Capital India Finance Limited – Privacy Policy

This Privacy Policy (“Policy”) explains how Capital India Finance Limited (“Capital India”, “CIFL”, “we”, “our”, or “us”) and our Lending Service Providers (LSPs), including Capital India Finance Pvt Ltd. and partners collect, use, disclose, store, and safeguard your information when you interact with our websites, apps, and services (collectively, the “Services”). 

1. Introduction

Capital India and its LSPs (such as Capital India Finance Pvt Ltd.) are committed to protecting the privacy and security of users accessing our digital platforms. This Privacy Policy applies to your use of the CIFL website, DLAs, and all services provided under our lending framework. 

2. Definitions

      • Personal Data: Information relating to an identifiable person, including name, address, phone number, Aadhaar, PAN, IP address, geolocation, etc.
      • Sensitive Personal Data: Financial credentials, passwords, biometric data — not collected. 
      • Borrower/User: A natural or legal person who accesses or uses CIFL’s Services. 

3. Scope

This Policy applies to data collected through: 

      • Capital India website: https://www.capitalindia.com
      • Lending platforms, DLAs, and LSPs including Capital India Finance
      • Any CIFL-managed or authorized system handling borrower data

4. Categories of Information Collected

    a. Voluntarily Provided Data

      • Name, gender, DOB
      • Contact details (email, phone, address)
      • PAN, Aadhaar, Passport, other KYC documents
      • Employment and income data
      • Bank account details

    b. Automatically Collected Data

      • Device ID, IP address, OS type
      • Browser type, session time, language
      • Cookies and location data (with consent)

    c. Data Collected by LSPs (e.g., Capital India Finance)

      • Transaction data (AEPS, POS, QR, etc.)
      • Merchant/business metadata
      • Device metadata and fraud risk flags

5. Purpose of Data Collection

      • KYC & AML verifications
      • Loan underwriting, disbursals & servicing
      • Security, fraud prevention & compliance
      • Account notifications and legal updates
      • Product enhancement and analytics 
      • Legal obligations and audit trail 

6. Granular Consent

We follow a granular opt-in model for collecting sensitive permissions: 

      • Third-party data sharing (Credit Bureau / RBI) as per necessity 

7. Right to Revoke, Delete, and Restrict

Customers may visit the Capital India Finance Website (https://capitalindia.com) and reach out to customer service team for any queries and concerns. 

8. Data Minimization

We and our LSPs: 

      • Collect only essential information
      • Do not store login credentials, OTPs, or biometric data
      • Minimize data retention to the loan lifecycle only 

9. Data Localization

      • All borrower data is stored within India
      • Our infrastructure complies with Indian data residency laws 

10. No Biometric Collection

We do not collect or store any biometric data

11. Data Retention & Destruction

      • Retained until loan closure = 7 years
      • Secure deletion via industry standards
      • Breach protocols follow CERT-In guidelines 

12. Disclosures to Third Parties

We may disclose data to: 

      • Credit Bureau(s) and RBI as per Necessity  

We do not sell or trade your personal information. 

13. Third-Party Tools & Cookies

    Cookies used for: 

      • Personalizing experience
      • Traffic monitoring
      • Improving load speed

Users may manage cookie preferences via browser settings. 

14. Grievance Redressal

Capital India Finance Ltd 
Grievance Officer: Mr. Mohit Gupta
Email: grievance@capitalindia.com
Address: 701, 7th Floor, Aggarwal Corporate Tower, Plot No. 23, District Centre,
Rajendra Place, New Delhi – 110008
Phone: +91-11-69146000

Our LSP Rapipay

Grievance Officer: Mr. Nripendra Pandey
Email: lendingofficer@rapipay.com
Address: A-8, 8th Floor (Q-Tower), Sector-68, Noida – 201309
Phone: +91-120-6366034

15. Security Measures

We use:

      • SSL encryption
      • Firewalls, access control
      • Role-based data access
      • Staff training on data privacy
      • Regular VAPT audits

However, we cannot guarantee absolute protection due to the inherent risks of the internet.

16. Promotional Communication

Opt-out options:

      • Emails: Click “Unsubscribe”
      • SMS: Reply with “STOP”
      • Calls: Inform the caller
      • App notifications: Adjust in app settings

Transactional and legally required alerts will still be sent.

17. Updates to This Policy

We may update this Policy periodically. The latest version is always available at:
https://www.capitalindia.com/privacy-policy

18. Governing Law & Dispute Resolution

      • Governed by Indian law
      • Jurisdiction: Courts in New Delhi