Privacy notice · Paisaflow Business
Privacy Policy
Who we are and what this covers
Paisaflow Business is the digital lending platform operated by EcoPlanet Fintech Pvt Ltd (“EcoPlanet”, “we”, “us”), CIN U65990KA2021PTC000000, acting as a Loan Service Provider (LSP) for Partner NBFC (to be named by the lender) (the “lender”), an NBFC registered with the Reserve Bank of India. The lender sanctions, prices, disburses and owns every loan. EcoPlanet sources applications, performs verification and services the loan on the lender's behalf.
This notice applies to the website paisaflow-business.pages.dev, the borrower application (“the app”), the staff CRM and any call, message or field visit made in connection with an application or loan. It is written to meet the Digital Personal Data Protection Act, 2023 (DPDP Act), the RBI Guidelines on Digital Lending and the RBI KYC Master Direction.
Under the DPDP Act, the lender is the data fiduciary for the loan decision and the loan account; EcoPlanet is a data fiduciary for the platform, the application process and collections servicing, and acts as a data processor for the lender where it handles the lender's data on the lender's instructions. Both are bound by this notice.
Data we collect
Everything below is collected only in the course of an application or an active loan. We do not access your contact list, call logs, media, files or continuous location. The app requests camera access only when you take a document photo or selfie, and one-time location only when you photograph your business premises (to geo-tag that photo).
| Category | Data | Source |
|---|---|---|
| Identity | Name, date of birth, gender, photograph, address, masked Aadhaar number (last four digits only), PAN, DigiLocker document metadata | DigiLocker (issuer-signed), PAN verification service, you |
| Liveness & face match | A live selfie, liveness score and face-match score against the Aadhaar photograph | You, via the app camera |
| Contact | Mobile number (your application ID), email, alternate number | You |
| Co-borrowers and key persons | Name, PAN, mobile, relationship, ownership percentage of co-borrower, partners, directors, beneficial owners or authorised signatory, each with their own OTP consent | Those persons |
| Business | Business name, constitution, GSTIN or Udyam number and filing status, nature of business, vintage, premises proof, geo-tagged shop photo, receipt channels (UPI, POS, cash), authority document | You, GST and Udyam portals |
| Financial | Bank statements (6–12 months) and derived cash-flow metrics, credit bureau report and score, existing obligations, UPI/POS receipts you choose to share | Account Aggregator, net banking or PDF upload; credit bureau |
| Loan and repayment | Sanction terms, Key Fact Statement, agreement, e-sign audit trail, mandate details, presentation and payment history, receipts, DPD, promises to pay, dispute or hardship flags | Generated during the loan |
| Communications | SMS, email, WhatsApp and in-app messages; call recordings and dispositions for verification and collection calls; grievance tickets | Generated during the loan |
| Device and usage | IP address, device identifier, app version, browser type, timestamps of consents and actions, crash and error logs | Automatically |
We never store your full Aadhaar number. DigiLocker shares the issuer-signed document; we retain the masked number, the demographic fields and the photograph as required by the KYC Master Direction.
Why we use it and on what basis
Each purpose below rests on a specific consent you give in the app (see the Consent terms for the exact wording and version of each), except where the law itself requires the processing (KYC, anti-money-laundering, bureau reporting, regulatory returns).
- Identity and KYC — verify who you are and who the key persons of the business are; comply with the KYC Master Direction and the Prevention of Money Laundering Act.
- Credit assessment — evaluate the business's receipts, cash flow, obligations and credit history to decide whether, how much and at what price the lender can lend. The decision is taken by the lender's credit desk under its policy; automated scoring assists but does not decide alone.
- Documentation and disbursal — generate the Key Fact Statement, sanction letter and agreement; execute e-sign; verify and lock the disbursement account (penny drop); register the repayment mandate.
- Servicing and collection — present instalments, send reminders and receipts, record promises to pay, handle disputes and hardship, and recover overdue amounts within the RBI conduct rules.
- Fraud and risk — screen against negative lists, sanctions and PEP lists; detect duplicate or fraudulent applications; early-warning monitoring on the portfolio.
- Grievances and legal obligations — resolve complaints, respond to regulators, courts and law enforcement, and maintain audit trails.
- Service communication — messages about your application and loan. Marketing messages are sent only if you tick the separate, optional communication consent, and stop when you withdraw it.
Where the data comes from and the consent behind it
| Source | Channel | Consent recorded |
|---|---|---|
| Aadhaar and PAN | DigiLocker (MeitY) via an authorised service provider; you authenticate with your Aadhaar-linked mobile and choose which documents to share | DigiLocker share consent + Privacy notice v1.2 |
| Selfie | App camera; liveness and face match by the KYC vendor | Shown on the selfie screen; part of the KYC consent |
| Credit bureau | Credit information company (e.g. CIBIL) through an authorised access provider | Credit bureau consent v1.1 |
| GST / Udyam | Government portals (GSTN, Udyam) via API, with OTP where the portal requires it | GST / Udyam data consent v1.0 |
| Bank statements | Account Aggregator (RBI-regulated, consent artefact recorded with the AA), net-banking fetch, or PDF you upload | Bank statement / Account Aggregator consent v1.0 |
| Repayment mandate | UPI AutoPay or eNACH through the sponsor bank / NPCI | Repayment mandate consent v1.0 |
| E-sign | Aadhaar OTP e-sign through a licensed e-sign service provider | Loan agreement & declarations v1.0, KFS receipt v1.0 |
Every consent is stored with its text version, a hash of the text, the timestamp, your IP address, device identifier and channel. You can see your consent ledger in the app under Dashboard → Consents and request a copy at any time.
Who we share it with
- The lender — receives the full application file, takes the credit decision, owns the loan account and reports it to credit bureaus as required by the Credit Information Companies (Regulation) Act, 2005.
- Regulated intermediaries — DigiLocker and the KYC service provider, credit bureaus, the Account Aggregator and its FIP banks, the e-sign service provider, the payment aggregator, sponsor bank and NPCI for mandates and UPI collections, and the disbursing bank. Each receives only the data needed for its function.
- Service providers under contract — cloud hosting (AWS, Mumbai region), SMS, email and WhatsApp gateways, document generation, analytics limited to service metrics. They process data on our instructions and may not use it for their own purposes.
- Collection staff — EcoPlanet employees carrying photo ID, who see only the accounts assigned to them. No third-party recovery agencies are used unless the lender appoints one; if it does, the agent's name and the appointment are disclosed to you in advance.
- Regulators, courts and law enforcement — the RBI, the ombudsman, courts, tax and law-enforcement authorities where required by law or a lawful order.
- Successors — in a merger, assignment or securitisation of the loan portfolio, subject to the same protections.
We do not sell personal data, share it with advertisers, or allow any third party to use it for its own marketing.
Where it is stored and how it is protected
All personal data is stored on servers located in India (AWS Asia Pacific — Mumbai). Data is encrypted in transit (TLS 1.2 or higher) and at rest. Documents and selfies are held in private object storage with time-limited signed links; database access is role-based and logged; staff see only the desks and accounts they are authorised for; every material action in the CRM records who did it, in which role, when and why. Production access requires multi-factor authentication. Vendors are assessed before onboarding and bound by data-processing terms.
If a breach affecting your personal data occurs, we will notify the Data Protection Board of India and you as required by the DPDP Act and its rules, and the lender will notify the RBI as required.
How long we keep it
| Data | Retention | Reason |
|---|---|---|
| KYC records (identity, address, selfie, consent trail) | 5 years after the loan is closed, or after the application is rejected or abandoned | KYC Master Direction, PMLA Rules |
| Loan agreement, KFS, sanction letter, e-sign audit trail, repayment ledger | 8 years after closure | Companies Act, limitation periods, RBI |
| Bank statements and derived cash-flow analysis | Retained with the credit file while the loan is live; raw statements deleted 1 year after closure or rejection; the summary analysis is kept with the credit file | Assessment evidence, audit |
| Credit bureau report | Duration of the loan + 5 years; not reused for a new application without a fresh consent | CIC Act, bureau terms |
| Call recordings and message logs | 2 years, longer if part of an open grievance or dispute | Conduct evidence |
| Device and access logs | 1 year | Security, fraud detection |
| Incomplete applications (no loan sanctioned) | Deleted or anonymised 12 months after last activity, except KYC records fetched under a consent, which follow the KYC rule | Data minimisation |
After the retention period, data is deleted or irreversibly anonymised. Where a statute requires a longer period, that period applies.
Your rights
Under the DPDP Act and RBI guidelines you can, free of charge:
- Access — obtain a summary of the personal data we hold about you, the purposes, and the recipients.
- Correct or update — fix inaccurate or incomplete data. Identity fields taken from DigiLocker are corrected by updating the source document.
- Erase — ask us to delete data that we no longer need for the purpose it was collected for or that the law does not require us to keep.
- Withdraw consent — at any time, with the effects described in the Consent terms. Withdrawal does not affect processing already done, and does not relieve you of obligations under a live loan.
- Restrict collection of specific data — you may decline any optional data item; the app tells you which items are needed for the application to proceed.
- Nominate — name a person to exercise these rights on your behalf if you die or become incapacitated.
- Grievance — complain to our Grievance Redressal Officer and, if unresolved, to the Data Protection Board of India (data matters) or the RBI Integrated Ombudsman (lending conduct). See Grievance redressal.
To exercise a right, write to grievance@ecoplanet.in from your registered email or raise a request in the app under Dashboard → My data. We verify your identity with an OTP on the registered mobile before acting. We respond within 30 days; if a request cannot be met because a law requires retention, we tell you which law.
Cookies and local storage
This website sets no cookies and runs no advertising or cross-site trackers. The borrower app stores a session token and interface preferences (such as theme) in your browser's local storage so you stay signed in; clearing the browser data signs you out. Server-side analytics are limited to aggregate service metrics (page load errors, completion rates) and do not profile individuals.
Children and eligibility
The product is offered only to persons aged 21 to 60 who operate a business. We do not knowingly collect data from anyone under 18; if such data is found, it is deleted.
Changes to this notice
Each version carries a number and an effective date. Material changes are notified in the app and by SMS or email at least 15 days before they take effect; continued use after that date means the new version applies to new processing. Consents you gave under an earlier version remain tied to that version's text, which you can always view in your consent ledger.
- v1.2 — 1 August 2026: added selfie liveness and face match; clarified Account Aggregator flow; added retention table.
- v1.1 — 1 March 2026: DPDP Act alignment; nomination right.
- v1.0 — 1 October 2025: first issue.
Contact
Grievance Redressal Officer (also the contact for data-protection requests), EcoPlanet Fintech Pvt Ltd
grievance@ecoplanet.in · +91 80 4000 0000 · Mon–Sat, 9 am – 6 pm
Lender Nodal Officer, Partner NBFC (to be named by the lender)
nodal@partner-nbfc.in · +91 22 4000 0000
Postal address: EcoPlanet Fintech Pvt Ltd, [registered office address], Bengaluru, Karnataka, India.