🔥 Today's Offer: Apply for any credit card & get ₹500 extra cashbackApply Now →

Privacy Policy

Last updated: 2026-07-10


Data Fiduciary: Navavista Technology Ventures Pvt. Ltd. (operating as "Creditsin", "we", "us", "our").

Registered Office: Bengaluru, Karnataka, India.


This Privacy Policy is issued in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. It explains how we, as a Data Fiduciary, collect, use, share and protect the personal data of you, the Data Principal.


1. Scope & Acceptance

This Policy is an electronic record under the Information Technology Act, 2000 and does not require any physical, electronic or digital signature. By accessing or using creditsin.in, our mobile app, or any Creditsin service, you agree to this Policy. If you do not agree, please stop using the platform. Your continued use after any update constitutes acceptance of the revised Policy.


2. Types of Information We Handle

  • Personal Information ("PI") — name, email, mobile, date of birth, address and any other data that identifies you directly or in combination with other data.
  • Sensitive Personal Data or Information ("SPDI") — passwords, financial data (bank account, card, UPI), biometric data and health data, as defined under the SPDI Rules, 2011.
  • Business Information — entity name, CIN, GST, PAN, authorised signatory, bank details and other data submitted by partners/DSAs.
  • Non-Personal Information — browser type, ISP, OS, device model, IP, screen resolution and other technical data that does not identify you.
  • Usage Information — pages viewed, clicks, session duration, referral source, cookies and behavioural analytics.

  • 3. Personal Data We Collect

  • Identity & Contact: name, email, mobile number, date of birth, address.
  • KYC Data: PAN, Aadhaar reference (masked), employment and income details — only for products that require it.
  • Financial Data: loan/credit-card application details, bank account (for payouts), transaction and wallet history.
  • Usage & Device Data: IP address, device identifiers, browser type, pages visited, referral source, cookies and similar technologies.

  • 4. Purposes for Which We Process Your Data

    We process your personal data only for the specific, lawful purposes for which you provide consent or which are otherwise permitted under the DPDP Act:

  • Creating and operating your Creditsin account.
  • Facilitating applications for credit cards, loans, demat and other financial products offered by our partner institutions.
  • Calculating and paying referral / cashback earnings.
  • Fraud prevention, security monitoring and legal compliance.
  • Product improvement, analytics and (with your separate consent) marketing communications.

  • 5. Legal Basis

    We rely on your consent for most processing. For certain purposes we may rely on legitimate uses as defined under Section 7 of the DPDP Act, including compliance with law, response to medical emergencies, and performance of a legal obligation.


    6. Credit Bureau Consent

    When you apply for a credit product through Creditsin, you expressly authorise Creditsin and our partner banks / NBFCs to fetch, receive and use your credit information report and credit score from credit information companies including CIBIL / TransUnion, Experian, Equifax and CRIF High Mark, in accordance with the Credit Information Companies (Regulation) Act, 2005 ("CICRA"). This information is used solely to assess your eligibility and present suitable offers, is kept confidential, and is retained only for the period necessary for the purpose or as required by law.


    7. Communication Consent (SMS, WhatsApp, Email, Call)

    By providing your mobile number and email, you consent to receive transactional messages (OTPs, application status, payout alerts, compliance notices) over SMS, WhatsApp, RCS, email and voice call. You may separately opt in to promotional communications; you can opt out at any time by replying STOP, using the unsubscribe link, or updating Account → Notification Preferences. This consent overrides your DND registration for service messages only, as permitted by TRAI regulations.


    8. Device Permissions (App & PWA)

    Where the Creditsin app or PWA requests a device permission, it is used strictly for the stated purpose:

  • Notifications — transactional and (opt-in) marketing alerts.
  • Camera / Photo library — uploading KYC documents or profile photo.
  • Location (approximate) — showing offers relevant to your city.
  • Contacts — only when you actively tap "Invite friends"; contacts are not uploaded to our servers.
  • We do not access biometric data, SMS inbox, call logs or media library outside these flows.


    9. Sharing of Personal Data

  • Partner banks / NBFCs / brokers — only the data required to process the product you apply for.
  • Service providers — hosting, analytics, communication, KYC verification vendors under strict confidentiality obligations.
  • Regulators / law-enforcement — where required by law, court order or subpoena.

  • We do not sell your personal data.


    10. Third-Party Links & Services

    The platform contains links to third-party websites (partner bank application pages, brokers, blog citations). We are not responsible for the content, privacy practices or terms of any third-party site. Before submitting information on such sites, please review their privacy policy and terms.


    11. Cross-Border Transfer

    Some service providers may process data outside India. Such transfers are made only to jurisdictions not restricted by the Central Government under Section 16 of the DPDP Act, and are protected by contractual safeguards.


    12. Cookies & Tracking Technologies

    We use cookies and similar technologies to keep you signed in, remember preferences, measure traffic and (with consent) show relevant offers.

  • Essential cookies are always on — required for login and security.
  • Analytics & marketing cookies are enabled only after you accept the cookie banner. You can change your choice any time from the cookie banner reset link in the footer or by clearing site data.
  • Session cookies are deleted when you close the browser; **persistent cookies** expire on the date set by us or the third party.
  • Third-party cookies may be set by Google Analytics, Meta and similar providers; their use is governed by their own privacy policies.

  • 13. Disclosure to Acquirers

    In the event of a merger, acquisition, reorganisation, sale of assets or insolvency, personal data held by Creditsin may be transferred to the acquiring or successor entity. We will require the recipient to honour the commitments made in this Policy or notify you of any material change.


    14. Use on Behalf of Another Person

    If you provide us with personal data about another individual (e.g. a family member for a joint application, or an employee), you confirm that you are authorised to share their data and have their informed consent to the processing described in this Policy.


    15. Data Retention

    We retain personal data only for as long as necessary for the purpose it was collected or as required by law:

  • KYC records: 5 years after the end of the customer relationship (RBI requirement).
  • Loan / credit-card application records: 8 years (as required by partner banks and applicable law).
  • Marketing & referral leads: 2 years from last activity.
  • Support tickets & communications: 3 years.

  • Once the retention period ends, data is deleted or irreversibly anonymised.


    16. Your Rights as a Data Principal

    Under Sections 11–14 of the DPDP Act, you have the right to:

  • Access a summary of your personal data and processing activities.
  • Correction, completion, updating and erasure of your personal data.
  • Withdraw consent at any time, with the same ease as it was given.
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Grievance redressal by contacting our Grievance Officer (see Section 20).

  • To exercise any right, email privacy@creditsin.in or use the "My Data" section in your account.


    17. Consent & Withdrawal

    Consent for marketing communications, analytics cookies and non-essential tracking is optional and can be withdrawn at any time from Account → Privacy Settings or by writing to privacy@creditsin.in. Withdrawal will not affect the lawfulness of processing carried out before withdrawal, and may limit your ability to use certain features.


    18. Children's Data

    Creditsin's services are intended for individuals 18 years and above. We hard-block signups where the declared date of birth indicates the applicant is under 18. We do not knowingly process the personal data of children or engage in behavioural monitoring or targeted advertising directed at children, as required by Section 9 of the DPDP Act.


    19. Security, Breach Notification & Limitation of Liability

    We follow reasonable security safeguards including encryption in transit, access controls, role-based access and audit logs. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act.


    To the maximum extent permitted by law, Creditsin shall not be liable for any indirect, incidental, special, punitive or consequential loss, or for any breach caused by a Force Majeure Event including hacking, cyber-terrorism, unauthorised access, denial-of-service attacks, acts of God, war, riots, pandemics, government action, failure of internet or telecom infrastructure and other events beyond our reasonable control.


    20. Grievance Officer


    For any concern regarding your personal data, referral earnings, applications or wallet transactions, please contact our Grievance Officer:


  • Name: Rahul Verma
  • Email: grievances@creditsin.in
  • Phone: +91-76196 95761
  • Office Hours: Mon – Sat, 10:00 AM – 6:00 PM IST

  • We acknowledge complaints within 48 hours and aim to resolve them within 30 days. For the full three-level escalation matrix (including senior and appellate officers) and external escalation to the Data Protection Board of India / RBI, please see our dedicated [Grievance Redressal Policy](/grievance-policy).


    21. Escalation to the Data Protection Board

    If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India as constituted under the DPDP Act, 2023.


    22. Governing Law & Dispute Resolution

    This Policy is governed by and construed in accordance with the laws of India. Any dispute arising out of or in connection with this Policy shall be referred to binding arbitration by a sole arbitrator under the Arbitration and Conciliation Act, 1996. The seat and venue of arbitration shall be Bengaluru, Karnataka, and the language shall be English. Subject to arbitration, the courts at Bengaluru, Karnataka shall have exclusive jurisdiction.


    23. Updates to this Policy

    We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be notified to you through the app or via email.


    24. How to Contact Us

  • Data Fiduciary: Navavista Technology Ventures Pvt. Ltd.
  • Registered Office: Bengaluru, Karnataka, India
  • Support: support@creditsin.in
  • Privacy queries: privacy@creditsin.in
  • Grievances: grievances@creditsin.in
  • Legal: legal@creditsin.in
  • Grievance Officer phone: +91-76196 95761