This page restates what our Privacy Policy says about the data we store, who processes it, how long we keep it, how you can have it deleted and how we protect it. If the two ever differ, the Privacy Policy governs.
Last updated 02-Oct-2026
The personal data we collect is listed in section 03 of our Privacy Policy:
Section 06 of the Privacy Policy lists the providers that process your data, and section 09 describes where we host it. Some processing happens outside India:
Section 16 of the Digital Personal Data Protection Act, 2023 permits transfers to any country the Central Government has not restricted by notification, and we make them only to perform the services you have asked us for. Where a sectoral law requires a particular record to be held in India, we keep that record in India.
Nothing about your loan requirement is shared with a lender or a Lender Partner until you approve it. We do not sell, rent or lease your personal data to anyone. See how we share your data.
We keep your data only as long as needed for the purposes in the Privacy Policy and to meet our legal obligations. These are the longest periods we keep each kind of record:
You can also ask for erasure at any time.
Section 12 of the DPDP Act, 2023 gives you the right to erasure, with no reason required. Section 13 of the Privacy Policy gives the email address to write to. The word "delete" is enough.
We acknowledge within 1 working day and may ask you to confirm your identity first. A member of our team then carries out the erasure by hand and confirms in writing once it is done.
What gets deleted:
Statutory exceptions. A few records are kept where the law requires: KYC records and tax invoices for 8 years (CGST Section 36), consent records for the period set by the DPDP Rules, 2025, records under an active legal claim or regulatory obligation, and anonymised analytics that no longer identify you. Where you have an active lender application or a disbursed loan, the lender holds its own copy of the records you submitted to it, governed by that lender's own policies.
If we decline a request, it is only when the law requires it. You may then escalate to our Grievance Officer (see grievance redressal) and then to the Data Protection Board of India.
We protect your data with TLS 1.2 or newer in transit, AES-256 at rest and role-based access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security against every loss, misuse or unauthorised access.
If there is a breach. If a personal data breach affects your data, we will tell you about it and report it to the Data Protection Board of India, in the form and within the timelines set by Section 8(6) of the DPDP Act, 2023 and the DPDP Rules, 2025. Our notice to you will describe what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.