Privacy Policy
Last updated: July 23, 2026
PRIVACY POLICY
Last Updated: 17th July 2026
1. INTRODUCTION
This Privacy Policy ("Policy") describes how Shreshtha Creditguru Fintech Private Limited, the parent company of "RupiXtra", a company incorporated under the Companies Act, 2013, having its registered office at PT-C-315, Aditya World City, Shahpur Bamheta, Ghaziabad, Uttar Pradesh – 201002 ("SCFPL", "Company", "we", "our" or "us"), collects, processes, stores, uses, discloses and protects Personal Data of users accessing or using our website www.rupixtra.com, mobile application(s), APIs, software platforms and allied digital services (collectively, the "Platform").
SCFPL operates as a financial technology company and, where applicable, as a Lending Service Provider ("LSP") facilitating digital lending and allied financial services in partnership with RBI-regulated Banks and Non-Banking Financial Companies ("Lending Partners").
We recognise the importance of privacy and are committed to processing Personal Data lawfully, fairly, transparently and securely.
This Policy forms an integral part of the Terms & Conditions governing the use of the Platform.
2. APPLICABILITY
This Policy applies to:
- visitors to the Platform;
- individuals registering on the Platform;
- prospective borrowers;
- existing customers;
- authorised representatives of business customers;
- guarantors, co-applicants or references (where applicable);
- any other person whose Personal Data is processed by SCFPL in connection with the Services.
This Policy applies irrespective of whether the Platform is accessed through a website, mobile application or any other digital interface.
3. GOVERNING LAWS
This Policy has been prepared having regard to, among others:
- the Digital Personal Data Protection Act, 2023;
- the Information Technology Act, 2000;
- the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable);
- RBI Digital Lending Guidelines;
- Credit Information Companies (Regulation) Act, 2005;
- Prevention of Money Laundering Act, 2002;
- Aadhaar Act and related regulations (where applicable);
- other applicable laws, regulations and governmental directions.
4. DEFINITIONS
For the purposes of this Policy:
"Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the Digital Personal Data Protection Act, 2023.
"Processing" includes collection, recording, storage, organisation, adaptation, retrieval, consultation, use, disclosure, sharing, transmission, alignment, restriction, erasure and destruction of Personal Data.
"Data Principal" means the individual to whom the Personal Data relates.
"Consent" means a free, specific, informed, unconditional and unambiguous indication of the Data Principal's agreement to the processing of Personal Data.
"Lending Partner" means an RBI-regulated bank, NBFC or other regulated entity offering financial products through the Platform.
"Credit Information Company (CIC)" means any company registered under the Credit Information Companies (Regulation) Act, 2005, including TransUnion CIBIL Limited, Experian Credit Information Company of India Private Limited, Equifax Credit Information Services Private Limited and CRIF High Mark Credit Information Services Private Limited.
"Applicable Law" means all applicable statutes, regulations, circulars, notifications, directions and judicial decisions in force in India.
5. PRINCIPLES OF DATA PROCESSING
SCFPL processes Personal Data in accordance with the following principles:
- lawfulness and fairness;
- transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- accountability.
We process only such Personal Data as is reasonably necessary to provide the Services or to comply with Applicable Law. We do not store any Personal Data beyond the consented use by the User or as required by law. All Personal data is forwarded as received by the User, to the Lending Partners or LSP, as the case may be. Users are encouraged to review the Terms and Conditions, which forms an integral part of this Policy.
6. PERSONAL DATA
Depending upon the nature of the Services, we may collect the following categories of Personal Data or such data that is required for us to deliver the required services.
6.1 Identity Information
- Full name
- Father's or Mother's name
- Date of birth
- Gender
- Photograph
- PAN (where legally permissible)
- Aadhaar (where legally permissible)
- Passport
- Driving Licence
- Voter ID
- Signature
- Other government-issued identity documents.
6.2 Contact Information
- Mobile number
- Email address
- Residential address
- Permanent address
- Office address
- Correspondence address.
6.3 Financial Information
- Bank account details
- IFSC
- Income details
- Salary slips
- Form 16
- Income Tax Returns
- GST details (where applicable)
- Business financial statements
- Loan repayment history
- Existing liabilities
- Credit bureau reports.
6.4 Employment and Business Information
- Employer name
- Occupation
- Designation
- Employment history
- Nature of business
- Business registration details
- Annual turnover.
6.5 Technical and Device Information
When you access the Platform, we may automatically collect:
- IP address;
- browser type;
- operating system;
- device identifiers;
- mobile device information;
- application version;
- time zone;
- crash logs;
- access times;
- pages visited;
- referral URLs;
- diagnostic information.
6.6 Location Information
Subject to your express consent and where necessary for KYC, fraud prevention or regulatory compliance, we may collect:
- GPS location;
- approximate location;
- IP-based location.
We do not continuously track your location.
6.7 KYC Information
We may collect or verify:
- PAN verification;
- CKYC records;
- DigiLocker documents;
- Aadhaar XML or Offline Aadhaar (where applicable);
- Video KYC recordings;
- facial verification;
- liveness detection results.
6.8 Communications
We may retain records of:
- customer support interactions;
- grievance submissions;
- emails;
- chat messages;
- call recordings (where notified);
- feedback;
- survey responses.
6.9 Transaction Information
We may collect information relating to:
- loan applications;
- sanction status;
- repayments;
- mandates;
- payment confirmations;
- refunds;
- settlement details.
7. DEVICE PERMISSIONS
The Platform may request access to limited device features solely for legitimate business purposes and only after obtaining your permission.
These permissions may include:
- Camera – for KYC verification, document capture and video verification.
- Microphone – where required for video KYC.
- Location – for fraud prevention, address verification or regulatory compliance.
SCFPL does not access or collect your personal contact list, SMS, call logs, photos, videos or other files stored on your device except where expressly permitted by law and with your explicit consent.
8. SOURCES OF PERSONAL DATA
We may collect Personal Data, submitted by you or authorised by you to be collected by SCFPL, from any or all of the following:
- directly from you;
- through forms completed on the Platform;
- from Lending Partners;
- from Credit Information Companies;
- from KYC agencies;
- from CKYC, DigiLocker and government-authorised repositories;
- from payment service providers;
- from fraud prevention agencies;
- from publicly available records where legally permissible;
- from service providers acting on our behalf.
9. ACCURACY OF INFORMATION
You represent and warrant that all Personal Data provided to SCFPL is true, complete and up to date.
You agree to promptly notify us of any changes to your Personal Data so that our records remain accurate.
Failure to provide accurate information may affect your eligibility for the Services or the processing of your loan application.
10. PURPOSE OF PROCESSING PERSONAL DATA
SCFPL processes Personal Data only for lawful and legitimate purposes connected with providing fintech and digital lending services.
The purposes for which we may process Personal Data include:
10.1 Identity Verification and KYC
We process Personal Data to:
- verify identity;
- complete customer onboarding;
- perform KYC checks;
- comply with anti-money laundering requirements;
- prevent identity fraud;
- satisfy regulatory obligations.
10.2 Loan Facilitation and Credit Assessment
Where you apply for financial products through the Platform, we process Personal Data to:
- assess eligibility;
- facilitate credit evaluation;
- obtain credit bureau reports;
- transmit applications to Lending Partners;
- enable underwriting by regulated lenders;
- facilitate loan documentation;
- monitor application status.
SCFPL does not independently sanction or reject loans. Credit decisions remain the sole responsibility of the relevant Lending Partner.
10.3 Fraud Prevention and Risk Management
Personal Data may be processed to:
- detect suspicious activity;
- prevent fraud;
- identify duplicate applications;
- conduct security assessments;
- protect customers and Platform integrity;
- comply with regulatory requirements.
10.4 Customer Support
We process Personal Data to:
- respond to queries;
- resolve complaints;
- provide customer assistance;
- maintain service records;
- improve customer experience.
10.5 Regulatory and Legal Compliance
We may process Personal Data to comply with:
- RBI directions;
- court orders;
- regulatory investigations;
- tax requirements;
- law enforcement requests;
- statutory reporting obligations.
10.6 Platform Improvement and Analytics
We may process aggregated or anonymised information to:
- improve Platform performance;
- analyse usage patterns;
- enhance security;
- develop new products;
- improve customer experience.
11. CONSENT MANAGEMENT
11.1 Consent-Based Processing
SCFPL shall process Personal Data based on:
- your explicit consent;
- legitimate uses permitted under Applicable Law;
- contractual necessity;
- legal obligations.
Consent shall be obtained through appropriate mechanisms including:
- acceptance boxes;
- OTP authentication;
- electronic confirmation;
- digital declarations;
- other legally recognised methods.
11.2 Withdrawal of Consent
You may withdraw consent at any time by contacting:
Email: legal@rupixtra.com
However, withdrawal of consent shall not affect:
- processing already undertaken lawfully before withdrawal;
- retention required under law;
- processing necessary for existing loan obligations;
- fraud prevention activities;
- regulatory reporting.
Withdrawal of consent may affect our ability to provide certain Services.
12. AUTOMATED DECISION-MAKING AND CREDIT PROFILING
12.1 Use of Technology-Based Assessment
To facilitate digital lending services, SCFPL and/or Lending Partners may use automated tools, algorithms, data analytics and technology-based systems for:
- eligibility assessment;
- fraud detection;
- risk evaluation;
- credit scoring support;
- document verification;
- customer authentication.
12.2 Nature of Automated Processing
Automated systems may analyse information such as:
- financial information;
- credit history;
- repayment behaviour;
- application information;
- verification results;
- transaction-related information.
12.3 Human Oversight
You acknowledge that automated tools assist the Lending Partner's assessment process.
Final lending decisions, including:
- approval;
- rejection;
- loan amount;
- pricing;
- tenure;
remain subject to the Lending Partner's internal policies and regulatory requirements.
12.4 No Guarantee of Approval
Use of automated processing does not guarantee:
- loan approval;
- availability of credit;
- specific interest rates;
- specific financial products.
13. DATA SHARING AND DISCLOSURE
SCFPL does not sell, rent or commercially trade Personal Data.
Personal Data may be shared only for legitimate purposes as described below.
13.1 Lending Partners
Where you apply for financial products, your Personal Data may be shared with RBI-regulated Lending Partners including Banks and NBFCs.
Such information may include:
- identity details;
- KYC information;
- income information;
- credit information;
- application details;
- supporting documents.
The Lending Partner independently processes such information in accordance with its own privacy policies and regulatory obligations.
13.2 Credit Information Companies
We may share and obtain credit information from registered Credit Information Companies including:
- TransUnion CIBIL Limited;
- Experian Credit Information Company of India Private Limited;
- Equifax Credit Information Services Private Limited;
- CRIF High Mark Credit Information Services Private Limited.
Such processing may be undertaken for:
- credit assessment;
- monitoring;
- reporting;
- regulatory compliance.
13.3 Service Providers
We may share Personal Data with trusted service providers providing:
- cloud hosting;
- cybersecurity;
- KYC verification;
- payment processing;
- communication services;
- analytics;
- fraud monitoring;
- customer support.
Such service providers are contractually required to maintain confidentiality and security.
13.4 Regulatory Authorities and Government Bodies
We may disclose Personal Data where required by:
- RBI;
- courts;
- government authorities;
- law enforcement agencies;
- statutory regulators;
- tax authorities.
13.5 Corporate Transactions
In the event of:
- merger;
- acquisition;
- restructuring;
- transfer of business;
- sale of assets;
Personal Data may be transferred to the relevant successor entity subject to Applicable Law and confidentiality obligations.
14. DATA LOCALISATION
SCFPL recognises the importance of protecting financial and personal information relating to Users.
Accordingly, SCFPL shall use best efforts to ensure that:
14.1 Personal Data collected in connection with digital lending activities shall be stored and processed in accordance with applicable RBI requirements and Indian data protection laws.
14.2 Regulated entities and service providers engaged in processing Personal Data comply with applicable data storage and localisation requirements.
14.3 Where cloud service providers or technology vendors involve infrastructure outside India, SCFPL shall implement appropriate safeguards and ensure compliance with Applicable Law.
14.4 Cross-border access or processing shall not reduce the level of protection applicable to your Personal Data.
15. CROSS-BORDER DATA TRANSFER
SCFPL may transfer Personal Data outside India only:
- where permitted under Applicable Law;
- where adequate contractual safeguards exist;
- where confidentiality obligations are maintained;
- where security standards are implemented.
Cross-border processing may occur for limited purposes including:
- cloud infrastructure;
- cybersecurity monitoring;
- technical support;
- fraud prevention;
- system maintenance.
16. COOKIES POLICY
The Platform may use cookies and similar technologies to improve functionality, security and user experience.
Cookies are categorised as follows:
16.1 Strictly Necessary Cookies
These cookies are essential for:
- Platform operation;
- authentication;
- security;
- session management.
These cannot generally be disabled.
16.2 Functional Cookies
These cookies enable enhanced functionality including:
- remembering user preferences;
- improving personalised experiences;
- maintaining settings.
16.3 Analytics Cookies
These cookies help us understand:
- Platform usage;
- visitor behaviour;
- performance issues;
- feature effectiveness.
Analytics data is generally aggregated or anonymised.
16.4 Marketing Cookies
Where applicable and subject to consent, marketing cookies may be used to:
- understand campaign effectiveness;
- deliver relevant communications;
- measure advertising performance.
16.5 Managing Cookies
You may control cookies through:
- browser settings;
- device settings;
- consent management tools.
Disabling certain cookies may affect Platform functionality.
17. MARKETING COMMUNICATIONS AND TRAI DND
SCFPL may communicate with Users regarding:
- Services;
- applications;
- transactions;
- regulatory updates;
- offers;
- products.
Where promotional communications are sent:
- appropriate consent shall be obtained where required;
- Users may opt out of marketing communications;
- TRAI-approved preferences and Do Not Disturb ("DND") requirements shall be respected.
Users may unsubscribe through:
- communication links;
- Platform settings;
- contacting SCFPL.
Withdrawal from marketing communications shall not affect essential service communications relating to:
- loan applications;
- repayments;
- regulatory notices;
- security alerts.
18. INFORMATION SECURITY
SCFPL is committed to maintaining the confidentiality, integrity and availability of Personal Data through administrative, technical and organisational safeguards appropriate to the nature and sensitivity of the information processed.
We maintain an information security programme designed to prevent unauthorised access, misuse, alteration, disclosure or destruction of Personal Data.
While no electronic system can be guaranteed to be completely secure, SCFPL continuously reviews and enhances its security measures in accordance with applicable industry standards and regulatory expectations.
19. SECURITY SAFEGUARDS
Without limiting the generality of the foregoing, SCFPL may implement the following security measures:
- encryption of data in transit using SSL/TLS protocols;
- encryption of sensitive data at rest using industry-standard encryption algorithms;
- role-based access controls;
- multi-factor authentication for privileged users;
- secure firewalls and intrusion detection systems;
- endpoint protection and malware prevention;
- security monitoring and logging;
- vulnerability assessments and penetration testing;
- periodic security audits;
- disaster recovery and business continuity measures;
- employee confidentiality obligations and regular privacy awareness training.
Access to Personal Data is restricted to personnel who require such access for legitimate business purposes and who are subject to appropriate confidentiality obligations.
20. DATA RETENTION
SCFPL retains Personal Data only for as long as necessary to fulfil the purposes described in this Policy or as required under Applicable Law.
The retention period may vary depending upon:
- applicable legal and regulatory requirements;
- contractual obligations;
- the duration of the customer relationship;
- dispute resolution requirements;
- fraud prevention requirements;
- audit and accounting obligations.
Examples of records that may be retained include:
- KYC records;
- loan application records;
- customer communications;
- consent records;
- grievance records;
- transaction logs;
- audit trails.
Upon expiry of the applicable retention period, Personal Data shall be securely deleted, anonymised or irreversibly de-identified, unless further retention is required by law.
21. ACCOUNT CLOSURE AND DATA ERASURE
A User may request closure of their Platform account by contacting SCFPL through the prescribed grievance or customer support channels.
Upon receipt of such request, SCFPL shall:
- verify the identity of the requesting User;
- assess whether any active contractual or regulatory obligations remain outstanding; and
- process the request in accordance with Applicable Law.
Account closure does not automatically result in deletion of all Personal Data. Certain records may continue to be retained where required for:
- compliance with statutory obligations;
- audit purposes;
- fraud prevention;
- regulatory reporting;
- enforcement or defence of legal claims.
Where deletion is legally permissible, Personal Data shall be erased or anonymised within a reasonable period.
22. CHILDREN'S PRIVACY
The Platform and Services are intended exclusively for persons who are eighteen (18) years of age or older and are legally competent to enter into binding contracts under Indian law.
SCFPL does not knowingly collect or process Personal Data of children or minors.
If SCFPL becomes aware that Personal Data relating to a person below the age of eighteen years has been collected inadvertently, such information shall, subject to applicable legal requirements, be deleted or anonymised without undue delay.
Parents or legal guardians who believe that a child has provided Personal Data to SCFPL may contact the Grievance Officer for appropriate action.
23. PERSONAL DATA BREACH MANAGEMENT
SCFPL maintains internal procedures for identifying, assessing, investigating and responding to actual or suspected Personal Data breaches.
Where SCFPL becomes aware of a Personal Data breach that is likely to result in significant harm to affected individuals or where notification is otherwise required under Applicable Law, SCFPL shall:
- promptly investigate the incident;
- take appropriate containment and remediation measures;
- notify affected individuals, where legally required;
- notify competent governmental or regulatory authorities, where required by law;
- maintain appropriate records of the incident and remedial actions taken.
Nothing in this Policy shall be construed as limiting SCFPL's ability to take urgent protective measures to safeguard users and systems.
24. RIGHTS OF DATA PRINCIPALS
Subject to the provisions of the Digital Personal Data Protection Act, 2023 and other Applicable Laws, Users may exercise the following rights in relation to their Personal Data.
24.1 Right to Access
You may request a summary of the Personal Data processed by SCFPL and information regarding the processing activities undertaken in relation to such data.
24.2 Right to Correction
You may request correction, completion or updating of inaccurate or incomplete Personal Data maintained by SCFPL.
24.3 Right to Erasure
You may request deletion of Personal Data where retention is no longer necessary or where deletion is otherwise required under Applicable Law, subject to statutory retention obligations.
24.4 Right to Withdraw Consent
Where processing is based on consent, you may withdraw such consent at any time by contacting SCFPL.
Withdrawal of consent shall not affect processing already undertaken lawfully prior to such withdrawal.
24.5 Right to Grievance Redressal
You have the right to raise concerns or complaints regarding the processing of your Personal Data through the grievance mechanism described in this Policy.
24.6 Right to Nominate
Where provided under Applicable Law, you may nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
SCFPL may require reasonable identity verification before acting upon any request relating to Personal Data.
25. CONSEQUENCES OF NON-PROVISION OF DATA
Certain categories of Personal Data are essential for the provision of the Services.
Failure to provide such information may result in:
- inability to create a user account;
- inability to complete KYC verification;
- inability to process loan applications;
- inability to provide customer support;
- rejection or discontinuation of certain Services;
- inability to comply with legal or regulatory requirements.
26. THIRD-PARTY LINKS
The Platform may contain links to websites, applications or services operated by third parties, including Lending Partners and payment service providers.
SCFPL does not control the privacy practices of such third parties and encourages Users to review their respective privacy policies before providing Personal Data.
SCFPL shall not be responsible for the privacy or security practices of third-party websites or services.
27. GRIEVANCE REDRESSAL
SCFPL is committed to addressing complaints and concerns relating to the processing of Personal Data promptly, fairly and transparently.
Any individual who has questions, concerns or grievances regarding this Privacy Policy or the processing of Personal Data may contact our designated Grievance Officer.
Complaints may relate to:
- collection of Personal Data;
- withdrawal of consent;
- correction or deletion requests;
- unauthorised disclosure;
- suspected misuse of Personal Data;
- marketing communications;
- security incidents;
- any other privacy-related issue.
SCFPL shall endeavour to:
- acknowledge complaints within 48 hours of receipt; and
- resolve complaints within the timelines prescribed under Applicable Law or, where no timeline is prescribed, within a reasonable period.
28. GRIEVANCE OFFICER
In accordance with the Digital Personal Data Protection Act, 2023 and applicable regulatory requirements, the Company has appointed a Grievance Officer.
Designation: Grievance Officer
Email: legal@rupixtra.com
Subject line: Attn: Grievance Officer
Registered Office:
Shreshtha Creditguru Fintech Private Limited
PT-C-315, Aditya World City
Shahpur Bamheta
Ghaziabad – 201002
Uttar Pradesh, India
29. DATA PROTECTION OFFICER (IF APPLICABLE)
Where required under Applicable Law or where voluntarily appointed by the Company, a Data Protection Officer ("DPO") shall oversee the Company's privacy governance framework.
Designation: Data Protection Officer
Email: legal@rupixtra.com
Subject line: Attn: Data Protection Officer
The DPO may be contacted regarding:
- exercise of data subject rights;
- privacy-related queries;
- security concerns;
- cross-border transfer questions;
- complaints regarding processing of Personal Data.
30. CHANGES TO THIS PRIVACY POLICY
SCFPL reserves the right to amend, revise or update this Privacy Policy from time to time to reflect:
- changes in Applicable Law;
- RBI circulars or regulatory directions;
- technological developments;
- business requirements;
- new products or services;
- security enhancements.
Updated versions shall be published on the Platform together with the revised "Last Updated" date.
Where required by Applicable Law, Users shall be notified of material changes through appropriate communication channels, including email, SMS, in-app notifications or publication on the Platform.
Continued use of the Platform following publication of the revised Privacy Policy shall constitute acknowledgement of the updated Policy, except where fresh consent is required by law.
31. CONTACT US
If you have any questions regarding this Privacy Policy or the Company's privacy practices, please contact:
Shreshtha Creditguru Fintech Private Limited
Registered Office:
PT-C-315, Aditya World City
Shahpur Bamheta
Ghaziabad – 201002
Uttar Pradesh, India
Email: legal@rupixtra.com
Website: www.rupixtra.com
32. MISCELLANEOUS
32.1 Entire Policy
This Privacy Policy, together with the Terms & Conditions and any other policies expressly incorporated by reference, constitutes the entire privacy policy governing the processing of Personal Data by SCFPL.
32.2 Severability
If any provision of this Privacy Policy is held invalid or unenforceable by a competent authority, the remaining provisions shall continue in full force and effect.
32.3 Waiver
Failure by SCFPL to enforce any provision of this Privacy Policy shall not constitute a waiver of any right or remedy.
32.4 Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of India.
32.5 Jurisdiction
Subject to any mandatory provisions of Applicable Law, disputes relating to this Privacy Policy shall be subject to the dispute resolution provisions contained in the Terms & Conditions.
SCHEDULE A
EXERCISING YOUR PRIVACY RIGHTS
A User wishing to exercise any rights under the Digital Personal Data Protection Act, 2023 may submit a request by emailing legal@rupixtra.com.
To protect against unauthorised requests, SCFPL may require verification of the requester's identity before acting upon any request.
Depending on the nature of the request, SCFPL may require:
- proof of identity;
- additional information to verify the request;
- clarification of the specific right being exercised.
Requests will be processed within the timeframes prescribed under Applicable Law.
SCHEDULE B
IMPORTANT REGULATORY DISCLOSURES
- SCFPL operates as a financial technology company and, where applicable, as a Lending Service Provider ("LSP") to RBI-regulated Lending Partners.
- SCFPL does not independently sanction or disburse loans.
- Loan approval, pricing, repayment terms and recovery remain the responsibility of the relevant Lending Partner.
- Personal Data is processed only for lawful purposes connected with the provision of Services, regulatory compliance and customer support.
- SCFPL implements reasonable security safeguards to protect Personal Data from unauthorised access, disclosure or misuse.
- Users are encouraged to read this Privacy Policy together with the Terms & Conditions before using the Platform.