free PDF crop tool to extract the right page.

The naming convention is the fourth-most-common cause. Some platforms name-check uploaded documents (the PAN upload must be named PAN.pdf or PAN.jpg); uploads with the wrong filename are sometimes rejected by the upload script. The desk recommends following the platform’s naming convention exactly, even where the convention looks arbitrary.

R2
Closings

Storing KYC documents

Keep a copy of every KYC document you upload; the desk recommends keeping them in a single folder on a password-protected backup. If your platform is compromised, you have the source documents for a customer-care escalation.

The single-folder rule is the easiest part of the storage practice. A reader who uploads KYC to ten platforms over five years usually has the documents scattered across email, chat attachments, and the platform’s own upload portal. A reader who keeps a single folder can find any document in seconds, and can re-upload to a new platform without going back to the source.

The password-protected backup is the second part. KYC documents are sensitive; the documents should not live on the desktop in plain text. The desk recommends a password-protected folder (a ZIP archive with AES encryption is sufficient) on a backup drive that the reader does not carry around. The archive is portable and survives a device loss.

The retention rule is the third part. The desk recommends keeping KYC documents for at least seven years from the last upload. The IT Act 2000 and the Income Tax Act retention windows are the baseline; the seven-year window covers the longer of the two and gives the reader a clean reference for any tax or audit query that may arise.

The deletion rule is the fourth part. Where a reader closes the account and the platform confirms the closure, the reader can delete the local copy of the KYC documents after the retention window expires. The desk finds that readers who follow a documented deletion practice have a cleaner experience when they move countries or change banks; the old KYC trail does not linger on the backup drive.

N
Final note

Read the safety desk before you share any KYC document.

The four reading tools on the safety desk apply to every platform. Use them once, before sharing your first document.

Play Now