Welcome to Credora Fintech Pvt Ltd (“Credora”, the “Company”, “we”, “us”, or “our”). The domain www.credorafin.com (the “Website”) is owned and operated by Credora, a company incorporated under the Companies Act, 2013 (CIN: U66190TN2025PTC181555; GST: 33AAMCC8358C1ZM), having its registered office at 1157, 17th Street, Anna Nagar West Extension, Padi, Chennai, Tamil Nadu 600050.
Credora Fintech is a loan structuring and financial advisory firm that helps businesses, traders, exporters, and professionals access funding by connecting them with a curated network of 70+ banks and Non-Banking Financial Companies (NBFCs). Credora is an advisory and placement intermediary; it is not a bank, NBFC, or direct lender, and does not itself sanction or disburse loans.
We respect the privacy of everyone who visits or uses the Website, our Contact Us and Referral Partner forms, and our customer/partner login portal (together, the “Credora Platforms”), and are committed to protecting personal information shared with us in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian laws.
Your use of the Credora Platforms signifies your acknowledgment and consent to this Privacy Policy. If you object to your information being collected, used, or shared as described herein, please do not submit your information through the Credora Platforms.
1Introduction
This Privacy Policy explains who we are, what personal information we collect, how we use it, with whom we share it, how long we keep it, and the rights you have over it. It applies to all visitors, inquirers, referral partners, and clients of the Credora Platforms, regardless of whether you proceed to engage our advisory services.
Credora is a financial advisory and loan-structuring intermediary. We do not sanction or disburse loans ourselves; we assess your funding requirement, structure your application, and present it to suitable banks and NBFCs in our network. This Policy describes how we handle your information across that journey.
This Privacy Policy does not create any contractual or other legal rights in favour of any visitor or user of the Credora Platforms beyond what is expressly stated herein. Capitalised terms used but not defined here have the meaning given to them in our Terms & Conditions.
2Information We Collect
We collect information in the following ways. The type of information depends on how you interact with the Credora Platforms and whether you choose to proceed with our advisory services.
2.1 Information You Provide Directly
Through our Contact Us / Inquiry form, you may provide your full name, business name, business type / industry, funding requirement (in ₹), phone number, email address, and a message describing your funding requirement. Through our Referral Partner registration, you may additionally provide your professional/business background and details of the business or individual you are referring. In our login portal, you may also provide account credentials and profile information.
2.2 Information Collected During an Advisory Engagement
We do not collect financial documents, bank statements, KYC documents, PAN, Aadhaar, or other sensitive personal data through the Website's public forms. Such information is requested only after an enquiry call, through secure offline or direct channels, and only once you choose to proceed with our advisory services. This may include:
- Identification information — name, address, contact details, PAN, signature, photograph
- Bank statements, financial statements, GST returns, and other documents relevant to assessing eligibility
- Credit bureau / CIBIL information, where you authorise us to review it
- Any other detail reasonably required to structure and present your funding requirement to lenders
2.3 Information We Collect Automatically (Usage Data)
When you browse the Website, certain non-identifying technical information is automatically recorded, including:
- IP address and approximate location (derived from IP, not precise device GPS)
- Browser type, operating system, and device type
- Pages visited, time spent on each page, and the date/time of your visit
- Referring website or campaign source (e.g. a Meta or Google advertisement)
This usage data helps us understand how visitors use the Website, improve its design, content, and performance, and measure our marketing campaigns. It does not, on its own, identify you personally.
2.4 Information We Receive From Referral Partners
If you have been referred to Credora by one of our Referral Partners (such as a chartered accountant, business consultant, or real estate agent), we may receive your name and contact details from that partner in order to reach out to you and assess your funding requirement. This information is then handled in the same manner as information you provide to us directly.
2.5 Information from Third-Party Tools
We may use, or in future integrate, third-party tools on the Website, including Google Analytics (usage analytics), Meta/Facebook Pixel (advertising and campaign measurement), WhatsApp Business API (customer communication), and Zoho CRM (lead and relationship management). These tools may independently collect information such as browsing behaviour, device identifiers, and interactions with our advertisements, subject to their own privacy policies.
3How We Use Your Information
We collect, retain, and use information only where we reasonably believe it helps us administer our business or provide our services to you. This includes:
- Responding to enquiries submitted through our forms and assessing your financial profile and funding requirement
- Processing and structuring your loan application, and presenting it to suitable banks/NBFCs in our network
- Operating and improving the customer/partner login portal and administering the Referral Partner program
- Communicating with you about service updates, application status, and (where permitted) promotional information about our services
- Investigating and resolving complaints, queries, or disputes
- Conducting research and analytics to improve our services, website, and marketing
- Complying with applicable law, regulation, or directions from a court, regulator, or government authority, including the Reserve Bank of India (RBI)
We do not use your personal information for any purpose that is incompatible with the purposes for which it was originally collected, without your consent.
5Data Security
We use commercially reasonable physical, managerial, and technical safeguards to protect your personal information, consistent with our information security practices. These safeguards are designed to guard against unauthorised access, alteration, disclosure, or destruction of your information.
5.1 Technical Safeguards
- Encryption of data in transit over public networks using HTTPS / TLS
- Role-based access controls — only authorised personnel with a legitimate business need can access personal information
- Secure, password-protected storage of enquiry and partner data in a local database with restricted access
- Regular internal reviews of our data handling practices
5.2 Organisational Safeguards
- Internal access reviews and confidentiality obligations for staff and service providers
- Documented procedures for handling and disposing of personal information once it is no longer required
- Awareness training for personnel involved in processing personal data
While we take reasonable steps to protect your information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, and any transmission of information to us is at your own risk. If a data breach occurs that is likely to cause you harm, we will notify you and the Data Protection Board in accordance with the DPDP Act, 2023.
6Data Retention
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, or as required to meet applicable legal, regulatory, accounting, or audit obligations — including any retention periods prescribed under RBI or other applicable regulatory guidelines.
- Website enquiry data: retained for the duration of the advisory engagement and a reasonable period thereafter for record-keeping
- Engagement / loan-application data: retained as required by applicable law and lender requirements, typically for the tenure of the loan plus a defined post-closure period
- Usage data: retained in aggregated, de-identified form for analytics, with raw logs retained only as long as needed for the purpose collected
- Referral partner data: retained for the duration of the partnership and a reasonable period thereafter for accounting and reward verification
Once the retention period expires, information is securely disposed of in accordance with our data-disposal procedures.
7Your Rights
Under the Digital Personal Data Protection Act, 2023, you have certain rights with respect to your personal data. To exercise any of these rights, please contact us using the details in Section 12. We will respond to verified requests within a reasonable period, not exceeding the timelines prescribed under the DPDP Act.
- Access — request a summary of the personal information we hold about you and the purposes for which it is processed
- Correction & Updating — request correction of inaccurate, incomplete, or outdated personal information
- Erasure — request deletion of your personal information, subject to legal or regulatory retention obligations
- Grievance Redressal — raise a complaint about how your personal data is processed, and receive a response within the prescribed timeframe
- Opt-out of Marketing — unsubscribe from promotional communications at any time; service-related communications necessary to process an ongoing enquiry or application may continue
- Withdrawal of Consent — withdraw any consent previously given for processing your personal data, where processing is based on consent
Please note that certain rights may be limited where compliance would conflict with applicable law, regulatory requirements, or the establishment, exercise, or defence of legal claims.
9Third-Party Links
The Website may contain links to third-party websites, including social media pages, partner platforms, and lender websites. This Privacy Policy does not extend to such third-party websites, and Credora is not responsible for their content or privacy practices. We encourage you to review the privacy policy of any linked website before sharing information with it.
10Children's Privacy
The Credora Platforms and our services are intended only for individuals who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If you believe a minor has provided personal information to us, please contact us using the details in Section 12 so that we can take appropriate action to delete such information.
11Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements (including amendments to the DPDP Act), or business operations. The updated Policy will be posted on this page with a revised “Last updated” date. Your continued use of the Credora Platforms after such changes constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.
Where we make material changes that affect your rights, we will provide a more prominent notice — such as on the Website homepage or via email, where we hold a valid email address — for a reasonable period before the changes take effect.
12Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal information, please contact our Data Protection Officer / Grievance Officer using the details below:
Credora Fintech Pvt Ltd
Email: admin@credora.in
Phone: +91 93448 99971
Registered Office: 1157, 17th Street, Anna Nagar West Extension, Padi, Chennai, Tamil Nadu 600050, India.
You can also reach out through our contact page. We will endeavour to acknowledge and resolve any grievance within 30 days of receipt.