Data Protection
Comprehensive security measures to protect your sensitive information
Last updated: 18 August 2026
Our Security Commitment
We implement industry-leading security measures and follow best practices to protect your data. Our multi-layered approach ensures that your sensitive information remains secure at all times.
Security First Approach
We treat data security as our top priority, implementing multiple layers of protection and continuously monitoring for threats to ensure your information remains safe.
Security Measures
Multi-layered security approach to protect your data
Encryption
- End-to-end encryption for all data transmission
- AES-256 encryption for data at rest
- TLS 1.3 for secure communication
- Encrypted database connections
Access Control
- Multi-factor authentication (MFA)
- Role-based access permissions
- Regular access reviews and audits
- Principle of least privilege
Infrastructure
- Secure cloud infrastructure (AWS/Azure)
- Regular security patches and updates
- Intrusion detection systems
- Proactive security monitoring
Data Handling
- Data anonymization and pseudonymization
- Secure data deletion procedures
- Data retention policies
- Regular data backups
Compliance
How we approach data protection and payment security
Data Protection Compliance
Aligned with applicable data-protection laws, including India's DPDP Act
- Right to access personal data
- Right to rectification
- Right to erasure
- Data portability
- Consent management
Secure Payment Processing
Payments are processed through a PCI-DSS-compliant payment gateway (Razorpay)
- Secure payment processing
- Card details are never stored on our servers
Your Data Rights
You have complete control over your personal data
Access
Request a copy of all personal data we hold about you
Rectification
Correct any inaccurate or incomplete personal data
Erasure
Request deletion of your personal data
Portability
Receive your data in a structured, machine-readable format
Restriction
Limit how we process your personal data
Objection
Object to certain types of data processing
Incident Response
Our structured approach to handling security incidents. We act promptly, in line with applicable legal requirements.
Detection
Automated monitoring and user reporting systems
Assessment
Security team evaluates the scope and impact
Containment
Isolate affected systems and prevent further damage
Investigation
Forensic analysis to determine cause and extent
Notification
Notify affected users and authorities if required
Recovery
Restore services and implement preventive measures
Data Retention
How long we keep your data and why
Personal Data
We retain your personal data only as long as necessary to provide our services and comply with legal obligations.
- • Account data: Until account deletion + 30 days
- • Transaction data: 7 years for tax compliance
- • Communication data: 3 years for support purposes
- • Analytics data: 2 years in anonymized form
Loan Records
Loan information is retained for legitimate business purposes and community protection.
- • Verified records: 10 years from last update
- • Unverified records: 2 years from creation
- • Disputed records: Until resolution + 1 year
- • Deleted records: 30 days in backup systems
Data Protection Questions?
Our data protection team is available to answer any questions about how we protect your information.