Compare offers from regulated banks, NBFCs and insurers with secure assisted applications.

Privacy & Data Protection

Privacy Policy

FINTARAA A unit of Xpertserve Services Private Limited PRIVACY POLICY https://fintaraa.com/ Last Updated: 23 June 2026

Effective status

Last Updated: 23 June 2026

Maintained for customers, applicants, borrowers, insured members, partners, and support teams working through Fintaraa.

IT Act 2000Consent BasedData SecurityGoogle Play Ready

Executive Summary

Fintaraa is not a lender, bank, NBFC, insurer, or financial institution.

Credit score and bureau information is accessed only after explicit user consent.

Users can request account and personal data deletion at support@fintaraa.com or https://fintaraa.com/delete-account.

01

1. Introduction and Scope

1.1 This Privacy Policy (“Policy”) describes the privacy practices of Fintaraa (“Fintaraa”, “we”, “us”, or “our”), a brand and unit operated by Xpertserve Services Private Limited, a company incorporated under the laws of India (collectively referred to as the “Company”). This Policy applies to the website located at https://fintaraa.com/, together with any associated mobile applications, platforms, and services operated by us (collectively, the “Platform”), and to the services we provide for distribution and facilitation of lending and financial products (“Services”) for our users (“User”, “Users”, “you”, or “your”). 1.2 This Policy outlines our practices with respect to the collection, storage, use, processing, sharing, and disclosure of Personal Information and Non-Personal Information (each as defined below) that you choose to share with us, or that we may otherwise collect, when you access or use the Platform and our Services. 1.3 This Policy is published in accordance with the Information Technology Act, 2000 and the rules made thereunder, which require the publication of rules, regulations, privacy policy, and terms of use on an online platform. 1.4 We are committed to protecting your privacy and your Personal Information. Please read this Policy together with our Terms of Use (“Terms”) carefully before you access or use the Platform or our Services. 1.5 By accessing or using the Platform, availing our Services, or otherwise providing us with your information, you agree to be bound by this Policy and expressly consent to the collection, use, processing, sharing, and disclosure of your Information in the manner described herein. If you do not agree with this Policy, please refrain from using the Platform or providing us with any Information. This Policy, read together with the Terms, governs your use of the Services.

02

Fintaraa is Not a Lender

Fintaraa is not a Bank, NBFC, lender, insurance company, or financial institution. Fintaraa operates as a technology platform, Loan Service Provider (LSP), and Direct Selling Agent (DSA) that connects users with regulated financial institutions. All lending, approval, underwriting, and disbursal decisions are made solely by the respective Bank, NBFC, or Insurance Provider. Fintaraa does not guarantee loan approval, credit card issuance, insurance issuance, or any financial product approval. Final decisions are solely at the discretion of the respective financial institution.

03

2. Information We Collect

2.1 In order to provide you with our Services, you may voluntarily provide information whenever you visit, access, register on, or use the Platform. We may also collect information automatically and combine it with other information to provide, operate, and improve our Services, products, content, and advertising. 2.2 Depending on the product, service, or feature requested, Personal Information we may collect includes: • Name • Mobile Number • Email • Address • PAN • Employment Information • Financial Information • Credit Information • Uploaded Documents 2.3 Non-Personal Information may include data received while you interact with or access the Platform, such as language preference, browser type, device type, IP address, operating system, internet service provider, usage patterns, cookies, and other tracking technologies. Together, Personal Information and Non-Personal Information are referred to as “Information”. Sources and Methods of Collection • Information you provide directly on applications, registration forms, or other forms on the Platform. • Information you send to us via any medium, including email, telephone, chat, or social media. • If you access the Platform via a mobile device, information transmitted from your device, including device identifiers and technical diagnostics. • Google Advertising ID (on Android devices), used solely for advertising and analytics purposes in accordance with Google Play policies and your device settings. • Information collected through your interactions with our customer service team. • Camera, storage/files, mobile number, location, microphone, and notification permissions only where relevant to a requested feature and only after user consent. • Log files, IP addresses, browser type, operating system, mobile device identifiers, usage patterns, and information about your internet service provider or mobile carrier, collected automatically due to standard internet communication protocols. 2.4 Fintaraa does not access, collect, store, or share a user's SMS messages, call logs, contact lists, or personal photos. Documents or images are processed only when selected by the user for upload or verification. 2.5 You agree to provide Information that is true, correct, current, and accurate. You may access, amend, alter, correct, or request deletion of your Information, in part or in full, by contacting our Grievance Officer (details set out in Section 11) or by updating your account information on the Platform. Information will be collected on a need basis, and we shall not be responsible for unverified information or information supplied by you. Children's Privacy 2.6 The Platform and our Services are intended for, and directed at, users who are 18 (eighteen) years of age or older. We do not knowingly collect Personal Information from individuals under the age of 18. However, we have no reliable means of independently verifying the age of users who access the Platform. If we become aware that we have inadvertently collected Personal Information from a person below the age of 18, we will take steps to delete such information within a reasonable time frame. If a parent or guardian becomes aware that their child has provided information to us without their consent, they should contact us using the details in Section 11 so that we may delete such information. We shall not be liable for any damage or injury suffered by a person below the age of 18 who uses the Services in contravention of this Policy and our Terms.

06

4. How We Use Your Information

We may collect, use, or process your Information, including Personal Information and Non-Personal Information, only for the following purposes: • To create, maintain, and provide you access to your registered account on the Platform. • To develop, deliver, operate, process, and improve our Services, products, and content, and to personalize and enhance your experience. • To inform you about our Services, products, offers, updates, and upcoming events, including order confirmations, invoices, technical notices, and security alerts. • To carry out identity verification, eligibility assessment, credit assessment, and onboarding in connection with lending and financial products. • For internal analytical and research purposes, including auditing, data analysis, and research to improve our Services, products, and customer communications. • To meet legal or regulatory requirements, or to comply with requests from governmental, judicial, or regulatory authorities. • To resolve any request, dispute, grievance, or complaint raised by you in relation to your use of the Platform. • To detect, investigate, and prevent fraudulent, unauthorized, or illegal activity on the Platform. • To create aggregate, deidentified, or anonymized data, which may be shared with partners, advertisers, and investors, and which does not identify you personally.

07

Permissions & Data Access

Fintaraa does not access, collect, store, or share a user's SMS messages, call logs, contact lists, or personal photos. The application may request access to specific device permissions only when required for functionality such as: • Camera - document capture, upload, video KYC, or verification. • Storage/Files - user-selected document upload. • Mobile Number - OTP verification and account security. • Location - service availability, branch mapping, fraud prevention, and support routing where applicable. • Microphone - consented video or voice verification where required. • Notifications - transactional and service alerts where enabled. Permissions are requested only with user consent.

08

5. Disclosure and Sharing of Information

5.1 Except as set out in this Policy, or as specifically agreed by you, we will not disclose your Personal Information to third parties. We may, however, disclose Information collected from you in the following circumstances: • To trusted third-party service providers, contractors, and vendors who assist us in providing the Services, including payment gateway providers, identity verification providers, communication automation providers, and providers that help us improve the quality and efficiency of our Services. Access by such parties is limited to what is reasonably necessary for them to perform their functions, and we contractually require them to (a) protect your Personal Information consistent with this Policy, and (b) not use or disclose it for any purpose other than providing services to us as required by applicable law. • With our affiliates, lenders, banks, non-banking financial companies (NBFCs), credit information companies (CICs), and other financial institutions, where necessary to enable application features and to provide the Services you request. • With credit rating agencies, regulatory or statutory authorities, auditors, or as otherwise required to improve business and service quality or as required by law. • Where disclosure is required under any law, judicial decree, or governmental request, or where we, in good faith, believe disclosure is necessary to protect our rights or the rights of other Users, to prevent harm to persons or property, or to address fraud, security, or credit risk. • As part of a reorganization, merger, acquisition, or sale of assets or business, in which case the receiving party will be required to maintain confidentiality and security measures at least as protective as those described in this Policy. You will have the opportunity to opt out of any such transfer if the new entity's planned processing of your Information differs materially from this Policy. • In the form of aggregated, deidentified, or anonymized data shared with advertisers, sponsors, investors, strategic partners, and others to help grow our business; such data does not identify you personally. 5.2 If we are legally compelled to disclose your Personal Information to a third party, we will attempt to notify you, unless doing so would violate the law or a court order. If you would prefer that we not share certain Information with our contractors and service providers as described above, you may write to our Grievance Officer to request this, subject to our internal policies and the nature of the Service availed by you. 5.3 We exercise care in our disclosure practices, but we do not exercise control over third-party websites, advertisers, or service providers that may independently collect information from you. We are not responsible for the privacy practices of such third parties, and this Policy does not apply to information you provide to such third-party websites or platforms.

09

6. International Transfer of Information

Your Information may be transferred to, stored, and processed in jurisdictions outside India, including where our or our service providers' servers are located, and within our affiliates, subsidiaries, and partners. We implement appropriate safeguards in accordance with applicable law, and require that recipients agree to maintain a level of data protection consistent with this Policy and the data protection laws of India. By using the Platform, you consent to such transfer of your Information. We will not be liable for any loss or distribution of data, or corruption of media storage, resulting from power failures, natural events, or other circumstances beyond our reasonable control.

10

7. Cookies, Web Beacons, and Online Advertising

7.1 Due to standard internet communication protocols, when you visit, access, or browse the Platform, we automatically receive information such as the URL from which you arrived, the website you visit on leaving the Platform, your IP address, browser type, operating system, usage patterns, and the name of your internet service provider or mobile carrier. This information is used to analyze User trends and to improve our Services. The link between your IP address and your Personal Information is not shared with third parties without your permission, except as described in this Policy or where required by law. 7.2 The Platform may use temporary cookies to store certain data. We do not store Personal Information in cookies. Cookies allow us to recognize you as a returning User, analyze how you use the Platform, and personalize content. Most browsers can be set to reject cookies; however, if you disable cookies, certain functionality of the Platform may not work correctly. 7.3 We may also use web beacons, pixels, and anonymous ad network tags to collect Non-Personal Information about your use of the Platform, for aggregated auditing, research, and reporting purposes for advertisers. We do not link Non-Personal Information from web beacons or cookies to Personal Information without your permission. 7.4 We may allow other companies, including third-party advertisement servers, advertisement agencies, advertisement technology vendors, and research firms, to serve advertisements to you based on a general profile. We do not use Personal Information to target advertisements. We may permit authorized third parties to place or recognize a unique cookie on your browser for these purposes. Google Advertising ID We use the Google Advertising ID (on Android devices) for advertising and analytics purposes, honoring your device's “Reset Advertising ID” and “Opt out of Interest-Based Advertising” settings. We do not connect the advertising ID to Personal Information without your consent. Aggregate Data We may combine Non-Personal Information from multiple Users to create aggregate data, which may be disclosed to third parties. Aggregate data does not identify you personally and does not include your personal contact information.

12

9. Communications, Testimonials, and Marketing

9.1 Call Recordings We may keep records of telephone calls made to, and received from, you for purposes including administration of the Services, research and development, training, business intelligence, business development, and quality assurance. We may share such records with third parties where required by law or to provide or facilitate the Services. 9.2 Testimonials and Public Forums With your consent, we may reproduce, publish, or edit testimonials and reviews provided by you in relation to the Services, including on the Platform. If you have concerns regarding the reproduction or publication of any testimonial or review provided by you, you may contact our Grievance Officer. Please note that information you post on public forums or blogs may be read, collected, and used by others, and we encourage you to exercise caution when sharing Personal Information in such spaces. 9.3 Do-Not-Disturb (DND) Where you provide your phone number to us, you authorize us, and our affiliates and partners, to contact you by call or SMS regarding our Services and promotional offers, including where your number is registered on a national Do-Not-Disturb registry, to the extent permitted by applicable law. You may withdraw this authorization at any time by contacting us or using the opt-out mechanisms provided. 9.4 Market Research We may conduct online research surveys to gather feedback about the Platform and opinions on relevant issues, through email invitations. Information collected through such surveys will be used only for research purposes and will not be sold to third parties without your consent, except as otherwise permitted under this Policy.

13

10. Data Security, Retention, and Your Rights

10.1 Security We have implemented security policies, rules, and technical measures required under applicable law, including firewalls, transport layer security, encryption, secure access controls, intrusion detection systems, and other physical and electronic safeguards, to protect your Personal Information from unauthorized access, use, disclosure, modification, or destruction. Your Information is contained within secured networks and is accessible only by authorized personnel who require it to perform their functions and who are bound by confidentiality obligations. While we make best efforts to maintain a secure environment, no method of transmission or storage is completely secure, and we cannot guarantee the absolute security of your Information. You agree that we shall not be held responsible for unauthorized access to your Information arising from events beyond our reasonable control, including acts of government, computer hacking, unauthorized access to data or storage devices, and breaches of security or encryption. You agree to immediately notify us of any unauthorized transactions or breach of security relating to your account or the Platform. 10.2 User ID and Password Your account credentials are kept confidential and separate, unless you have shared your user ID and password with someone else. You are responsible for safeguarding your credentials and must not share them with anyone. If you believe your credentials have been compromised, please contact our Grievance Officer immediately. 10.3 Type and Retention of Data We adhere to applicable regulations regarding data security, privacy, and compliance, and store only the Information permitted under applicable law, including basic contact details such as name, address, contact number, and email ID, and any other information required on a need basis. We will retain your Information for internal record-keeping purposes and for as long as necessary to fulfil the purposes described in this Policy, or as required or permitted under applicable law, including for any investigations or proceedings before courts, tribunals, or regulatory authorities, and to enhance and improve our Services. 10.4 Restrictions on Use of Data • Purpose Limitation: We collect Information only for specific, clear, and legitimate purposes and do not use it for any other purpose without your consent. • Data Security: We maintain appropriate organizational and technical measures, including encryption, secure access controls, firewalls, and intrusion detection, to protect your Information, while acknowledging that no method of transmission or storage is completely secure. • Access and Correction: You may update your Information at any time, withdraw your consent, and request that any inaccurate or deficient Information be corrected or amended, subject to our internal policies and the status of the product or Service availed by you. 10.5 Exemptions This Policy does not apply to any information you post or share from the Platform to other third-party websites, due to the public nature of such postings.

14

11. Opt-Out and Account Management

11.1 Third-party service providers with whom we share your Information are not permitted to market their own services or send you promotional communications. We provide you the opportunity to opt out of receiving non-essential, promotional, or marketing communications from us or our partners. If your Information changes, or if you no longer wish to use the Platform, you may correct, update, or deactivate your Information and/or account through the account management section of the Platform, or by contacting us at support@fintaraa.com or via the Grievance Officer details in Section 13. 11.2 If you wish to remove your contact information from our mailing lists and newsletters, you may click the “unsubscribe” link in any email, follow the instructions provided, or contact our Grievance Officer. We reserve the right to limit access to certain communications based on the availability of your contact information, and we will notify you by email prior to taking any such action.

15

Data Deletion Request

Users may request deletion of their account and personal data by emailing support@fintaraa.com or by visiting https://fintaraa.com/delete-account. Subject to legal and regulatory retention requirements, eligible deletion requests will be processed within 30 business days. Requests should include the registered mobile number or email address used with Fintaraa so that we can verify account ownership before deletion. Data linked to pending applications, active financial products, legal obligations, fraud prevention, audit requirements, or partner/regulatory retention requirements may be retained for the period required under applicable law.

16

12. Modifications to this Policy

This is our entire Privacy Policy and it supersedes any earlier version. We reserve the right to amend this Policy at any time. Any modified Policy will be posted on the Platform and will take effect immediately upon posting. Any Information we hold about you, whether collected before or after such modification, will be governed by the most current version of this Policy. If we make any material changes, we will notify you by email or by posting a prominent notice on the Platform prior to the change becoming effective. We encourage you to review this Policy periodically. Your continued use of the Platform or Services after such changes constitutes your acceptance of the revised Policy. If you do not accept the terms of this Policy, your only remedy is to discontinue use of the Platform and Services.

17

13. Grievance Redressal

13.1 If you have any questions, concerns, or complaints regarding this Policy or the Platform, you may contact our Grievance Officer at the details below: Company: Xpertserve Services Private Limited (operating as Fintaraa) Website: https://fintaraa.com/ Email: support@fintaraa.com [Grievance Officer name, designation, and registered address to be inserted by Fintaraa] 13.2 Upon receipt of your complaint, the Grievance Officer or Nodal Officer shall assign an acknowledgement ID and communicate it to you to enable tracking of the complaint's status. The Grievance Officer shall endeavour to redress your complaint within 15 (fifteen) working days from the date of receipt, excluding (a) the time taken by you to provide relevant information or documents, and (b) any delay caused by a third party where the redressal involves such third party.

18

14. Governing Law and Jurisdiction

This Policy shall be governed by and construed in accordance with the laws of India. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts in Gurugram, Haryana, India.

19

15. Severability

Wherever possible, each provision of this Policy shall be interpreted so as to be valid under applicable law. If any provision is held to be invalid or unenforceable, such provision shall be ineffective only to the extent of such invalidity or unenforceability, without affecting the validity of the remaining provisions of this Policy.

20

16. Contact Us

Should you have any questions about this Privacy Policy, the Platform, or our Services, please contact us at support@fintaraa.com or write to our Grievance Officer using the details set out in Section 13.

21

17. Data Storage Policy

Fintaraa, a unit of Xpertserve Services Private Limited, recognizes the critical importance of data storage in ensuring the security, integrity, and availability of its information assets. This Data Storage Policy outlines the guidelines and procedures for the secure storage, retention, and disposal of data throughout its lifecycle. 17.1 Data Classification All data shall be classified based on its sensitivity, criticality, and regulatory requirements. Data classification levels include: Confidential, Restricted, Internal, and Public. The classification level determines the appropriate level of security controls and access restrictions applied to the data. 17.2 Data Storage Locations Fintaraa uses AWS cloud servers based in India to store all its data. 17.3 Data Encryption Confidential and Restricted data shall be encrypted at rest and in transit using industry-standard encryption algorithms. Encryption keys shall be securely managed and stored separately from the encrypted data. Encryption shall be applied to data stored on servers, databases, backup media, and portable devices. 17.4 KYC Data KYC data is collected as required by law and only to the extent necessary for processing loans. It is processed following stringent security measures to ensure data protection, and securely purged from our systems once processing is complete, following the defined data retention schedule. This schedule includes verification that processing is complete, secure deletion using industry-standard data erasure techniques, and documentation of the data deletion for compliance and auditing purposes. 17.5 Access Control Fintaraa employs a robust two-fold approach to manage security permissions and access controls across its applications, ensuring data protection at both the API and UI levels. Data Visibility Access Control: Data visibility access controls govern the level of data that users can access based on their roles and responsibilities. Access to sensitive data is restricted to authorized personnel only, following the principle of least privilege. Role-based access control (RBAC) is implemented to ensure that users can only view and interact with data relevant to their job functions. Regular reviews and audits are conducted to maintain the integrity and confidentiality of stored data. User Operations Controls: User operations controls govern the actions a user can perform on the data they have access to. Granular permissions are defined for each user role, specifying allowed operations such as view, create, update, or delete. Segregation of duties is enforced to prevent unauthorized modifications. Privileged operations require additional approvals, and multi-factor authentication is implemented for critical operations. Access logs and audit trails are maintained to track user activities and detect unauthorized operations. 17.6 Data Backup and Retention Regular data backups shall be performed to ensure the recoverability of data in case of incidents or disasters. Backup frequency and retention periods shall be determined based on the criticality of the data and regulatory requirements. Backups shall be stored in secure, geographically dispersed locations to mitigate the risk of data loss. 17.7 Data Disposal Data that has reached the end of its retention period or is no longer required shall be securely disposed of. Disposal methods, such as secure deletion, overwriting, or physical destruction, shall be used based on the sensitivity of the data. A record of data disposal activities shall be maintained for audit and compliance purposes. 17.8 Third-Party Data Storage When using AWS Servers or any other service provider’s servers for data storage, due diligence shall be conducted to ensure that their security practices align with Fintaraa’s requirements. Contractual agreements with AWS or any other third parties shall include provisions for data confidentiality, security, and audit rights. Regular monitoring and audits shall be conducted to ensure that AWS and/or other third parties adhere to the agreed-upon security standards. 17.9 Incident Notification Fintaraa employees, agents, and consultants shall promptly report any data breaches, security incidents, or unauthorized access to Fintaraa’s data. 17.10 Vendor Management Fintaraa recognizes the importance of ensuring that its vendors and third-party service providers adhere to stringent data storage and security standards. The following vendor management practices shall be implemented: prior to engaging with a vendor, a thorough due diligence process shall be conducted; contractual agreements shall include clear provisions regarding data storage, confidentiality, security responsibilities, and audit rights; vendor access shall be restricted based on the principle of least privilege; vendors shall be required to implement robust security controls including encryption and access controls; vendors shall store and process Fintaraa’s data within the specified geographic boundaries in compliance with applicable data localization regulations; regular monitoring and audits shall be conducted; vendors shall promptly notify Fintaraa of any data breaches; and upon termination of the vendor contract, all data shall be securely retrieved and remaining copies securely destroyed. 17.11 Compliance and Audit Data storage practices shall comply with relevant laws, regulations, and industry standards, including the applicable data protection laws and RBI guidelines. Regular internal and external audits shall be conducted to assess the effectiveness of data storage controls and identify areas for improvement. Audit findings and recommendations shall be addressed in a timely manner to maintain the security and integrity of stored data. 17.12 Employee Training and Awareness Fintaraa plans to provide all employees regular training on data storage policies, procedures, and best practices. Awareness programs shall be conducted to educate employees about their responsibilities in handling and protecting stored data. By adhering to this Data Storage Policy, Fintaraa aims to safeguard its valuable data assets, maintain the trust of its customers and stakeholders, and ensure compliance with legal and regulatory requirements.

Need clarification?

For questions about this document, consent, data rights, partner responsibilities, or grievance escalation, contact the Fintaraa support desk.

support@fintaraa.com