← Back to Paisaflow Business

Privacy notice · Paisaflow Business

Privacy Policy

Version v1.2Effective 1 August 2026Last reviewed 22 September 2026

Who we are and what this covers

Paisaflow Business is the digital lending platform operated by EcoPlanet Fintech Pvt Ltd (“EcoPlanet”, “we”, “us”), CIN U65990KA2021PTC000000, acting as a Loan Service Provider (LSP) for Partner NBFC (to be named by the lender) (the “lender”), an NBFC registered with the Reserve Bank of India. The lender sanctions, prices, disburses and owns every loan. EcoPlanet sources applications, performs verification and services the loan on the lender's behalf.

This notice applies to the website paisaflow-business.pages.dev, the borrower application (“the app”), the staff CRM and any call, message or field visit made in connection with an application or loan. It is written to meet the Digital Personal Data Protection Act, 2023 (DPDP Act), the RBI Guidelines on Digital Lending and the RBI KYC Master Direction.

Under the DPDP Act, the lender is the data fiduciary for the loan decision and the loan account; EcoPlanet is a data fiduciary for the platform, the application process and collections servicing, and acts as a data processor for the lender where it handles the lender's data on the lender's instructions. Both are bound by this notice.

Short version: we collect only what is needed to assess, sanction, disburse and collect one loan; we ask for a separate, recorded consent before each data source is accessed; your data stays on servers in India; you can see, correct, download and ask us to delete it; and nothing is sold.

Data we collect

Everything below is collected only in the course of an application or an active loan. We do not access your contact list, call logs, media, files or continuous location. The app requests camera access only when you take a document photo or selfie, and one-time location only when you photograph your business premises (to geo-tag that photo).

CategoryDataSource
IdentityName, date of birth, gender, photograph, address, masked Aadhaar number (last four digits only), PAN, DigiLocker document metadataDigiLocker (issuer-signed), PAN verification service, you
Liveness & face matchA live selfie, liveness score and face-match score against the Aadhaar photographYou, via the app camera
ContactMobile number (your application ID), email, alternate numberYou
Co-borrowers and key personsName, PAN, mobile, relationship, ownership percentage of co-borrower, partners, directors, beneficial owners or authorised signatory, each with their own OTP consentThose persons
BusinessBusiness name, constitution, GSTIN or Udyam number and filing status, nature of business, vintage, premises proof, geo-tagged shop photo, receipt channels (UPI, POS, cash), authority documentYou, GST and Udyam portals
FinancialBank statements (6–12 months) and derived cash-flow metrics, credit bureau report and score, existing obligations, UPI/POS receipts you choose to shareAccount Aggregator, net banking or PDF upload; credit bureau
Loan and repaymentSanction terms, Key Fact Statement, agreement, e-sign audit trail, mandate details, presentation and payment history, receipts, DPD, promises to pay, dispute or hardship flagsGenerated during the loan
CommunicationsSMS, email, WhatsApp and in-app messages; call recordings and dispositions for verification and collection calls; grievance ticketsGenerated during the loan
Device and usageIP address, device identifier, app version, browser type, timestamps of consents and actions, crash and error logsAutomatically

We never store your full Aadhaar number. DigiLocker shares the issuer-signed document; we retain the masked number, the demographic fields and the photograph as required by the KYC Master Direction.

Why we use it and on what basis

Each purpose below rests on a specific consent you give in the app (see the Consent terms for the exact wording and version of each), except where the law itself requires the processing (KYC, anti-money-laundering, bureau reporting, regulatory returns).

  1. Identity and KYC — verify who you are and who the key persons of the business are; comply with the KYC Master Direction and the Prevention of Money Laundering Act.
  2. Credit assessment — evaluate the business's receipts, cash flow, obligations and credit history to decide whether, how much and at what price the lender can lend. The decision is taken by the lender's credit desk under its policy; automated scoring assists but does not decide alone.
  3. Documentation and disbursal — generate the Key Fact Statement, sanction letter and agreement; execute e-sign; verify and lock the disbursement account (penny drop); register the repayment mandate.
  4. Servicing and collection — present instalments, send reminders and receipts, record promises to pay, handle disputes and hardship, and recover overdue amounts within the RBI conduct rules.
  5. Fraud and risk — screen against negative lists, sanctions and PEP lists; detect duplicate or fraudulent applications; early-warning monitoring on the portfolio.
  6. Grievances and legal obligations — resolve complaints, respond to regulators, courts and law enforcement, and maintain audit trails.
  7. Service communication — messages about your application and loan. Marketing messages are sent only if you tick the separate, optional communication consent, and stop when you withdraw it.
SourceChannelConsent recorded
Aadhaar and PANDigiLocker (MeitY) via an authorised service provider; you authenticate with your Aadhaar-linked mobile and choose which documents to shareDigiLocker share consent + Privacy notice v1.2
SelfieApp camera; liveness and face match by the KYC vendorShown on the selfie screen; part of the KYC consent
Credit bureauCredit information company (e.g. CIBIL) through an authorised access providerCredit bureau consent v1.1
GST / UdyamGovernment portals (GSTN, Udyam) via API, with OTP where the portal requires itGST / Udyam data consent v1.0
Bank statementsAccount Aggregator (RBI-regulated, consent artefact recorded with the AA), net-banking fetch, or PDF you uploadBank statement / Account Aggregator consent v1.0
Repayment mandateUPI AutoPay or eNACH through the sponsor bank / NPCIRepayment mandate consent v1.0
E-signAadhaar OTP e-sign through a licensed e-sign service providerLoan agreement & declarations v1.0, KFS receipt v1.0

Every consent is stored with its text version, a hash of the text, the timestamp, your IP address, device identifier and channel. You can see your consent ledger in the app under Dashboard → Consents and request a copy at any time.

Who we share it with

We do not sell personal data, share it with advertisers, or allow any third party to use it for its own marketing.

Where it is stored and how it is protected

All personal data is stored on servers located in India (AWS Asia Pacific — Mumbai). Data is encrypted in transit (TLS 1.2 or higher) and at rest. Documents and selfies are held in private object storage with time-limited signed links; database access is role-based and logged; staff see only the desks and accounts they are authorised for; every material action in the CRM records who did it, in which role, when and why. Production access requires multi-factor authentication. Vendors are assessed before onboarding and bound by data-processing terms.

If a breach affecting your personal data occurs, we will notify the Data Protection Board of India and you as required by the DPDP Act and its rules, and the lender will notify the RBI as required.

How long we keep it

DataRetentionReason
KYC records (identity, address, selfie, consent trail)5 years after the loan is closed, or after the application is rejected or abandonedKYC Master Direction, PMLA Rules
Loan agreement, KFS, sanction letter, e-sign audit trail, repayment ledger8 years after closureCompanies Act, limitation periods, RBI
Bank statements and derived cash-flow analysisRetained with the credit file while the loan is live; raw statements deleted 1 year after closure or rejection; the summary analysis is kept with the credit fileAssessment evidence, audit
Credit bureau reportDuration of the loan + 5 years; not reused for a new application without a fresh consentCIC Act, bureau terms
Call recordings and message logs2 years, longer if part of an open grievance or disputeConduct evidence
Device and access logs1 yearSecurity, fraud detection
Incomplete applications (no loan sanctioned)Deleted or anonymised 12 months after last activity, except KYC records fetched under a consent, which follow the KYC ruleData minimisation

After the retention period, data is deleted or irreversibly anonymised. Where a statute requires a longer period, that period applies.

Your rights

Under the DPDP Act and RBI guidelines you can, free of charge:

To exercise a right, write to grievance@ecoplanet.in from your registered email or raise a request in the app under Dashboard → My data. We verify your identity with an OTP on the registered mobile before acting. We respond within 30 days; if a request cannot be met because a law requires retention, we tell you which law.

Cookies and local storage

This website sets no cookies and runs no advertising or cross-site trackers. The borrower app stores a session token and interface preferences (such as theme) in your browser's local storage so you stay signed in; clearing the browser data signs you out. Server-side analytics are limited to aggregate service metrics (page load errors, completion rates) and do not profile individuals.

Children and eligibility

The product is offered only to persons aged 21 to 60 who operate a business. We do not knowingly collect data from anyone under 18; if such data is found, it is deleted.

Changes to this notice

Each version carries a number and an effective date. Material changes are notified in the app and by SMS or email at least 15 days before they take effect; continued use after that date means the new version applies to new processing. Consents you gave under an earlier version remain tied to that version's text, which you can always view in your consent ledger.

Contact

Grievance Redressal Officer (also the contact for data-protection requests), EcoPlanet Fintech Pvt Ltd
grievance@ecoplanet.in · +91 80 4000 0000 · Mon–Sat, 9 am – 6 pm

Lender Nodal Officer, Partner NBFC (to be named by the lender)
nodal@partner-nbfc.in · +91 22 4000 0000

Postal address: EcoPlanet Fintech Pvt Ltd, [registered office address], Bengaluru, Karnataka, India.