Privacy Policy
Information we collect
We collect information that helps us deliver, secure and improve the Services. This includes:
Account & identity information
- Name, email address, phone number, designation and organisation details
- Login credentials, authentication tokens and password hashes
- KYC documents where required by applicable financial regulations
Transactional & financial data
- EMI plan details, mandate references, repayment schedules and collection statuses
- Bank account references, UPI IDs and tokenised mandate identifiers — full card or account numbers are never stored in plaintext
- Borrower data uploaded by you as a customer of Emi Shield, processed strictly as a data processor on your behalf
Technical & usage data
- IP addresses, device identifiers, browser type, operating system, time zone and language settings
- Pages visited, features used, API call logs and timestamps
- Cookies and similar technologies — see Cookies & tracking below
Device data (for EMI Locker)
- For locker-enabled devices: device ID, OS version, network state and lock-status events needed to operate the EMI Locker feature
- We do not access photos, contacts, messages, location or other personal content on locked devices
How we use information
We use the data we collect to:
- Provide, operate and maintain the Services, including processing EMI mandates and collections
- Authenticate users, prevent fraud and secure the platform against unauthorised access
- Communicate with you about service updates, security notices, billing and support
- Generate aggregated, anonymised analytics to improve product performance
- Comply with legal, tax, audit and regulatory obligations under Indian law
Data security
We employ industry-standard safeguards to protect your information:
- AES-256 encryption at rest and TLS 1.3 in transit
- Tokenisation of mandate and payment instruments
- Role-based access control, SSO, and IP allow-listing
- SOC 2 / ISO 27001-aligned operational controls
- Continuous monitoring, intrusion detection and immutable audit logs
- Regular third-party penetration testing and vulnerability assessments
While we apply these measures rigorously, no system is completely impervious. If we ever discover a breach affecting your data, we'll notify affected parties and the relevant authorities within the timelines required by law.
Data retention
We retain personal data only as long as necessary for the purposes set out in this policy, or as required by law:
- Active account data is retained for the duration of your subscription
- Financial transaction records are retained for at least 8 years, as required by Indian tax and accounting regulations
- Audit logs are retained for 7 years for compliance purposes
- On account closure, data is anonymised or securely destroyed within 90 days, except where retention is mandated by law
Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete information
- Delete your data, subject to our legal retention obligations
- Restrict or object to certain types of processing
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with the relevant data protection authority
To exercise any of these rights, contact us at prince.mishra89@gmail.com. We respond within 30 days.
Cookies & tracking
We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the Services are used. You can manage cookies through your browser settings — disabling certain cookies may affect functionality.
Children's privacy
The Services are not directed to individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, contact us and we'll delete it promptly.
International data transfers
Emi Shield primarily stores data on servers located in India. Where data is transferred outside India for limited operational purposes — such as support tooling — we ensure equivalent safeguards through contractual measures.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or an in-app notice at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Grievance officer
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address your concerns:
OFSL Techno Solutions Pvt Ltd
3rd Floor , SIC Office , Dhawari Satna
CIN: U66190MP2024PTC069421 · GSTIN: 23AAECO2815Q1Z8
