Data storage policy

What we store, and for how long

This page restates what our Privacy Policy says about the data we store, who processes it, how long we keep it, how you can have it deleted and how we protect it. If the two ever differ, the Privacy Policy governs.

Last updated 02-Oct-2026

What we store

The personal data we collect is listed in section 03 of our Privacy Policy:

  • Identity and contact details (name, mobile, email, city)
  • KYC identifiers for promoters and signatories (PAN, and where a promoter chooses Aadhaar e-KYC, the Aadhaar number used to send a UIDAI one-time code, of which we retain only the last four digits)
  • Business details (entity type, GST, Udyam, vintage)
  • Financial documents (bank statements, GST returns, ITR)
  • Your loan requirement (amount, purpose, tenure)
  • Usage and device information
  • Payout details, for referral partners
  • Communications with us

Where it is processed

Section 06 of the Privacy Policy lists the providers that process your data, and section 09 describes where we host it. Some processing happens outside India:

  • Microsoft Azure OpenAI (Azure AI Foundry) reads your uploaded documents and powers the AI assistant in our website chat. It processes this content on servers outside India, currently in the United States. Your content is not used to train any AI model.
  • PostHog records session replays in our portals, including what you type. It processes that data in the United States.
  • Our website analytics providers, our advertising partners (Google Ads and Meta) and Google reCAPTCHA process usage and device data outside India.

Section 16 of the Digital Personal Data Protection Act, 2023 permits transfers to any country the Central Government has not restricted by notification, and we make them only to perform the services you have asked us for. Where a sectoral law requires a particular record to be held in India, we keep that record in India.

Nothing about your loan requirement is shared with a lender or a Lender Partner until you approve it. We do not sell, rent or lease your personal data to anyone. See how we share your data.

How long we keep it

We keep your data only as long as needed for the purposes in the Privacy Policy and to meet our legal obligations. These are the longest periods we keep each kind of record:

  • Application and facilitation records: 7 years after your last loan requirement is closed or disbursed
  • KYC records and tax invoices: 8 years (CGST)
  • Consent records: for the period set by the DPDP Rules, 2025

You can also ask for erasure at any time.

How to have it deleted

Section 12 of the DPDP Act, 2023 gives you the right to erasure, with no reason required. Section 13 of the Privacy Policy gives the email address to write to. The word "delete" is enough.

We acknowledge within 1 working day and may ask you to confirm your identity first. A member of our team then carries out the erasure by hand and confirms in writing once it is done.

What gets deleted:

  • Account and business profile
  • All uploaded documents
  • Your loan enquiry and facilitation records
  • Financial analysis we generated
  • Support and contact history
  • Consents and the data pulls made under them
  • Analytics and error-monitoring records

Statutory exceptions. A few records are kept where the law requires: KYC records and tax invoices for 8 years (CGST Section 36), consent records for the period set by the DPDP Rules, 2025, records under an active legal claim or regulatory obligation, and anonymised analytics that no longer identify you. Where you have an active lender application or a disbursed loan, the lender holds its own copy of the records you submitted to it, governed by that lender's own policies.

If we decline a request, it is only when the law requires it. You may then escalate to our Grievance Officer (see grievance redressal) and then to the Data Protection Board of India.

How we protect it

We protect your data with TLS 1.2 or newer in transit, AES-256 at rest and role-based access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security against every loss, misuse or unauthorised access.

If there is a breach. If a personal data breach affects your data, we will tell you about it and report it to the Data Protection Board of India, in the form and within the timelines set by Section 8(6) of the DPDP Act, 2023 and the DPDP Rules, 2025. Our notice to you will describe what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.