Findoly Provider portal Provider login
Findoly Solutions LLP

Privacy Policy

How Findoly handles Provider information, account security data, payments, marketplace activity and customer lead information.

Effective and last updated: 30 July 2026

Provider responsibility

After you unlock and independently use customer information, you are responsible for using it lawfully, securely and only for the submitted service requirement.

On this page
  1. Introduction and scope
  2. Our role and your role
  3. Provider and authorised-user information
  4. Authentication and security data
  5. Marketplace, lead and activity data
  6. Payments, subscriptions and credit records
  7. Device, log and technical information
  8. Support and grievance communications
  9. Sources of information
  10. Purposes of processing
  11. Lawful processing, consent and legitimate uses
  12. Matching and automated processing
  13. Service and promotional communications
  14. Service providers and processors
  15. Internal access and CRM synchronisation
  16. Sharing between Customers and Providers
  17. Legal, safety and corporate disclosures
  18. Cookies and browser storage
  19. Data retention
  20. Security safeguards
  21. Accuracy and correction
  22. Access, correction, erasure and other rights
  23. Account closure and deletion requests
  24. Children and authorised business use
  25. Processing and transfers across locations
  26. Third-party sites and services
  27. Policy changes
  28. Privacy questions and grievances

1. Introduction and scope

This Privacy Policy explains how Findoly Solutions LLP collects, uses, stores, shares and protects personal data in connection with the Provider Portal. It applies to provider applicants, approved Providers, authorised users, people who contact support, and individuals whose information is processed through provider-account activity.

This Policy should be read with the Terms and Conditions, Acceptable Use and Lead Data Policy, Cookie and Storage Notice and any specific notice displayed when information is collected. It does not govern a Provider’s independent processing of customer data after access; the Provider is separately responsible for that activity.

Back to contents

2. Our role and your role

For personal data processed to operate the Provider Portal, verify accounts, manage subscriptions, secure transactions and administer the marketplace, Findoly generally determines the purpose and means of processing. Depending on applicable law, this role may be described as a data fiduciary or similar controller.

After a Provider unlocks a lead and independently contacts a Customer, the Provider decides how it uses the information for its own quotation and service relationship. The Provider must provide any notice, obtain any consent and meet any retention, security or rights obligations applicable to that independent use.

Back to contents

3. Provider and authorised-user information

We may collect legal name, trading name, contact person, mobile number, email address, business address, service categories, subcategories, service locations, PIN codes, geographic coordinates, operating radius, profile description, logos, business documents, tax details, eligibility status, CRM identifiers and other onboarding or verification information.

We may also record the authority of a person using an organisation’s account and communications concerning profile updates, suspension, verification or support.

Back to contents

4. Authentication and security data

We process the registered mobile number, OTP request and verification outcomes, request time, resend or verification limits, IP address, user agent, session identifiers, CSRF tokens, security events and related diagnostic information. OTP values are handled through the authorised OTP service and are not displayed in the Provider Portal.

Authentication records are used to establish account access, prevent abuse, investigate compromise and maintain an audit trail. Security controls may identify repeated requests, unusual activity or invalid sessions.

Back to contents

5. Marketplace, lead and activity data

We collect records of enquiries displayed to the Provider, matching inputs, lead views, unlock attempts, successful unlocks, credit deductions, direct payments, provider outcome selections, activity statuses, reasons, notes and timestamps. We may derive operational metrics such as pending follow-up, conversion reporting, category performance and marketplace quality indicators.

Customer details contained in a lead may include name, mobile number, location, requirement, category, description, preferred timing and other information supplied for the enquiry. Access is restricted until the applicable unlock and must then be used only for the submitted requirement.

Back to contents

6. Payments, subscriptions and credit records

We process order identifiers, plan selection, billing cycle, price, GST, credit quantity, bonus credits, payment gateway order and payment identifiers, signature or webhook verification results, status, fulfilment time, subscription dates, credit allocations, deductions, expiry and balance history.

The payment gateway directly handles sensitive payment credentials such as full card data, CVV or UPI PIN. Findoly may receive masked or limited payment metadata and status information necessary to verify, reconcile, support and document the transaction.

Back to contents

7. Device, log and technical information

When you use the Platform, servers and security systems may log IP address, browser type, operating system, device characteristics, requested URL, referring URL, response status, timestamps, session state, error details, request identifiers and performance information.

We use this information to deliver pages, diagnose failures, secure the service, prevent fraud, investigate incidents, enforce limits and improve reliability.

Back to contents

8. Support and grievance communications

If you contact support or submit a complaint, we process your email address, registered mobile number, description, attachments, transaction or lead references, correspondence history, resolution notes and any information reasonably needed to investigate.

Please do not send unnecessary sensitive personal data, OTPs, passwords, full card details or UPI PINs. We may redact or restrict access to information not needed for the case.

Back to contents

9. Sources of information

Information may come directly from you, your authorised organisation, Findoly’s CRM and internal teams, customer enquiry channels, payment gateways, OTP providers, banks or network status, hosting and security systems, location or mapping services, support correspondence and lawful public or third-party verification sources.

Where information comes from another source, we use it only where we have a lawful and legitimate basis and according to any applicable notice or restriction.

Back to contents

10. Purposes of processing

  • Create, verify, maintain and secure Provider accounts.
  • Match Providers with relevant enquiries and enforce marketplace visibility rules.
  • Display restricted lead information after an authorised unlock.
  • Create orders, verify payments, allocate, deduct and expire credits, and maintain subscriptions.
  • Provide dashboards, records, support and grievance handling.
  • Prevent fraud, spam, customer-data misuse, unauthorised access and transaction abuse.
  • Improve product reliability, matching, usability and operational decision-making.
  • Comply with law, court orders, tax, accounting, audit, payment and regulatory obligations.
  • Establish, exercise or defend legal claims and enforce Platform terms.
Back to contents

11. Lawful processing, consent and legitimate uses

We process personal data for lawful purposes connected with account onboarding, performance of the Provider relationship, requested transactions, security, compliance and other legitimate uses recognised by applicable law. Where consent is required, the relevant notice will describe the purpose and you may withdraw consent through the stated method, subject to consequences for services that cannot operate without the data.

Withdrawal does not affect processing already lawfully completed and does not require deletion of records that must be retained for a transaction, security, legal claim or statutory obligation.

Back to contents

12. Matching and automated processing

The Platform uses rule-based processing to determine which enquiries may be displayed, using factors such as approved categories, subcategories, service PIN codes, distance, account status, lead status, priority, expiry and marketplace limits. These rules support relevance and access control.

Findoly may review and update such rules. A Provider may contact support about an apparent matching or eligibility error. The Platform does not represent that automated matching is a final assessment of a Provider’s professional suitability or a guarantee of business.

Back to contents

13. Service and promotional communications

We may send OTPs, security alerts, account notices, lead alerts, payment confirmations, credit or subscription updates, policy notices and support responses through the registered channels. These are transactional or service communications required to operate the account.

Promotional communication, where used, will be managed according to applicable consent and opt-out requirements. Opting out of marketing does not stop essential security, transaction or account messages.

Back to contents

14. Service providers and processors

We may share limited personal data with vendors that provide OTP delivery, payment processing, cloud hosting, databases, security, monitoring, email, customer support, mapping, analytics, legal, accounting or audit services. They receive only information reasonably necessary for their function and are expected to protect it under contractual or legal obligations.

Current integrations may include the Findoly OTP service, Razorpay checkout and payment infrastructure, cloud or database providers, and mapping services. Providers may also choose to open WhatsApp or another external service from a lead page; that service then processes information under its own terms.

Back to contents

15. Internal access and CRM synchronisation

Provider information may be synchronised with Findoly’s CRM so authorised personnel can approve accounts, manage categories, service areas, eligibility, credits, support and operational records. Access is limited according to role and business need.

Findoly personnel may access records to support the Provider, investigate misuse, reconcile payments, administer lead distribution, maintain systems and meet legal obligations.

Back to contents

16. Sharing between Customers and Providers

Before unlock, the Platform limits the customer information visible to a Provider. After a successful unlock, the Provider receives the information available for that enquiry so it can respond to the customer’s stated requirement.

A Customer may receive or be told information about a Provider where necessary to facilitate the enquiry, support transparency, investigate a complaint or operate a provider listing. Findoly does not authorise either party to use the other’s information for unrelated purposes.

Back to contents

17. Legal, safety and corporate disclosures

We may disclose information where reasonably necessary to comply with law, legal process, court or regulatory direction; protect rights, safety or property; investigate fraud, cyber incidents, unlawful content or customer-data misuse; enforce agreements; or establish, exercise or defend claims.

If Findoly undergoes a merger, acquisition, financing, restructuring, insolvency or transfer of all or part of the business, information may be transferred with appropriate confidentiality and legal safeguards.

Back to contents

18. Cookies and browser storage

The Platform uses essential cookies for authentication and cross-site request forgery protection. The authentication cookie is HTTP-only and, in production, secure; the CSRF cookie must be readable by the browser so requests can include the security token. Cookie duration and same-site settings are configured to protect sessions and support portal use.

The Platform also uses local storage for a Provider’s lead-view preference and session storage to remember dismissal of a dashboard reminder during the browser session. The separate Cookie and Storage Notice provides more detail.

Back to contents

19. Data retention

We retain personal data for as long as reasonably necessary for the purpose collected, including while an account is active and for an appropriate period afterwards. Retention depends on the type of record, transaction history, account status, fraud and security risk, support needs, legal limitation periods, tax or accounting duties and dispute requirements.

OTP rate-limit records are designed to expire automatically after their security purpose. Session cookies expire according to configured duration or logout. Transaction, credit, lead-unlock, audit and grievance records may be retained longer because they evidence financial or contractual activity. Data may be deleted, anonymised or aggregated when no longer required.

Back to contents

20. Security safeguards

We use reasonable administrative, technical and organisational measures such as OTP authentication, signed sessions, secure production cookies, CSRF protection, origin checks, rate limits, role-based access, payment-signature verification, restricted lead visibility, database controls, logging and secure transport configuration.

No system is completely secure. You must protect your device, mobile number and session, use trusted networks, log out from shared devices and report suspected compromise. Do not send OTPs or payment secrets to anyone claiming to be Findoly support.

Back to contents

21. Accuracy and correction

Providers should keep their information accurate and notify support when a correction cannot be made through the Platform. Some profile fields are controlled through Findoly’s CRM and may require verification before update.

We may request evidence to prevent unauthorised changes. Correcting a display field does not require alteration of historical transaction records that were accurate when created.

Back to contents

22. Access, correction, erasure and other rights

Subject to applicable law and its commencement, you may request information about personal data processed by Findoly, correction of inaccurate or incomplete data, erasure of data no longer required, and grievance redressal. You may also have rights concerning consent withdrawal or nomination where provided by law.

Requests must be sent from a verifiable channel and include enough detail to identify the account and request. We may ask for reasonable verification, reject fraudulent or excessive requests, redact another person’s data, and retain information where processing is required by law, contract, security, payment reconciliation or legal claims.

Back to contents

23. Account closure and deletion requests

A request to close a Provider account may stop future access but does not automatically erase all records. Findoly may preserve transaction, invoice, credit, lead-unlock, complaint, security and audit records for legal, accounting, fraud-prevention and dispute purposes.

Where deletion is appropriate, Findoly may delete or de-identify data after completing verification and any required retention. Closure does not convert credits into cash or change the Refund Policy.

Back to contents

24. Children and authorised business use

The Provider Portal is for adults acting for service businesses and is not intended for children. You must not create an account for a child or submit a child’s personal data unless there is a lawful, necessary and properly authorised reason.

If we learn that a child’s data was submitted contrary to this rule, we may restrict the account and take reasonable steps to remove or protect the information, subject to legal retention.

Back to contents

25. Processing and transfers across locations

Findoly and its service providers may process information in locations where they operate infrastructure or support services. Any transfer outside India will be handled subject to applicable restrictions, contractual protections and government directions in force at the relevant time.

We do not promise that every vendor or data copy is located in a particular city or state unless a specific written agreement says so.

Back to contents

26. Third-party sites and services

Links to Razorpay, WhatsApp or other third-party services are provided for convenience. Their privacy policies govern information they collect directly. Findoly does not control their independent processing and you should review their terms before use.

This Policy does not cover a Provider’s own website, CRM, messaging, call-recording or customer database.

Back to contents

27. Policy changes

We may update this Policy for legal, security, vendor or product changes. The revised date will be displayed. Material changes may also be notified through the Platform or registered contact details. Where law requires fresh consent, we will request it before the relevant processing.

Back to contents

28. Privacy questions and grievances

Send privacy requests and questions to support@findoly.com with the subject “Privacy Request”. Include the registered mobile number, the right or issue involved and sufficient detail to verify and locate the information.

The Grievance Redressal Policy explains escalation and response handling.

Back to contents
Policies and support
Terms Privacy Refund policy Digital delivery Lead data use Marketplace disclaimer Cookies Intellectual property Grievances Contact Help & support
© 2026 Findoly Solutions LLP support@findoly.com