Privacy Policy
Last updated: 2026-07-10
Data Fiduciary: Navavista Technology Ventures Pvt. Ltd. (operating as "Creditsin", "we", "us", "our").
Registered Office: Bengaluru, Karnataka, India.
This Privacy Policy is issued in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. It explains how we, as a Data Fiduciary, collect, use, share and protect the personal data of you, the Data Principal.
1. Scope & Acceptance
This Policy is an electronic record under the Information Technology Act, 2000 and does not require any physical, electronic or digital signature. By accessing or using creditsin.in, our mobile app, or any Creditsin service, you agree to this Policy. If you do not agree, please stop using the platform. Your continued use after any update constitutes acceptance of the revised Policy.
2. Types of Information We Handle
3. Personal Data We Collect
4. Purposes for Which We Process Your Data
We process your personal data only for the specific, lawful purposes for which you provide consent or which are otherwise permitted under the DPDP Act:
5. Legal Basis
We rely on your consent for most processing. For certain purposes we may rely on legitimate uses as defined under Section 7 of the DPDP Act, including compliance with law, response to medical emergencies, and performance of a legal obligation.
6. Credit Bureau Consent
When you apply for a credit product through Creditsin, you expressly authorise Creditsin and our partner banks / NBFCs to fetch, receive and use your credit information report and credit score from credit information companies including CIBIL / TransUnion, Experian, Equifax and CRIF High Mark, in accordance with the Credit Information Companies (Regulation) Act, 2005 ("CICRA"). This information is used solely to assess your eligibility and present suitable offers, is kept confidential, and is retained only for the period necessary for the purpose or as required by law.
7. Communication Consent (SMS, WhatsApp, Email, Call)
By providing your mobile number and email, you consent to receive transactional messages (OTPs, application status, payout alerts, compliance notices) over SMS, WhatsApp, RCS, email and voice call. You may separately opt in to promotional communications; you can opt out at any time by replying STOP, using the unsubscribe link, or updating Account → Notification Preferences. This consent overrides your DND registration for service messages only, as permitted by TRAI regulations.
8. Device Permissions (App & PWA)
Where the Creditsin app or PWA requests a device permission, it is used strictly for the stated purpose:
We do not access biometric data, SMS inbox, call logs or media library outside these flows.
9. Sharing of Personal Data
We do not sell your personal data.
10. Third-Party Links & Services
The platform contains links to third-party websites (partner bank application pages, brokers, blog citations). We are not responsible for the content, privacy practices or terms of any third-party site. Before submitting information on such sites, please review their privacy policy and terms.
11. Cross-Border Transfer
Some service providers may process data outside India. Such transfers are made only to jurisdictions not restricted by the Central Government under Section 16 of the DPDP Act, and are protected by contractual safeguards.
12. Cookies & Tracking Technologies
We use cookies and similar technologies to keep you signed in, remember preferences, measure traffic and (with consent) show relevant offers.
13. Disclosure to Acquirers
In the event of a merger, acquisition, reorganisation, sale of assets or insolvency, personal data held by Creditsin may be transferred to the acquiring or successor entity. We will require the recipient to honour the commitments made in this Policy or notify you of any material change.
14. Use on Behalf of Another Person
If you provide us with personal data about another individual (e.g. a family member for a joint application, or an employee), you confirm that you are authorised to share their data and have their informed consent to the processing described in this Policy.
15. Data Retention
We retain personal data only for as long as necessary for the purpose it was collected or as required by law:
Once the retention period ends, data is deleted or irreversibly anonymised.
16. Your Rights as a Data Principal
Under Sections 11–14 of the DPDP Act, you have the right to:
To exercise any right, email privacy@creditsin.in or use the "My Data" section in your account.
17. Consent & Withdrawal
Consent for marketing communications, analytics cookies and non-essential tracking is optional and can be withdrawn at any time from Account → Privacy Settings or by writing to privacy@creditsin.in. Withdrawal will not affect the lawfulness of processing carried out before withdrawal, and may limit your ability to use certain features.
18. Children's Data
Creditsin's services are intended for individuals 18 years and above. We hard-block signups where the declared date of birth indicates the applicant is under 18. We do not knowingly process the personal data of children or engage in behavioural monitoring or targeted advertising directed at children, as required by Section 9 of the DPDP Act.
19. Security, Breach Notification & Limitation of Liability
We follow reasonable security safeguards including encryption in transit, access controls, role-based access and audit logs. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act.
To the maximum extent permitted by law, Creditsin shall not be liable for any indirect, incidental, special, punitive or consequential loss, or for any breach caused by a Force Majeure Event including hacking, cyber-terrorism, unauthorised access, denial-of-service attacks, acts of God, war, riots, pandemics, government action, failure of internet or telecom infrastructure and other events beyond our reasonable control.
20. Grievance Officer
For any concern regarding your personal data, referral earnings, applications or wallet transactions, please contact our Grievance Officer:
We acknowledge complaints within 48 hours and aim to resolve them within 30 days. For the full three-level escalation matrix (including senior and appellate officers) and external escalation to the Data Protection Board of India / RBI, please see our dedicated [Grievance Redressal Policy](/grievance-policy).
21. Escalation to the Data Protection Board
If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India as constituted under the DPDP Act, 2023.
22. Governing Law & Dispute Resolution
This Policy is governed by and construed in accordance with the laws of India. Any dispute arising out of or in connection with this Policy shall be referred to binding arbitration by a sole arbitrator under the Arbitration and Conciliation Act, 1996. The seat and venue of arbitration shall be Bengaluru, Karnataka, and the language shall be English. Subject to arbitration, the courts at Bengaluru, Karnataka shall have exclusive jurisdiction.
23. Updates to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be notified to you through the app or via email.