Information marked pending is awaiting confirmation. This page is under review before publication.

How we protect you, your data and your loan

When you apply for a loan, you share some of the most personal information you have: who you are, what you earn, where you bank. You should know exactly how it's looked after, and what we promise in return. This page sets it out plainly, so you can hold us to it.

Loans offered through Rinn, the personal loan app from Rinncrest, are provided by RBI-regulated lending partners (NBFCs and banks), listed on our Lending Partners page. The lender decides who gets a loan and on what terms. Rinncrest is a Lending Service Provider (LSP): it runs the app and the services around your loan, and does not lend. Some commitments below are ours; some are the lender's, and we say which.

In short

  • Rinncrest is certified to ISO/IEC 27001:2022 (information security, Cert. No. IN/96828132/6481) and ISO 9001:2015 (quality, Cert. No. IN/84728131/5962).
  • You'll see every cost in your Key Fact Statement before you accept. Applying is free and no fee is ever collected before disbursal.
  • Rinn never accesses your contacts, SMS, call logs or photo gallery.
  • Rinn's data is stored in India. Personal data is encrypted in transit and at rest, access is limited to those who need it, and every access is logged.
  • If a personal-data breach affects you, you, the lender and the authorities will be told as the law requires.
  • Found a vulnerability? Email support@rinncrest.in. Act in good faith under the rules below and we will not take legal action against you.
  • We will never ask for your OTP, PIN or password.

Pending confirmation: security-control wording and vulnerability-reporting arrangements await engineering and legal review.

Independently certified

Rinncrest is certified to two international standards:

  • ISO/IEC 27001:2022 — information security management. An independent certification body has audited how we identify information-security risks and the controls we use to manage them.
  • ISO 9001:2015 — quality management. Our processes are documented, measured and improved under an audited quality management system.

Both certifications cover Rinncrest's activities as a Lending Service Provider. They are not a lending, payments or RBI licence, and they say nothing about whether a loan will be approved.

DetailISO/IEC 27001:2022ISO 9001:2015
Certification bodyICV Assessments Pvt. Ltd.ICV Assessments Pvt. Ltd.
AccreditationEGAC (CAB #011907A), an IAF MLA signatoryEGAC (CAB #011907A), an IAF MLA signatory
Certificate numberIN/96828132/6481IN/84728131/5962
ScopeDesign, development, hosting and support of financial technology platforms, including digital loan origination and servicing as a Lending Service Provider, AI-enabled omnichannel debt collections solutions and credit analytics servicesDesign, development and provision of financial technology platforms and services, including digital loan origination and lifecycle management as a Lending Service Provider, AI voice bot, IVR and omnichannel (WhatsApp/SMS) debt collections solutions and real-time credit analytics dashboards for NBFCs, banks and fintech partners
Issued7 October 20267 October 2026
Valid until6 October 2029, subject to annual surveillance audits6 October 2029, subject to annual surveillance audits

You can check either certificate with the certification body at icvassessments.com.

Our responsible-lending commitments

Borrowing should never feel like a trap. These are the promises we make to everyone who uses Rinn and to the lenders we work with. They're written so you can hold us to them.

Our commitments to borrowers

1. You'll know what it costs before you say yes

Interest starts from 16% p.a. Your actual rate depends on the lender's assessment. Before you accept, Rinn shows your interest rate, Annual Percentage Rate (APR), EMI, total amount payable and any applicable charges, such as a processing fee, in your Key Fact Statement. No charge that isn't in your Key Fact Statement can be added later. See rates and charges and your Key Fact Statement, explained (page not available yet).

2. Free to apply. No upfront fee, ever

Applying through Rinn is free. No fee is ever collected before your loan is disbursed, and Rinncrest does not charge borrowers anything. If anyone asks you to pay to "approve" or "release" a loan, it isn't us. Report it.

3. Only the data the loan needs

We collect what's needed to verify you, let the lender assess your application and service your loan, and nothing more. Rinn asks for very few phone permissions and never reads your contacts — so no one acting for Rinn can ever call them. Exactly what Rinn can and can't see is set out below.

4. Your consent, asked properly

Each consent is asked separately, explained in plain language and never pre-ticked. The lender's credit-bureau check needs its own explicit yes. You can withdraw consent for anything that isn't required for an active loan or by law. We don't sell your data or use it for third-party advertising. Full details: data, consent and app permissions.

5. A loan that fits your budget

The lender assesses whether you can repay before offering a loan. Rinn shows your EMI and total cost up front, so you can choose an amount and tenure you can manage, anywhere from ₹10,000 to ₹2,00,000 over 3 to 24 months. Your loan amount or any credit limit is never increased without your explicit consent. We don't promote borrowing for speculation, gambling or to repay other loans. Not sure what the EMI would be? Try the EMI calculator.

6. Time to change your mind

Every loan comes with a cooling-off period. You can exit the loan during the cooling-off period stated in your Key Fact Statement by repaying the principal and proportionate APR, without a prepayment penalty Pending confirmation: period set by the lender's Board.. How the cooling-off period works.

7. Repayments go only to the lender

You repay the lender only, through the Rinn app or an e-mandate set up in the app, into accounts in the lender's name Pending confirmation: mandate types.. Never to an individual, a personal UPI ID or in cash. Repaying your loan.

8. If a payment is missed, you'll be treated fairly

If you miss an EMI, the Rinn team may contact you on the lender's behalf. Rinncrest manages reminders and collections for its lending partners with its own staff; it isn't a debt collection agency, and no outside agency is used. Every contact follows the lender's Fair Practices Code and RBI's norms for recovery agents: no threats, no abuse, no contact at unreasonable hours, and no contacting your family, friends or colleagues about your loan.

If you think you might miss a payment, tell us early; it gives you more options. If you miss or expect to miss an EMI · Recovery and collection practices.

10. Accessible to more people

We write in plain language, explain any term we have to use, and build Rinn and this website to work with screen readers and larger text settings Pending confirmation: accessibility standard targeted and tested, e.g. WCAG 2.1 AA, for the website and app.. If something is hard to use, tell us and we'll help you another way. Accessibility statement.

Pending confirmation: availability of Hindi or other Indian-language versions of the app, Key Fact Statement and support.

Our commitments to lenders

Responsible lending depends on lenders and service providers holding the same standard. To every institution we work with, we commit to:

  • Your decision stays yours. Credit decisions, pricing and the loan contract always remain with you. Our services support your own obligations under the RBI Digital Lending Directions, outsourcing rules, the Fair Practices Code and data-protection law; they never transfer them.
  • Honest status. Every capability we offer is described as available today, being built or planned, and stays that way until it's true.
  • Evidence by default. Consent records, Key Fact Statement delivery logs, grievance records and audit trails are available to support your oversight and audits.
  • Your borrowers treated as you would want. Servicing and collections run within your policies, your Fair Practices Code and borrower rights, whatever the account status.
  • Data handled on your instructions. For loan-related personal data you are the Data Fiduciary; we process it only as you instruct and keep it stored in India Pending confirmation: F-83 / F-87..
  • No surprises. Incidents are reported promptly, with root cause and corrective action.

Lenders evaluating Rinncrest can request our security and compliance documentation — certificate details, our information-security policy summary and data-processing terms — under a non-disclosure agreement. See risk, compliance and governance or start a partnership conversation.

These commitments only mean something if you can act when we miss one. If we fall short, tell us through the contacts below or follow the full escalation path on raise a complaint.

What Rinn can and can't see on your phone

Rinn asks for very little.

PermissionWhen and why
LocationOnce, when you apply, to check serviceability and help prevent fraud. Never in the background
CameraOnly for the KYC selfie and liveness check
FilesOnly the single document you choose to upload, through your phone's file picker

Rinn never accesses: your contacts, SMS, call logs, photo gallery or media, the list of apps installed on your phone, your location continuously or in the background, or a device fingerprint for profiling.

That's a deliberate choice. Loan apps that harvest contacts have been used to harass borrowers and their families. Rinn can't do that, because it never has the data. More on data, consent and app permissions.

Information security

This is a public summary of how Rinncrest Financial Technologies Private Limited ("Rinncrest", "we") protects information on the Rinn app, the Rinncrest website and the systems behind them. It is not our full internal policy, which we do not publish for security reasons.

1. Scope and the law we follow

1.1 Rinncrest processes personal data relating to loans as a Data Processor for the lender. Our controls are designed to be consistent with the lender's Board-approved privacy policy, its information-security and data-protection requirements, and the obligations it places on us in our written agreement. Pending confirmation: controls to be reconciled against the lender's information-security policy and the LSP agreement.

1.2 Our approach reflects the Information Technology Act, 2000 and the reasonable security practices required under the SPDI Rules, 2011; the Digital Personal Data Protection Act, 2023; the RBI (Digital Lending) Directions, 2025; and RBI's directions on outsourcing and IT governance as they apply to service providers of NBFCs.

1.3 Who is responsible for your data. For loan-related personal data, the lender is the Data Fiduciary and Rinncrest is a Data Processor acting on its instructions. For our own website, enquiry forms and tools, Rinncrest is the Data Fiduciary Pending confirmation (F-87).. See the Privacy Policy and data retention.

1.4 Definitions. "ISMS" means information security management system — the policies, processes and controls by which we manage information risk. "Personal data breach" means any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. "Vulnerability" means a weakness in our systems that could be exploited to compromise the confidentiality, integrity or availability of information. "Researcher" means a person who reports a vulnerability to us under section 5.

2. Our information security management system

2.1 Rinncrest's ISMS is certified to ISO/IEC 27001:2022 (Cert. No. IN/96828132/6481), and its quality management system to ISO 9001:2015 (Cert. No. IN/84728131/5962), by ICV Assessments Pvt. Ltd. (see the certificate table above).

2.2 The ISMS is owned by Rinncrest's senior management, which approves the information-security policy, sets risk appetite and reviews performance at least annually. Pending confirmation: name or role of the information-security owner.

2.3 Information risks are assessed at least once a year and whenever a significant change is made, and are treated using controls drawn from ISO/IEC 27001:2022.

2.4 The ISMS is audited internally and by the certification body on the schedule the standard requires.

3. Key controls

The control statements below are pending engineering confirmation before publication.

AreaWhat we do
Data minimisationThe Rinn app collects only what the lender needs (see what Rinn can and can't see). Your customer record holds only a masked Aadhaar number (the last four digits), never the full 12-digit number.
EncryptionPersonal data is encrypted in transit using current TLS — between your phone, our systems and the lender — and at rest. Raw credit-bureau reports are kept encrypted and purged after 30 days. Pending confirmation (F-86).
Access controlRole-based access on a least-privilege basis: people see only the data their role requires. Multi-factor authentication for staff access to production systems and administrative tools; access reviewed regularly and removed promptly when roles change. Pending confirmation: MFA and access-review cadence.
Logging and audit trailsEvery access to, and change in, personal data is logged. The consent ledger records the exact wording of each consent you give, with its time and type. The consent ledger and audit trail are tamper-evident: once written, records cannot be altered or deleted.
Data locationPersonal data is stored on servers in India (AWS Mumbai region). If any processing incidentally occurs outside India, the data is deleted there and brought back to India within 24 hours. Pending confirmation: backups, logs, CDN and every third-party SDK and vendor confirmed India-resident.
Secure developmentSecurity requirements are part of design; code is peer-reviewed; dependencies are scanned for known vulnerabilities; the app and website are tested for security before major releases. Pending confirmation: penetration-testing frequency and provider type.
Infrastructure securityNetwork segmentation, hardened configurations, managed firewalls, timely patching and continuous monitoring for suspicious activity.
Vendor managementService providers that handle personal data are assessed before engagement, bound in writing to confidentiality and security obligations equivalent to ours, may use the data only for the stated purpose, and are reviewed periodically. See third-party service providers.
PeopleStaff are background-checked where lawful, sign confidentiality undertakings, and complete security and data-protection training when they join and at least annually.
Business continuityBackups are encrypted and tested; continuity and recovery plans are maintained and exercised. Pending confirmation: backup location — must be India-resident under F-83.
Retention and disposalData is kept only as long as the law or its purpose requires, then securely deleted or anonymised. See data retention.

No system connected to the internet is perfectly secure, and we don't claim ours is. What we can promise is that security is designed in, independently audited and continuously reviewed.

4. Incident response and breach notification

4.1 We maintain an incident-response plan covering detection, containment, investigation, recovery and lessons learned. It is tested at least once a year. Pending confirmation: incident-response test cadence.

4.2 If a personal-data breach occurs, we will:

(a) act at once to contain it and limit harm; (b) inform the lender without delay, so that it can meet its obligations as Data Fiduciary; (c) notify the Data Protection Board of India and each affected person, in the manner and within the timelines prescribed under the Digital Personal Data Protection Act, 2023 and its rules — directly, or through the lender, as our agreement with it provides; (d) report cyber-security incidents to CERT-In within the timelines set by its directions under the Information Technology Act, 2000; and (e) support the lender in any reporting it must make to the Reserve Bank of India.

4.3 When we tell you about a breach, we will explain in plain language what happened, what data was involved, the likely consequences, what we have done, and what you can do to protect yourself, with a contact for questions.

4.4 We will never tell you about a breach by asking you to click a link and enter a password or OTP. Any message that does so is not from us.

Report a vulnerability

We welcome reports from security researchers and anyone else who finds a weakness in Rinn, this website or any Rinncrest system. If you follow these rules, we will work with you and treat your report as help, not as an attack.

5.1 How to report. Email support@rinncrest.in. Please include:

  • the affected URL, app version or component;
  • the type of vulnerability and its potential impact;
  • clear steps to reproduce it, with screenshots or a proof of concept where possible; and
  • how we can contact you, and whether you would like to be credited.

Reports in English are preferred. Pending confirmation: whether a PGP key will be published for encrypted reports.

5.2 In scope.

  • rinncrest.in and its sub-domains operated by Rinncrest
  • the Rinn app for Android, published on Google Play by Rinncrest Financial Technologies Private Limited
  • APIs used by the Rinn app

5.3 Out of scope.

  • systems operated by the lender or by other third parties, including KYC, credit-bureau, payment and cloud providers — please report those to the relevant organisation
  • denial-of-service or volume-based testing
  • social engineering, phishing or physical attacks against our staff, offices or users
  • spam, or findings that require a rooted or compromised device, outdated browser or unlikely user interaction
  • missing best-practice headers or configurations with no demonstrable security impact
  • reports generated only by automated scanners, without verification

5.4 Rules of engagement. You must:

(a) act in good faith, and test only to the extent needed to demonstrate the vulnerability; (b) use only accounts you own or have been given permission to test, and never access, modify, download or delete another person's data — if you come across personal data, stop, do not keep it, and tell us; (c) not degrade or disrupt our services or affect any user; (d) not use the vulnerability for any purpose other than reporting it, or demand payment in exchange for not disclosing it; (e) give us a reasonable time to fix the issue before telling anyone else — we ask for 90 days from your report, or less by agreement; and (f) comply with the law.

5.5 Safe harbour. If you report a vulnerability to us in good faith and follow clause 5.4, Rinncrest:

(a) will not bring any civil claim against you, or make a complaint to law enforcement about you, in relation to your research; (b) will regard your research as authorised by us for the purposes of our Terms of Use; and (c) if a third party brings legal action against you for activity covered by this programme, will make it known that your actions were in line with this programme.

This safe harbour covers only Rinncrest's own systems and rights. It cannot authorise testing of third-party systems or override the law.

5.6 What happens after you report.

StepOur target
Acknowledge your reportWithin Pending confirmation: acknowledgement time, e.g. 3 working days.
Initial assessment and severityWithin Pending confirmation: triage time, e.g. 10 working days.
Updates while we fix itAt least every Pending confirmation: update interval, e.g. 14 days.
Confirmation when fixedWhen the fix is deployed

5.7 Recognition. With your permission, we will credit you in this section once the issue is fixed. We do not currently offer monetary rewards. Pending confirmation: bug bounty decision.

5.8 security.txt. Machine-readable reporting details will be published once the security mailbox and canonical website address are confirmed.

How we help protect you from fraud

Fraudsters copy real loan apps. Here's how to tell if it's really Rinn.

  • We never ask for money to approve a loan. No processing fee, insurance fee or "release" charge is ever collected before disbursal.
  • We never ask for your OTP, PIN or password, by phone, message or email — and neither does anyone genuinely from Rinn, Rinncrest or the lender.
  • We never ask you to install screen-sharing or remote-access apps. Hang up on any caller who does.
  • One app, one store. Rinn is available only on Google Play, published by Rinncrest Financial Technologies Private Limited. Coming soon on iOS. There is no APK download. Any "Rinncrest" app on the App Store is not ours.
  • One email domain. We only ever write from addresses ending in @rinncrest.in.
  • Repayments go to the lender only. You repay the lender through the app or your e-mandate, never to an individual, a personal UPI ID or in cash.
  • Check the regulator's list. Rinn appears in RBI's public directory of Digital Lending Apps, as reported by the lender, an RBI-regulated NBFC or bank. Appearing in the directory is not an approval or endorsement by RBI Pending confirmation (F-17)..

If something feels wrong, stop and check on verify it's really us. If you've lost money or been threatened, call 1930 or report at cybercrime.gov.in (external, opens in a new tab), tell us, and see fraud alerts.

Contact

PurposeContact
Security vulnerabilitiessupport@rinncrest.in
Privacy and data protectionsupport@rinncrest.in
ComplaintsBipasa Adhikary, Grievance Redressal Officer · grievance@rinncrest.in · +91 82309 07903

Rinncrest Financial Technologies Private Limited · CIN U62099WB2026PTC287520 · 2nd Floor, Flat-2, Shivalik, 42, Prince Anwar Shah Road, Tollygunge, Kolkata 700033, West Bengal

Check it's really us

Read our Privacy Policy

Frequently asked questions

Is the Rinn loan app safe to use?

Yes. Rinn is the personal loan app of Rinncrest Financial Technologies Private Limited, loans come from RBI-regulated lending partners, and Rinncrest is certified to ISO/IEC 27001:2022 for information security. Rinn's data is stored in India. You can check our official channels and the lending partners page at any time.

Does Rinn read my contacts, SMS or photos?

No. Rinn never accesses your contacts, SMS, call logs, photo gallery or the list of apps on your phone. It uses your location once when you apply, your camera only for the KYC selfie, and only the single file you choose to upload.

Who can see my personal data, and do you sell it?

We do not sell your data or use it for third-party advertising. We collect only what is needed to verify you, let the lender assess your application and service your loan, and access is limited to people who need it. For loan data the lender is the Data Fiduciary and Rinncrest acts on its instructions; the Privacy Policy has the details.

Can I withdraw my consent or delete my data?

You can withdraw consent for anything that is not required for an active loan or by law. Each consent is asked separately and is never pre-ticked. To close your account, use delete my account, or write to support@rinncrest.in.

Will anyone contact my family or friends if I miss an EMI?

No. Rinn never has your contacts, and every contact about a missed payment follows the lender's Fair Practices Code and RBI's norms: no threats, no abuse and no contacting your family, friends or colleagues about your loan. If you think you might miss an EMI, tell us early; it gives you more options. See Fair Practices and Recovery.

How do I know a message, call or app is really from Rinn?

Check three things. Rinn is available only on Google Play, published by Rinncrest Financial Technologies Private Limited; we write only from addresses ending in @rinncrest.in; and we never ask for your OTP, PIN or password, or for money to release a loan. If something feels wrong, use verify it's really us.

How do I report a security problem or make a complaint?

For a security weakness, email support@rinncrest.in; if you act in good faith, we will treat your report as help. For a complaint, write to our Grievance Officer, Bipasa Adhikary, at grievance@rinncrest.in or +91 82309 07903. If your complaint is not resolved within 30 days of the lender receiving it, or you're unhappy with the reply, you can complain to the RBI Integrated Ombudsman at cms.rbi.org.in or call 14448.