Chapter 1 — INTRODUCTION, SCOPE & ACCEPTANCE
1.1 Introduction
Welcome to FinDeals, an online Financial Classifieds Platform owned and operated by SMARTAXIS PRIVATE LIMITED ("Company", "we", "our", or "us").
SMARTAXIS PRIVATE LIMITED values the privacy of every User and is committed to handling personal data responsibly, transparently, and in accordance with applicable laws.
This Privacy Policy explains how we collect, use, process, store, share, protect, and retain personal information when Users access or use the FinDeals Platform.
1.2 Purpose
The purpose of this Privacy Policy is to:
- Explain what information we collect.
- Explain why we collect information.
- Explain how information is used.
- Explain when information may be shared.
- Explain Users' privacy rights.
- Explain our security practices.
- Promote transparency regarding our data handling practices.
1.3 About SMARTAXIS PRIVATE LIMITED
FinDeals is owned and operated by:
The Company develops and operates technology platforms that connect independent Users through digital services.
For the purposes of this Privacy Policy, SMARTAXIS PRIVATE LIMITED acts as the entity responsible for determining how personal information is collected and processed in connection with the operation of the FinDeals Platform, subject to applicable law.
1.4 About FinDeals
FinDeals is an online technology platform that enables Users to:
- Publish Financial Requirement Listings.
- Discover financial service providers.
- Connect with eligible Business Members.
- Use Membership Services.
- Purchase Credits.
- Unlock Contact Information.
- Communicate through Platform features.
FinDeals does not provide banking, lending, NBFC, escrow, or regulated financial advisory services.
1.5 Scope
This Privacy Policy applies to information collected through:
The FinDeals Website.
- Mobile Applications.
- Business Dashboard.
- Customer Support.
- Platform Messaging.
- Membership Services.
- Contact Unlock.
- Payment-related interactions.
- Marketing communications.
- Any other Platform services operated by SMARTAXIS PRIVATE LIMITED.
1.6 Persons Covered
This Privacy Policy applies to:
- Individual Users.
- Business Members.
- Consultants.
- Financial Institutions.
- Visitors.
- Prospective Users.
- Customer Support Contacts.
- Individuals communicating with the Company.
1.7 Information Covered
This Privacy Policy applies to:
- Personal Information.
- Business Information.
- Technical Information.
- Device Information.
- Usage Information.
- Communication Records.
- Payment-related Information.
- Verification Information.
- Any other information collected through the Platform.
1.8 Acceptance
By:
- Visiting the Platform
- Creating an Account
- Publishing a Listing
- Purchasing Membership
- Purchasing Credits
- Using Contact Unlock
- Communicating through the Platform
- Continuing to use FinDeals
Users acknowledge that they have read and understood this Privacy Policy and consent to the collection, processing, and use of their information as described herein, to the extent permitted or required by applicable law.
Where applicable law requires separate or express consent for particular processing activities, the Company will obtain such consent before carrying out those activities.
1.9 Relationship with Terms & Conditions
This Privacy Policy forms an integral part of the FinDeals Terms & Conditions.
In the event of any inconsistency between this Privacy Policy and the Terms & Conditions regarding privacy practices, this Privacy Policy shall govern the Company's handling of personal information, unless applicable law requires otherwise.
1.10 Changes to this Privacy Policy
The Company may update this Privacy Policy from time to time where reasonably necessary to:
- Reflect legal changes.
- Improve transparency.
- Introduce new services.
- Improve security.
- Address operational requirements.
- Comply with regulatory obligations.
Where required by applicable law, Users will be provided with appropriate notice before material changes become effective.
The latest version shall always be available on the Platform.
1.11 Privacy Principles
The Company seeks to handle information in accordance with the following principles:
- Lawfulness.
- Fairness.
- Transparency.
- Purpose Limitation.
- Data Minimization.
- Accuracy.
- Security.
- Accountability.
- Confidentiality.
- Reasonable Retention.
- These principles are applied subject to applicable law and the nature of the services provided.
1.12 No Sale of Personal Information
Except as described in this Privacy Policy or as required or permitted by applicable law, SMARTAXIS PRIVATE LIMITED does not sell Users' personal information to third parties.
The Company may share information with service providers or business partners only as reasonably necessary to operate the Platform, fulfill contractual obligations, or comply with legal requirements.
1.13 Children's Privacy
The FinDeals Platform is intended for individuals who are legally eligible to use its services under applicable law.
Persons who are not legally permitted to use the Platform should not submit personal information through the Platform.
- Additional provisions regarding children's privacy are set out later in this Privacy Policy.
1.14 Contact Information
Questions regarding this Privacy Policy may be directed to the Company's designated privacy or grievance contact through the official communication channels published on the FinDeals Platform.
- Contact information may be updated from time to time.
1.15 Chapter Summary
This Chapter introduces the FinDeals Privacy Policy and explains its purpose, scope, applicability, relationship with the Terms & Conditions, and the Company's commitment to protecting personal information. It also establishes the principles governing the Company's privacy practices and informs Users that detailed information regarding data collection, use, sharing, and protection is provided in the chapters that follow.
Chapter 2 — CATEGORIES OF PERSONAL INFORMATION WE COLLECT
2.1 Purpose
This Chapter explains the categories of information that SMARTAXIS PRIVATE LIMITED may collect when Users access or use the FinDeals Platform.
The Company collects only such information as is reasonably necessary to operate, improve, secure, and administer the Platform, comply with legal obligations, and provide requested services.
The categories described below are illustrative and may evolve as the Platform introduces new features, subject to applicable law.
2.2 Information Provided Directly by Users
The Company may collect information voluntarily provided by Users during:
- Account Registration
- Profile Creation
- Publishing Listings
- Membership Registration
- Business Verification
- Customer Support
- Contact Unlock
- Payments
- Platform Messaging
- Feedback
- Surveys
- Other interactions with the Platform
2.3 Identity Information
The Company may collect identity-related information including:
- Full Name
- Date of Birth (where applicable)
- Gender (where voluntarily provided)
- Photograph or Profile Image
- Identity Verification Status
Government-issued identification details (only where required or voluntarily submitted for verification)
- Signature (where applicable)
The Company does not require government identification unless reasonably necessary for verification, fraud prevention, or legal compliance.
2.4 Contact Information
The Company may collect:
- Mobile Number
- Email Address
- Alternate Contact Number
- Business Contact Number
- Communication Preferences
- Postal Address
- District
- City
- State
- Country
- Postal Code
2.5 Account Information
When Users register, the Company may collect:
- Username
- Account ID
- Login Credentials
- Password (stored securely using appropriate security practices)
- OTP Verification Status
- Account Status
- Membership Status
- Registration Date
- Last Login Date
- Security Preferences
2.6 Business Information
Business Members may provide:
- Business Name
- Organization Type
- Business Address
- GST Details (where applicable)
- Registration Number
- PAN (where applicable)
- Professional Licences
- Regulatory Registration Details
- Business Website
- Business Email
- Business Logo
- Office Contact Details
2.7 Financial Requirement Information
Users publishing Financial Requirement Listings may voluntarily provide information such as:
- Requirement Category
- Loan Type
- Purpose of Finance
- Requirement Amount
- Preferred Location
- Employment Type
- Occupation
- Business Type
- Property Information
- Vehicle Information
- Gold Information
- Other collateral-related details
- Additional information included in the Listing
Users are responsible for ensuring that the information they submit is accurate and lawful to disclose.
2.8 Verification Information
Where verification is offered or required, the Company may collect:
- Identity Documents
- Business Documents
- Professional Licences
- GST Registration
- Company Registration Certificates
- Address Proof
- Other supporting documentation reasonably required for verification
- Submission of verification documents does not guarantee approval or verification status.
2.9 Payment Information
Where Users purchase Memberships, Credits, or other paid services, the Company or its authorized payment service providers may process information including:
- Transaction ID
- Payment Status
- Payment Date
- Payment Method
- Invoice Information
- GST Information
- Refund Status
- Payment Reference Number
The Company does not ordinarily store complete debit card, credit card, UPI PIN, internet banking credentials, or other sensitive payment authentication information unless required for lawful operational purposes and handled in accordance with applicable standards.
2.10 Device Information
The Company may automatically collect:
- Device Type
- Device Model
- Operating System
- Browser Type
- Browser Version
- Screen Resolution
- Language Settings
- Time Zone
- Device Identifiers
- Application Version
2.11 Technical Information
The Company may collect technical information including:
- IP Address
- Internet Service Provider
- Network Information
- Login Timestamp
- Logout Timestamp
- Session Duration
- Device Fingerprint
- Authentication Logs
- Error Logs
- Crash Reports
- Performance Information
2.12 Usage Information
The Company may collect information regarding Platform usage, including:
- Pages Viewed
- Features Used
- Listings Viewed
- Search Queries
- Filters Applied
- Membership Usage
- Contact Unlock Activity
- Credit Usage
- Time Spent
- Navigation Patterns
- Click Activity
- Such information helps improve Platform performance and user experience.
2.13 Location Information
Depending on User settings and applicable permissions, the Company may collect:
- Country
- State
- District
- City
- Approximate Geographic Location
- GPS-based Location (where expressly permitted by the User)
Precise location information will only be collected where Users have granted the necessary permissions or where otherwise permitted by applicable law.
2.14 Communication Information
The Company may collect records relating to:
- Customer Support Requests
- Chat Messages
- Email Communications
- Complaint Records
- Feedback
- Survey Responses
- Call Records (where calls are recorded with appropriate notice or consent, as required by law)
- Notification Preferences
2.15 Marketing Information
The Company may collect:
- Marketing Preferences
- Subscription Preferences
- Promotional Campaign Responses
- Advertisement Interaction
- Referral Information
- Coupon Usage
- Campaign Participation
Users may opt out of promotional communications where required by applicable law.
2.16 Cookies and Similar Technologies
The Platform may collect information through:
- Cookies
- Session Cookies
- Persistent Cookies
- Pixel Tags
- Web Beacons
- Local Storage
- Device Identifiers
- Similar Technologies
- Detailed information is provided in the Cookie Policy.
2.17 User-Generated Content
Users may voluntarily submit content including:
- Financial Requirement Listings
- Business Profiles
- Images
- Documents
- Reviews
- Ratings
- Comments
- Messages
- Attachments
- Feedback
Users remain responsible for the content they upload to the Platform.
2.18 Information from Third Parties
The Company may receive information from trusted third parties including:
- Payment Service Providers
- Identity Verification Providers
- Business Verification Partners
- Analytics Providers
- Customer Support Platforms
- Marketing Partners
- Publicly Available Sources
- Government Databases (where lawfully accessible)
The Company shall use such information only for lawful purposes.
2.19 Sensitive Personal Information
Where applicable law recognizes categories of sensitive personal information, the Company shall collect and process such information only where:
- Necessary for providing requested services.
- Required by law.
- Required for fraud prevention.
- Necessary for verification.
- Otherwise permitted by applicable law.
- Additional safeguards may be applied to such information where required.
2.20 Information We Do Not Intentionally Collect
Unless specifically required for a lawful purpose, the Company does not intentionally request or collect:
- Banking Passwords
- Debit Card PINs
- Credit Card PINs
- UPI PINs
- Internet Banking Passwords
One-Time Passwords (except those generated solely for authentication during Platform login or verification)
- Other confidential authentication credentials unrelated to the operation of the Platform
Users should never disclose such confidential credentials through Platform Messaging or customer support channels.
2.21 Accuracy of Information
Users are responsible for ensuring that the information they provide is:
- Accurate
- Complete
- Current
- Lawfully obtained
- Lawfully disclosed
Users should promptly update their information if it changes.
2.22 Changes to Information Collected
- As the Platform evolves, the categories of information collected may change.
Where required by applicable law, the Company shall update this Privacy Policy and provide appropriate notice before collecting materially different categories of personal information.
2.23 Chapter Summary
This Chapter explains the categories of personal and business information that SMARTAXIS PRIVATE LIMITED may collect from Users and Business Members. The information collected supports account management, Platform functionality, security, fraud prevention, customer support, regulatory compliance, and service improvement. The Company is committed to collecting information only for lawful purposes and handling it in accordance with this Privacy Policy and applicable law.
Chapter 3 — HOW WE COLLECT INFORMATION
3.1 Purpose
This Chapter explains the methods by which SMARTAXIS PRIVATE LIMITED collects information when Users interact with the FinDeals Platform.
Information may be collected directly from Users, automatically through technology, from trusted third parties, or through lawful operational activities necessary to provide and improve the Platform.
The Company collects information only through lawful means and for purposes consistent with this Privacy Policy and applicable law.
3.2 Information Provided Directly by Users
Users may voluntarily provide information when they:
- Create an Account.
- Complete a Profile.
- Publish a Financial Requirement Listing.
- Register as a Business Member.
- Purchase Memberships.
- Purchase Credits.
- Use Contact Unlock.
- Upload documents.
- Submit verification information.
- Contact Customer Support.
- Participate in surveys.
- Submit reviews or feedback.
- Send messages through Platform features.
Users are responsible for ensuring that the information they provide is accurate and lawfully disclosed.
3.3 Information Collected During Account Registration
When a User registers an Account, the Company may collect information including:
- Name.
- Mobile Number.
- Email Address.
- Password.
- OTP Verification Status.
- Referral Information (where applicable).
- Registration Date and Time.
- Device Information associated with registration.
3.4 Information Collected Through Financial Requirement Listings
When Users publish Financial Requirement Listings, the Company collects the information voluntarily entered by the User, including:
- Listing Title.
- Requirement Category.
- Loan Type.
- Requirement Amount.
- Property Details.
- Business Information.
- Supporting Documents.
- Images.
- Location Information.
- Other Listing Content.
The Company does not create Listing information on behalf of Users unless expressly requested through a supported Platform feature.
3.5 Information Collected During Business Registration
Business Members may provide information during registration including:
- Business Details.
- Registration Certificates.
- Professional Licences.
- GST Information.
- Contact Details.
- Office Address.
- Verification Documents.
The Company may verify certain information using internal processes or trusted verification providers.
3.6 Information Collected During Payments
When Users purchase Memberships, Credits, or other paid services, information may be collected during the payment process, including:
- Transaction Reference Number.
- Payment Status.
- Payment Date.
- Invoice Details.
- GST Information.
- Refund Requests.
- Subscription Information.
- Payment authentication is generally processed by authorized third-party payment service providers.
3.7 Information Collected Through Contact Unlock
When a Business Member uses the Contact Unlock feature, the Platform may record:
- User initiating the Contact Unlock.
- Listing involved.
- Credits used.
- Date and Time.
- Contact Unlock History.
- Device Information.
- Audit Logs.
- These records assist in service delivery, fraud prevention, and dispute resolution.
3.8 Information Collected Through Membership Services
The Company may collect information relating to:
- Membership Plan Selection.
- Subscription Period.
- Renewals.
- Expiry Dates.
- Membership Benefits.
- Geographic Access.
- Membership Activity.
3.9 Information Collected Through Customer Support
When Users contact Customer Support, the Company may collect:
- Contact Information.
- Complaint Details.
- Attachments.
- Screenshots.
- Correspondence.
- Resolution History.
- Feedback regarding support services.
Support interactions may be recorded where appropriate notice is provided or consent is obtained, if required by law.
3.10 Information Collected Automatically
Certain information is collected automatically when Users access the Platform, including:
- IP Address.
- Browser Information.
- Device Information.
- Operating System.
- Session Information.
- Login Activity.
- Platform Usage.
- Error Reports.
- Crash Information.
- Performance Metrics.
- Automatic collection helps improve security, reliability, and user experience.
3.11 Cookies and Similar Technologies
The Platform may automatically collect information using:
- Cookies.
- Session Cookies.
- Persistent Cookies.
- Pixel Tags.
- Local Storage.
- Device Identifiers.
- Similar Technologies.
These technologies may be used to:
- Maintain User Sessions.
- Improve Platform Performance.
- Remember Preferences.
- Measure Analytics.
- Detect Fraud.
- Enhance Security.
- Further information is available in the Cookie Policy.
3.12 Device Information Collection
The Platform may collect device-related information such as:
- Device Type.
- Device Model.
- Operating System.
- Browser Version.
- Screen Resolution.
- Language Settings.
- Device Identifier.
- Mobile Application Version.
This information assists with compatibility, troubleshooting, and security.
3.13 Usage Analytics
The Company may collect analytics information including:
- Pages Visited.
- Features Used.
- Search Activity.
- Click Patterns.
- Navigation Behaviour.
- Session Duration.
- Listing Views.
- Contact Unlock Usage.
- Membership Usage.
- Credit Usage.
- Analytics information helps improve Platform performance and usability.
3.14 Security Monitoring
The Company may collect information necessary to:
- Detect Fraud.
- Prevent Abuse.
- Monitor Login Attempts.
- Detect Suspicious Activity.
- Identify Security Incidents.
- Investigate Policy Violations.
- Protect User Accounts.
- Security monitoring may involve automated systems and manual review where appropriate.
3.15 Information from Third Parties
The Company may receive information from trusted third parties including:
- Payment Gateway Providers.
- Identity Verification Providers.
- Cloud Service Providers.
- Analytics Providers.
- Customer Support Platforms.
- Government Records (where lawfully available).
- Business Verification Partners.
The Company processes such information only for lawful purposes.
3.16 Information from Public Sources
Where permitted by applicable law, the Company may obtain information from publicly available sources, including:
- Public Business Registries.
- Regulatory Databases.
- Public Company Records.
- Official Government Portals.
- Such information may be used to support verification, fraud prevention, or regulatory compliance.
3.17 Information Generated Through Platform Use
The Platform may generate operational records including:
- Login History.
- Logout History.
- Audit Logs.
- Security Logs.
- Credit Transactions.
- Membership Activity.
- Contact Unlock Records.
- Notification History.
- System Events.
- These records help operate and secure the Platform.
3.18 AI-Assisted Platform Features
Where the Platform offers AI-assisted features, the Company may process relevant information to:
- Improve search results.
- Recommend Listings.
- Detect suspicious behaviour.
- Prevent fraud.
- Enhance customer support.
- Improve Platform functionality.
Where applicable law requires additional notice or consent for AI-assisted processing, the Company shall comply with such requirements.
3.19 Information Collected Through Communications
The Company may collect information exchanged through:
- Platform Messaging.
- Customer Support.
- Email.
- SMS.
- Push Notifications.
- WhatsApp Communications.
- In-App Communications.
Such information may be retained as reasonably necessary for service delivery, security, dispute resolution, and legal compliance.
3.20 Information We Do Not Collect by Default
The Company does not intentionally collect or request:
- Debit Card PINs.
- Credit Card PINs.
- Internet Banking Passwords.
- UPI PINs.
- Passwords for third-party services.
- OTPs unrelated to authentication on the FinDeals Platform.
Users should never share such confidential information through the Platform.
3.21 Collection of Additional Information
If the Company introduces new Platform features requiring additional categories of information, it will update this Privacy Policy and, where required by applicable law, provide appropriate notice or obtain any necessary consent before collecting such information.
3.22 Chapter Summary
This Chapter explains the various methods through which SMARTAXIS PRIVATE LIMITED collects information in connection with the FinDeals Platform. Information may be collected directly from Users, automatically through the Platform, from trusted third-party service providers, or through operational records generated during Platform use. These collection methods support Platform functionality, security, fraud prevention, customer support, regulatory compliance, and continuous improvement while remaining subject to this Privacy Policy and applicable law.
Chapter 4 — HOW WE USE YOUR INFORMATION
4.1 Purpose
This Chapter explains the purposes for which SMARTAXIS PRIVATE LIMITED collects, processes, uses, stores, and manages personal information in connection with the FinDeals Platform.
The Company processes personal information only for lawful purposes, in accordance with applicable law, this Privacy Policy, and the FinDeals Terms & Conditions.
4.2 Platform Operations
The Company may use personal information to:
- Operate the FinDeals Platform.
- Provide Platform Services.
- Maintain User Accounts.
- Enable Financial Requirement Listings.
- Facilitate communication between Users.
- Deliver Membership Services.
- Operate the Credits System.
- Provide Contact Unlock services.
- Improve Platform performance.
4.3 Account Creation and Management
Information may be used to:
- Create User Accounts.
- Authenticate Users.
- Verify mobile numbers.
- Verify email addresses.
- Maintain User Profiles.
- Update Account information.
- Recover Accounts.
- Reset passwords.
- Manage security settings.
4.4 Identity Verification
Where verification is offered or required, the Company may process information to:
- Verify User identity.
- Verify Business Members.
- Verify professional credentials.
- Confirm business registrations.
- Detect identity fraud.
- Prevent impersonation.
- Protect Platform integrity.
- Verification activities are conducted only where reasonably necessary and subject to applicable law.
4.5 Financial Requirement Listings
The Company may process Listing information to:
- Publish Listings.
- Display Listings to eligible Users.
- Improve search results.
- Categorize Listings.
- Recommend Listings.
- Prevent duplicate Listings.
- Detect fraudulent Listings.
- Moderate content.
4.6 Contact Unlock Services
Information may be processed to:
- Enable Contact Unlock.
- Record Contact Unlock activity.
- Deduct Credits.
- Maintain audit logs.
- Prevent misuse.
- Detect suspicious activity.
- Resolve disputes relating to Contact Unlock.
4.7 Membership Services
The Company may process information to:
- Activate Memberships.
- Manage subscription periods.
- Process renewals.
- Deliver Membership benefits.
- Manage geographic access.
- Provide premium services.
- Administer Membership plans.
4.8 Credits Management
Information may be used to:
- Allocate Credits.
- Deduct Credits.
- Maintain Credit balances.
- Record Credit transactions.
- Detect fraudulent Credit activity.
- Resolve Credit-related disputes.
- Prevent abuse of the Credits System.
4.9 Customer Support
The Company may process information to:
- Respond to enquiries.
- Resolve complaints.
- Investigate issues.
- Provide technical support.
- Improve customer service.
- Verify User identity during support interactions.
- Follow up on support requests.
4.10 Fraud Prevention
Information may be processed to:
- Detect fraud.
- Prevent identity theft.
- Prevent fake Listings.
- Prevent fake Business Members.
- Prevent unauthorized Account access.
- Identify suspicious behaviour.
- Detect policy violations.
- Protect Users.
The Company may use automated tools together with human review where appropriate.
4.11 Platform Security
The Company may process information to:
- Secure User Accounts.
- Monitor login activity.
- Detect cyber threats.
- Prevent hacking attempts.
- Protect Platform infrastructure.
- Investigate security incidents.
- Preserve system integrity.
4.12 Communication Services
Information may be used to:
- Send transactional communications.
- Send OTPs.
- Send verification messages.
- Send payment confirmations.
- Deliver Customer Support responses.
- Send security alerts.
- Notify Users regarding Platform activities.
4.13 Notifications
The Company may send notifications regarding:
- Membership expiry.
- Credit balances.
- Contact Unlock activity.
- Listing status.
- Account verification.
- Platform maintenance.
- Policy updates.
- Security alerts.
- Regulatory notices.
4.14 Analytics and Service Improvement
The Company may analyze information to:
- Improve Platform performance.
- Improve User experience.
- Enhance search functionality.
- Improve recommendation systems.
- Understand usage trends.
- Optimize Platform features.
- Develop new services.
- Measure service quality.
Where practicable, analytics may be performed using aggregated or de-identified information.
4.15 AI-Assisted Features
Where AI-assisted features are available, the Company may process information to:
- Improve search relevance.
- Recommend Listings.
- Detect suspicious activity.
- Improve customer support.
- Categorize Listings.
- Reduce spam.
- Improve fraud detection.
- Enhance Platform efficiency.
The Company does not make legally significant decisions solely through automated processing where prohibited by applicable law.
4.16 Marketing Communications
Subject to applicable law, the Company may use information to:
- Inform Users about new services.
- Send Membership offers.
- Share promotional campaigns.
- Recommend Platform features.
- Send newsletters.
- Provide educational content.
- Conduct surveys.
Users may opt out of promotional communications where required by applicable law.
4.17 Personalization
Information may be used to personalize the Platform by:
- Displaying relevant Listings.
- Suggesting Business Members.
- Showing preferred geographic content.
- Remembering User preferences.
- Improving search results.
- Customizing the User experience.
4.18 Regulatory Compliance
The Company may process information to:
- Comply with applicable laws.
- Meet regulatory obligations.
- Respond to lawful government requests.
- Fulfill tax obligations.
- Maintain legally required records.
- Cooperate with regulatory authorities.
4.19 Legal Claims and Dispute Resolution
Information may be processed to:
- Investigate complaints.
- Resolve disputes.
- Enforce these Terms.
- Protect legal rights.
- Defend legal claims.
- Exercise contractual rights.
- Comply with court orders.
4.20 Audits and Business Administration
The Company may process information for:
- Internal audits.
- Risk management.
- Financial reporting.
- Corporate governance.
- Compliance reviews.
- Operational planning.
- Business continuity.
- Service monitoring.
4.21 Research and Development
The Company may use information to:
- Improve existing services.
- Develop new Platform features.
- Test new technologies.
- Improve fraud detection systems.
- Enhance cybersecurity.
- Conduct internal research.
Where feasible, research activities may rely on anonymized or aggregated information.
4.22 Business Transactions
If SMARTAXIS PRIVATE LIMITED undergoes a:
- Merger.
- Acquisition.
- Corporate restructuring.
- Sale of assets.
- Investment transaction.
personal information may be transferred as part of that transaction, subject to appropriate safeguards and applicable law.
Users will be notified where required by law.
4.23 Protection of Rights
The Company may process information where reasonably necessary to:
- Protect Users.
- Protect Business Members.
- Protect Company property.
- Protect intellectual property.
- Prevent abuse.
- Detect illegal activity.
- Protect public safety.
4.24 No Processing Beyond Stated Purposes
The Company shall not process personal information for purposes materially incompatible with those described in this Privacy Policy unless:
- Required by applicable law.
The User provides additional consent where required.
- Another lawful basis exists under applicable law.
4.25 Chapter Summary
This Chapter explains how SMARTAXIS PRIVATE LIMITED uses personal information to operate, maintain, secure, and improve the FinDeals Platform. Information is processed for purposes including account management, Financial Requirement Listings, Membership Services, Contact Unlock, fraud prevention, customer support, analytics, AI-assisted features, regulatory compliance, legal protection, and service improvement. The Company processes personal information only for lawful purposes and in accordance with applicable law and this Privacy Policy.
Chapter 5 — LEGAL BASIS FOR PROCESSING PERSONAL INFORMATION
5.1 Purpose
This Chapter explains the legal grounds on which SMARTAXIS PRIVATE LIMITED processes personal information in connection with the FinDeals Platform.
The Company processes personal information only where there is a lawful basis under applicable law and only to the extent reasonably necessary for the purposes described in this Privacy Policy.
5.2 Commitment to Lawful Processing
The Company is committed to ensuring that personal information is processed:
- Lawfully.
- Fairly.
- Transparently.
- For specified purposes.
- In a manner consistent with applicable law.
- Using appropriate safeguards.
5.3 User Consent
Where required by applicable law, the Company processes personal information based on the User's consent.
Consent may be obtained through:
- Account Registration.
- Acceptance of the Terms & Conditions.
- Acceptance of this Privacy Policy.
- Verification processes.
- Cookie preferences.
- Marketing opt-ins.
- Other consent mechanisms made available through the Platform.
- Consent shall be requested in clear and understandable language where required by law.
5.4 Performance of a Contract
The Company may process personal information where such processing is reasonably necessary to perform or administer its contractual relationship with the User, including to:
- Create and maintain Accounts.
- Provide Platform Services.
- Publish Financial Requirement Listings.
- Operate Contact Unlock.
- Manage Memberships.
- Process Credits.
- Deliver Customer Support.
- Process payments.
- Maintain Platform security.
- Without such processing, the Company may be unable to provide some or all Platform Services.
5.5 Compliance with Legal Obligations
The Company may process personal information where reasonably necessary to comply with applicable legal or regulatory obligations, including:
- Court Orders.
- Government Directions.
- Regulatory Requirements.
- Tax Laws.
- Corporate Law Requirements.
- Cybersecurity Obligations.
- Anti-fraud Requirements.
- Record Retention Obligations.
5.6 Fraud Prevention and Security
The Company may process personal information to:
- Prevent fraud.
- Detect identity theft.
- Prevent unauthorized access.
- Protect User Accounts.
- Investigate suspicious activities.
- Detect cyber threats.
- Maintain Platform security.
- Protect Users and Business Members.
- Such processing helps safeguard the integrity of the Platform and its Users.
5.7 Protection of Legal Rights
The Company may process personal information where reasonably necessary to:
- Enforce these Terms.
- Protect Company property.
- Protect Intellectual Property.
- Defend legal claims.
- Exercise contractual rights.
- Resolve disputes.
- Investigate complaints.
- Cooperate with law enforcement where legally required.
5.8 Platform Administration
The Company may process information for administrative purposes including:
- Platform Management.
- Business Operations.
- Internal Audits.
- Compliance Monitoring.
- Risk Management.
- Financial Reporting.
- Business Continuity Planning.
- Operational Improvements.
5.9 Service Improvement
The Company may process information to improve:
- Platform Stability.
- Search Functionality.
- Recommendation Systems.
- Customer Experience.
- Fraud Detection.
- User Interface.
- Performance.
- New Platform Features.
Where reasonably practicable, service improvement activities may use aggregated or anonymized information.
5.10 AI-Assisted Processing
Where AI-assisted technologies are used, the Company may process information to:
- Improve search accuracy.
- Categorize Listings.
- Detect fraudulent activity.
- Identify spam.
- Improve Customer Support.
- Enhance Platform security.
- Recommend relevant Listings.
The Company will not rely solely on automated processing to make decisions producing legal or similarly significant effects where prohibited by applicable law.
5.11 Communications
The Company may process personal information to send:
- Account Notifications.
- OTPs.
- Security Alerts.
- Membership Updates.
- Payment Confirmations.
- Customer Support Responses.
- Legal Notices.
- Policy Updates.
- Service Announcements.
- These communications are generally necessary for the operation and security of the Platform.
5.12 Marketing Communications
Where permitted by applicable law, the Company may process personal information to:
- Send promotional offers.
- Recommend Membership Plans.
- Announce new Platform features.
- Conduct surveys.
- Share newsletters.
- Deliver educational content.
Users may withdraw from receiving promotional communications at any time using available opt-out mechanisms.
- Withdrawal from promotional communications does not affect essential service-related communications.
5.13 Verification Services
The Company may process personal information to:
- Verify Business Members.
- Verify User identities.
- Validate supporting documents.
- Prevent impersonation.
- Maintain Platform trust.
- Verification does not constitute a guarantee regarding any User or Business Member.
5.14 Public Interest and Safety
Where permitted or required by applicable law, the Company may process information where reasonably necessary to:
- Protect public safety.
- Prevent criminal activity.
- Respond to cybersecurity incidents.
- Cooperate with competent authorities.
- Prevent financial fraud.
- Protect Users from abuse.
5.15 Corporate Transactions
If SMARTAXIS PRIVATE LIMITED undergoes:
- Merger.
- Acquisition.
- Corporate Restructuring.
- Sale of Business.
- Investment Transaction.
personal information may be processed as reasonably necessary to evaluate or complete such transaction, subject to appropriate confidentiality obligations and applicable law.
Where required by law, Users shall be notified.
5.16 Withdrawal of Consent
Where processing is based on consent, Users may withdraw their consent at any time, subject to applicable law.
Withdrawal of consent:
- Shall not affect the lawfulness of processing carried out before withdrawal.
- May affect the availability of certain Platform features or services that rely on such consent.
- Will not affect processing required to comply with legal obligations or other lawful bases.
Requests to withdraw consent may be submitted through the Company's designated privacy or customer support channels.
5.17 Consequences of Not Providing Information
- Certain personal information is necessary for the operation of the Platform.
If a User chooses not to provide required information, the Company may be unable to:
- Create an Account.
- Verify identity.
- Publish Listings.
- Process Memberships.
- Process Credits.
- Enable Contact Unlock.
- Provide Customer Support.
- Comply with applicable legal obligations.
The Company will collect only the information reasonably necessary for the requested services.
5.18 Data Minimization
The Company seeks to collect and process only the personal information that is reasonably necessary for:
- Providing requested services.
- Meeting legal obligations.
- Maintaining Platform security.
- Improving Platform functionality.
- Preventing fraud.
The Company endeavors to avoid collecting information that is excessive or unrelated to these purposes.
5.19 Accountability
The Company maintains internal policies and procedures designed to promote responsible handling of personal information.
These measures may include:
- Access Controls.
- Employee Confidentiality Obligations.
- Internal Reviews.
- Security Monitoring.
- Compliance Programs.
- Risk Assessments.
Such measures may be updated from time to time to reflect changes in technology, business operations, and applicable law.
5.20 Chapter Summary
This Chapter explains the legal grounds on which SMARTAXIS PRIVATE LIMITED processes personal information. Depending on the circumstances, processing may be based on User consent, the performance of contractual obligations, compliance with applicable laws, fraud prevention, Platform security, protection of legal rights, service improvement, or other lawful bases recognized under applicable law. The Company is committed to processing personal information responsibly, transparently, and only to the extent reasonably necessary for legitimate operational and legal purposes.
Chapter 6 — SHARING, DISCLOSURE & TRANSFER OF PERSONAL INFORMATION
6.1 Purpose
This Chapter explains the circumstances under which SMARTAXIS PRIVATE LIMITED may share, disclose, or transfer personal information collected through the FinDeals Platform.
The Company shares personal information only where reasonably necessary to operate the Platform, provide requested services, comply with applicable law, protect legal rights, or with the User's consent where required.
The Company does not disclose personal information for purposes unrelated to those described in this Privacy Policy unless required or permitted by applicable law.
6.2 General Principle
The Company seeks to limit the sharing of personal information to:
- Authorized recipients.
- Legitimate business purposes.
- Lawful requirements.
- Service providers acting on the Company's behalf.
- Other situations described in this Privacy Policy.
Information shared shall generally be limited to what is reasonably necessary for the applicable purpose.
6.3 Sharing with Business Members
Where a User publishes a Financial Requirement Listing, certain information may be shared with eligible Business Members to facilitate legitimate business interactions.
Depending on the Platform feature used, shared information may include:
- Name (where applicable).
- Listing Details.
- Requirement Category.
- Location.
- Contact Information (through the Contact Unlock feature).
- Other information voluntarily included by the User in the Listing.
Business Members are contractually expected to use such information only for lawful purposes related to the Platform.
6.4 Contact Unlock
Where a Business Member successfully uses the Contact Unlock feature:
The eligible contact information selected by the User for sharing may be disclosed.
The disclosure shall occur only after applicable Platform conditions are satisfied.
The Company maintains records of Contact Unlock activities for operational, audit, fraud prevention, and dispute resolution purposes.
The Company cannot control how a recipient uses information after it has been lawfully disclosed through the Platform, although misuse may result in enforcement action under the Terms & Conditions.
6.5 Payment Service Providers
The Company may share limited information with authorized payment service providers to facilitate:
- Membership purchases.
- Credit purchases.
- Refund processing.
- Invoice generation.
- Payment verification.
- Fraud prevention.
- Payment service providers operate under their own privacy practices and legal obligations.
6.6 Cloud Infrastructure Providers
The Company may use cloud service providers for:
- Data hosting.
- Platform infrastructure.
- Backup.
- Disaster recovery.
- Performance optimization.
- Security monitoring.
Such providers may process personal information only to the extent reasonably necessary to provide contracted services.
6.7 Communication Service Providers
The Company may share limited information with service providers responsible for:
- SMS delivery.
- Email delivery.
- Push notifications.
- WhatsApp communications.
- OTP delivery.
- Transaction notifications.
- Only the information reasonably necessary to deliver the communication may be shared.
6.8 Identity Verification Providers
Where identity verification services are used, the Company may share verification-related information with trusted verification providers to:
- Verify identities.
- Verify businesses.
- Detect fraud.
- Confirm authenticity of submitted documents.
- Improve Platform security.
Verification providers are expected to process information in accordance with applicable contractual and legal obligations.
6.9 Customer Support Providers
Where Customer Support functions are provided with the assistance of third-party service providers, the Company may share information reasonably necessary to:
- Respond to enquiries.
- Resolve complaints.
- Investigate technical issues.
- Improve support services.
Access to personal information shall be limited to authorized personnel with a legitimate business need.
6.10 Analytics Providers
The Company may share certain technical and usage information with analytics providers to:
- Measure Platform performance.
- Improve User experience.
- Understand usage patterns.
- Identify system issues.
- Improve search functionality.
Where reasonably practicable, analytics information may be aggregated or de-identified before analysis.
6.11 Technology Service Providers
The Company may engage technology service providers for services including:
- Hosting.
- Software Development.
- Security Monitoring.
- Performance Optimization.
- Data Storage.
- Artificial Intelligence Features.
- System Maintenance.
Such providers may access information only to the extent reasonably necessary to perform contracted services.
6.12 Professional Advisors
The Company may disclose information to its professional advisors where reasonably necessary, including:
- Advocates.
- Chartered Accountants.
- Company Secretaries.
- Auditors.
- Consultants.
- Insurance Advisors.
- Such disclosures shall generally be subject to professional confidentiality obligations.
6.13 Government Authorities
The Company may disclose personal information to competent governmental authorities where required or permitted by applicable law, including:
- Courts.
- Police Authorities.
- Cybercrime Agencies.
- Regulatory Authorities.
- Tax Authorities.
- Financial Intelligence Units.
- Other Government Departments.
Such disclosures shall be limited to the extent reasonably necessary to comply with applicable legal obligations or lawful requests.
6.14 Legal Proceedings
The Company may disclose information where reasonably necessary to:
- Protect legal rights.
- Defend legal claims.
- Enforce these Terms.
- Respond to court orders.
- Comply with legal processes.
- Investigate fraud.
- Prevent unlawful activities.
6.15 Corporate Transactions
If SMARTAXIS PRIVATE LIMITED undergoes:
- Merger.
- Acquisition.
- Investment.
- Sale of Assets.
- Corporate Restructuring.
- Business Transfer.
personal information may be transferred as part of the transaction, subject to appropriate confidentiality obligations and applicable law.
Where required by law, Users shall be informed of such transfers.
6.16 International Transfers
The Company may use service providers whose infrastructure operates in jurisdictions outside the User's country.
Where personal information is transferred internationally, the Company shall take reasonable steps to ensure that such transfers comply with applicable law and are subject to appropriate safeguards.
6.17 Disclosure with User Consent
The Company may disclose personal information to third parties where the User has expressly authorized or consented to such disclosure.
Users may withdraw such consent where permitted by applicable law; however, withdrawal will not affect disclosures already made lawfully before the withdrawal.
6.18 Aggregated and De-identified Information
The Company may use, analyze, publish, or share information that has been aggregated or de-identified so that it does not reasonably identify an individual User.
Such information may be used for:
- Statistical Analysis.
- Platform Improvement.
- Business Reporting.
- Research.
- Product Development.
6.19 Situations Where We Do Not Share Personal Information
Except as described in this Privacy Policy or required by applicable law, the Company does not disclose personal information to unrelated third parties for their independent marketing purposes without the User's consent.
The Company also does not intentionally disclose confidential authentication credentials such as passwords or PINs.
6.20 User Control
Where applicable, Users may have the ability to:
- Update Profile Information.
- Modify certain privacy preferences.
- Control promotional communications.
- Withdraw certain consents.
- Request correction of personal information.
- Request deletion of personal information, subject to legal and operational requirements.
Some information sharing may be mandatory for the operation of the Platform and cannot be disabled without affecting the availability of certain services.
6.21 Protection During Sharing
The Company seeks to implement reasonable contractual, organizational, and technical measures to protect personal information shared with authorized recipients.
However, once information has been lawfully disclosed to another User or Business Member through Platform features, the Company cannot guarantee or control how the recipient subsequently uses that information.
6.22 Chapter Summary
This Chapter explains the circumstances in which SMARTAXIS PRIVATE LIMITED may share, disclose, or transfer personal information. Information may be shared with Business Members, payment processors, cloud service providers, communication providers, verification partners, professional advisors, and competent authorities where reasonably necessary to operate the Platform, provide requested services, comply with applicable law, or protect legal rights. The Company seeks to limit disclosures to the minimum information reasonably necessary and to apply appropriate safeguards during such sharing.
Chapter 7 — INFORMATION SECURITY, DATA PROTECTION & INCIDENT RESPONSE
7.1 Purpose
This Chapter explains the measures adopted by SMARTAXIS PRIVATE LIMITED to protect personal information processed through the FinDeals Platform.
The Company is committed to implementing reasonable administrative, technical, organizational, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
While the Company strives to maintain appropriate security standards, no internet-connected system or method of electronic storage can be guaranteed to be completely secure.
7.2 Security Principles
The Company's information security program is designed around the following principles:
- Confidentiality
- Integrity
- Availability
- Accountability
- Least Privilege
- Security by Design
- Risk-Based Protection
- Continuous Improvement
7.3 Administrative Safeguards
The Company may implement administrative safeguards including:
- Information Security Policies.
- Employee Background Verification (where appropriate).
- Confidentiality Agreements.
- Employee Security Training.
- Access Management Procedures.
- Incident Reporting Procedures.
- Vendor Security Assessments.
- Internal Security Reviews.
- Compliance Monitoring.
- Risk Management Programs.
7.4 Technical Safeguards
The Company may implement technical controls including:
- Secure Authentication.
- Encryption where appropriate.
- Firewalls.
- Web Application Firewalls.
- Anti-malware Protection.
- Intrusion Detection Systems.
- Intrusion Prevention Systems.
- Network Monitoring.
- Security Logging.
- Secure Configuration Management.
- Patch Management.
- Vulnerability Assessments.
- Endpoint Protection.
The Company may modify these controls as technology and security practices evolve.
7.5 Encryption
Where appropriate and reasonably practicable, the Company may use encryption to protect:
- Data transmitted over networks.
- Stored personal information.
- Authentication credentials.
- Backup data.
- Administrative communications.
- Encryption methods may be updated periodically to reflect evolving security standards.
7.6 Authentication and Access Control
Access to personal information is generally limited to authorized personnel who require such access to perform their responsibilities.
The Company may implement:
- Role-Based Access Control (RBAC).
- Multi-Factor Authentication (where available).
- Password Security Requirements.
- Session Management.
- Device Authentication.
- Login Monitoring.
- Account Lockout Mechanisms.
- Access Logging.
7.7 Password Security
Users are responsible for maintaining the confidentiality of their Account credentials.
Users should:
- Use strong passwords.
- Keep passwords confidential.
- Avoid password reuse.
- Change passwords periodically where appropriate.
- Never share passwords or OTPs.
- Report suspected compromise immediately.
The Company will never request a User's password or banking PIN through email, SMS, WhatsApp, or Platform Messaging.
7.8 Network Security
The Company may employ network security measures including:
- Firewalls.
- Network Segmentation.
- Traffic Monitoring.
- Secure Network Architecture.
- Access Restrictions.
- DDoS Protection.
- VPN Access for authorized personnel where appropriate.
7.9 Data Storage Security
Personal information may be stored using secure infrastructure that includes reasonable safeguards such as:
- Secure Servers.
- Controlled Access.
- Encrypted Storage where appropriate.
- Backup Systems.
- Disaster Recovery Infrastructure.
- Redundancy Mechanisms.
- Storage locations may change as the Company's infrastructure evolves.
7.10 Backup and Disaster Recovery
The Company may maintain backup systems to support:
- Business Continuity.
- Disaster Recovery.
- System Restoration.
- Data Recovery.
- Infrastructure Resilience.
Backups may be retained only for periods reasonably necessary for operational, legal, and security purposes.
7.11 Security Monitoring
The Company may continuously monitor Platform activity to:
- Detect unauthorized access.
- Identify suspicious behaviour.
- Detect malware.
- Detect cyberattacks.
- Investigate fraud.
- Prevent abuse.
- Protect Platform infrastructure.
- Monitoring may involve automated systems and manual review where appropriate.
7.12 Vulnerability Management
The Company may periodically conduct:
- Security Testing.
- Vulnerability Assessments.
- Penetration Testing.
- Configuration Reviews.
- Software Updates.
- Security Patch Deployment.
- Risk Assessments.
- Security vulnerabilities may be addressed according to their severity and operational priorities.
7.13 Third-Party Security
Where third-party service providers process personal information on behalf of the Company, the Company seeks to engage providers that maintain appropriate security measures.
The Company may evaluate such providers through contractual commitments, security assessments, or other reasonable due diligence processes.
7.14 Employee Confidentiality
Employees, contractors, consultants, and authorized personnel who have access to personal information are expected to:
- Maintain confidentiality.
- Access information only where necessary.
- Follow Company security policies.
- Protect User information.
- Report suspected security incidents.
Unauthorized access or misuse of personal information may result in disciplinary action and other legal consequences where applicable.
7.15 User Responsibilities
Users also play an important role in protecting personal information.
Users should:
- Protect Account credentials.
- Keep software updated.
- Use trusted devices.
- Avoid phishing attempts.
- Verify communications claiming to be from the Company.
- Report suspicious activity promptly.
- Log out from shared devices.
- Failure to follow reasonable security practices may increase the risk of unauthorized access.
7.16 Security Incident Response
If the Company becomes aware of a security incident affecting the Platform, it may:
- Identify the incident.
- Contain the incident.
- Investigate the cause.
- Assess potential impact.
- Restore affected services.
- Preserve relevant evidence.
- Implement corrective measures.
- Cooperate with competent authorities where required.
The Company's response procedures may evolve to reflect changes in technology, threats, and applicable law.
7.17 Data Breach Notification
Where a personal data breach occurs and notification is required by applicable law, the Company may:
- Notify affected Users.
- Notify relevant regulatory authorities.
- Provide available information regarding the incident.
- Describe mitigation measures.
- Recommend appropriate protective actions for affected Users.
Notification timing and content shall be determined in accordance with applicable legal requirements.
7.18 Fraud Prevention
The Company may implement security measures designed to:
- Detect fake Accounts.
- Prevent identity theft.
- Detect fraudulent Listings.
- Prevent unauthorized Contact Unlock activity.
- Detect suspicious payment activity.
- Identify automated abuse.
- Prevent spam.
- Fraud prevention measures may include automated systems, manual review, and verification processes.
7.19 Business Continuity
The Company seeks to maintain reasonable business continuity measures designed to reduce service interruptions arising from:
- Infrastructure Failures.
- Hardware Failures.
- Cybersecurity Incidents.
- Natural Disasters.
- Power Interruptions.
- Network Failures.
- Business continuity measures may be reviewed and updated periodically.
7.20 Security Limitations
Despite implementing commercially reasonable security measures, the Company cannot guarantee that:
The Platform will never experience security incidents.
- Unauthorized access will never occur.
- Cyberattacks will always be prevented.
- Data transmission over the Internet is completely secure.
- Third-party systems will always remain secure.
Users acknowledge the inherent risks associated with internet-based services.
7.21 Reporting Security Concerns
Users who become aware of:
- Unauthorized Account Access.
- Security Vulnerabilities.
- Phishing Attempts.
- Fraudulent Communications.
- Suspected Data Misuse.
- Other Security Concerns.
- should promptly notify the Company through its official support or security reporting channels.
7.22 Continuous Improvement
The Company continuously reviews and improves its information security practices by:
- Updating security technologies.
- Reviewing policies.
- Conducting internal assessments.
- Evaluating emerging threats.
- Improving incident response capabilities.
- Enhancing employee awareness.
- Strengthening technical controls.
- Security measures may change over time to address evolving risks and legal requirements.
7.23 Chapter Summary
This Chapter explains the security measures adopted by SMARTAXIS PRIVATE LIMITED to protect personal information processed through the FinDeals Platform. The Company implements reasonable administrative, technical, organizational, and physical safeguards, including access controls, encryption where appropriate, security monitoring, vulnerability management, employee confidentiality obligations, and incident response procedures. While the Company is committed to maintaining a secure Platform, Users are also responsible for protecting their own Accounts, and no internet-based system can be guaranteed to be completely secure.
Chapter 8 — DATA RETENTION, ARCHIVING & DELETION
8.1 Purpose
This Chapter explains how SMARTAXIS PRIVATE LIMITED retains, archives, anonymizes, and deletes personal information collected through the FinDeals Platform.
The Company retains personal information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with applicable law, protect legal rights, resolve disputes, enforce agreements, and operate the Platform.
8.2 Retention Principles
The Company follows the following data retention principles:
- Retain information only where reasonably necessary.
- Comply with applicable legal and regulatory requirements.
- Protect Users and the Platform.
- Support fraud prevention.
- Preserve evidence where required.
- Securely delete or anonymize information when retention is no longer necessary.
8.3 Factors Used to Determine Retention Periods
The Company may determine retention periods based on factors including:
- Nature of the information.
- Purpose of collection.
- Operational requirements.
- User relationship.
- Applicable legal obligations.
- Tax requirements.
- Fraud prevention needs.
- Ongoing disputes.
- Regulatory investigations.
- Information security requirements.
- Retention periods may therefore vary depending on the category of information.
8.4 Account Information
The Company may retain Account information while an Account remains active.
Following Account closure, certain information may continue to be retained where reasonably necessary for:
- Legal compliance.
- Fraud prevention.
- Audit purposes.
- Dispute resolution.
- Security investigations.
- Enforcement of contractual rights.
8.5 Financial Requirement Listings
Information relating to Financial Requirement Listings may be retained to:
- Maintain Platform records.
- Prevent duplicate Listings.
- Investigate complaints.
- Detect fraud.
- Resolve disputes.
- Meet legal obligations.
- Support internal audits.
Expired or removed Listings may continue to exist in secure archival systems for a limited period where reasonably necessary.
8.6 Membership Records
The Company may retain Membership-related information including:
- Membership history.
- Subscription records.
- Payment references.
- Renewal history.
- Geographic access history.
- Membership invoices.
- Such information assists with customer support, financial reporting, audits, and legal compliance.
8.7 Credits History
The Company may retain records relating to:
- Credit purchases.
- Credit usage.
- Credit deductions.
- Credit refunds.
- Contact Unlock activity.
- Credit disputes.
- These records help maintain accurate financial and operational records.
8.8 Payment Records
Payment-related information may be retained for purposes including:
- Accounting.
- Tax compliance.
- Financial audits.
- Refund processing.
- Chargeback investigations.
- Fraud prevention.
- Legal obligations.
Sensitive payment authentication data is generally processed by authorized payment providers rather than stored by the Company.
8.9 Customer Support Records
Customer Support communications may be retained to:
- Improve service quality.
- Resolve future enquiries.
- Investigate complaints.
- Identify recurring technical issues.
- Prevent abuse.
- Support legal claims where necessary.
8.10 Security Logs
Security-related information may be retained including:
- Login history.
- Device history.
- Authentication events.
- Security alerts.
- IP logs.
- Audit logs.
- Fraud detection records.
- Incident investigation records.
- Retention of such information helps protect Platform security.
8.11 Communication Records
The Company may retain records relating to:
- Emails.
- SMS messages.
- Push notifications.
- WhatsApp communications.
- Customer Support interactions.
- Platform messaging.
- Legal notices.
- Retention supports operational continuity, dispute resolution, and regulatory compliance.
8.12 Verification Information
Where Users or Business Members undergo verification, the Company may retain verification records to:
- Prevent repeated verification fraud.
- Maintain Platform trust.
- Resolve identity disputes.
- Meet legal obligations.
- Investigate complaints.
8.13 Analytics Information
Analytics information may be retained for:
- Platform performance analysis.
- Usage trend analysis.
- Service improvement.
- Fraud detection.
- Statistical reporting.
Where reasonably practicable, analytics information may be aggregated or anonymized.
8.14 Backup Copies
Personal information may continue to exist within secure backup systems for a limited period after deletion from active systems.
Backup information may be retained for purposes including:
- Disaster recovery.
- System restoration.
- Business continuity.
- Security resilience.
- Backup copies are generally subject to the same security protections as active systems.
8.15 Archival Storage
The Company may archive certain information where reasonably necessary for:
- Historical business records.
- Regulatory compliance.
- Legal proceedings.
- Corporate governance.
- Internal audits.
- Fraud investigations.
- Archived information is generally subject to restricted access controls.
8.16 Account Deletion Requests
Users may request deletion of their Accounts through available Platform features or by contacting Customer Support.
Before processing a deletion request, the Company may verify the identity of the requesting User to protect against unauthorized deletion requests.
Deletion requests may not result in immediate removal of all information where continued retention is required or permitted by applicable law.
8.17 Information That May Be Retained After Account Deletion
Even after an Account is deleted, the Company may retain certain categories of information where reasonably necessary, including:
- Transaction records.
- Payment information.
- Tax records.
- Audit logs.
- Fraud prevention records.
- Legal correspondence.
- Security investigation records.
- Court-related records.
- Regulatory compliance records.
Such retention shall be limited to the purposes for which continued retention is reasonably necessary.
8.18 Secure Deletion
Where information is no longer required, the Company seeks to securely delete, anonymize, or otherwise render the information inaccessible using methods appropriate to the nature of the information and available technology.
Deletion practices may vary depending on:
- System architecture.
- Storage media.
- Backup processes.
- Operational requirements.
- Legal obligations.
8.19 Anonymization
Where appropriate, the Company may anonymize personal information so that it can no longer reasonably identify an individual.
Anonymized information may be used for:
- Statistical analysis.
- Product improvement.
- Research.
- Business reporting.
- Service development.
Information that has been effectively anonymized is generally no longer considered personal information.
8.20 Litigation Hold
Where information is relevant to:
- Legal proceedings.
- Government investigations.
- Regulatory enquiries.
- Arbitration.
- Fraud investigations.
- Court Orders.
the Company may suspend routine deletion until such matters have been resolved or legal obligations have been satisfied.
8.21 Business Closure or Platform Discontinuation
If the Company discontinues the FinDeals Platform or permanently ceases operations, personal information will be handled in accordance with applicable law.
The Company may:
- Retain information where legally required.
- Securely delete unnecessary information.
- Transfer information as part of a lawful corporate transaction, subject to appropriate safeguards.
- Notify Users where required by applicable law.
8.22 User Responsibilities
Users are encouraged to:
- Maintain copies of information they may require in the future.
- Update inaccurate information.
- Remove unnecessary content from their Accounts where possible.
- Submit deletion requests through official channels.
The Company is not responsible for preserving User-generated content beyond applicable retention periods or legal obligations.
8.23 Periodic Review
The Company periodically reviews its retention practices to:
- Remove unnecessary information.
- Improve data management.
- Reflect technological developments.
- Comply with evolving legal requirements.
- Enhance information security.
- Retention schedules may be updated from time to time.
8.24 Chapter Summary
This Chapter explains how SMARTAXIS PRIVATE LIMITED retains, archives, anonymizes, and deletes personal information associated with the FinDeals Platform. Information is retained only for as long as reasonably necessary to provide services, comply with applicable legal obligations, prevent fraud, resolve disputes, and protect legal rights. When information is no longer required, the Company seeks to securely delete or anonymize it, subject to legal, regulatory, operational, and security requirements.
Chapter 9 — USER RIGHTS & CHOICES REGARDING PERSONAL INFORMATION
9.1 Purpose
This Chapter explains the rights and choices available to Users regarding their personal information processed by SMARTAXIS PRIVATE LIMITED through the FinDeals Platform.
The Company is committed to providing Users with reasonable control over their personal information while balancing legal, regulatory, operational, security, and fraud prevention obligations.
The availability of specific rights may depend on applicable law and the nature of the information involved.
9.2 General Principles
The Company seeks to ensure that Users are able to:
- Understand how their information is processed.
- Access eligible personal information.
- Correct inaccurate information.
- Update outdated information.
- Request deletion where appropriate.
- Withdraw consent where applicable.
- Manage communication preferences.
- Raise privacy-related concerns.
- Contact the Company's Grievance Officer.
Certain rights may be subject to verification, legal limitations, operational feasibility, and applicable law.
9.3 Right to Access Personal Information
Subject to applicable law, Users may request access to certain personal information maintained by the Company.
Access requests may include information relating to:
- Account Information.
- Profile Information.
- Membership Details.
- Credit History.
- Listing Information.
- Contact Unlock Activity.
- Communication Preferences.
- Verification Status.
The Company may limit access where disclosure would adversely affect the rights of others, compromise security, or conflict with legal obligations.
9.4 Right to Correct or Update Information
Users are encouraged to keep their personal information accurate and current.
Users may update eligible information through their Account settings or by contacting Customer Support.
The Company may require verification before making material changes to:
- Name.
- Mobile Number.
- Email Address.
- Business Information.
- Verification Details.
- Other sensitive account information.
The Company may decline requests that are fraudulent, misleading, or inconsistent with applicable law.
9.5 Right to Request Deletion
Where permitted by applicable law, Users may request deletion of their personal information or Account.
Deletion requests may be submitted through:
- Account settings (where available).
- Customer Support.
The designated privacy contact.
The Company may retain certain information where reasonably necessary for:
- Compliance with legal obligations.
- Fraud prevention.
- Security investigations.
- Tax and accounting requirements.
- Dispute resolution.
- Enforcement of contractual rights.
- Regulatory compliance.
Deletion of an Account does not necessarily result in immediate removal of all associated information.
9.6 Right to Withdraw Consent
Where processing is based on User consent, Users may withdraw that consent at any time through available Platform features or by contacting the Company.
Withdrawal of consent:
- Does not affect processing carried out before the withdrawal.
- Does not affect processing based on another lawful basis.
- May limit access to certain Platform features that depend on such consent.
9.7 Right to Manage Communication Preferences
Users may manage certain communication preferences, including:
- Marketing Emails.
- Promotional SMS.
- Promotional WhatsApp Messages.
- Newsletters.
- Product Updates.
- Educational Communications.
Users cannot opt out of essential communications relating to:
- Account Security.
- OTP Verification.
- Payment Confirmations.
- Membership Status.
- Legal Notices.
- Service Announcements.
- Fraud Alerts.
9.8 Right to Request Information About Processing
Where recognized by applicable law, Users may request information regarding:
- Categories of personal information processed.
- Purposes of processing.
- Categories of recipients.
- Retention practices.
- Available privacy rights.
- Contact details for privacy enquiries.
The Company may provide such information in accordance with applicable legal requirements.
9.9 Right to Request a Copy of Personal Information
Where applicable law provides such a right, Users may request a copy of certain personal information maintained by the Company.
The Company may:
- Verify the User's identity.
- Limit repeated or excessive requests.
- Exclude information protected by law or affecting the rights of others.
- Provide information in a commonly used electronic format where reasonably practicable.
9.10 Right to Object to Certain Processing
Where applicable law provides such rights, Users may object to certain processing activities.
The Company will review such requests and determine whether continued processing is required for:
- Legal obligations.
- Contractual performance.
- Fraud prevention.
- Security.
- Protection of legal rights.
- Other lawful purposes.
The Company will inform the User of the outcome where required by applicable law.
9.11 Right to Restrict Processing
Where recognized under applicable law, Users may request restriction of certain processing activities while the Company reviews:
- Accuracy disputes.
- Identity verification.
- Legal objections.
- Complaints.
- Other eligible circumstances.
Restriction requests may not apply where processing remains necessary to comply with legal obligations or protect legal rights.
9.12 Right to Lodge a Privacy Complaint
Users who believe their privacy rights have been affected may submit a complaint to the Company's designated Grievance Officer or Privacy Contact.
Privacy complaints may relate to:
- Improper disclosure.
- Unauthorized access.
- Incorrect information.
- Account-related privacy concerns.
- Security incidents.
- Processing practices.
- Other privacy matters.
The Company will review complaints in accordance with applicable law and internal procedures.
9.13 Identity Verification
To protect Users against unauthorized requests, the Company may require reasonable identity verification before processing requests relating to:
- Account access.
- Information correction.
- Account deletion.
- Data access.
- Consent withdrawal.
- Privacy complaints.
The Company may decline requests where identity cannot reasonably be verified.
9.14 Authorized Representatives
Where permitted by applicable law, an authorized representative may submit a request on behalf of a User.
The Company may require:
- Written authorization.
- Proof of authority.
- Identity verification of both the User and the representative.
- Additional documentation where reasonably necessary.
9.15 Response Time
The Company aims to respond to eligible privacy requests within the timeframe required by applicable law.
Where additional time is reasonably necessary due to the complexity or volume of requests, the Company may extend the response period where permitted by law and will inform the User accordingly.
9.16 Circumstances Where Requests May Be Declined
The Company may decline or limit a request where:
The request is fraudulent.
- Identity cannot be verified.
- Disclosure would violate applicable law.
- Disclosure would affect another person's rights.
- Information is protected by legal privilege.
The request is repetitive or excessive.
The Company is legally required to retain the information.
- Processing remains necessary for fraud prevention or security.
Where appropriate, the Company will explain the basis for its decision.
9.17 No Fee for Ordinary Requests
The Company generally does not charge a fee for reasonable privacy requests.
However, where permitted by applicable law, the Company may charge a reasonable administrative fee or decline requests that are:
- Manifestly unfounded.
- Excessive.
- Repetitive.
- Technically unreasonable.
- Any applicable fee will be communicated before processing the request.
9.18 Updating Your Information
Users are encouraged to review and update their personal information periodically.
Maintaining accurate information helps:
- Improve Platform security.
- Prevent fraud.
- Ensure effective communication.
- Deliver requested services.
- Reduce verification delays.
Users remain responsible for ensuring that information submitted through the Platform is accurate and up to date.
9.19 Contacting the Privacy Team
Users may contact the Company's designated Privacy Team or Grievance Officer regarding:
- Privacy enquiries.
- Requests relating to personal information.
- Consent withdrawal.
- Correction requests.
- Deletion requests.
- Complaints.
- Security concerns.
The Company's current contact details are provided in the "Contact Information" chapter of this Privacy Policy and may be updated from time to time.
9.20 Chapter Summary
This Chapter explains the rights and choices available to Users regarding their personal information. Subject to applicable law, Users may request access to, correction of, deletion of, or information about their personal information, withdraw consent where applicable, manage communication preferences, and submit privacy-related complaints. The Company may verify identity before acting on requests and may decline or limit requests where required or permitted by applicable law, including for fraud prevention, security, legal compliance, or protection of the rights of others.
Chapter 10 — COOKIES, TRACKING TECHNOLOGIES & ONLINE ANALYTICS
10.1 Purpose
This Chapter explains how SMARTAXIS PRIVATE LIMITED uses cookies, tracking technologies, and online analytics in connection with the FinDeals Platform.
These technologies help operate, secure, maintain, improve, and personalize the Platform while supporting analytics, fraud prevention, and user experience.
The Company uses such technologies in accordance with applicable law and this Privacy Policy.
10.2 What Are Cookies?
- Cookies are small text files stored on a User's device by a website or application.
Cookies allow the Platform to:
- Recognize returning Users.
- Maintain login sessions.
- Remember preferences.
- Improve performance.
- Enhance security.
- Analyze Platform usage.
- Deliver a better user experience.
Cookies generally do not contain executable code and cannot independently access information stored elsewhere on a User's device.
10.3 Types of Technologies Used
The Company may use various technologies including:
- Cookies.
- Session Cookies.
- Persistent Cookies.
- Local Storage.
- Browser Storage.
- Pixel Tags.
- Web Beacons.
- Software Development Kits (SDKs).
- Device Identifiers.
- Log Files.
- Similar technologies.
- These technologies may be updated as industry practices and technologies evolve.
10.4 Essential Cookies
- Essential cookies are necessary for the proper operation of the Platform.
They may be used for:
- User Authentication.
- Secure Login.
- Session Management.
- Security Protection.
- Fraud Prevention.
- Load Balancing.
- Platform Stability.
- Without these cookies, certain Platform features may not function correctly.
10.5 Functional Cookies
Functional cookies help improve usability by remembering User preferences such as:
- Language Selection.
- Region Preferences.
- Display Settings.
- Accessibility Preferences.
- Saved Preferences.
- Notification Preferences.
- These cookies improve convenience but are generally not essential for basic Platform operation.
10.6 Performance Cookies
- Performance cookies help the Company understand how Users interact with the Platform.
They may collect information regarding:
- Page Load Speed.
- Navigation Patterns.
- Error Reports.
- Feature Usage.
- System Performance.
- Session Duration.
- User Interaction.
- Performance information helps improve Platform reliability and efficiency.
10.7 Analytics Cookies
Analytics technologies may be used to understand:
- Number of Visitors.
- User Engagement.
- Search Behaviour.
- Listing Performance.
- Membership Usage.
- Contact Unlock Activity.
- Device Statistics.
- Feature Adoption.
Where reasonably practicable, analytics information may be aggregated or de-identified.
10.8 Security Cookies
Security-related cookies may be used to:
- Detect fraudulent activity.
- Protect User Accounts.
- Identify suspicious login attempts.
- Prevent automated attacks.
- Prevent spam.
- Improve authentication.
- Maintain Platform integrity.
- These cookies help safeguard both Users and the Platform.
10.9 Advertising and Marketing Technologies
Where the Company conducts marketing activities, cookies or similar technologies may be used to:
- Measure advertising effectiveness.
- Understand campaign performance.
- Prevent repeated advertisements.
- Improve promotional communications.
- Analyze marketing engagement.
Where required by applicable law, such technologies will be used only after obtaining the necessary consent.
10.10 Third-Party Analytics
The Company may engage trusted third-party analytics providers to help understand Platform usage and improve services.
Such providers may process limited technical information including:
- Browser Type.
- Device Information.
- Operating System.
- IP Address.
- Session Information.
- Referral Source.
- Usage Statistics.
These providers are expected to process information in accordance with contractual obligations and applicable law.
10.11 Mobile Applications
If FinDeals provides mobile applications, the applications may use technologies including:
- Device Identifiers.
- Application Instance IDs.
- Crash Reporting Tools.
- Performance Monitoring Tools.
- Push Notification Tokens.
- Mobile Analytics SDKs.
- These technologies help improve application functionality, reliability, and security.
10.12 Log Files
The Platform may automatically generate system logs containing information such as:
- IP Address.
- Browser Type.
- Operating System.
- Device Information.
- Access Time.
- Login Activity.
- Error Logs.
- Security Events.
- Referral URLs.
- Log information assists with troubleshooting, performance monitoring, security, and compliance.
10.13 Consent for Cookies
Where required by applicable law, the Company will seek the User's consent before placing or accessing non-essential cookies or similar technologies.
Users may be presented with a cookie banner, consent tool, or similar mechanism allowing them to:
- Accept all cookies.
- Reject non-essential cookies.
- Customize cookie preferences.
- Change previously selected preferences.
Essential cookies may continue to operate because they are necessary for the functioning and security of the Platform.
10.14 Managing Cookie Preferences
Users may manage cookies through:
- Platform Cookie Settings (where available).
- Browser Settings.
- Mobile Device Settings.
- Operating System Controls.
- Third-Party Preference Tools.
Disabling certain cookies may affect Platform functionality or reduce the availability of some features.
10.15 Browser Controls
Most modern browsers allow Users to:
- View stored cookies.
- Delete cookies.
- Block cookies.
- Restrict third-party cookies.
- Receive cookie notifications.
- Clear browsing data.
- Browser settings vary depending on the software used by the User.
10.16 Do Not Track (DNT)
- Some browsers provide a "Do Not Track" (DNT) setting.
Because there is currently no universally accepted standard governing DNT signals, the Company may not respond uniformly to all DNT requests unless required by applicable law.
If industry standards or legal requirements change, the Company may update its practices accordingly.
10.17 Similar Tracking Technologies
In addition to cookies, the Company may use technologies such as:
- Pixels.
- SDKs.
- Local Storage.
- Session Storage.
- API-Based Tracking.
- Authentication Tokens.
- Device Recognition Technologies.
- These technologies support Platform functionality, security, and analytics.
10.18 Third-Party Websites
The FinDeals Platform may contain links to third-party websites or services.
Third-party websites may place their own cookies or tracking technologies, which are governed by their respective privacy policies.
The Company is not responsible for the privacy practices or tracking technologies used by third-party websites or services.
10.19 Updates to Cookie Technologies
The Company may introduce new cookie technologies or discontinue existing ones as:
- Platform features evolve.
- Security requirements change.
- Industry standards develop.
- Applicable laws are updated.
Material changes to cookie practices will be reflected in this Privacy Policy or a separate Cookie Policy where appropriate.
10.20 Separate Cookie Policy
The Company may maintain a separate Cookie Policy providing additional details regarding:
- Cookie categories.
- Individual cookies.
- Retention periods.
- Third-party providers.
- Preference management.
- Consent mechanisms.
Where a separate Cookie Policy exists, it forms part of this Privacy Policy and should be read together with it.
10.21 User Responsibilities
Users should understand that disabling cookies may:
- Affect Platform functionality.
- Prevent automatic login.
- Reset preferences.
- Reduce personalization.
- Impact security features.
- Limit certain Platform services.
Users remain responsible for configuring their own browser and device privacy settings.
10.22 Chapter Summary
This Chapter explains how SMARTAXIS PRIVATE LIMITED uses cookies and similar technologies to operate, secure, personalize, and improve the FinDeals Platform. These technologies support authentication, performance, analytics, fraud prevention, security, and user preferences. Where required by applicable law, Users may manage or consent to the use of non-essential cookies through available preference tools, while essential cookies remain necessary for the operation and security of the Platform.
Chapter 11 — CHILDREN'S PRIVACY & AGE RESTRICTIONS
11.1 Purpose
This Chapter explains the Company's policies regarding children, minors, age eligibility, and the processing of personal information belonging to individuals who have not attained the legal age required to use the FinDeals Platform.
SMARTAXIS PRIVATE LIMITED recognizes the importance of protecting children's privacy and is committed to complying with applicable laws relating to the processing of children's personal information.
11.2 Platform Intended for Adults
FinDeals is a financial classifieds platform intended primarily for:
- Adults.
- Business Members.
- Financial Service Providers.
- Companies.
- Registered Businesses.
- Self-employed Professionals.
- Individuals legally capable of entering into binding contracts.
The Platform is not designed or marketed for children.
11.3 Minimum Age Requirement
Users must satisfy the minimum legal age required under applicable law to create an Account and use the Platform.
By registering an Account, a User represents and warrants that:
- They meet the applicable minimum age requirement.
- They possess the legal capacity to enter into binding agreements.
The information provided regarding their age is accurate.
- Providing false information regarding age may result in suspension or termination of the Account.
11.4 No Intentional Collection of Children's Personal Information
The Company does not knowingly collect, solicit, or process personal information from children except where expressly permitted or required by applicable law.
The Platform is not intended to attract children, and the Company does not intentionally offer financial services or financial classifieds to children.
11.5 Discovery of Child Accounts
If the Company becomes aware that:
- An Account belongs to a child who is not legally eligible to use the Platform; or
- Personal information has been collected from a child in a manner inconsistent with applicable law
the Company may take appropriate action, including:
- Restricting the Account.
- Suspending Platform access.
- Requesting age verification.
- Removing Listings.
- Deleting the Account.
- Deleting associated personal information where required by law.
11.6 Age Verification
Where reasonably necessary, the Company may request additional information to verify a User's age.
Age verification may be required:
- During Account Registration.
- During Business Verification.
- Following suspected misuse.
- During fraud investigations.
- Before providing certain Platform features.
- Failure to complete reasonable age verification may result in restrictions on Platform access.
11.7 Parents and Legal Guardians
If a parent or legal guardian believes that a child has provided personal information to the Company without appropriate authorization or contrary to applicable law, they may contact the Company using the contact details provided in this Privacy Policy.
Upon receiving a verified request, the Company may:
- Investigate the matter.
- Verify the identity and authority of the requester.
- Remove the child's Account where appropriate.
- Delete eligible personal information, subject to applicable law.
- Provide an appropriate response in accordance with legal requirements.
11.8 Removal of Children's Information
Where the Company determines that it has unintentionally collected personal information from a child contrary to applicable law, it will take reasonable steps to:
- Delete the information from active systems where appropriate.
- Restrict further processing.
- Prevent future collection through the same mechanism.
- Review internal procedures where necessary.
Certain information may continue to be retained where legally required, including for fraud prevention, regulatory compliance, or legal proceedings.
11.9 Educational Use
The FinDeals Platform is not intended for educational use by schools or children.
Any educational content provided through the Platform is intended for adult Users, Business Members, and professionals.
11.10 Financial Responsibility
Children should not:
- Publish Financial Requirement Listings.
- Purchase Membership Plans.
- Purchase Credits.
- Use Contact Unlock.
- Register as Business Members.
- Enter into financial arrangements through the Platform.
These activities are intended only for individuals legally capable of entering into binding agreements under applicable law.
11.11 Child Safety
The Company encourages parents and legal guardians to:
- Supervise children's online activities.
- Educate children about online privacy.
- Prevent unauthorized sharing of personal information.
- Monitor internet usage where appropriate.
The Company cannot supervise Users outside the Platform and encourages responsible parental involvement.
11.12 Third-Party Services
The Platform may integrate with or link to third-party services.
The privacy practices of such third parties are governed by their respective privacy policies.
Parents and guardians should review those policies independently before permitting children to use such services.
11.13 Marketing to Children
The Company does not knowingly:
- Direct advertising to children.
- Send promotional communications to children.
- Encourage children to register Accounts.
- Conduct marketing campaigns targeting children.
If the Company becomes aware that promotional communications have been sent to a child contrary to applicable law, it will take reasonable steps to discontinue such communications.
11.14 Reporting Concerns
Any person who believes that:
- A child has created an Account.
- A child's personal information has been improperly collected.
- A child is using the Platform in violation of these Terms.
- may notify the Company through its designated support or privacy contact channels.
The Company will review such reports in accordance with applicable law and internal procedures.
11.15 Compliance with Applicable Law
The Company will handle children's personal information in accordance with applicable child protection and data protection laws.
Where future legal requirements impose additional obligations relating to children's privacy, the Company may update this Privacy Policy and its operational practices accordingly.
11.16 Chapter Summary
This Chapter explains the Company's approach to protecting children's privacy. FinDeals is intended for adults and individuals legally capable of entering into binding agreements. The Company does not knowingly collect personal information from children or market the Platform to them. If the Company becomes aware that information relating to a child has been collected contrary to applicable law, it will take appropriate steps to investigate, restrict processing, and delete such information where required.
Chapter 12 — INTERNATIONAL DATA TRANSFERS & CROSS-BORDER PROCESSING
12.1 Purpose
This Chapter explains how SMARTAXIS PRIVATE LIMITED may process, store, transfer, or permit access to personal information across national borders in connection with the operation of the FinDeals Platform.
As a technology platform, FinDeals may use cloud infrastructure, software services, security providers, and other technology partners located in different jurisdictions. The Company is committed to ensuring that any international processing of personal information is carried out in accordance with applicable law and appropriate safeguards.
12.2 Global Technology Infrastructure
To provide reliable, secure, and scalable services, the Company may use technology infrastructure located in one or more countries.
Such infrastructure may include:
- Cloud Computing Services.
- Data Storage Systems.
- Backup Infrastructure.
- Content Delivery Networks (CDNs).
- Disaster Recovery Facilities.
- Security Monitoring Systems.
- Communication Platforms.
- Analytics Platforms.
The physical location of servers may change over time as business and operational requirements evolve.
12.3 Cross-Border Processing
Personal information may be processed outside the User's country where reasonably necessary for:
- Platform Operations.
- Cloud Hosting.
- Backup and Recovery.
- Customer Support.
- Security Monitoring.
- Fraud Prevention.
- Performance Monitoring.
- Analytics.
- Software Maintenance.
- Technical Support.
- Such processing does not reduce the Company's commitment to protecting personal information.
12.4 International Service Providers
The Company may engage trusted service providers located in various jurisdictions, including providers of:
- Cloud Infrastructure.
- Payment Processing.
- Identity Verification.
- Artificial Intelligence Services.
- Email Delivery.
- SMS Services.
- Push Notifications.
- Customer Support.
- Cybersecurity.
- Analytics.
- Business Continuity.
These providers process personal information only to the extent reasonably necessary to provide contracted services.
12.5 Compliance with Applicable Law
The Company seeks to ensure that international transfers of personal information comply with:
- Applicable Indian data protection laws.
- Other applicable privacy and data protection laws.
- Regulatory requirements.
- Court orders.
- Government directives that are legally binding.
Where applicable law imposes restrictions on international transfers, the Company will implement appropriate measures before transferring personal information.
12.6 Appropriate Safeguards
Where personal information is transferred across borders, the Company may implement safeguards including:
- Written Data Processing Agreements.
- Confidentiality Obligations.
- Technical Security Measures.
- Encryption where appropriate.
- Access Controls.
- Vendor Security Assessments.
- Contractual Security Commitments.
- Periodic Compliance Reviews.
These safeguards are intended to provide a level of protection appropriate to the nature of the personal information being processed.
12.7 Data Localization Requirements
Where applicable law requires certain categories of personal information to be stored or processed within a particular jurisdiction, the Company will take reasonable steps to comply with such legal requirements.
If future legal or regulatory requirements relating to data localization change, the Company may update its data handling practices accordingly.
12.8 Access from Multiple Countries
Authorized employees, contractors, or service providers located in different jurisdictions may access personal information where reasonably necessary to:
- Maintain Platform Operations.
- Provide Customer Support.
- Resolve Technical Issues.
- Detect Fraud.
- Respond to Security Incidents.
- Perform Compliance Functions.
- Maintain Business Continuity.
- Such access is generally subject to role-based access controls and confidentiality obligations.
12.9 International Cloud Storage
The Company may use internationally distributed cloud storage infrastructure to improve:
- Reliability.
- Availability.
- Performance.
- Disaster Recovery.
- Data Redundancy.
- Service Continuity.
Cloud providers are expected to maintain security measures consistent with applicable contractual obligations.
12.10 Security During International Transfers
The Company seeks to protect personal information transferred internationally through measures such as:
- Encryption during transmission where appropriate.
- Secure communication protocols.
- Authentication controls.
- Network security.
- Monitoring of unauthorized access.
- Audit logging.
- Vendor security requirements.
Despite these safeguards, no method of electronic transmission can be guaranteed to be completely secure.
12.11 Government Access Requests
Where a foreign government authority requests access to personal information held by the Company or its service providers, the Company will evaluate such requests in accordance with applicable law.
Unless prohibited by law, the Company may:
- Review the legal validity of the request.
- Seek to limit disclosure to what is legally required.
- Protect User privacy where reasonably possible.
- Notify affected Users where legally permitted and appropriate.
12.12 Business Continuity and Disaster Recovery
International infrastructure may be used to support:
- Backup Services.
- Disaster Recovery.
- Failover Systems.
- Infrastructure Redundancy.
- Service Availability.
- Business Continuity Planning.
- These systems help maintain Platform availability during technical failures or emergency situations.
12.13 Third-Party Responsibilities
Third-party service providers that process personal information on behalf of the Company are generally expected to:
- Process information only on documented instructions from the Company.
- Maintain appropriate security measures.
- Protect confidentiality.
- Assist with compliance obligations where applicable.
- Notify the Company of relevant security incidents in accordance with contractual terms.
The Company may periodically review such providers as part of its vendor management process.
12.14 Changes in International Processing
The Company may introduce new international service providers or modify existing infrastructure as technology and business needs evolve.
Material changes affecting the processing of personal information may be reflected through updates to this Privacy Policy or by providing additional notice where required by applicable law.
12.15 User Acknowledgement
By using the FinDeals Platform, Users acknowledge that personal information may be processed, stored, or accessed in jurisdictions outside their country, subject to the safeguards described in this Privacy Policy and applicable law.
- Nothing in this Section limits any rights available to Users under applicable law.
12.16 No Sale of Personal Information Through International Transfers
The Company does not transfer personal information internationally for the purpose of selling personal information to unrelated third parties.
International transfers occur only where reasonably necessary to:
- Operate the Platform.
- Provide requested services.
- Maintain security.
- Support business operations.
- Comply with legal obligations.
12.17 Periodic Review
The Company periodically reviews its international data processing practices to:
- Improve security.
- Evaluate vendor compliance.
- Reflect legal developments.
- Enhance operational resilience.
- Reduce privacy risks.
Policies and procedures relating to international transfers may be updated as business operations and legal requirements evolve.
12.18 Chapter Summary
This Chapter explains how SMARTAXIS PRIVATE LIMITED manages international transfers and cross-border processing of personal information. To operate the FinDeals Platform effectively, the Company may use global cloud infrastructure and trusted service providers located in different jurisdictions. Where such processing occurs, the Company seeks to implement appropriate contractual, technical, and organizational safeguards, comply with applicable legal requirements, and protect personal information throughout its lifecycle.
Chapter 13 — CHANGES TO THIS PRIVACY POLICY, CONTACT INFORMATION & GRIEVANCE REDRESSAL
13.1 Purpose
This Chapter explains how SMARTAXIS PRIVATE LIMITED may update this Privacy Policy, how Users will be informed of significant changes, and how Users may contact the Company regarding privacy-related matters, grievances, or complaints.
The Company is committed to maintaining transparency regarding its privacy practices and providing appropriate channels for Users to exercise their rights and seek assistance.
13.2 Policy Updates
The Company may revise, amend, modify, replace, or update this Privacy Policy from time to time to reflect:
- Changes in applicable laws.
- Regulatory requirements.
- Court decisions.
- Business operations.
- Platform features.
- Technology developments.
- Security practices.
- Industry standards.
- Corporate restructuring.
- Operational improvements.
The Company reserves the right to make such updates where reasonably necessary.
13.3 Effective Date
This Privacy Policy shall become effective on the date specified at the beginning of the Policy.
Unless otherwise stated, amendments become effective from the date they are published on the FinDeals Platform.
13.4 Version Control
To improve transparency, the Company may maintain:
- Privacy Policy Version Number.
- Effective Date.
- Last Updated Date.
- Summary of Material Changes.
- Historical versions may be retained for internal record-keeping and legal compliance.
13.5 Notification of Material Changes
Where required by applicable law or where the Company considers a change to be material, Users may be notified through one or more of the following:
- Email.
- SMS.
- WhatsApp.
- Push Notifications.
- In-App Notifications.
- Platform Announcements.
- Website Notices.
The method of notification may depend on the nature of the changes and the communication details available.
13.6 User Responsibility
Users are encouraged to review this Privacy Policy periodically to remain informed about the Company's privacy practices.
Continued use of the FinDeals Platform after the effective date of an updated Privacy Policy may constitute acceptance of the revised Policy, to the extent permitted by applicable law.
Where applicable law requires fresh consent for specific processing activities, the Company will obtain such consent before relying on the updated processing activity.
13.7 Relationship with Other Policies
This Privacy Policy should be read together with:
- Terms & Conditions.
- Cookie Policy.
- Refund & Cancellation Policy.
- Membership Policy.
- Credits Policy.
- Community Guidelines.
- Contact Unlock Policy.
- Grievance Policy.
- Any other applicable Platform policies.
In the event of a conflict, applicable law shall prevail. Otherwise, the relevant policy governing the specific subject matter shall apply.
13.8 Contact Information
Users may contact SMARTAXIS PRIVATE LIMITED regarding privacy-related matters using the official contact details published on the FinDeals Platform.
Official contact channels may include:
- Registered Office Address.
- Customer Support Email.
- Privacy Email Address.
- Customer Support Phone Number.
- Official Website Contact Form.
The Company may update its contact details from time to time without affecting the validity of this Privacy Policy.
13.9 Grievance Officer
The Company shall designate a Grievance Officer or other authorized officer as required by applicable law.
The published details may include:
- Name.
- Designation.
- Email Address.
- Postal Address.
- Contact Information.
The Grievance Officer shall handle privacy-related grievances and complaints in accordance with applicable law.
Publication Note: Before publishing this Privacy Policy, replace this placeholder with the actual details of the appointed Grievance Officer.
13.10 Privacy Requests
Users may submit requests relating to:
- Access to Personal Information.
- Correction of Information.
- Deletion Requests.
- Consent Withdrawal.
- Privacy Complaints.
- Security Concerns.
- Data Processing Enquiries.
The Company may require reasonable identity verification before processing such requests.
13.11 Complaint Resolution Process
Upon receiving a privacy complaint, the Company may:
- Acknowledge receipt.
- Verify the identity of the complainant where appropriate.
- Review the complaint.
- Conduct necessary investigations.
- Request additional information where required.
- Respond within the timeframe required by applicable law.
- Implement corrective measures where appropriate.
The Company seeks to resolve complaints fairly, promptly, and in accordance with applicable legal requirements.
13.12 Escalation
If a User is dissatisfied with the Company's response, the User may pursue any remedies available under applicable law, including approaching the appropriate regulatory authority, tribunal, or court having jurisdiction.
- Nothing in this Privacy Policy limits any statutory rights available to Users.
13.13 Compliance with Applicable Law
The Company seeks to comply with all applicable laws governing the processing of personal information, including, where applicable:
The Digital Personal Data Protection Act, 2023 (India).
The Information Technology Act, 2000.
- Rules and regulations issued under those Acts.
Other applicable Indian laws relating to privacy, cybersecurity, electronic records, and consumer protection.
- If applicable laws change, the Company may update this Privacy Policy accordingly.
13.14 Governing Law
This Privacy Policy shall be governed by and interpreted in accordance with the laws of India.
Any disputes relating to this Privacy Policy shall be resolved in accordance with the dispute resolution provisions contained in the FinDeals Terms & Conditions, unless otherwise required by applicable law.
13.15 Severability
If any provision of this Privacy Policy is determined by a court or competent authority to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect to the fullest extent permitted by law.
13.16 No Waiver
Failure by the Company to enforce any provision of this Privacy Policy shall not constitute a waiver of that provision or of any other rights available under applicable law.
13.17 Entire Privacy Policy
This Privacy Policy constitutes the complete statement of the Company's privacy practices relating to the FinDeals Platform and supersedes previous versions of this Privacy Policy.
This Privacy Policy does not replace the FinDeals Terms & Conditions, which continue to govern the contractual relationship between the Company and Users.
13.18 Survival
Any provisions of this Privacy Policy which, by their nature, are intended to survive termination of a User's Account shall continue to apply after Account closure, including provisions relating to:
- Data Retention.
- Legal Compliance.
- Fraud Prevention.
- Security.
- Dispute Resolution.
- Regulatory Obligations.
- Protection of Legal Rights.
13.19 Electronic Records
This Privacy Policy is published electronically and does not require a physical or digital signature to be legally effective, except where applicable law expressly requires otherwise.
The electronic version published by SMARTAXIS PRIVATE LIMITED shall be the official version.
13.20 Final Statement
SMARTAXIS PRIVATE LIMITED values the trust placed in it by Users of the FinDeals Platform.
The Company is committed to handling personal information responsibly, lawfully, fairly, and transparently while continuously improving its privacy, security, and governance practices.
Users are encouraged to contact the Company whenever they have questions or concerns regarding the processing of their personal information.
For questions about this document, contact us at contact@findeals.in or visit our Contact Us page.