Wallets · Lending · Neobank · Wealth · Insurance · Remittance

Fintech App Development Services — Compliance-First Mobile Builds for Wallets, Lending, Neobanks, and Wealth

UPI apps, prepaid wallets, digital lending, neobank front-ends, wealth and mutual-fund apps, insurance journeys, and B2B payment builds — engineered from Ahmedabad since 2012 with RBI, PCI-DSS, and DPDP Act 2023 controls baked in from day one. Fixed INR pricing, source code in your Git, App Store and Play Store review handled by our team.

  • UPI, wallets, lending, neobank, wealth, and insurance apps built on one hardened stack
  • e-KYC via Signzy, Karza, Hyperverge, Digio, IDfy — Aadhaar OKYC + DigiLocker + CKYCR wired in
  • Razorpay, Cashfree, PayU, Setu, M2P, Zeta, RuPay, and RBI-authorised PA / PG rails
  • PCI-DSS SAQ-A scope, RBI card-tokenisation, DPDP consent capture, and MFA at every login
  • Signed NDA, IP assignment, audit-ready code, and source ownership on day of launch

Why a fintech app is a fundamentally different build from a generic consumer app

A fintech app is not a UX problem with a payment button bolted on the last screen. It is a regulated money-movement product, and the failure modes are different from anything a founder building a food, ecommerce, or content app has dealt with. Real user money moves through the app in real time, the Reserve Bank of India audits the rails, the Personal Data Protection framework audits the consent flow, and the App Store and Play Store review teams have a special queue for financial products — where anything ambiguous gets held for two more weeks.

The wall this creates is where most first-time fintech builds collapse. A template picked up from CodeCanyon does not handle RBI card-tokenisation, does not know what a CKYCR record is, does not surface Aadhaar OKYC failures gracefully, and has never survived a PCI-DSS SAQ-A scoping exercise. A generic Flutter freelancer who has shipped a couple of consumer apps builds the same login flow that works for a food-delivery product — and then discovers on the day of Play Store submission that the Data Safety declaration cannot honestly say "we do not collect financial information" when the app clearly does. The launch stalls, the compliance rewrites cost more than the original build, and the KYC provider bill lands at the wrong time in the runway.

Fruxinfo has been building custom software from Ahmedabad since 2012, and fintech-adjacent projects since 2014. The apps we ship today are engineered for the regulatory reality Indian fintech operates under — RBI PSS Act rules for prepaid instruments, the RBI Digital Lending Guidelines 2022, RBI card-tokenisation rules, PCI-DSS SAQ-A for tokenised card flows, DPDP Act 2023 consent capture, Aadhaar Regulations for OKYC, and the Play Store Financial Services policy plus the App Store Guidelines 3.1.5 for in-app purchase versus real-money flows. That knowledge lives inside the build discipline, not in a checklist bolted on at the end.

Must-have features and typical MVP scope for a fintech app

Every fintech founder shows up with a feature list that reads like PayPal at year fifteen. The right first move, as with any custom app build, is to cut the scope back to what a regulated first user can actually onboard, verify, transact through, and dispute against — and defer everything else to a version-two conversation. Below is the MVP scope that ships in twelve to twenty weeks for the four most-common fintech categories we build.

The universal MVP layer is the same for every fintech product. It is the compliance and safety spine every regulator expects to see before granting authorisation, and every user expects to see before trusting the app with money.

  • Sign-up with phone OTP, email verification, Google or Apple sign-in, and forced MFA on every login (SMS OTP, TOTP, or biometric)
  • Full e-KYC — PAN + Aadhaar OKYC via UIDAI, video-KYC where the product needs it, PEP and sanctions screening, CKYCR record lookup and upload
  • Wallet or account opening flow — either an RBI-authorised PPI issuer partnership (M2P, Zeta, Yes Bank, IndusInd, RBL BaaS) or a bank-account creation journey wired to a partner-bank API
  • UPI stack — VPA creation, collect and pay via NPCI, mandate creation for recurring debits, refund flow, dispute raising
  • Card issuance and management — virtual and physical RuPay or Visa cards via M2P, Zeta, or a partner-bank BIN, RBI-compliant tokenisation, freeze / unfreeze / block controls
  • Transaction ledger and statements — real-time balance, filterable transaction history, downloadable PDF statements, GST-compliant invoices where applicable
  • In-app support and dispute engine — RBI-mandated response SLAs, chargeback initiation, ticket escalation, and a full audit trail per case
  • Compliance surfaces — DPDP consent capture, data-deletion route, App Tracking Transparency for iOS 14+, terms and privacy screens auto-versioned

Cost to build a fintech app in India — the real INR ranges

Fintech app pricing carries more variance than any other app category we build, because the scope of "a fintech app" ranges from a two-lakh referral-and-cashback wallet on top of an existing bank rail to a two-crore neobank with its own BaaS stack, card programme, and lending engine. Below are the honest ranges we quote after a proper discovery — not a range copied off a marketing blog. Every number assumes a Flutter build (one codebase, iOS + Android), a Node.js or Laravel backend, source code in your Git repository, and App Store plus Play Store submission handled by our team under your developer accounts.

A UPI referral or payment-collection app — a light wallet layer, VPA creation, collect and pay, referral engine, and one KYC tier — starts at around ₹3.5 lakh and ships in ten to fourteen weeks. A prepaid wallet with PPI issuance through a BaaS partner, virtual RuPay card, add-money via UPI or card, spend-and-withdraw, and full KYC (Aadhaar OKYC + video-KYC) sits in the ₹9-22 lakh range and ships in fourteen to twenty weeks. A digital lending app compliant with the RBI Digital Lending Guidelines 2022 — bureau pull via CIBIL, Experian, or Equifax, PAN and Aadhaar OKYC, income verification through Perfios or Karza, e-agreement via NSDL eSign or Digio, and eNACH mandate setup — lands in the ₹12-30 lakh range and ships in sixteen to twenty-four weeks. A neobank front-end with a partner-bank account, debit card, UPI, statements, and a light PFM layer runs ₹18-45 lakh across twenty to twenty-eight weeks. A wealth or mutual-fund app with BSE StAR MF or NSE NMF-II integration, portfolio views, SIP setup, KYC via CVLKRA / CAMS KRA, and eSign-based investment agreements runs ₹9-25 lakh across sixteen to twenty-two weeks. A full B2C neobank plus lending stack with in-house LOS / LMS and card issuance is quoted after discovery and starts at ₹45 lakh.

Recurring costs are worth planning against, because the fintech unit economics are shaped as much by API bills as by developer time. e-KYC via Signzy, Digio, Hyperverge, IDfy, or Karza costs ₹15-35 per Aadhaar OKYC and ₹40-90 per video-KYC. CKYCR upload is around ₹8-15 per record. Bureau pulls run ₹40-95 per soft pull and ₹15-45 per additional endpoint. Bank account verification via penny-drop or NPCI IMPS is ₹1-4 per verification. Razorpay charges 2 percent on domestic cards, ₹5-15 flat on netbanking, and free on UPI. Card issuance through a BaaS partner is ₹40-150 per virtual card and ₹120-350 per physical card plus a per-transaction switching fee. AWS or GCP hosting typically runs USD 300-1,500 per month at launch scale, climbing with active-user growth. AppsFlyer, Branch, or Adjust attribution starts at USD 400 per month.

Every build is fixed-scope. The number in the quotation is the number you pay, and every change request during the build is estimated in writing before work begins. Post-launch, an optional support retainer covers bug fixes, dependency upgrades, iOS and Android OS updates, security patching, and a 24-hour SLA on P0 issues.

  • UPI collection / referral wallet — ₹3.5-8 lakh, 10-14 weeks
  • Prepaid wallet + virtual RuPay card (PPI via BaaS) — ₹9-22 lakh, 14-20 weeks
  • Digital lending app (RBI DLG 2022 compliant) — ₹12-30 lakh, 16-24 weeks
  • Neobank front-end (partner-bank account, card, UPI, PFM) — ₹18-45 lakh, 20-28 weeks
  • Wealth / MF app (BSE StAR MF or NSE NMF-II) — ₹9-25 lakh, 16-22 weeks
  • Full B2C neobank + in-house lending stack — from ₹45 lakh, quoted after discovery
  • e-KYC APIs — ₹15-90 per journey; bureau pulls ₹40-95; penny-drop ₹1-4
  • Card issuance — ₹40-150 virtual, ₹120-350 physical + switching fees per transaction

Tech stack, compliance controls, and integrations a fintech app runs on

A fintech app lives on the reliability of about a dozen integrations, each governed by a different regulator, contract, and SLA. Miss one and the launch stalls at the compliance audit. Below is the reference stack we ship, the compliance controls that go in by default, and the integrations Indian fintech teams actually ask for on the first call.

The frontend is Flutter for iOS and Android on one codebase, with Next.js for the admin dashboard, compliance console, and any customer-facing web portal. The backend runs on Node.js (NestJS with strict TypeScript) or Laravel, chosen against the team you plan to grow later. Realtime events (transaction status, KYC status, dispute updates) run over a WebSocket layer with Redis pub-sub underneath. Transactional data lives in PostgreSQL (preferred for fintech because of the stronger constraint model), with encrypted at-rest storage on AWS RDS or GCP Cloud SQL. Sensitive fields — PAN, Aadhaar reference numbers, tokenised card handles — are envelope-encrypted with per-tenant KMS keys, and every read is logged to an immutable audit table.

KYC and identity is where fintech-specific integration density peaks. Aadhaar OKYC through UIDAI-authorised sub-KUAs (Signzy, Digio, Hyperverge, IDfy, Karza, Sumsub), video-KYC through the same partners with liveness detection, PAN validation via NSDL, CKYCR lookup and upload via CERSAI, PEP and sanctions screening against RBI, SEBI, OFAC, and UN lists, DigiLocker document pull for driving licence and Aadhaar XML. Bank-account verification runs penny-drop through Cashfree, Razorpay, or Setu, or IMPS via NPCI. Bureau pulls run through CIBIL, Experian, Equifax, or CRIF via their B2B APIs.

Payments plug into Razorpay, Cashfree, PayU, PhonePe, and Paytm on the collections side, and NPCI UPI, IMPS, NEFT, and RTGS on the payout side via an RBI-authorised PA-PG partner. PPI issuance runs through M2P, Zeta, or a direct partner-bank arrangement (Yes Bank, IndusInd, RBL, ICICI BaaS programmes). Card programmes plug into M2P, Zeta, or the partner-bank BIN, with mandatory RBI card-tokenisation for any stored card data. eNACH mandates run through NPCI-authorised sponsor banks. eSign runs through NSDL eSign, Protean, or Digio.

Compliance controls are not a document — they are wired into the code. MFA is enforced on every login and every payment above a configurable threshold. RBI card-tokenisation is mandatory — we never store PAN, expiry, or CVV; only network-issued tokens. Cardholder Data Environment (CDE) scope is architected to PCI-DSS SAQ-A (fully outsourced card data) unless the product needs to hold card data itself. Session security enforces short JWT lifetimes, refresh-token rotation, device binding, and jailbreak / root detection. RBI-mandated 24-hour customer response SLAs are enforced by the dispute engine. DPDP Act 2023 consent capture is versioned per policy revision. Every write to a money-moving endpoint hits an immutable audit log with actor, IP, device, timestamp, and diff. SOC 2 Type 2 and ISO 27001 alignment is architected from day one where the roadmap calls for external certification later.

Analytics and monitoring round the stack. GA4 for product analytics, Mixpanel or Amplitude for funnel and retention, Sentry and Datadog for error and performance, AppsFlyer / Branch / Adjust for attribution. Feature flags run on LaunchDarkly or self-hosted Unleash so a bad release can be killed without a redeploy. If the fintech product connects to a CRM for customer lifecycle, we integrate with [Fruxinfo's CRM for Financial Services](/crm-for-financial-services) build, which is engineered to speak to the same identity, KYC, and ledger stack.

  • Flutter iOS + Android on one codebase, Next.js admin + compliance console
  • Node.js (NestJS) or Laravel backend; PostgreSQL + Redis + AWS KMS envelope encryption
  • e-KYC — Signzy, Digio, Hyperverge, IDfy, Karza, Sumsub; DigiLocker + CKYCR wired in
  • Bureau pulls — CIBIL, Experian, Equifax, CRIF; penny-drop and NPCI IMPS bank verification
  • PPI / card issuance via M2P, Zeta, Yes Bank, IndusInd, RBL BaaS; RBI card-tokenisation mandatory
  • eNACH via NPCI sponsor banks; eSign via NSDL / Protean / Digio; RBI DLG 2022 controls in the LMS
  • MFA on every login, jailbreak / root detection, session binding, immutable audit trail
  • PCI-DSS SAQ-A scope by default; SOC 2 Type 2 and ISO 27001 architected from day one
Flutter (iOS + Android)Next.js (Admin + Compliance Console)Node.js / NestJSLaravelPostgreSQLRedisAWS KMS Envelope EncryptionSignzyDigioHypervergeIDfyKarzaSumsubUIDAI Aadhaar OKYCDigiLockerCKYCR (CERSAI)NSDL PAN ValidationCIBIL / Experian / Equifax / CRIFPerfiosSetuCashfree Penny-DropNPCI UPI / IMPS / NEFT / RTGSRazorpayCashfree PaymentsPayUPhonePe SDKJuspayM2PZetaYes Bank BaaSIndusInd BaaSRBL BaaSICICI BaaSRuPay / Visa / MastercardRBI Card TokenisationNSDL eSign / Protean / Digio eSignNPCI eNACHBSE StAR MFNSE NMF-IICAMS KRA / CVLKRAIRDAI POSP APIsFirebase FCM + APNSWhatsApp Business APIGA4 + Mixpanel + AmplitudeAppsFlyer / Branch / AdjustSentry + DatadogLaunchDarklyPCI-DSS SAQ-ADPDP Act 2023 ConsentRBI DLG 2022 ControlsSOC 2 Type 2 ArchitectedISO 27001 Architected

Monetization models — how fintech apps actually make money in India

Fintech apps have the widest revenue mix of any category we build, and the choice of model at launch shapes both the unit economics and the regulatory perimeter. Below are the levers we architect for, with real India-market ranges. Most successful fintech builds run two or three of these in combination — a single revenue lever rarely covers the KYC cost, the API bill, and the CAC in the first eighteen months.

Interchange revenue is the neobank staple. Every debit-card swipe on a RuPay or Visa card issued through your BIN or partner-bank BIN generates 0.15-0.90 percent interchange, split between the issuer, the card programme, and the BaaS partner. A launch-scale programme keeps 0.10-0.35 percent net after all cuts. This is the primary revenue lever for prepaid wallets and neobank cards, and it scales linearly with spend volume.

Convenience or platform fees on payment collections are the cleanest lever. Bill payment, rent payment, education fee payment, and merchant collections carry a ₹2-15 convenience fee per transaction. UPI collections are free to the platform under current NPCI rules for retail, but the platform captures a small fee on B2B or vertical-specific collections. This model has near-zero variable cost once the rails are live.

Lending interest and fees are the highest-margin lever in Indian fintech. Personal loans, buy-now-pay-later, consumer durables loans, credit-line products, and merchant advances typically carry 1.5-3.5 percent processing fees plus 14-36 percent APR interest depending on the RBI category the lender falls under. This lever requires an NBFC licence, a partnership with an NBFC or bank as the lender-of-record, and full RBI Digital Lending Guidelines 2022 compliance in the app.

Wealth advisory or platform fees for mutual-fund, stock, or alternate-investment apps run 0.1-1 percent AUM per year or a flat platform fee of ₹99-499 per month. Insurance distribution as a corporate agent or POSP under IRDAI regulations captures 5-30 percent commission on premium depending on the product line — motor, health, term, and general insurance carry very different rates.

Foreign exchange spreads on cross-border remittance apps carry 40-120 basis points depending on the corridor and the volume. Card-issuing on prepaid forex cards adds 100-250 basis points on the load and interchange on spend. This model is tightly regulated under FEMA and requires an AD-II or AD-I licence or a partnership.

Subscription revenue is the emerging retention lever. A ₹99-499 monthly plan bundling zero-fee transactions, higher card limits, better cashback, cashback multipliers, or premium wealth or credit features. Subscription revenue is the highest-margin recurring line item once the base grows.

Referral and cross-sell commissions on partner products — loans referred to partner NBFCs, insurance sold on behalf of partner insurers, credit cards referred to partner banks — capture ₹200-3,500 per successful conversion. Small, but the CAC recovery model at launch scale.

  • Debit-card interchange — 0.10-0.35% net; scales with card spend volume
  • Platform / convenience fees on bill and merchant payments — ₹2-15 per transaction
  • Lending processing fees 1.5-3.5% + APR 14-36% (RBI DLG 2022 compliant)
  • Wealth AUM fees 0.1-1% p.a. or platform ₹99-499 / month
  • Insurance distribution — 5-30% commission on premium (IRDAI POSP / CA)
  • Cross-border FX spreads — 40-120 bps + card load and interchange
  • Subscription plans — ₹99-499 / month bundling fee waivers and premium features
  • Partner referral commissions — ₹200-3,500 per successful loan / insurance / card conversion

Timeline and delivery process — how we ship a fintech build

We work in fixed-scope, milestone-billed sprints with a weekly Friday demo. The clients we ship for know what will be on staging every Friday, and they know exactly which invoice covers which milestone. Below is the standard timeline for the two most-common fintech scopes — a prepaid wallet with PPI and card issuance, and a digital lending app under RBI DLG 2022.

Weeks 1-3 are the blueprint and compliance-mapping phase. Discovery with the founder, compliance head, and product lead — on-site in Ahmedabad or on Zoom. We walk through the regulatory perimeter (PPI, PA-PG, NBFC-as-service, MF distributor, insurance CA, whatever applies), the KYC tiering the product needs, the payment rails and payout SLAs, the dispute and refund flow, and the audit-log requirements. We come out with a written scope document, a compliance-control map (RBI, DPDP, PCI-DSS SAQ-A, Aadhaar, PMLA), wireframes for every screen, a data model with PII classification, a KYC and identity-partner shortlist, a fixed-price quotation, and a milestone timeline. Nothing gets coded until the scope is signed.

Weeks 4-8 are backend, KYC, and identity. The backend, database schema with envelope encryption, admin console, KYC flow (PAN, Aadhaar OKYC, video-KYC if in scope), CKYCR lookup, and the compliance audit-log layer are the first modules built and demoed. The KYC partner is contracted and the sandbox is live by end of week 6. Bureau, penny-drop, and any identity-verification APIs are integrated by end of week 8.

Weeks 9-14 are the customer app and money-movement layer. The Flutter customer app is built module by module — onboarding, KYC journey, wallet or account view, UPI or payment stack, transaction history, statements, and support. Card issuance (virtual first, physical activation later) is wired via the BaaS partner. UPI is wired via the PA-PG partner. Every payment endpoint gets a full audit-log integration test, an idempotency check, and a chargeback simulation. By end of week 14 the app is on internal-test tracks on TestFlight and Play Internal Testing.

Weeks 15-20 are compliance hardening, lending or advanced modules, and launch prep. For a lending app, the loan-origination system, e-agreement (NSDL eSign or Digio), eNACH mandate, and repayment engine ship in this window. For a wallet or neobank, the card personalisation, KYC-tier upgrade paths, and the dispute-and-chargeback flows harden here. External penetration testing runs in week 16-17. RBI or DPDP compliance walkthrough with the client's legal or CS team runs in week 18. App Store and Play Store review submission happens in week 18-19, with our team handling the Financial Services declarations and any first-round reviewer questions. Launch checklist — MFA audit, tokenisation audit, audit-log audit, DPDP consent audit, Data Safety declaration audit — is signed off before go-live in week 20.

Post-launch, the first four weeks are a hyper-care sprint — daily standup, live production monitoring on Sentry and Datadog, and same-day patches on P0 issues. From month two onwards, the app moves to the standard retainer cadence — a fortnightly release, a monthly compliance review, a quarterly roadmap conversation, and continuous OS-version and dependency patching. For a deeper look at how we run the underlying build discipline across every category, see the [App Development](/app-development) pillar.

Who this build is for — the four fintech client patterns we ship for

Every fintech enquiry that lands on our contact form falls into one of four patterns. The scope, the timeline, and the price map cleanly to the pattern — knowing which one you are running lets the first call move quickly to numbers instead of vocabulary.

The founder-led wallet or vertical fintech has a specific vertical (student payments, gig-worker payouts, D2C brand loyalty, temple donations, alumni-giving) and wants a compliant wallet or payment layer on top of a real user community they already have. Scope is a prepaid wallet with PPI issued through a BaaS partner, UPI collect and pay, a virtual RuPay card, and a light PFM view. Typical build is ₹9-18 lakh and ships in fourteen to eighteen weeks. Compliance is anchored on the BaaS partner's PPI licence, which shortens the regulatory perimeter meaningfully.

The digital lending app is either an NBFC building a direct-to-consumer channel or a startup partnering with an NBFC as the lender-of-record under the RBI DLG 2022 framework. Scope is the customer app (onboarding, KYC, bureau pull, income verification, e-agreement, eNACH mandate, disbursal and repayment), the collections app or web console, and the LOS / LMS. Typical build is ₹15-30 lakh and ships in eighteen to twenty-four weeks. The compliance load is heavier than any other category — the DLG 2022 disclosures, cool-off period, key-fact statement, and grievance-redress SLA are all wired into the app itself, not left as external policy documents.

The neobank front-end is a startup partnering with a scheduled commercial bank for the underlying account, debit card, and payment rails. Scope is the customer app (account view, card management, UPI, statements, PFM, cashback, referrals), the admin and CS console, and the KYC and onboarding flow. Typical build is ₹20-45 lakh and ships in twenty to twenty-eight weeks. The bank partnership contract typically determines half the scope (which BINs, which rails, which limits) — we recommend having the term sheet at least outlined before the discovery call.

The wealth or investment app is an AMC, distributor, or startup building a mutual-fund, stock, or alternate-investment product for retail investors. Scope is KYC via CVLKRA or CAMS KRA, BSE StAR MF or NSE NMF-II integration, portfolio and holdings view, SIP setup, transaction and eSign flows, and a research or advisory layer if positioned as an RIA or IA under SEBI. Typical build is ₹9-25 lakh and ships in sixteen to twenty-two weeks. SEBI compliance and the underlying platform's technical rules (BSE and NSE both publish specifications that shape the UX meaningfully) drive the scope more than the aesthetic.

If your build does not fit cleanly into one of these four, that is normal — cross-border remittance, insurance-only apps, B2B invoice financing, and stablecoin or crypto-adjacent apps are their own conversations. The blueprint call is where we place the project on the map and quote against the closest reference. For teams building both a customer app and an internal ops CRM, we usually recommend the [CRM for Financial Services](/crm-for-financial-services) build as the ops-side backbone.

The next step — book a fintech app blueprint call

The fastest way to know what your fintech app should cost, which regulatory perimeter it will sit inside, and what should be in the launch scope is a 30-minute conversation. We will ask about the product category (wallet, lending, neobank, wealth, insurance, remittance, or a hybrid), the licensing route (own licence, partner-bank BaaS, NBFC-as-service, distributor), the KYC tiering your users will pass through, the payment and payout rails your customers need, and the timeline and runway you are working against. At the end of the call you get a written blueprint — recommended scope, compliance-control map, module list, integration shortlist, indicative timeline, and a fixed-price quotation — with no obligation to move forward.

Call +91-99245-12890 or drop an enquiry through the contact form. We reply the same working day.

Fintech app questions we hear on the first call

What fintech founders, NBFC product leads, neobank teams, and wealth-app operators ask before starting a build. If yours isn’t here, we will answer it on the discovery call.

A UPI collection or referral-wallet app starts at around ₹3.5 lakh and ships in ten to fourteen weeks. A prepaid wallet with PPI issuance through a BaaS partner and a virtual RuPay card sits in the ₹9-22 lakh range across fourteen to twenty weeks. A digital lending app compliant with the RBI Digital Lending Guidelines 2022 runs ₹12-30 lakh across sixteen to twenty-four weeks. A neobank front-end with a partner-bank account, card, UPI, and PFM runs ₹18-45 lakh across twenty to twenty-eight weeks. A wealth or mutual-fund app runs ₹9-25 lakh. A full B2C neobank plus in-house lending stack is quoted after discovery and starts at ₹45 lakh. Every number is fixed-scope — the amount in the quotation is what you pay.