Legal

Privacy Policy

CredLyf is a technology and distribution platform for Digital Partners. This policy explains what information we process, why we process it, and with whom it may be shared.

Version 2.0 · Effective 18 August 2026 · Last updated 18 August 2026

1. Scope and Operating Model

CredLyf operates a digital distribution and technology platform (the Platform) through which registered Digital Partners source and submit leads for financial products. CredLyf is not a bank, NBFC, insurer or investment adviser. Financial products are offered, underwritten, approved, priced and serviced solely by the respective banks, NBFCs, insurers, financial institutions and other product providers (each a Lender / Financial Institution).

There is no customer registration, customer login, customer account or customer dashboard on the Platform. A person whose details are submitted by a Digital Partner is a Prospective Customer / Applicant, not a registered Platform user.

2. Who Uses CredLyf

  • Digital Partners — the only external registered users of the Platform.
  • Authorised internal CredLyf users — Operations, Admin, Super Admin, Finance, Compliance, Support and other authorised employees or contractors, each with role-based access limited to what their function requires.
  • Prospective Customers / Applicants — individuals or entities whose information is submitted by a Digital Partner as a lead. They do not hold an account on the Platform.

3. Information We Process

From Digital Partners, we may process:

  • Name, mobile number and email address.
  • PAN and KYC information where applicable.
  • Business or professional information (entity type, GST details where provided, place of business, experience).
  • Bank and payment information required for commission and payout processing.
  • Documents submitted during partner KYC and onboarding.
  • Login and authentication information, including OTP verification records and session data.
  • Device and browser information such as IP address, device type, operating system and app version.
  • Platform usage information such as pages viewed, leads created, actions performed and support interactions.

For leads submitted by a Digital Partner, we may process:

  • Name of the prospective customer / applicant.
  • Mobile number and email address.
  • Professional details and employment type (salaried or self-employed).
  • Monthly income.
  • The financial product or requirement selected.
  • Any further information or documents voluntarily submitted by the Digital Partner or by the prospective customer in connection with the opportunity.

A lead is a prospective applicant record submitted by a Digital Partner. It does not create a CredLyf account for that person.

4. Purpose of Processing

  • Partner onboarding, eligibility checks and partner KYC.
  • Authentication, account security and access control.
  • Lead submission, lead management and de-duplication.
  • Processing financial-product opportunities and application tracking.
  • Communication with Digital Partners and, where required, with prospective customers regarding a submitted lead.
  • Coordination with banks, NBFCs and other financial institutions.
  • Commission calculation, partner payout processing and related financial records.
  • Fraud prevention, misuse detection, security monitoring and audit.
  • Support, grievance handling and dispute resolution.
  • Compliance with legal, regulatory, tax and record-keeping requirements.
  • Analytics and improvement of Platform features, reliability and user experience.

5. Sharing of Information

Lead information submitted by a Digital Partner may be shared with relevant banks, NBFCs, financial institutions, lending partners, insurance partners, banking partners and investment or other product partners, strictly where necessary to process the relevant financial-product opportunity and subject to applicable law and the applicable consent/authorisation requirements.

We may also share information with:

  • Service providers who support the Platform (cloud hosting, communication and messaging providers, e-sign/KYC verification providers, analytics and payout processors), under contractual confidentiality and security obligations.
  • Professional advisers, auditors and insurers, where reasonably required.
  • Government, regulatory, judicial or law-enforcement authorities where disclosure is required by law or legal process.
  • An acquirer or successor entity in the event of a merger, restructuring or business transfer, subject to this policy.

CredLyf does not sell personal information. CredLyf does not underwrite, sanction, price or disburse any financial product; those decisions rest solely with the relevant Lender / Financial Institution.

6. Data Security

  • Encryption of data in transit and encryption at rest for stored records and documents.
  • Role-based access control, so internal users can access only the data required for their role.
  • OTP-based authentication for partner access, with hashed one-time codes and session controls.
  • Time-limited signed URLs for document access instead of public document links.
  • Row-level database access policies, activity logging and audit trails for record changes.
  • Monitoring, alerting and periodic review of access rights and security configuration.

No system can be guaranteed absolutely secure. Digital Partners must keep their login credentials and OTPs confidential and notify us immediately of any suspected unauthorised access.

7. Data Retention

Information is retained for as long as reasonably necessary for:

  • Operation of the Platform and the ongoing partner relationship.
  • Lead and application processing and status tracking.
  • Commission, payout, tax and accounting records.
  • Legal, regulatory and audit obligations.
  • Dispute resolution, grievance handling and fraud prevention.

Where information is no longer required for these purposes, it is deleted or anonymised in line with our internal retention schedule.

8. Digital Partner Responsibility

A Digital Partner who submits another person’s information must have the appropriate authority and, where required, the consent of that person to share the information with CredLyf and its financial-institution partners for the purpose of the relevant financial-product opportunity.

A Digital Partner must not:

  • Submit false, fabricated, duplicate or fictitious information.
  • Submit leads without proper authority or consent.
  • Misuse, retain, resell or further share personal information obtained through the Platform.
  • Upload documents that are not required for the relevant opportunity.
  • Use the Platform for spam, unsolicited marketing or any fraudulent or unlawful activity.

Breach of these obligations may result in suspension or termination of the partner account and further action under applicable law. See the Partner Terms.

9. Your Privacy Choices

Subject to applicable Indian law, including the Information Technology Act, 2000 with the SPDI Rules, 2011 and the Digital Personal Data Protection Act, 2023 (as and when its provisions and rules come into force), you may write to us to:

  • Request access to the personal information we hold about you.
  • Request correction or updating of inaccurate or incomplete information.
  • Withdraw a consent you previously provided, where processing is based on consent.
  • Request erasure of information, where we are not required to retain it for legal, regulatory, contractual or dispute-resolution purposes.
  • Raise a grievance about how your information has been handled.

Where a request relates to a lead, we may need to verify your identity and may need to coordinate with the Digital Partner who submitted the lead or with the relevant financial institution. Requests are actioned within a reasonable period. Withdrawing consent may mean an opportunity can no longer be processed.

10. Cookies, Devices and Communications

The Platform uses cookies and similar technologies for authentication, session management, security and analytics. Mobile applications may request device permissions (such as camera or file access) solely to enable features like document upload; permissions can be managed in your device settings. Service communications relating to your partner account, leads and payouts are operational and cannot be opted out of while your account is active.

11. Changes to This Policy

We may update this policy to reflect changes in our services, technology or legal obligations. Revisions are published on this page with an updated version number and “Last Updated” date. Continued use of the Platform after publication constitutes acceptance of the revised policy.

12. Contact Us

Privacy queries: grievance@credlyf.com

General support: support@credlyf.com · info@credlyf.com

Office: Mumbai, Maharashtra, India

Registered entity details and, if applicable, statutory Data Protection Officer details to be confirmed by CredLyf legal and compliance.

To raise a formal complaint, use the Grievance Redressal process.

Document control

Version 2.0

Effective Date: 18 August 2026

Last Updated: 18 August 2026

Future revisions will be published on this page with an updated version number and “Last Updated” date. Continued use of the platform after such publication constitutes acceptance of the revised document.