Privacy Policy
Last updated August 2026 · Applies to users of Swacredit in India
1. Overview & Compliance Standard
Swacredit operates as a digital revolving credit platform committed to safeguarding client privacy while providing structured financial accessibility. This Privacy Policy sets forth our practices regarding the collection, handling, transmission, and preservation of personal details, strictly adhering to the Digital Personal Data Protection Act (DPDPA), 2023 of India and the Reserve Bank of India (RBI) Regulatory Framework for Digital Lending.
By downloading, accessing, or utilizing our services, you grant explicit consent to the data operations defined herein. To avoid leakage and misuse of this information, we transfer user data to the following secure endpoint: https://ce.swasakthiflexifund.com.
2. Purpose-Driven Data Collection & Protection Protocol
In alignment with data minimization standards, we capture only necessary information essential for risk evaluation, identity confirmation, fraud prevention, and regulatory compliance.
Phone Number (Mandatory)
Purpose of Collection: Needed to establish a unique user profile and authenticate account owner identity.
Usage Mechanism: To deliver One-Time Passwords (OTP), issue updates on revolving credit status, and secure account access.
Protection Measures: Encrypted during transmission via TLS 1.3 protocol and stored in physically segregated, access-controlled databases.
Email Address (Optional)
Purpose of Collection: Provided voluntarily to set up a secondary channel for account notifications.
Usage Mechanism: Used for transmitting monthly billing summaries, official statements, and system alerts.
Protection Measures: Protected using SHA-256 cryptographic hashing algorithms to prevent unauthorized access.
Camera & Image Data (Optional)
Purpose of Collection: Allows real-time document capture required for financial verification procedures.
Usage Mechanism: To capture Know Your Customer (KYC) documents and user photos for identity verification during underwriting.
Protection Measures: Hardware permission is prompted exclusively during active usage. Background camera access is strictly prohibited.
Emergency Contact Information (Mandatory)
Purpose of Collection: Required to construct a secondary identity validation framework and evaluate risk.
Usage Mechanism: Used to verify identity or reach out solely if the applicant becomes uncontactable regarding credit obligations or during fraud investigations.
Protection Measures: Encrypted and stored in restricted vaults. Contact details are never marketed or shared with third parties.
User ID, Device ID & Advertising ID (Optional)
Purpose of Collection: To recognize unique device environments and protect against account takeover risks.
Usage Mechanism: Aids in preventing multi-account fraud and optimizing application performance across hardware types.
Protection Measures: Anonymized and decoupled from real-world identification numbers in secondary database environments.
Coarse / Approximate Location (Optional)
Purpose of Collection: Ensures jurisdictional compliance with Indian regional lending rules.
Usage Mechanism: Verifies that credit requests originate within serviced geographic territories and flags unusual login locations.
Protection Measures: Converted into generalized regional codes without recording high-precision GPS coordinates.
Application Crash Logs (System)
Purpose of Collection: Needed to monitor system stability and diagnose software failures.
Usage Mechanism: Helps engineering teams debug application errors, minimize latency, and improve software reliability.
Protection Measures: Diagnostic data is completely scrubbed of personally identifiable information (PII) before storage.
Installed Applications Inventory (Security)
Purpose of Collection: To detect system-level fraud tools and unauthorized screen-sharing applications.
Usage Mechanism: Scans for malicious utilities or remote-access software that pose risks to credit line security.
Protection Measures: Evaluated through temporary local runtime execution without constructing permanent user software logs.
Comprehensive Device Information (Security)
Purpose of Collection: Storage status, battery information, Bluetooth state, hardware model, RAM usage, network status, and sensor data.
Usage Mechanism: Generates an anti-fraud device fingerprint to block automated bots, emulator usage, and device cloning attempts.
Protection Measures: Parameters are hashed into an irreversible checksum, ensuring raw telemetry is kept confidential.
SMS Permissions (Optional)
Purpose of Collection: To verify financial transactions and streamline credit risk assessments.
Usage Mechanism: Evaluates transactional SMS messages sent by financial institutions to gauge credit history; personal messages are filtered out.
Protection Measures: Scanned locally using automated parsing rules. Personal conversations are strictly ignored and never uploaded.
3. Data Retention, Security & User Rights
We implement 256-bit SSL encryption to safeguard all data transactions. In accordance with RBI guidelines, customer records and loan logs are retained for a minimum period of five (5) years following the termination of the credit agreement.
User Rights: Under the DPDPA 2023, you hold the right to access, rectify, or request deletion of your personal data. Deletion requests for non-statutory data will be fulfilled within 15 business days upon identity verification.
4. Contact & Support Details
Official Website: https://www.swasakthiflexifund.com
Privacy Policy URL: https://www.swasakthiflexifund.com/privacy-policy
Contact Email: business@swasakthiflexifund.com
Secure Data Endpoint: https://ce.swasakthiflexifund.com