Legal and regulatory information
Privacy Policy
This policy brings together everything about your personal data in one place: what we collect, the consents and permissions we ask for, who receives your data, how long it is kept, how our website uses cookies, and how to use your rights or complain.
- About this policy
- Words with a special meaning
- Who we are and the two roles we play
- The personal data we collect
- Why we use your data, and on what basis
- Consent and app permissions
- Who receives your data: service providers and sharing
- Where your data is stored
- How long we keep your data
- How we protect your data
- Your rights
- Children
- Cookies on our website
- Messages we send you, and marketing
- Personal data breaches
- Questions, complaints and escalation
- Common questions
- Changes to this policy
- Contact
1. About this policy
1.1 This policy explains how Rinncrest Financial Technologies Private Limited collects, uses, shares, stores and protects personal data through:
- (a) Rinn, our Android app (listed on Google Play as Rinn)
- (b) our website, rinncrest.in >, including the tools on it such as the eligibility checker and the;
- (c) the forms and email addresses we publish for support, complaints, partnerships, investor relations, press and careers; and
- (d) the account-deletion form at /delete-account.
1.2 We have written it to meet the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which are in force today, and the standard set by the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, whose main obligations apply from 13 May 2027. We have chosen to meet the DPDP standard now rather than wait. It also reflects the data and consent rules in the Reserve Bank of India (Digital Lending) Directions, 2025.
1.3 This policy and the lender's policy work together. For loan-related data, the lender's privacy policy is the governing notice, because the lender is the Data Fiduciary. This policy is written to agree with it, describes the same categories of recipient and the same complaint route, and explains our part. If the two ever appear to differ on a loan matter, the lender's policy governs and we will correct ours. You can read the Lender's privacy policy through the link on our Lending Partners page.
1.4 This policy does not replace your Key Fact Statement, loan agreement or the Terms of Use. It works alongside them.
1.5 You can ask for this policy in any of the languages listed in the Eighth Schedule to the Constitution of India by writing to support@rinncrest.in
2. Words with a special meaning
In this policy:
| Term | Meaning |
|---|---|
| Rinncrest, we, us, our | Rinncrest Financial Technologies Private Limited, CIN U62099WB2026PTC287520, registered office 2nd Floor, Flat-2, Shivalik, 42, Prince Anwar Shah Road, Tollygunge, Kolkata 700033, West Bengal, India, |
| Rinn or the app | The personal loan app operated by Rinncrest. |
| Lender | The RBI-regulated non-banking financial company (NBFC) or bank that sanctions and disburses your loan. The Lender for your loan is named in your Key Fact Statement and loan agreement, and all current lending partners are listed on our Lending Partners page. |
| Website | rinncrest.in and its pages, tools and forms. |
| You, your | The person the personal data is about. The DPDP Act calls you the Data Principal. |
| Personal data | Any data about you that can identify you, directly or with other information. |
| Sensitive personal data | The categories the SPDI Rules treat with extra care. For a loan, this mainly means financial information such as bank account details, and any biometric information. |
| Data Fiduciary | The organisation that decides why and how personal data is processed, and is accountable to you for it. |
| Data Processor | An organisation that processes personal data on behalf of a Data Fiduciary, only on its instructions. |
| Service provider | An outside organisation that processes personal data for us or for the lender under a written contract. Where it handles loan data, it acts as a sub-processor on the lender's instructions. |
| Processing | Anything done with personal data: collecting, recording, storing, using, sharing, deleting and so on. |
| Consent ledger | Our tamper-evident record of each consent you give or withdraw: the exact wording you saw, the time, and the action you took (section 6.16). |
| Deletion and anonymisation | What happens to data at the end of its retention period, as defined in sections 9.8 and 9.10. |
| Cookies | Small files and similar technologies that a website stores in or reads from your browser, as explained in section 13.2. |
| KFS | The Key Fact Statement the lender gives you before you accept a loan, showing the rate, APR, charges and total cost. |
| Credit information company | A company licensed by the Reserve Bank of India to hold credit records, also called a credit bureau. |
| DPDP Act and DPDP Rules | The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. |
| SPDI Rules | The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. |
| Digital Lending Directions | The Reserve Bank of India (Digital Lending) Directions, 2025. |
3. Who we are and the two roles we play
3.1 Rinncrest is a Lending Service Provider. We built and run Rinn, and we provide technology and operating services to the lender. We are not a lender. We do not decide who gets a loan, set interest rates or hold borrowers' money.
3.2 We are also the lender's authorised recovery agent for Rinn loans. If an EMI is missed, our own staff handle reminders, collections and recovery on the lender's instructions; the lender does not use any outside recovery agency for Rinn loans. In that work we remain the lender's Data Processor.
3.3 Because of this, we play two different roles depending on what you are doing :
| What you are doing | Who decides how your data is used (Data Fiduciary) | Our role | Who answers for it |
|---|---|---|---|
| Creating a Rinn account, applying for a loan, completing KYC, accepting a KFS and agreement, repaying, being contacted about a missed EMI, getting support for a loan, complaining about a loan | The Lender | Data Processor. We process your data only on the lender's documented instructions, under a written agreement that binds us to confidentiality and security obligations | The lender, with our help. You can still come to us first |
| Browsing the website, using the eligibility checker before you start an application, using the EMI or affordability calculators, sending us an enquiry, writing to us as a lending institution, investor, journalist or job applicant | Rinncrest | Data Fiduciary | Rinncrest, directly |
Pending confirmation: whether creating a Rinn account (mobile number and OTP) before any loan application begins is treated as lender (Data Fiduciary) data or Rinncrest data — this draft treats it as the lender's.
3.4 When the eligibility checker hands you over to Rinn. If you verify your mobile number on our eligibility checker and then start an application in Rinn, the data you give from that point is collected for the lender. The data you entered on the website remains ours and is kept only as long as section 9.6 allows.
3.5 Outsourcing any part of the loan journey to us, including recovery, does not reduce the lender's responsibility to you or to the regulator.
4. The personal data we collect
We collect only what is needed for the purpose we tell you about. We do not ask for data "just in case".
4.1 If you apply for or hold a loan through Rinn
| Category | What it includes | Where it comes from | Required? |
|---|---|---|---|
| Identity and contact | Name, mobile number, email address, date of birth, address | You | Yes |
| Statutory identifiers | PAN, and your Aadhaar number in masked form only (for example, XXXXXXXX1234). Your customer record never holds your full 12-digit Aadhaar number. The Aadhaar and PAN documents fetched from DigiLocker are stored encrypted Pending confirmation: whether the stored DigiLocker e-Aadhaar contains the full Aadhaar number, and if it does, that it is held in an Aadhaar Data Vault as UIDAI requires. | The Central KYC Records Registry (CKYC), run by CERSAI, which we search first; if you have no CKYC record, your DigiLocker account, after you approve the request in DigiLocker; PAN verification | Yes |
| KYC selfie and liveness check | A live photo taken through the camera, checked for liveness and matched against the photo in your KYC record, to confirm that you are the person on the documents | You, through the app camera | Yes |
| Employment and income | Employer name, employment type, monthly income, and documents you choose to upload, such as a salary slip or bank statement | You | Yes |
| Bank account | Account number, IFSC and account-holder name, for disbursal and repayment, and the result of the account verification | You; bank-account verification services | Yes |
| Repayment mandate | UPI AutoPay mandate details, mandate status, and related repayment information | You; the payment and mandate providers | Yes, for a disbursed loan |
| Credit information | Your credit report and score, obtained only after your separate, explicit consent | Credit information companies, through the lender | Yes, to be assessed |
| Loan records | Application, decision, KFS, loan agreement, schedule, payments, statements, closure and NOC records | The lender and our systems | Yes |
| Location | Your device location, captured once, when you submit your application, to check serviceability and help prevent fraud | Your device, with your permission | Yes, at application |
| Support and complaints | Messages, call notes and recordings where you are told a call is recorded, complaint details | You | When you contact us |
| WhatsApp messages | Your mobile number, WhatsApp profile name, the messages you send and receive, any photos, videos, documents or voice notes you send us, and delivery and read status | You, through WhatsApp; Meta's WhatsApp Business Platform (Cloud API) | Only if you message us on WhatsApp or agree to WhatsApp updates |
| Consent and audit records | Each consent you gave or withdrew, the wording you saw, timestamps, IP address, device or browser type | Our systems | Yes, required by law |
| Communication preferences | Your choices about service channels and optional marketing | You | Marketing is optional |
4.2 If you use our website, tools or contact us
| Category | What it includes | Where it comes from | Required? |
|---|---|---|---|
| Eligibility checker | Mobile number, one-time password verification result, and any details you choose to enter in the checker Pending confirmation: exact fields collected by the eligibility checker — e.g. employment type, monthly income, PIN code.. No credit check is made | You | Mobile number only |
| Enquiries and support | Name, email, phone, your message | You | As marked on the form |
| Lending institutions and partners | Name, job title, organisation, work email and phone, details of what you want to discuss | You | As marked on the form |
| Investors, press, careers | Name, contact details, organisation or publication, your message; for job applicants, your CV and the information in it | You | As marked on the form |
| Deletion requests | Mobile number, email, the option you choose, your reason if you give one, the verification result | You | Yes, to verify the request |
| Website technical data | IP address, browser and device type, pages viewed, time of visit, and security logs | Your browser; strictly necessary cookies | Yes, to run the site securely |
| Analytics | How the website is used, in aggregated form | Analytics cookies (section 13) | No |
4.3 What we do not collect
4.3.1 Rinn does not access your contacts, SMS, call logs, photo gallery or media library, the list of apps installed on your phone, a device fingerprint, or your location continuously or in the background. Section 6.5 lists each of these in plain words.
4.3.2 We do not store biometric data such as fingerprints or face templates. The KYC selfie is a photograph used to verify your identity; it is not converted into a stored biometric template Pending confirmation: that Decentro, which runs the face match and liveness check, returns only a result and does not retain a face template..
4.3.3 We do not ask for your religion, caste, health information, sexual orientation or political views, and we do not use them in any way.
5. Why we use your data, and on what basis
5.1 Indian data-protection law allows personal data to be processed on a small number of grounds. The ones that apply here are:
- Consent — you have said yes, clearly and specifically, after seeing a notice (section 6 explains how we ask);
- Legitimate uses allowed by the DPDP Act — mainly where you have voluntarily given data for a specific purpose and have not said you object, and where processing is needed to comply with a law, a court order or a regulator; and
- Legal obligation — where a law requires the data to be kept or reported, such as the KYC and anti-money-laundering rules.
Under the SPDI Rules, sensitive personal data is collected only with your consent, given in writing (electronically), for the stated purpose.
5.2 Loan-related purposes (the lender is the Data Fiduciary; we act on its instructions)
| Purpose | Data used | Basis |
|---|---|---|
| Verify your identity (KYC) and check you are eligible | Identity, statutory identifiers, KYC selfie, employment and income | Consent; legal obligation (KYC and anti-money-laundering rules) |
| Assess your application. The lender makes the credit decision under its own credit policy; Rinncrest does not | Credit information, income, employment, bank account verification, location check | Consent, including a separate consent for the credit-bureau enquiry |
| Prevent and detect fraud and identity misuse, and screen applicants against sanctions lists, such as the UN Security Council Consolidated Sanctions List, as anti-money-laundering rules require | Identity, location captured at application, technical audit data | Consent; legal obligation |
| Prepare and show your KFS, loan agreement and sanction | Identity, loan details | Consent; legal obligation (KFS rules) |
| Disburse the loan and collect EMIs into the lender's account | Bank account, mandate details | Consent; performance of the loan you asked for |
| Service the loan: statements, schedules, reminders, closure and NOC | Contact details, loan records | Consent |
| Answer your questions and complaints | Contact details, support records, loan records | Consent; legal obligation (grievance-redressal rules) |
| Report your loan to credit information companies and to regulators where required | Identity, loan records | Legal obligation |
| If an EMI is missed, contact you to recover the amount due, in line with the lender's Fair Practices Code. Rinncrest does this with its own staff as the lender's authorised recovery agent | Contact details, loan records | Consent given at application; legal and contractual rights of the lender |
| Keep records for audit, inspection and legal claims | Loan records, consent ledger, audit trail | Legal obligation |
5.3 Purposes where Rinncrest is the Data Fiduciary
| Purpose | Data used | Basis |
|---|---|---|
| Run the eligibility checker and verify your mobile number | Mobile number, OTP result, details you enter | Consent (a separate, unticked checkbox before we send the OTP) |
| Answer enquiries and support messages sent through the website | Contact details, message | Legitimate use: you gave the data for this purpose |
| Discuss partnerships, investor relations and press requests | Business contact details, message | Legitimate use: you gave the data for this purpose |
| Consider a job application | CV and contact details | Consent |
| Process an account-deletion request and prove we did | Deletion-request data | Legal obligation; legitimate use |
| Keep the website secure and working | Technical data, strictly necessary cookies, security logs | Legitimate use; legal obligation (cyber-security reporting rules) |
| Understand how the website is used and improve it | Analytics data | Legitimate use; you can opt out (section 13) |
| Send you marketing about Rinn | Name, mobile number, email | Separate, optional consent Pending confirmation: whether marketing to Rinn users is carried out by Rinncrest as Data Fiduciary or on the lender's instructions. |
5.4 No other purposes. We do not use your data for any purpose unrelated to the ones above without first telling you and, where required, asking again. We do not use your credit information, or any data collected to assess your loan, for marketing or advertising, and we do not build advertising profiles of you. Section 7.5 sets out the other things we never do with your data.
6. Consent and app permissions
This section sets out every consent and phone permission Rinn asks for, the consents our website asks for, what happens if you say no, and how to withdraw each one.
Who you are consenting to, and how we ask
6.1 Who you are consenting to. Consents you give in Rinn for your loan are given to the Lender, which is the Data Fiduciary for loan-related data. Rinncrest collects and records them on the lender's behalf as its Data Processor. Consents you give on our website, such as for the eligibility checker, are given to Rinncrest.
6.2 How we ask. Every consent request is preceded by a short notice that tells you, in plain language:
- (a) exactly which data will be collected;
- (b) what it will be used for;
- (c) how long it will be kept;
- (d) how to withdraw the consent and use your other rights; and
- (e) how to make a complaint, including to the Data Protection Board of India.
You then give consent by a clear action: tapping a button that says what it does, or ticking an unticked box. We never use pre-ticked boxes. Scrolling, continuing to use the app or staying silent is never treated as consent. These rules follow the consent requirements of the Digital Lending Directions, the DPDP Act and Rules, and the SPDI Rules.
6.3 One purpose, one consent. Where purposes are different, the requests are separate. In particular, the credit-bureau enquiry, optional marketing, and keeping your data after a rejected application for future offers each have their own request. You will never be asked to accept marketing, or to let us keep your data for future offers, as a condition of applying. Saying no to an optional consent never affects your loan application.
Phone permissions
6.4 Permissions Rinn uses. Rinn asks for a permission only at the moment it is needed and tells you why first. You can refuse; the table explains what happens if you do.
| Permission | When Rinn asks | What it is used for | What Rinn does not do | If you say no |
|---|---|---|---|---|
| Location | Once, when you submit your loan application | To check the lender serves your area and to help prevent fraud Pending confirmation: that the app requests approximate location only (ACCESS_COARSE_LOCATION); Google Play does not allow personal-loan apps to request precise location. | Does not track you, does not run in the background, does not capture location again after submission | The application cannot be submitted |
| Camera | During KYC | Your KYC selfie and liveness check | Is not used for anything else, and does not access photos already on your phone | KYC cannot be completed, so the application cannot continue |
| File picker | When the lender needs a document, such as a bank statement | You choose a single file; Rinn receives only that file | Does not browse, read or upload anything else from your storage | You cannot upload that document. The app tells you if another option exists |
| Notifications | After you sign in | Updates on your application, EMIs and messages from the lender Pending confirmation: whether the app requests notification permission. | Is not used for advertising unless you have separately agreed to marketing | You still see updates in the app and by SMS and email |
| One-time password autofill | When you sign in | Android can offer to fill in the OTP from a single message you approve using Android's SMS Retriever API, which passes Rinn only the one message that carries its OTP Pending confirmation: that the Android manifest declares no READ_SMS or RECEIVE_SMS permission. | Does not give Rinn access to your inbox | You type the OTP yourself |
Pending confirmation: and that the Android manifest contains no permission beyond those listed here.
6.5 Permissions Rinn never asks for. Rinn does not access:
| Not accessed | In plain words |
|---|---|
| Contacts | Rinn cannot see your phonebook and will never contact your friends, family or colleagues from it |
| SMS | Rinn cannot read your text messages. If Android offers to fill in an OTP for you, you approve that one message; Rinn does not get your inbox Pending confirmation: that the Android manifest declares no READ_SMS or RECEIVE_SMS permission; OTP autofill uses the SMS Retriever API. |
| Call logs | Rinn cannot see who you call or who calls you |
| Photo gallery and media | Rinn cannot see your photos or videos; only the single file you choose |
| Installed apps | Rinn cannot see which other apps you have |
| Background or continuous location | Location is captured once, at application, and never again in the background |
| Device fingerprinting | Rinn does not build a device fingerprint or persistent identifier to profile you |
| Microphone | Not requested today. If the lender ever introduces video-based KYC, Rinn will ask separately, explain why, and this policy will be updated first Pending confirmation: microphone not requested — F-84 is silent on microphone. |
6.6 Changing a permission. You can review or turn off any permission at any time in your phone's settings (Settings → Apps → Rinn → Permissions) Pending confirmation (F-84).. Turning off location or camera after you have finished KYC and submitted your application does not affect a loan already in progress.
Every consent Rinn asks for
6.7 The table follows the order in which you will meet each consent. "Required" means the step cannot continue without it; "optional" means you can say no and carry on exactly as before.
| # | Consent | When | Why it is needed | Required? | If you decline |
|---|---|---|---|---|---|
| 1 | Terms of Use and privacy notice | When you create your Rinn account with your mobile number and OTP | To create and secure your account and record that you have seen how your data is handled | Required | You cannot create an account |
| 2 | Processing your data for a loan application | When you start an application | To collect and use your identity, contact, employment, income and bank details to verify you and let the lender assess your application, and to service and recover the loan if one is disbursed | Required | You cannot apply |
| 3 | KYC verification | During KYC | To search the Central KYC Records Registry (CKYC) for your KYC record and download it; if you have none, to fetch your Aadhaar and PAN from your DigiLocker account, which you approve in DigiLocker; and to verify your PAN. Rinn does not use Aadhaar OTP or biometric e-KYC, or offline Aadhaar XML | Required | KYC cannot be completed |
| 4 | KYC selfie and liveness check | During KYC | To confirm you are the person named in the documents | Required | KYC cannot be completed |
| 5 | Credit-bureau enquiry | Before the lender checks your credit record. Always a separate consent | To let the lender obtain your credit report from Experian, a credit information company | Required for a decision | The lender may be unable to assess your application |
| 6 | Bank-account verification | When you add your bank account | To confirm the account is in your name before money is sent to it | Required | The loan cannot be disbursed |
| 7 | Repayment mandate | After you accept the KFS and agreement | To set up e-NACH or UPI AutoPay so EMIs are collected into the lender's account | Required for disbursal | The loan cannot be disbursed |
| 8 | WhatsApp messages | When you choose your message channels | To receive service updates on WhatsApp as well as SMS and email. | Optional | You receive updates by SMS, email and in the app |
| 9 | Keep my data after a rejected application | Only if your application is not approved | To keep your application data so you can be considered for a future offer without starting again | Optional | Your application data is deleted within 30 days of the decision (section 9.3) |
| 10 | Marketing | Shown separately, never as part of the application | To tell you about new features or offers on Rinn | Optional | Nothing changes for your application or loan |
6.8 Accepting the KFS and loan agreement is not a data consent; it is you entering into the loan contract with the lender. Rinn records it, with the time and the version you saw, in the same way.
6.9 Rinncrest does not make the credit decision. Consents 2 to 6 let the lender decide under its own credit policy. Giving them does not guarantee a loan.
Consents on our website
6.10 Where Rinncrest is the Data Fiduciary, our website asks for these consents:
| Consent | Where | Why | Required? | If you decline |
|---|---|---|---|---|
| Eligibility checker | Before we send an OTP to your mobile number | To verify your number and pass you to Rinn to continue. No credit check is made | Required to use the checker | You can download Rinn and start there instead |
| Job applications | Careers form or email | To consider your application | Required to apply | We cannot consider the application |
| Keep my CV for future roles | Careers form | To contact you about future roles | Optional | Your CV is kept only for the period in section 9.6 and then deleted Pending confirmation: careers retention period. |
Withdrawing a consent
6.11 Ways to withdraw. You can withdraw any consent at any time, and it is as easy as giving it:
- In Rinn: Settings → Privacy and consents Pending confirmation: in-app consent screen exists and its menu path.;
- By email: support@rinncrest.in Pending confirmation (F-59)., from your registered email address or quoting your registered mobile number;
- Marketing: the unsubscribe link in any email, or reply STOP to any SMS or WhatsApp message;
- Phone permissions: your phone's settings (section 6.6);
- Website analytics: your browser's cookie settings, or Google's opt-out add-on (section 13).
6.12 What happens when you withdraw each consent. Numbers refer to the table in section 6.7.
| Consent withdrawn | Before a loan is disbursed | While a loan is outstanding | After the loan is closed |
|---|---|---|---|
| Processing for a loan application (2), KYC (3, 4) | Your application stops. Data is deleted unless a law requires it to be kept | Withdrawal does not cancel the loan or your duty to repay. The lender continues the processing it needs to service the loan, meet its legal obligations, report to credit information companies and recover amounts due | Processing stops except for records the law requires to be kept |
| Credit-bureau enquiry (5) | The lender may be unable to assess you, and the application may close | No new enquiry is made on the basis of that consent. Reporting the loan to credit information companies continues, because it is the lender's legal obligation | No new enquiry is made |
| Repayment mandate (7) | Not applicable | Cancelling a mandate does not cancel your EMIs. You must pay each EMI to the lender by another method shown in the app before the due date. A missed payment has the consequences set out in your KFS | Mandates end automatically on closure Pending confirmation: mandate auto-revocation on closure. |
| WhatsApp (8) | Messages switch to SMS and email | Messages switch to SMS and email | — |
| Keep my data after rejection (9) | Data is deleted within 30 days of your withdrawal | — | — |
| Marketing (10) | Marketing stops within 2 working days Pending confirmation: opt-out turnaround. | Same. Service messages about your loan continue | Same |
6.13 What withdrawal does and does not do. Withdrawal stops further processing for that purpose from the time it takes effect. It does not make earlier processing unlawful. Data tied to a legal retention duty is kept only for as long as that duty lasts and is then deleted or anonymised (section 9). We act on a withdrawal within Pending confirmation: consent-withdrawal turnaround — proposed 2 working days. of receiving it and confirm by SMS or email when it is done.
6.14 If you want your data deleted, rather than only stopping a consent, use the account-deletion form.
The consent ledger
6.15 Every consent you give or withdraw is recorded. Each entry holds:
- the consent type and the exact wording and version you were shown;
- what you did (accepted, declined or withdrew);
- the date and time;
- your IP address and device or browser type; and
- the channel (app, website, email).
6.16 The consent ledger is tamper-evident: entries cannot be altered or deleted once written. It exists so that you, the lender and a regulator can see exactly what you agreed to, and when.
6.17 It is kept for the life of your relationship with the lender plus 8 years, as the lender's retention schedule requires, and then deleted Pending confirmation (F-86).. This applies even after other data is deleted, because it is the proof that your data was handled lawfully.
6.18 You can ask for a copy of your consent history at support@rinncrest.in. We will send it within 30 days Pending confirmation: consent-history export turnaround..
Consent Managers
6.19 The DPDP Act allows you to give, manage, review and withdraw consent through a Consent Manager registered with the Data Protection Board of India. Registration of Consent Managers is scheduled to open on 13 November 2026 Pending confirmation: DPDP Rules phased commencement date for Consent Manager registration.. Once registered Consent Managers are operating, we will update this policy to explain whether, and how, you can use one with Rinn and Rinncrest.
7. Who receives your data: service providers and sharing
7.1 We share personal data only with the categories of organisation in section 7.4, only what each one needs, and only for the purposes in section 5. Sharing is limited to what is strictly needed for the lending process, as the Digital Lending Directions require. These are the same categories of recipient that the lender's privacy policy describes.
7.2 For loan-related data, Rinncrest acts as a Data Processor for the lender, and the providers below that handle loan data act as sub-processors on the lender's instructions. For data where Rinncrest is the Data Fiduciary, such as website enquiries, the providers act on our instructions.
The safeguards every provider must meet
7.3 Every service provider that handles personal data for us or for the lender must, under a written contract:
- (a) process it only on documented instructions and only for the stated purpose;
- (b) keep it confidential, and limit access to staff who need it and are bound by confidentiality;
- (c) protect it with security at least as strong as this policy describes, including encryption in transit and at rest;
- (d) store and process it in India, and if any processing happens outside India incidentally, delete it there and bring it back within 24 hours;
- (e) not pass it to anyone else without prior written approval, and impose the same terms on anyone it does use;
- (f) tell us about any personal data breach without delay Pending confirmation: contractual breach-notification window for vendors — proposed within 6 hours of discovery.;
- (g) help us and the lender respond to your rights requests;
- (h) delete or return the data when the service ends, and confirm in writing that it has done so; and
- (i) allow audits by us, the lender and regulators, including the Reserve Bank of India.
Who receives personal data
7.4 The table lists every category of recipient, with named organisations where we can name them.
| Category | Who | Purpose | Personal data shared | Where processed | Additional safeguards |
|---|---|---|---|---|---|
| The Lender | The RBI-regulated NBFC or bank that sanctions and disburses your loan (named in your Key Fact Statement) | Credit decision, loan agreement, disbursal, servicing, regulatory reporting, grievance redressal. It is the Data Fiduciary for loan data | All loan-related data in section 4.1 | India | Written LSP agreement; regulated by the Reserve Bank of India |
| Credit information companies | Experian, for the credit report obtained during your application. Loans are reported to TransUnion CIBIL, Experian, Equifax and CRIF High Mark, as the law requires | Credit report, after your separate consent; reporting of loan performance as the law requires | Name, date of birth, PAN, contact and address details, loan details and repayment history | India | Licensed by the Reserve Bank of India; credit information regulations govern use |
| KYC and identity verification | Decentro (PAN verification, DigiLocker retrieval of your Aadhaar and PAN, face match and liveness check); the Central KYC Records Registry run by CERSAI, which we query directly to search for and download your KYC record | Find your KYC record; where there is none, fetch your Aadhaar and PAN from DigiLocker; verify your PAN; match your selfie to your KYC photo and check liveness | PAN, name, date of birth, address, KYC selfie, masked Aadhaar number and the documents returned by DigiLocker or CKYC | CERSAI: India. Decentro: Pending confirmation: Decentro processing location. | CKYC records are fetched under the Prevention of Money-laundering (Maintenance of Records) Rules; DigiLocker documents are fetched only after you approve the request in DigiLocker; no biometric template retained |
| Bank-account verification | Decentro (bank-account verification, including reverse penny drop) | Confirm the bank account is in your name before disbursal | Account number, IFSC, name | Pending confirmation: Decentro processing location. | — |
| Payments and repayment mandates | Razorpay (loan repayment checkout and disbursal payouts) and Decentro (UPI AutoPay mandates), and the banks and payment systems they use Pending confirmation: e-NACH mandate provider, if e-NACH is offered. | Disburse loans to your account; collect EMIs into the lender's account through e-NACH or UPI AutoPay | Name, bank account, mandate details, amounts and dates | Pending confirmation: Razorpay and Decentro processing locations. | Regulated by the Reserve Bank of India and the rules of the payment systems used. Money always flows to accounts in the lender's name, never through Rinncrest |
| Digital signing | Awaiting details: SDK and vendor list — e-sign or click-wrap provider, if any. | Execute the loan agreement electronically | Name, mobile number, signing record | Awaiting details: SDK and vendor list. | — |
| Communications | 2Factor.in (SMS OTPs); our transactional email provider Awaiting details: name of the transactional email provider.; for WhatsApp, Meta Platforms, Inc. through the WhatsApp Business Platform (Cloud API) | Send OTPs, service messages and in-app notifications, WhatsApp messages where you have agreed (consent 8), and marketing only with your consent | Mobile number, email, message content | Pending confirmation: 2Factor.in and email provider processing locations. | SMS sent through registered sender IDs and templates; no use for the provider's own purposes |
| Maps and address lookup | Google Maps Platform (address and PIN-code geocoding); Ola Maps (address and location lookup); OpenStreetMap Nominatim (location lookup in the app) | Turn your address or PIN code into a map location, and look up your area from the location captured at application | Address, PIN code and location coordinates Pending confirmation: that no name or contact details are sent with them. | Google: processed by Google, may be outside India. Ola Maps: Pending confirmation: Ola Maps processing location.. Nominatim: OpenStreetMap Foundation servers, outside India | — |
| Cloud hosting | Amazon Web Services (AWS) | Host Rinn, our systems and the website | All data we hold, encrypted | India — Mumbai (ap-south-1) Pending confirmation: including backups, logs and CDN. | Encryption at rest and in transit; access restricted to our authorised staff |
| App analytics and crash reporting | Google, through Firebase Crashlytics (crash reports) and Google Analytics for Firebase (app usage) | Keep the app stable and understand app performance | Crash reports, device model, operating-system and app version, a Firebase installation identifier, and in-app events such as screens viewed Pending confirmation: that Google Analytics for Firebase is configured with Advertising ID collection and ad personalisation turned off. | Processed by Google; may be outside India | No advertising use; no access to contacts, SMS, media or installed apps |
| Website analytics | Google Analytics 4 (Google) | Understand how the website is used | Pseudonymous identifier, pages viewed, device and browser type, approximate region | Processed by Google; may be outside India | IP truncation or equivalent; no advertising features; see section 13 |
| Customer support tools | Awaiting details: SDK and vendor list — helpdesk, telephony and call-recording providers. | Record and answer your questions and complaints | Name, contact details, messages, call recordings where you are told a call is recorded | Awaiting details: SDK and vendor list. | Role-based access; retention as in section 9 |
| Website hosting, forms and security | Not yet published: website host, form handler, bot-protection and email-delivery providers. | Run the website, its forms and the account-deletion form securely | Form contents, IP address, security logs | Not yet published: website vendor locations. | Strictly necessary processing only |
| Recovery (Rinncrest itself) | Not outsourced. Rinncrest is the lender's authorised recovery agent for Rinn loans and does this work with its own staff, so no outside recovery agency receives your data | Contact you about overdue amounts, only after a missed EMI | Name, contact details, loan and overdue details | India | Bound by the lender's Fair Practices Code and the Reserve Bank of India's rules on recovery agents. See Recovery and collection practices |
| Auditors, legal advisers, certification bodies and insurers | Our statutory and internal auditors, legal advisers, insurers and our ISO certification body Awaiting details: ISO certificate details. | Audit our controls and accounts, take legal advice and maintain certifications | Only what each review needs | India | Professional confidentiality duties or written confidentiality terms |
| Regulators, courts and law enforcement | For example, the Reserve Bank of India, the Data Protection Board of India, CERT-In, the Financial Intelligence Unit-India, courts and police acting under lawful authority | Where the law requires disclosure | Only what the law or order requires | India | Disclosed only against a legal requirement, which we check before responding |
What we never do
7.5 We never:
- sell or rent personal data;
- share personal data with data brokers;
- use your credit information, or data collected to assess your loan, for marketing or advertising, or share it with anyone for their marketing;
- give any provider access to your contacts, SMS, call logs, photo gallery or installed apps, because Rinn does not access them; or
- let our recovery staff, or anyone else, contact your friends, family or colleagues using data from Rinn.
7.6 No other lender. We do not share your personal data with any other lender or financial institution unless you have asked for it through a feature that clearly says so. Today there is only one lender on Rinn.
7.7 Business changes. If Rinncrest is ever involved in a merger, acquisition or transfer of its business, personal data may pass to the new owner only under the same protections as this policy, and we will tell you before it does.
Other websites and services
7.8 Rinn and our website link to other services, such as the lender's website, Google Play, the RBI websites and, during your application, verification or payment pages run by regulated providers. Those services have their own privacy notices, which we encourage you to read. This policy does not cover sites we do not control. Where a provider works for us or for the lender as a processor inside the Rinn journey, it is bound by section 7.3 and listed in section 7.4.
Keeping this list up to date
7.9 We review this list at least every six months and whenever we appoint or change a provider Pending confirmation: review frequency.. Section 18.3 explains when we tell you about a change.
7.10 You can ask us for more detail about any provider that handles your data at support@rinncrest.in.
8. Where your data is stored
8.1 Rinn app and user account data is stored on servers located in India. Website analytics collected by Google Analytics is processed by Google and may be processed outside India.
8.2 If any processing ever takes place outside India incidentally, the data is deleted from the system outside India and brought back to India within 24 hours, as the Digital Lending Directions require.
8.3 We do not transfer personal data to any country or territory that the Government of India restricts under the DPDP Act.
8.4 WhatsApp. WhatsApp messages travel through Meta's WhatsApp Business Platform before they reach us, and WhatsApp's own terms and privacy policy apply to your use of WhatsApp. Once received, your WhatsApp messages and media are stored encrypted in our systems
9. How long we keep your data
9.1 The principle. The DPDP Act requires personal data to be erased once its purpose is served or consent is withdrawn, unless another law requires it to be kept. Lending is a regulated activity, and several laws do require certain records to be kept for set periods. We keep those records for those periods, restrict who can see them, and delete or anonymise them when the period ends. These periods are ceilings set by law, not entitlements. We do not keep personal data indefinitely.
9.2 Two schedules. For loan-related data, the lender is the Data Fiduciary, and its Board has approved the schedule in section 9.3, which we apply as its Data Processor. For data where Rinncrest is the Data Fiduciary, such as website enquiries, the schedule in section 9.6 applies.
Loan-related data (the lender's schedule)
9.3 The schedule below applies to every borrower and applicant Pending confirmation: retention schedule adopted from the Lender's Board-approved policy; counsel to confirm each row and its basis..
| Data | How long it is kept | Why (basis) | The clock starts |
|---|---|---|---|
| Raw credit-bureau report | 30 days, encrypted. During that time it may be used for a re-decision, a dispute or an audit. Then it is deleted. Only the credit decision and the score band are kept, as part of the loan or application record | Storage limitation: the full report is not needed once a decision is made | The date the report is obtained |
| KYC and identity records (PAN, masked Aadhaar number, DigiLocker and CKYC documents, KYC selfie, address details, KYC verification results) | 5 years | Prevention of Money-laundering Act, 2002 and the rules made under it, and the Reserve Bank of India's Master Direction on Know Your Customer | The date the loan is closed or the relationship with the lender ends, whichever is later |
| Loan and financial records (application, decision, KFS, loan agreement, sanction, disbursal, repayment schedule, payments, statements, mandate records, closure and NOC) | 8 years | Books-of-account retention under the Companies Act, 2013 | The date the loan is closed |
| Consent ledger and audit trail | For the life of the relationship, plus 8 years | Proof that data was collected and used lawfully, for audit, inspection and legal claims | The date the relationship with the lender ends |
| Data from a rejected application | Deleted within 30 days of the decision, unless you have separately agreed to it being kept for future offers (consent 9). If you agreed, it is kept until you withdraw that consent Pending confirmation: F-86 rule for rejected applications, and the maximum period data may be kept under a "future offers" consent. | The Digital Lending Directions and storage limitation | The date of the rejection decision |
| Data from an application you withdraw or abandon before a decision | Treated like a rejected application: deleted within 30 days Pending confirmation: treatment of withdrawn and abandoned applications, and after how many days of inactivity an application counts as abandoned. | Storage limitation | The date you withdraw, or the date the application is marked abandoned |
| Support and complaint records linked to a loan | For as long as the related loan record is kept | Grievance-redressal and audit requirements | As for the related loan record |
| Location captured at application | For as long as the related application or loan record is kept Pending confirmation: whether location is retained with the loan record or deleted sooner. | Fraud prevention and audit | As for the related record |
9.4 Records kept even for a rejected application. The consent ledger entries showing what you agreed to, and the fact and date of the decision, are kept under the consent-ledger row, even when the rest of your application data is deleted. They prove that your data was collected and deleted lawfully Pending confirmation: whether KYC records created for an applicant who is later rejected fall under the 30-day rule or the 5-year KYC rule — counsel to reconcile..
9.5 When is a loan "closed"? A loan is closed when the lender's records show nothing more is payable on it and the account has been closed in its books, for example after full repayment, foreclosure or exit during the cooling-off period. See Closing your loan and getting your NOC.
Data where Rinncrest is the Data Fiduciary
9.6 Pending confirmation: retention periods for Rinncrest's own data — proposed in this draft; not part of F-86.
| Data | How long it is kept | Why | The clock starts |
|---|---|---|---|
| Eligibility checker (mobile number, OTP result, details you entered) when you do not go on to apply in Rinn | 30 days | Only needed to verify your number and hand you over to Rinn | The date you used the checker |
| Website enquiries and support messages | 2 years | To answer you and handle any follow-up | The date of our last reply |
| Photos, videos, documents and voice notes you send us on WhatsApp | 30 days, then deleted automatically | Only needed to deal with your message | The day you send it |
| Lending-institution, partnership and investor correspondence | For the duration of the discussion, then 3 years | Business records and follow-up | The date the discussion ends |
| Press enquiries | 2 years | Follow-up | The date of our last reply |
| Job applications | Until the role is filled or closed, then 6 months; longer only if you agree to be considered for future roles | To consider your application and answer any query about the decision | The date the role is filled or closed |
| Account-deletion requests (request details, verification result, what was deleted and when) | 3 years | Proof that your request was handled | The date the deletion is completed |
| Marketing opt-out list (a coded form of your mobile number or email) | For as long as we send marketing | So we never message you again after you opt out | The date you opt out |
| Website security logs | 180 days | Security monitoring and investigation of incidents, and the log-retention duties in cyber-security rules | The date of the log entry |
| Analytics data (Google Analytics) |
GA4 event data: 14 months. The _ga and
_ga_<id> cookies expire after 2 years
|
Aggregated website improvement | The date collected |
Credit-bureau reporting
9.7 The lender reports loans to credit information companies, such as TransUnion CIBIL, Experian, Equifax and CRIF High Mark. This is the lender's legal obligation, and it continues independently of anything in this section. The credit information companies keep that information for as long as required under applicable credit information regulations. Deleting your Rinn account, or asking us to delete your data, does not remove your loan from your credit report. If you think something on your credit report is wrong, see Your loan and your credit report.
What "deletion" and "anonymisation" mean
9.8 Deletion We delete personal data when it is no longer required for the purpose for which it was collected,unless we are required to retain it under applicable law, regulatory requirements, or for legitimate legal, security, or fraud-prevention purposes.
9.9 Backups Data stored in encrypted backups is deleted or overwritten in accordance with our backup-retention cycle. Backups are used only for security, recovery, or business-continuity purposes.
9.10 Anonymisation Where personal data is anonymised so that an individual can no longer reasonably be identified, it is no longer treated as personal data. We may use anonymised or aggregated information for analytics, reporting, and service improvement.
9.11 Legally Required Retention Where data must be retained to comply with applicable Indian laws, RBI requirements, regulatory obligations, or legal proceedings, we retain it for the required period and restrict access to authorised personnel.
When data may be kept longer: legal holds
9.12 We or the lender may keep specific data beyond the periods above only while one of these applies:
- a dispute, complaint or legal claim about it is open;
- a court, tribunal or regulator has ordered it to be kept;
- it is needed for an investigation by a regulator or law-enforcement agency; or
- it is needed to investigate suspected fraud or identity misuse.
9.13 A legal hold covers only the data needed for that purpose. When the matter ends, the normal period applies again, and if it has already passed, the data is deleted or anonymised.
Asking us to delete your data
9.14 You can ask us to delete your account and your data at any time using the account-deletion form. Data covered by a legal retention period will be kept for that period, restricted as described in section 9.11, and then deleted. Everything else will be deleted.
10. How we protect your data
10.1 We protect personal data with security measures appropriate to its sensitivity, including:
- encryption of data in transit and at rest;
- role-based access, so people see only what their job needs, with least-privilege access and multi-factor authentication for administrative access Pending confirmation: MFA on administrative access.;
- logging of every access to, and change of, personal data;
- a consent ledger and audit trail that cannot be altered or deleted once written;
- written contracts, security reviews and confidentiality duties for every service provider (section 7.3) and every member of staff; and
- an information security management system certified to ISO/IEC 27001:2022.
10.2 These measures are intended to meet the "reasonable security practices" standard of the SPDI Rules and the security safeguards the DPDP Rules require. A public summary is on our Information security page, where you can also report a vulnerability to support@rinncrest.in.
10.3 No system connected to the internet is perfectly secure. Please help protect your account: never share your OTP, PIN or password with anyone, including someone claiming to be from Rinn. Rinn and Rinncrest never ask for them. See Fraud alerts and Verify it's really us.
11. Your rights
11.1 You have the following rights over your personal data. Some are already available to you under the SPDI Rules and the Digital Lending Directions; we extend the full set the DPDP Act provides to you now.
| Right | What it means | How to use it |
|---|---|---|
| Access | Get a summary of the personal data processed about you, the processing carried out, and who it has been shared with | Email support@rinncrest.in |
| Correction and completion | Have inaccurate or incomplete data corrected, completed or updated | Many details can be updated in Rinn; otherwise email us. Some KYC details can only be changed through fresh verification. See Your account and profile |
| Erasure | Have data deleted when it is no longer needed for its purpose or required by law | Use the account-deletion form, or email us. Section 9.14 explains what must be kept |
| Withdraw consent | Stop processing that relies on your consent | In Rinn, under the privacy and consent settings Pending confirmation: that Rinn has an in-app screen to view and withdraw consents., or any route in section 6.11 |
| Nomination | Name another person to use your rights if you die or become unable to act | Email us and we will send you the nomination form Pending confirmation: nomination process and form. |
| Grievance redressal | Have a complaint about your data answered | See section 16 |
11.2 How we handle your request. We may ask you to confirm your identity, usually with an OTP sent to your registered mobile number, before we act. We will not charge you. We will acknowledge your request within Pending confirmation (F-51). working days and respond in full within 30 days. If we cannot do what you asked, for example because a law requires a record to be kept, we will tell you why and what we will do instead.
11.3 If the request is about loan data. The lender is accountable for loan-related data, so we act on your request under its instructions. You can send the request to us, and we will pass it to the lender within Pending confirmation: processor-to-lender forwarding time — proposed 2 working days. and keep you informed, or you can write to the lender directly.
11.4 Your duties. The DPDP Act also asks you to give accurate information, not to impersonate anyone and not to file false or frivolous complaints.
12. Children
Loans through Rinn are available only to adults who can enter into a binding contract and meet the lender's eligibility criteria, including the age range of 18 to 55 years Pending confirmation (F-28).. Rinn and our website are not intended for anyone under 18, and we do not knowingly collect their personal data. If we learn that we have collected personal data of a child, we will delete it, subject only to any law that requires otherwise.
14. Messages we send you, and marketing
14.1 Service messages. While you have an application or a loan, we and the lender send messages you need, such as OTPs, application updates, KFS and agreement copies, EMI reminders, receipts and closure confirmations. These are part of the service and cannot be switched off while the loan is active, though you can choose your preferred channel where a choice exists. Calls about your loan are made only between 8:00 a.m. and 7:00 p.m. Pending confirmation: calling-hours rule as set in the lender's Fair Practices Code..
14.2 Marketing. We send marketing only if you have given a separate consent for it (consent 10). That consent is never pre-ticked and never a condition of a loan. Each marketing message tells you how to stop. You can also stop all marketing by emailing support@rinncrest.in or through the app's settings. We process an opt-out within 2 working days Pending confirmation: marketing opt-out turnaround.. Marketing never uses your credit information.
14.3 We will never ask you, by phone, SMS, email or WhatsApp, for an OTP, PIN, password or any advance fee. Rinncrest only writes from addresses ending @rinncrest.in.
14.4 WhatsApp. We use the WhatsApp Business Platform (Cloud API) to send service updates where you have agreed (consent 8) and to reply when you message us. Any media you send us on WhatsApp is deleted 30 days after the day you send it. To delete your WhatsApp chat history and other account data, use the account-deletion page.
15. Personal data breaches
15.1 If a personal data breach affects loan-related data, we will inform the lender without delay and give it everything it needs, so that it can inform you and the Data Protection Board of India in the manner and within the time the DPDP Rules prescribe.
15.2 If a breach affects data for which Rinncrest is the Data Fiduciary, we will inform you and the Data Protection Board of India ourselves, in the same way.
15.3 Any notice to you will explain, in plain language, what happened, when, what data was involved, the likely consequences, what we are doing about it, what you can do to protect yourself, and who to contact. We also report cyber-security incidents to CERT-In as the law requires.
16. Questions, complaints and escalation
16.1 Start with us. Our Data Protection Officer is Smriti Gupta, Director. You can also raise any data-protection matter with our Grievance Officer.
Bipasa Adhikary, Grievance Redressal Officer Rinncrest Financial Technologies Private Limited Email: support@rinncrest.in (data protection) · grievance@rinncrest.in (all complaints) Phone: +91 82309 07903 Post: 2nd Floor, Flat-2, Shivalik, 42, Prince Anwar Shah Road, Tollygunge, Kolkata 700033, West Bengal Hours: Pending confirmation: Grievance Officer working hours.
16.2 We acknowledge complaints within Pending confirmation (F-51). working days and resolve them within 30 days. Please include your registered mobile number, your application or loan number if you have one, and what you would like us to do. The full process is on Raise a complaint and in our Grievance Redressal Policy.
16.3 The escalation route. These are the same levels the lender's privacy policy sets out. You do not have to start again at each level.
| Level | Who | How to reach them |
|---|---|---|
| 1 | Rinn customer support (Rinncrest) | In-app Help · support@rinncrest.in · +91 81003 92196 · Pending confirmation: support hours.. See Contact support |
| 2 | Grievance Redressal Officer, Rinncrest | Bipasa Adhikary, as in section 16.1 |
| 3 | Grievance Redressal Officer, the Lender | Named in your Key Fact Statement and on our Lending Partners page Pending confirmation (F-52). |
| 4 | Principal Nodal Officer, the Lender | Not yet published: the Lender's Principal Nodal Officer contact. |
| 5 | Reserve Bank of India | For a lending matter, if your complaint is rejected, you are not satisfied with the reply, or you have not had a reply within 30 days: the Reserve Bank – Integrated Ombudsman Scheme, 2021, at cms.rbi.org.in (external site), toll-free 14448, or by post to the Centralised Receipt and Processing Centre, Reserve Bank of India, Chandigarh |
16.4 About how your personal data has been handled: once you have used the grievance process above, you may also complain to the Data Protection Board of India.
17. Common questions
Does Rinn read my contacts or SMS?
No. Rinn does not request access to your contacts, SMS or call logs, and it never contacts anyone from your phonebook. Section 6.5 lists everything Rinn does not access.
Why does Rinn need my location?
To check, once, that the lender serves your area and to help prevent fraud. It is captured when you submit your application and never tracked afterwards.
Can I say no to marketing and still get a loan?
Yes. Marketing is a separate, optional consent, and declining it has no effect on your application or the lender's decision.
If I withdraw consent, is my loan cancelled?
No. Withdrawing consent does not cancel a loan or your duty to repay it. To exit a loan early, see the cooling-off period or prepayment and foreclosure.
How long does Rinn keep my data if my loan application is rejected?
Your application data is deleted within 30 days of the decision, unless you have separately chosen to let it be kept for future offers. A record of your consents and the decision is kept to prove the data was handled lawfully.
How long is my credit report kept?
The full credit report is kept for 30 days, encrypted, and then deleted. Only the lender's decision and your score band are kept with your application or loan record.
Can I make you delete my KYC records straight away?
No, not while a law requires them to be kept. KYC records must be kept for 5 years after the loan closes or the relationship ends. During that time they are restricted, and afterwards they are deleted.
Does deleting my data remove my loan from my credit report?
No. Reporting loans to credit information companies is the lender's legal obligation and continues independently of any deletion request.
Who do I complain to about my data or a consent?
Our Grievance Officer, Bipasa Adhikary, at support@rinncrest.in or +91 82309 07903. If you are not satisfied, follow the escalation route in section 16.3.
18. Changes to this policy
18.1 We will update this policy when the law, our services or our practices change. The version number and "Last updated" date at the top always show the current version, and earlier versions are available on request.
18.2 If a change is material, for example a new purpose, a new category of recipient or a change in where data is stored, we will tell you in Rinn and by email or SMS before the change takes effect. Where a change needs fresh consent, we will ask for it and will not rely on your continued use alone.
18.3 In particular, we will update this policy before:
- a new category of service provider starts receiving personal data, or any provider starts processing outside India (section 7);
- any change that shortens your rights or lengthens a retention period takes effect (section 9), and we will tell you about it; and
- we add or change a cookie (section 13).
19. Contact
| For | Contact |
|---|---|
| Help with the app or your loan | support@rinncrest.in · +91 81003 92196 · in-app Help |
| Privacy and data-protection requests | support@rinncrest.in |
| Complaints | Bipasa Adhikary, Grievance Redressal Officer · grievance@rinncrest.in · +91 82309 07903 |
| Delete your account | /delete-account |
| Security vulnerabilities | support@rinncrest.in |
| Registered office | Rinncrest Financial Technologies Private Limited, 2nd Floor, Flat-2, Shivalik, 42, Prince Anwar Shah Road, Tollygunge, Kolkata 700033, West Bengal · CIN U62099WB2026PTC287520 |
| The Lender | Contact details are in your Key Fact Statement and on our Lending Partners page |
