1. Introduction
Fundifine (“Fundifine”, “we”, “us”, or “our”) operates a B2B Software-as-a-Service (SaaS) Customer Relationship Management (CRM) platform for loan Direct Selling Agents (DSAs) and their authorised staff. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our website, CRM platform, and related services.
This Privacy Policy should be read together with our Terms & Conditions. By accessing or using Fundifine, you acknowledge that you have read and understood this Privacy Policy.
Fundifine is not a bank, NBFC, or lender. We provide CRM and workflow tools. End loan applicants / borrowers do not create accounts or log into Fundifine directly.
2. Scope & Roles
This Privacy Policy applies to:
- DSA Staff, DSA Admin, and Super Admin users who access the Fundifine CRM;
- End applicants / borrowers whose personal data is entered into Fundifine by DSA users on their behalf for loan origination and processing;
- visitors to our website (including DSA registration and contact forms).
DSA organisations typically act as the primary point of contact for their applicants. Fundifine processes applicant data on behalf of DSA users to provide the CRM platform and related services. DSAs remain responsible for obtaining valid consent from applicants before entering or processing their data, as described in our Terms & Conditions.
3. Information We Collect
3.1 DSA user account information
When a DSA organisation or user registers for or uses Fundifine, we may collect:
- name, designation, and role (DSA Staff, DSA Admin, Super Admin);
- company / DSA organisation name and business details;
- work email address and mobile number;
- login credentials and authentication records;
- staff permissions, activity logs, and platform usage data.
3.2 Applicant / end-customer data
DSA users enter and manage applicant information on behalf of their customers. This may include:
- identity and KYC information (e.g. PAN, Aadhaar, date of birth);
- contact details (name, address, email, mobile number);
- employment, income, and financial information;
- loan application details, documents, and status history;
- lead and customer relationship records.
3.3 Credit bureau, ITR & third-party API data
Where authorised DSA users trigger paid third-party API services (such as credit bureau reports or Income Tax Return (ITR) data retrieval), we may process:
- applicant identifiers required for the API request;
- OTP-based consent records linked to the applicant’s registered mobile number;
- reports, scores, or data returned by the third-party vendor;
- API request metadata, timestamps, and transaction logs.
3.4 Website & communication data
When you visit our website or submit forms (e.g. DSA registration, demo requests, contact enquiries), we may collect information you provide voluntarily, such as company name, contact name, email, mobile number, and message content.
3.5 Technical & log data
We automatically collect certain technical information when you access our website or platform, including IP address, browser type, device information, access times, pages viewed, and error or security logs.
4. How We Use Information
We use personal data for the following purposes:
- providing, operating, and maintaining the Fundifine CRM platform;
- enabling DSA users to manage leads, applications, KYC workflows, and customer records;
- facilitating third-party API services (e.g. credit bureau and ITR retrieval) initiated by authorised DSA users for legitimate loan processing purposes;
- authenticating users, managing accounts, and enforcing access controls;
- responding to support requests, grievances, and platform communications;
- monitoring platform security, preventing fraud, and ensuring compliance;
- improving our services, troubleshooting, and generating aggregated analytics;
- complying with applicable legal and regulatory obligations.
Applicant data and bureau/ITR outputs are used solely for legitimate loan processing and related DSA operational purposes, and not for unrelated marketing, resale, or profiling outside those purposes.
5. Consent & Third-Party API Processing
Before retrieving credit bureau reports, ITR data, or similar regulated information, the Fundifine platform is designed to capture OTP-based consent from the applicant’s registered mobile number. Such retrieval is initiated by an authorised DSA user on behalf of the applicant — applicants do not log into Fundifine directly.
DSA users are responsible for ensuring that consent is valid, informed, and obtained before entering applicant data or triggering API requests. Fundifine relies on instructions and data provided by DSA users in good faith.
Third-party API vendors (e.g. credit bureau aggregators, ITR data providers) process data under their own privacy policies and technical controls. When an API call is made, necessary applicant data is transmitted to the relevant vendor to fulfil the request.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, including:
- providing the CRM and related services to DSA users;
- maintaining loan application and customer records as configured by the DSA organisation;
- meeting legal, regulatory, audit, and dispute-resolution requirements;
- preserving security logs and consent/API transaction records as needed.
Retention periods may vary depending on data type, DSA account settings, and applicable law. When data is no longer required, we take reasonable steps to delete, anonymise, or securely archive it.
8. Data Security
We implement administrative, technical, and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or misuse. These measures may include access controls, encryption in transit where applicable, secure hosting, activity logging, and role-based permissions.
No method of transmission or storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security. DSA users are responsible for safeguarding their login credentials and ensuring appropriate internal access controls within their organisation.
9. Your Rights & Choices
9.1 DSA platform users
Depending on applicable law, DSA users may have rights to access, correct, update, or request deletion of their account information, or to raise concerns about how their data is processed. Requests may be submitted using the contact details in Section 12.
9.2 End applicants / borrowers
Because applicants do not log into Fundifine directly, requests relating to applicant data should generally be directed to the relevant DSA organisation that entered or manages the data. Fundifine will assist DSAs and respond to lawful requests where applicable and permitted by law.
We may need to verify identity before processing certain requests and may decline requests that are unfounded, excessive, or prohibited by law.
11. Children’s Privacy
Fundifine is a B2B platform intended for business users and loan origination workflows. It is not directed at children under 18 years of age, and we do not knowingly collect personal data from children through the platform.
12. Grievance Officer & Contact
For privacy-related questions, complaints, or requests regarding this Privacy Policy or our data practices, contact:
Entity: Fundifine
Registered address: Office No. 702, Pride Classic, Sadhuvashvani Road, Rajkot, Near Patidar Chowk, Rajkot, PIN: 360005, India
Grievance Officer: Bhavin Baraiya
Email: info@shreejatechnology.com
Phone: +91 99999 88888
We will endeavour to acknowledge and address privacy grievances within a reasonable period consistent with applicable law.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Last updated” date. Material changes may also be communicated through the platform or by email where appropriate.
Continued use of Fundifine after changes become effective constitutes acceptance of the updated Privacy Policy.
14. Governing Law
This Privacy Policy is governed by the laws of India. Subject to applicable mandatory requirements, courts located in Rajkot, Gujarat, India shall have jurisdiction over disputes relating to this Privacy Policy.
This Privacy Policy is issued by Fundifine and applies to the Fundifine website and CRM platform. For platform use terms, see our Terms & Conditions.