Privacy Policy
This Privacy Policy ("Policy") of FatakPay Digital Private Limited ("FDPL", "FatakPay", "we", or "us" or "our") is aimed at informing the users, members, unregistered visitors, and any person(s) using or accessing the Platform (as defined below) (hereinafter collectively referred to as the "Users" or "You" or "Your" or "Yours") of the practices in relation to the collection, storage, use, processing, and disclosure of personal information and personal data that You have chosen to share with us, when You use or access our website hosted at www.fatakpay.com ("Website") and/ or download and use our mobile application namely 'FatakPay' ("App"). The Website and the App shall hereinafter be collectively referred to as (the "Platform").
FatakPay is a fintech company which is engaged in the business of facilitating provision of various products and services. Through the Platform, we facilitate provision of Credit Facility, insurance products, mutual fund portals, digital gold / silver investments, secured Credit Cards, Bharat Bill Payment Services ("BBPS") (collectively referred to as "Product(s)"), operate as a third party app provider ("TPAP"), and also offer services, such as job portal access, access to credit reports based on Your consent, and various reward programs, in association with our partners offering such Products (collectively, "Services"). Our Services, inter alia includes provision of short-term credit facilities to borrowers ("Credit Facility"), by connecting them with various non-banking financial company ("NBFC") partners and Scheduled and Commercial Banks, who are authorized by the Reserve Bank of India ("RBI") to offer and sanction such Credit Facility ("Lending Partners") on the Platform.
FatakPay, through this Policy, aims to demonstrate its commitment towards protecting Your personal data and respecting Your privacy in compliance with the Information Technology Act, 2000 and Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information), Rules, 2011 ("Rules"), the Digital Personal Data Protection Act, 2023 ("DPDPA"), the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and the Reserve Bank of India (Non-Banking Financial Companies — Credit Facilities) Directions, 2025 ("RBI Digital Lending Directions") and any other guidelines that maybe issued by RBI from time to time (all of such guidelines, "RBI Guidelines").
This Policy is applicable to all the information collected, received, owned, controlled, stored, processed, dealt with, shared with, accessed by, or handled by FatakPay in respect of a User. Please read this Policy along with the Terms and Conditions available at www.fatakpay.com.
This Policy is an electronic record in the form of an electronic contract formed under applicable laws. This Policy does not require any physical, electronic, or digital signature. By accessing, browsing, using, or registering on our Platform, or by providing us with your personal data, you signify that you have read, understood, and agree to be bound by the terms of this Policy and consent to the processing of your personal data as described herein. If you do not agree with the terms of this Policy, please do not access or use our Platform or Services.
- USER ACKNOWLEDGEMENT AND CONSENT
- User acknowledges that by accessing the Platform, User expressly consents and confirms to collection, maintenance, usage, handling, processing, storage and disclosure of User information, including personal data, by FatakPay in connection with the Services we offer to You through the Platform, in accordance with this Policy.
- Users acknowledge that they have the option to not provide or agree to the collection of personal data. If a User chooses to not grant us access to such personal data when requested, we will not be in a position to provide the User with the Services. In such an event, we encourage You to stop using the Services and accessing the Platform. In addition to this, in the event You do not consent to our access to Your personal data, we may have to terminate, suspend or limit Your access to the Services or Platform or part thereof, as may be the case.
- PURPOSE OF COLLECTION OF INFORMATION
- In general, you can browse the Website of FatakPay without disclosing Your identity or revealing any personal information about Yourself. However, to create an account on the Platform You will be required to provide us with certain personal information in connection with the Services. Our primary goal in accessing, collecting, processing and using Your information, is to provide You with a safe, efficient, smooth and customized experience of our Services. More importantly, in connection with the Credit Facility, we only collect and process basic minimal personal information of the User that we consider necessary for providing the Services and enabling Your use of our Platform.
- WHAT WE COLLECT AND HOW WE USE YOUR PERSONAL DATA
- FatakPay collects the following types of data sets from You for facilitating provision of various Services.
- The table below sets out (i) the personal data We collect, (ii) the corresponding purpose of collection, (iii) the device permission (if any) through which We access the personal data, (iv) the frequency of such access, and (v) the Service use case for which the data set is collected/ to which the purpose is linked.
Personal Data Purpose of Collection Permission / Mode of Access Frequency of Access Service Use Case Name Verification of User identity, and registering / onboarding the account on the Platform. Direct in-App entry by User At onboarding Credit Facility; access to credit reports; Insurance; BBPS; mutual funds; digital gold / silver; secured Credit Cards; reward programs; job portal access; credit builder program Date of birth Age verification, (minors below 18 years are restricted from availing the Services); and identity verification Direct in-App entry by User At onboarding Credit Facility; access to credit reports; Insurance Gender Identity verification; risk-rating for insurance underwriting where required by the insurer Direct in-App entry by User At onboarding Insurance Employment status / occupation Verification of financial credibility prior to sanction of a Credit Facility by the Lending Partner Direct in-App entry by User At loan application; on material change notified by User Credit Facility Contact information (email ID, mobile number) Identity verification; verification of credit-worthiness; service communications including OTP-based authentication and communications relating to any Credit Facility availed or applied for Direct in-App entry by User At onboarding and on update by User Credit Facility; access to credit reports; Insurance; BBPS; mutual funds; digital gold / silver; secured Credit Cards; reward programs; job portal access; Credit builder program Residential / correspondence address; Pincode Determination of serviceability, and identity / address verification Direct in-App entry by User At onboarding Credit Facility PAN details and other Government-issued identification documents (Officially Valid Documents) Identity verification; and assessment of eligibility for the Credit Facility Camera (one-time / on-demand) for Credit Facility use case and Storage / Files (read) where User uploads a soft copy One-time or on-demand for each KYC session; not accessed in the background Credit Facility; access to credit reports; Insurance; mutual funds; secured Credit Cards (and any other Service where the partner requires statutory KYC); credit builder program Selfie Identity verification; and assessment of eligibility for the Credit Facility Camera (one-time / on-demand) for Credit Facility use case One-time or on-demand for each KYC session; not accessed in the background Credit Facility; access to credit reports; Insurance; mutual funds; secured Credit Cards (and any other Service where the partner requires statutory KYC); credit builder program Income details Verification of credit-worthiness, and eligibility for the Credit Facility offered through Lending Partners Direct in-App entry by User; Storage / Files (read) where User uploads supporting documents Loan application Credit Facility Bank account details / UPI details Verification of credit-worthiness & disbursement and availing value-added services Direct in-App entry by User; Storage / Files (read) where User uploads bank statements At loan application and on update by User Credit Facility; BBPS; mutual funds; digital gold / silver; secured Credit Cards; Insurance; Rewards Program NACH / e-mandate details Repayment of amounts due under the Credit Facility through the Lending Partner Direct in-App entry by User At loan sanction; on each scheduled repayment cycle Credit Facility; Digital gold / silver Nominee details Recording the nominee in respect of the insurance policy as required under the Insurance Act, 1938 and applicable IRDAI regulations Direct in-App entry by User At policy issuance; on update by User Insurance Transactional SMS metadata (from 6-digit alphanumeric senders only) Verification and analysis of financial position; determination of cash flow, credits, income and spending patterns to assess creditworthiness. Personal SMSs, OTPs (save where required solely to enable onboarding on the Platform) and account details are not read or stored. SMS (read) — collected only with the User's explicit prior consent and with audit trail in accordance with the RBI Digital Lending Directions Collected only during loan application and underwriting; not accessed in the background after underwriting is complete Credit Facility Device GPS location Reducing fraud risk associated with loan applications, and determining serviceability of a loan application based on location Location Accessed at the time of onboarding and loan application; not accessed continuously in the background Credit Facility Device data (IP address, browser type and version, time-zone, operating system, device information) Data analytics; fraud prevention; security monitoring and incident detection. Captured server-side at session level On each session; not accessed in the background All Services Marketing and communications preferences Recording the User's preferences regarding marketing communications and communications under DND / NCPR settings Direct in-App entry by User At onboarding and on update by User All Services - Where a particular data set is required by a Lending Partner, insurer, card issuer, BBPS operating unit or other regulated partner over and above the data sets listed above, that partner shall separately notify You of such requirement and obtain Your specific consent in accordance with applicable law before any such additional data is collected.
- Personal Data Collected from Third Parties
- This type of data is personal data about You received from various third parties and public sources including our third-party service providers for advertising and User analytics purposes, and other publicly available sources in connection with our provision of Services to You, or in connection with Your use of the Platform or Services that You choose to avail. Please note that we do not have any control over personal data that You may choose to make publicly available. For example, if You post reviews, comments, or messages on public sections of the Platform or on an application store (such as the Play Store), You do so at Your own risk. We are not liable for any third-party misuse of such data.
- USE OF PERSONAL DATA
By using our Platform and submitting Your personal data to FatakPay, You expressly acknowledge and consent to use of such information in a manner specified under this Policy. Such personal data may be used for the following purposes:
- To register You as a user of the Platform and verifying User identity;
- Facilitating User's usage of Platform and our Services. Please note that certain data sets may only be used/collected if the User intends to use the Service for a specific Product on the Platform as indicated above.
- To manage our relationship with You, including notifying You of changes to any Services;
- For extension of Credit Facility and other Services to the User from Lending Partners and other financial partners;
- To ensure compliance with all legal obligations of Lending Partners, vis-à-vis Know-your Customer, Prevention of Money Laundering, CKYRC requirements, etc. for the purposes of facilitation of the Services and Products;
- For fraud prevention and detection;
- To send User surveys and marketing communications that FatakPay believes may be of User's interest;
- To facilitate for repayment of the Credit Facility availed or recovery of outstanding payments on behalf of the Lending Partners;
- To diagnose technical problems, provide support and help Users in addressing troubleshoot problems;
- To send and receive communications, show advertisements, notifications and make promotional offers;
- To prepare reports, review and filing as per applicable laws;
- To contact Users regarding Lending Partners and the various Services being facilitated through FatakPay, third party services and offers;
- To understand User preferences requirements;
- To permit User to participate in interactive features offered through the Platform;
- To improve the content, our business and delivery models and protect the integrity of the Platform;
- To increase/improve the Services offered on the Platform;
- To ensure compliance with all applicable laws;
- To respond to court orders, establish or exercise our legal rights, or defend ourselves against legal claims;
- To perform our obligations that arise out of the arrangement we are about to enter or have entered with You; and
- To enforce our Terms and Conditions available at www.fatakpay.com.
- HOW YOUR PERSONAL DATA IS SHARED
- Except as required under applicable laws or pursuant to a court/government order or for purposes set forth in clause 5.2 below, any information or data shared by us with third parties shall be undertaken, solely to render the Services to You.
- We will share Your information with third parties to facilitate provisioning of Services by us to You only in such manner as described below:
- We may disclose Your information to our Lending Partners on the Platform to facilitate provision of Credit Facility for You;
- We may disclose Your information to our third-party service providers for providing the Services, such as mutual funds and insurance products, as detailed under the Terms & Conditions or for recovery of outstanding Credit Facility sanctioned to You by the Lending Partners;
- We may share Your information with our third-party partners in order to conduct data analysis in order to serve You better and provide services on our Platform;
- We may disclose Your information, without prior notice, if required under any law or if we are under a duty to do so in order to comply with any legal obligation or an order from the government and/or a statutory authority, or in order to enforce or apply our Terms and Conditions or assign such information in the course of corporate divestitures, mergers, or to protect the rights, property, or safety of us, our Users, or others.
- We may share Your data with our affiliates and/or group companies for data processing and analysis;
- We and our affiliates may share Your information with another business entity should we (or our assets) merge with, or be acquired by that business entity, or re-organization, amalgamation, restructuring of business for continuity of business.
- If You fail to provide consent for sharing of such data when requested by us, we may not be able to provide the Services to You.
- Third parties with whom we may share Your data for providing services are as below:
S.No. Vendor's Entity Name Address Email ID Personal Data Shared Purpose of Sharing i. HyperVerge 12, 17th Cross Rd, Sector 7, HSR Layout, Bengaluru, Karnataka 560102 [email protected] Name; date of birth; PAN; Officially Valid Documents; photograph; Video KYC recording Performing identity verification, OCR-based document parsing and Video KYC on behalf of the Lending Partners / partner regulated entity. ii. Ignosi Systems Private Limited (Ignosis) Block A - 807 Navratna Corporate Park, Iscon Ambli Road, Ahmedabad, Daskroi, Gujarat, India - 380058 [email protected] / [email protected] Bank statements and other financial documents uploaded by the User Document parsing and structured data extraction to support underwriting by the Lending Partner iii. Equifax 9, Mota Nagar, Andheri East, Mumbai, Maharashtra 400047 [email protected] Name; date of birth; PAN; address; mobile number Generating credit information reports and supporting credit-worthiness assessment. iv. Razorpay 22, 1st Floor, Sjr Cyber, Laskar-Hosur Road, Adugodi, Bangalore- 560030 [email protected] Name; mobile number; email ID; bank account / UPI / card reference; transaction amount and reference Processing of payment transactions (including BBPS bill payments, mutual fund payments and disbursement / collection where applicable) v. Cashfree Payments 1st Floor, Vaishnavi Summit, No. 6/B, Summit, 80 Feet Rd, Koramangala 3rd Block, Bangalore - 560034 [email protected] Name; mobile number; email ID; bank account / UPI / card reference; transaction amount and reference Processing of payment transactions (including payment collection, merchant payouts, automated settlements, and disbursement where applicable) vi. Easebuzz No. 101, 1st Floor, City Center, Hinjewadi Phase 1, Hinjewadi, Pune - 411057 [email protected] Name; mobile number; email ID; bank account / UPI / card reference; transaction amount and reference Processing of payment transactions (including payment collection, merchant payouts, automated settlements, and disbursement where applicable) vii. Gupshup Technology 101, Silver metropolis Building, Bimbisar Nagar Rd, Bimbisar Nagar, Goregaon, Mumbai, Maharashtra 400063 [email protected] Name; mobile number; email ID; transactional message content (OTPs, account alerts, repayment reminders) Delivery of transactional and service communications (SMS/ WhatsApp / email) to the User viii. ICS ICS Mobile (P) Ltd., #57 8th Main Road, 3rd Phase JP Nagar, Near SBI Bank, Bengaluru, Karnataka 560078 [email protected] Name; mobile number; transactional context or variables (such as OTP codes, loan account alerts, and payment link strings) Transmission and routing of critical system communications (including transactional OTPs, WhatsApp business notifications, service triggers, and account alerts) ix. CRIF High Mark Credit Information Services B-04,05,06, 4th Floor, Art Guild House, Phoenix Market City, L.B.S Marg, Kurla (West), Mumbai Mumbai City MH 400070 [email protected] Name; date of birth; PAN; address; mobile number Generating credit information reports and supporting credit-worthiness assessment x. TransUnion CIBIL Limited One World Centre, Tower 2A, 19th Floor, Senapati Bapat Marg, Elphinstone Road, Mumbai - 400 013. [email protected] Name; date of birth; PAN; address; mobile number Generating credit information reports and supporting credit-worthiness assessment xi. Doqfy No. 42, 1st Main Road, 3rd Phase, J.P. Nagar, Bangalore - 560078 [email protected] Name; mobile number; email ID; permanent address; identity proof parameters (such as PAN or Aadhaar card elements); loan transaction details Facilitating automated execution of digital loan agreements xii. NSDL (Protean eGov Technologies Limited) Times Tower, 1st Floor, Kamala Mills Compound, Senapati Bapat Marg, Lower Parel, Mumbai - 400013 [email protected] Name; D.O.B.; PAN number Verification of user credentials xiii. Webengage 4th Floor, Commercial Building, Unit No. 401 & 402, its-01, Akruti Star, Central Road, MIDC, Andheri (East), Mumbai - 400093 [email protected] Name; mobile number; email ID; device tokens; platform interaction events; transaction success/failure notifications Processing of user behavioral data and automation of customer engagement triggers (including delivery of push notifications, marketing campaigns, in-app updates, and customized lifecycle journeys where applicable) xiv. Lending Partners (Regulated Entities — Banks / NBFCs) As listed at the URL set out below the table As listed at the URL set out below the table All categories of personal data that are necessary for loan origination, including identity, KYC, contact, financial, transactional, NACH and device data. Loan origination, underwriting, sanction, disbursement, servicing, recovery and statutory reporting in accordance with the RBI Digital Lending Directions. xv. Insurance partners (insurers and insurance intermediaries registered with IRDAI) As disclosed at the time of policy issuance As disclosed at the time of policy issuance Name; date of birth; gender; address; mobile number; email ID; PAN; nominee details; policy and claim data Issuance, servicing and settlement of insurance policies and claims under the Insurance Act, 1938 and applicable IRDAI regulations xvi. Asset Management Companies / mutual fund distributors As disclosed at the time of investment As disclosed at the time of investment Name; PAN; KYC documents; bank details; nominee details; transaction details Facilitating mutual fund subscription, redemption and unit-holder servicing xvii. BBPS / NPCI Bharat BillPay Limited and biller operating units As notified by NPCI Bharat BillPay Limited As notified by NPCI Bharat BillPay Limited Name; mobile number; biller customer reference; bill amount; transaction details Routing and settlement of bill payments through the BBPS network xviii. Credit card issuers As disclosed at the time of card issuance As disclosed at the time of card issuance Name; KYC documents; address; mobile number; email ID; PAN; financial data; nominee details (where required) Facilitating issuance, activation and servicing of credit cards xix. Cloud infrastructure / hosting service provider (India-based) As contracted from time to time As contracted from time to time All personal data hosted on FDPL's systems Hosting and storage of data at rest, with all storage on servers located in India in accordance with the RBI Digital Lending Directions xx. Recovery agents engaged by Lending Partners As notified to the User in advance of any contact As notified to the User in advance of any contact Name; contact details; loan account details; outstanding amount Recovery of overdue Credit Facility on behalf of the Lending Partner. xxi. Affiliates and group companies of FatakPay Same registered office as FDPL (or as separately notified) Same as FDPL (or as separately notified) Limited personal data necessary for the specified processing or analytics activity Internal data processing and analytics to enable and improve the Services, subject to the same safeguards as apply under this Policy xxii. Banking Partners – ICICI Bank, Axis Bank As contracted from time to time As contracted from time to time Name; bank account / UPI / card reference; transaction amount and reference; transaction details Processing of payment transactions xxiii. DSA (Direct Selling Agents / Business Correspondents) As per the respective local corporate address of the empaneled partner agency As per the respective local corporate address of the empaneled partner agency Name; mobile number; email ID; employment details; monthly income; basic identity parameters (such as PAN or Aadhaar card details) Facilitating offline/online loan sourcing and customer onboarding (including primary document collection, lead generation, and distribution of loan product marketing where applicable) - COOKIES
- FatakPay may use "cookies" as required on the Website. "Cookies" is a term generally used for small text files a web site uses to recognize repeat users, facilitate the User's ongoing access to and use of the site, allow a site to track usage behaviour and compile aggregate data that will allow content improvements and targeted advertising, preferences etc. Cookies themselves do not personally identify the User, but it identifies User devices. For the purpose of this Policy, Users are informed that cookies also exist within mobile applications when a browser is needed to view certain content or display an advertisement within the application. Generally, cookies work by assigning a unique number to the computer that has no meaning outside the assigning site.
- Users are being made aware that FatakPay cannot control the use of cookies or the resulting information by advertisers or third parties hosting data on FatakPay's Platform. If Users do not want information collected through the use of cookies, they may change the settings in the browsers that allows them to deny or accept the cookie feature as per User discretion and in the manner agreed by them.
- WEB BEACONS
The web pages of the Website contain electronic images known as "web beacons", sometimes called single-pixel gifs and are used along with cookies to compile aggregated statistics to analyse how the Website is used. Web beacons may also be used in some of FatakPay's emails so as to know which emails and links recipients have opened, allowing it to gauge the effectiveness of its customer communications and marketing campaigns.
- DATA PROTECTION AND SECURITY
- We shall protect personal data by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum
- appropriate data security measures, including securing of such personal data through its encryption, obfuscation or masking or the use of virtual tokens mapped to that personal data;
- appropriate measures to control access to the computer resources
- visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence;
- reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, including by way of data backups;
- for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise;
- appropriate technical and organisational measures to ensure effective observance of security safeguards.
- Some of the safeguards we use are firewalls and bit data encryption using (Secure Sockets Layer) SSL, and information access authorization controls. We use reasonable safeguards to preserve the integrity and security of Your information against loss, theft, unauthorized access, disclosure, reproduction, use or amendment. To achieve the same, we use reasonable security practices and procedures as mandated under applicable laws for the protection of Your information.
- We shall protect personal data by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum
- YOUR LEGAL RIGHTS
- Data Storage and Revocation of Consent:
- We will store Your information and/or data for such period as may be required by FatakPay/Lending Partners to (i) enforce or enable Lending Partner to enforce its legal rights and obligations against You; (ii) to ensure compliance with its obligations and responsibilities or the Lending Partner's obligations and responsibilities under applicable laws, as specified by the RBI (iii) provide Services to you.
- You may, however, withdraw Your consent at any time. Such a request shall be complied with by Us subject to the applicable laws and the terms of the Credit Facility availed through the Platform. You further understand and agree that neither the repayment of a Credit Facility, nor the deletion of Your account with the Platform, automatically rescinds the consents You have provided to us under the Policy.
- You may request Your data deletion by writing to us at [email protected].
- Data Retention
You agree and acknowledge that Your personal data will continue to be stored and retained by us as required or permitted by applicable laws or as required for defending future legal claims against us or our financial partners, including Lending Partners. All the other details will be deleted upon Your request for the deletion of the data, provided there is no active Credit Facility or Service being availed by You.
As a Lending Service Provider, We facilitate loan origination on behalf of Lending Partners. Following transmission of verified data to the relevant Lending Partner, primary data controllership in respect of loan account data passes to that Lending Partner. Customers should also refer to the privacy policy of the relevant Lending Partner for retention periods applicable to data held by the Lending Partner.
Your data shall not be retained beyond the applicable retention period, except where: (a) retention is required for the resolution of an ongoing dispute or legal proceeding; (b) a competent regulatory authority has directed retention of the data; or (c) the Customer has not yet repaid the Credit Facility in full.
Data Sets Purpose of Retention Retention Period KYC records and supporting documents (PAN, Officially Valid Documents, photograph, Video KYC recording) Statutory KYC record-keeping; defence of legal claims; supervisory inspection 5 (five) years from the date of cessation of the business relationship with the User or the date of the relevant transaction, whichever is later (and any longer period prescribed by the Lending Partner / partner regulated entity) Basic minimal data for Credit Facility viz. name, address and contact details Statutory record-keeping; defence of legal claims; reporting to Credit Information Companies ("CIC(s)"); supervisory inspection by the RBI FDPL, as a Lending Service Provider, retains only the minimal data permitted under the RBI Digital Lending Directions. Credit information report data Provision of access to the User's credit information report under the Credit Information Companies (Regulation) Act, 2005 Retained only for the duration necessary to provide the User with access to the credit information report or six (6) months from date of consent, whichever is earlier, and thereafter purged in accordance with our contractual arrangement with the relevant CIC. Mutual fund and digital gold / silver transaction records Statutory record-keeping under the SEBI (Mutual Funds) Regulations, 1996, the SEBI (Intermediaries) Regulations, 2008 and the PMLA, 2002 Retained by the AMC / Registrar and Transfer Agent / partner intermediary for the longer of (a) 8 (eight) years from the date of the transaction (SEBI record-retention norms) and (b) 5 (five) years from the cessation of the business relationship (PMLA) BBPS transaction records Statutory record-keeping under the RBI framework for the Bharat Bill Payment System; settlement and dispute resolution under the NPCI Bharat BillPay procedural guidelines Retained for the period prescribed by NPCI Bharat BillPay Limited and the RBI, typically 10 (ten) years from the date of the transaction Device data, access logs and processing logs Fraud prevention; detection, investigation and remediation of unauthorised access and security incidents Minimum 1 (one) year, in line; for longer where compliance with any other applicable law (including RBI cyber-security directions) requires Account / profile data (name, contact, profile information) Maintenance of the User's account on the Platform and continued provision of the Services For the duration of the User's account; thereafter as required by applicable law or for defence of legal claims. Marketing and communications preferences Honouring the User's communication preferences (including DND / NDNC opt-outs) For the duration of the User's account, or until withdrawn by the User, whichever is earlier Consent records and audit trails Demonstration of valid consent under Section 6 of the DPDPA, the DPDP Rules, 2025 and the RBI Digital Lending Directions; defence of legal claims Retained for the duration of the underlying processing activity and for a minimum of 1 (one) year thereafter, or longer where required by applicable law Grievance / complaint records Grievance redressal under the DPDP Rules, 2025 and the RBI Digital Lending Directions; supervisory inspection Minimum 3 (three) years from resolution of the complaint, or such longer period as may be required by applicable law Personal data that has been irreversibly anonymized, such that it can no longer be used to identify any individual, ceases to constitute personal data for regulatory purposes. We may retain anonymized or aggregated datasets for internal analytics and statistical purposes following the expiry of the applicable retention period.
- Data destruction protocol
You can request the erasure of Your personal data. This enables you to ask us to forget personal data. We shall comply with any request, subject to applicable laws, retention of any data required to defend us in a future legal action, and the terms of the Credit Facility that are sanctioned through the Platform.
- Data Storage and Revocation of Consent:
- UPDATE USER INFORMATION
Users are required to update their information available with FatakPay as and when there are any changes. Users are also entitled to review the information provided and ensure that any personal information or sensitive personal data or information found to be inaccurate or deficient be corrected or amended as feasible. Such corrections/updations may be done by the User's account on the Platform.
- TRANSFER OF PERSONAL DATA
Please note that all Your data, including financial data, is only stored on systems located in India. We shall not transfer Your personal data to any third country.
- THIRD-PARTY WEBLINKS
User acknowledges that the Platform may contain links to other websites. If a User clicks on a third-party link, the User will be directed to that website. Note that these external sites are not operated by FatakPay. Therefore, it is strongly advised that Users review the privacy policy of these websites/external links. FatakPay has no control over and assumes no responsibility for the content, privacy policies, or practices of any third-party sites or services.
- YOUR DUTIES AS THE USER
- You are required to:
- Not impersonate another person while providing your personal data for any specified purpose;
- Not suppress any material information while providing your personal data for any purpose;
- Provide only such information as is true, necessary, and verifiable for the purpose for which it is provided.
- You are required to:
- DND / COMMUNICATION OPT-OUT
Once You register on the Platform and sign in, You are not anonymous to the Company. In the event Your account is created using Your cell phone number and password, email address and password, or social media logins (as applicable), You authorize us (including its business partners) to send texts and email alerts to You with Your login details and any other service requirements, including promotional communications, even if You have registered yourself under DND or DNC or NCPR services. Your authorization shall be valid as long as Your account is not deactivated.
You confirm that laws concerning unsolicited communication referred to in the "National Do Not Call Registry" (NDNC Registry) will not be applicable for communications received from us in connection with Your loan application for Credit Facility and the Services.
- CHANGES TO PRIVACY POLICY
In the event that FatakPay modifies this Policy, the same will be updated on the Platform. In case of any material changes to the Policy, the Users will be notified by means of a notice on Platform prior to the change becoming effective. The Users are encouraged to periodically review this page for the latest information on FatakPay's privacy practices.
- GRIEVANCE REDRESSAL OFFICER
FatakPay has designated a Grievance Officer. Users can contact the Grievance Redressal Officer (GRO) with respect to any complaints or concerns regarding the handling, storage, or disclosure of User Information.
All queries, disputes, issues and questions regarding the Policy can be addressed using the Company's Grievance Redressal Mechanism available at https://fatakpay.com/redressal
The GRO can be contacted between 10:30 a.m. to 6:00 p.m. from Monday to Friday except on public holidays.




