Privacy Policy
Code draft reviewed: August 9, 2026. Legal owner approval and effective date are pending.
1. Current Scope
This notice describes the reviewed website and Flutter lead-assistance MVP. Browsing alone is not consent to credit checks, marketing or lender sharing. A lead is submitted only after the user checks the explicit consent control.
2. Information Currently Collected
- Quick callback: mobile number.
- Assistance request: name, email, mobile, selected loan category, income and amount bands, employment type, optional message and referral code where present.
- Partnership-interest review: name, email, mobile, city/state, profession, experience band, self-reported lead band and optional reason.
- Operational metadata: source page, consent timestamp/policy marker, idempotency key and backend reference.
- Restricted integration UAT, only after an approved secure backend session: applicant identity/contact/address fields and transaction data shown by that workflow. Public use remains disabled until contracts and security controls are approved.
The public CIBIL page does not collect PAN, Aadhaar or date of birth. The public/mobile MVP has no customer account, KYC upload or payment-card form.
3. Intended Use
Use is limited to saving the requested callback/assistance record, contacting the user about that request, reviewing possible next steps, preventing accidental duplicate submission and maintaining required audit evidence. The website does not itself make a credit, eligibility or approval decision.
5. Security Status
The client uses HTTPS endpoints, explicit consent, server-confirmed success, masked receipt displays and fail-closed unavailable states. This is not proof of end-to-end production security. Backend authentication, authorization, tenant isolation, encryption at rest, access controls, retention enforcement, incident response, monitoring and log redaction require separate evidence. Never send OTPs, passwords, bank credentials or card data through free text.
6. Retention and Deletion
No approved production retention/deletion schedule or in-app deletion workflow is evidenced in this repository. Data must be limited to the documented purpose and applicable law; production release is blocked until retention, correction, access and erasure handling are approved and enforced.
7. Access, Correction and Erasure Requests
Use the contact page, identify the relevant server reference and state the requested action. Keep a copy of the request and acknowledgement. Formal identity verification, response SLA and escalation procedure require owner/legal approval.
8. Contact
Use the contact page. A formally appointed privacy officer and verified privacy-response SLA have not yet been published.