Privacy Policy
How Findoly handles Provider information, account security data, payments, marketplace activity and customer lead information.
Effective and last updated: 30 July 2026
1. Introduction and scope
This Privacy Policy explains how Findoly Solutions LLP collects, uses, stores, shares and protects personal data in connection with the Provider Portal. It applies to provider applicants, approved Providers, authorised users, people who contact support, and individuals whose information is processed through provider-account activity.
This Policy should be read with the Terms and Conditions, Acceptable Use and Lead Data Policy, Cookie and Storage Notice and any specific notice displayed when information is collected. It does not govern a Provider’s independent processing of customer data after access; the Provider is separately responsible for that activity.
Back to contents2. Our role and your role
For personal data processed to operate the Provider Portal, verify accounts, manage subscriptions, secure transactions and administer the marketplace, Findoly generally determines the purpose and means of processing. Depending on applicable law, this role may be described as a data fiduciary or similar controller.
After a Provider unlocks a lead and independently contacts a Customer, the Provider decides how it uses the information for its own quotation and service relationship. The Provider must provide any notice, obtain any consent and meet any retention, security or rights obligations applicable to that independent use.
Back to contents3. Provider and authorised-user information
We may collect legal name, trading name, contact person, mobile number, email address, business address, service categories, subcategories, service locations, PIN codes, geographic coordinates, operating radius, profile description, logos, business documents, tax details, eligibility status, CRM identifiers and other onboarding or verification information.
We may also record the authority of a person using an organisation’s account and communications concerning profile updates, suspension, verification or support.
Back to contents4. Authentication and security data
We process the registered mobile number, OTP request and verification outcomes, request time, resend or verification limits, IP address, user agent, session identifiers, CSRF tokens, security events and related diagnostic information. OTP values are handled through the authorised OTP service and are not displayed in the Provider Portal.
Authentication records are used to establish account access, prevent abuse, investigate compromise and maintain an audit trail. Security controls may identify repeated requests, unusual activity or invalid sessions.
Back to contents5. Marketplace, lead and activity data
We collect records of enquiries displayed to the Provider, matching inputs, lead views, unlock attempts, successful unlocks, credit deductions, direct payments, provider outcome selections, activity statuses, reasons, notes and timestamps. We may derive operational metrics such as pending follow-up, conversion reporting, category performance and marketplace quality indicators.
Customer details contained in a lead may include name, mobile number, location, requirement, category, description, preferred timing and other information supplied for the enquiry. Access is restricted until the applicable unlock and must then be used only for the submitted requirement.
Back to contents6. Payments, subscriptions and credit records
We process order identifiers, plan selection, billing cycle, price, GST, credit quantity, bonus credits, payment gateway order and payment identifiers, signature or webhook verification results, status, fulfilment time, subscription dates, credit allocations, deductions, expiry and balance history.
The payment gateway directly handles sensitive payment credentials such as full card data, CVV or UPI PIN. Findoly may receive masked or limited payment metadata and status information necessary to verify, reconcile, support and document the transaction.
Back to contents7. Device, log and technical information
When you use the Platform, servers and security systems may log IP address, browser type, operating system, device characteristics, requested URL, referring URL, response status, timestamps, session state, error details, request identifiers and performance information.
We use this information to deliver pages, diagnose failures, secure the service, prevent fraud, investigate incidents, enforce limits and improve reliability.
Back to contents8. Support and grievance communications
If you contact support or submit a complaint, we process your email address, registered mobile number, description, attachments, transaction or lead references, correspondence history, resolution notes and any information reasonably needed to investigate.
Please do not send unnecessary sensitive personal data, OTPs, passwords, full card details or UPI PINs. We may redact or restrict access to information not needed for the case.
Back to contents9. Sources of information
Information may come directly from you, your authorised organisation, Findoly’s CRM and internal teams, customer enquiry channels, payment gateways, OTP providers, banks or network status, hosting and security systems, location or mapping services, support correspondence and lawful public or third-party verification sources.
Where information comes from another source, we use it only where we have a lawful and legitimate basis and according to any applicable notice or restriction.
Back to contents10. Purposes of processing
- Create, verify, maintain and secure Provider accounts.
- Match Providers with relevant enquiries and enforce marketplace visibility rules.
- Display restricted lead information after an authorised unlock.
- Create orders, verify payments, allocate, deduct and expire credits, and maintain subscriptions.
- Provide dashboards, records, support and grievance handling.
- Prevent fraud, spam, customer-data misuse, unauthorised access and transaction abuse.
- Improve product reliability, matching, usability and operational decision-making.
- Comply with law, court orders, tax, accounting, audit, payment and regulatory obligations.
- Establish, exercise or defend legal claims and enforce Platform terms.
11. Lawful processing, consent and legitimate uses
We process personal data for lawful purposes connected with account onboarding, performance of the Provider relationship, requested transactions, security, compliance and other legitimate uses recognised by applicable law. Where consent is required, the relevant notice will describe the purpose and you may withdraw consent through the stated method, subject to consequences for services that cannot operate without the data.
Withdrawal does not affect processing already lawfully completed and does not require deletion of records that must be retained for a transaction, security, legal claim or statutory obligation.
Back to contents12. Matching and automated processing
The Platform uses rule-based processing to determine which enquiries may be displayed, using factors such as approved categories, subcategories, service PIN codes, distance, account status, lead status, priority, expiry and marketplace limits. These rules support relevance and access control.
Findoly may review and update such rules. A Provider may contact support about an apparent matching or eligibility error. The Platform does not represent that automated matching is a final assessment of a Provider’s professional suitability or a guarantee of business.
Back to contents13. Service and promotional communications
We may send OTPs, security alerts, account notices, lead alerts, payment confirmations, credit or subscription updates, policy notices and support responses through the registered channels. These are transactional or service communications required to operate the account.
Promotional communication, where used, will be managed according to applicable consent and opt-out requirements. Opting out of marketing does not stop essential security, transaction or account messages.
Back to contents14. Service providers and processors
We may share limited personal data with vendors that provide OTP delivery, payment processing, cloud hosting, databases, security, monitoring, email, customer support, mapping, analytics, legal, accounting or audit services. They receive only information reasonably necessary for their function and are expected to protect it under contractual or legal obligations.
Current integrations may include the Findoly OTP service, Razorpay checkout and payment infrastructure, cloud or database providers, and mapping services. Providers may also choose to open WhatsApp or another external service from a lead page; that service then processes information under its own terms.
Back to contents15. Internal access and CRM synchronisation
Provider information may be synchronised with Findoly’s CRM so authorised personnel can approve accounts, manage categories, service areas, eligibility, credits, support and operational records. Access is limited according to role and business need.
Findoly personnel may access records to support the Provider, investigate misuse, reconcile payments, administer lead distribution, maintain systems and meet legal obligations.
Back to contents16. Sharing between Customers and Providers
Before unlock, the Platform limits the customer information visible to a Provider. After a successful unlock, the Provider receives the information available for that enquiry so it can respond to the customer’s stated requirement.
A Customer may receive or be told information about a Provider where necessary to facilitate the enquiry, support transparency, investigate a complaint or operate a provider listing. Findoly does not authorise either party to use the other’s information for unrelated purposes.
Back to contents17. Legal, safety and corporate disclosures
We may disclose information where reasonably necessary to comply with law, legal process, court or regulatory direction; protect rights, safety or property; investigate fraud, cyber incidents, unlawful content or customer-data misuse; enforce agreements; or establish, exercise or defend claims.
If Findoly undergoes a merger, acquisition, financing, restructuring, insolvency or transfer of all or part of the business, information may be transferred with appropriate confidentiality and legal safeguards.
Back to contents19. Data retention
We retain personal data for as long as reasonably necessary for the purpose collected, including while an account is active and for an appropriate period afterwards. Retention depends on the type of record, transaction history, account status, fraud and security risk, support needs, legal limitation periods, tax or accounting duties and dispute requirements.
OTP rate-limit records are designed to expire automatically after their security purpose. Session cookies expire according to configured duration or logout. Transaction, credit, lead-unlock, audit and grievance records may be retained longer because they evidence financial or contractual activity. Data may be deleted, anonymised or aggregated when no longer required.
Back to contents20. Security safeguards
We use reasonable administrative, technical and organisational measures such as OTP authentication, signed sessions, secure production cookies, CSRF protection, origin checks, rate limits, role-based access, payment-signature verification, restricted lead visibility, database controls, logging and secure transport configuration.
No system is completely secure. You must protect your device, mobile number and session, use trusted networks, log out from shared devices and report suspected compromise. Do not send OTPs or payment secrets to anyone claiming to be Findoly support.
Back to contents21. Accuracy and correction
Providers should keep their information accurate and notify support when a correction cannot be made through the Platform. Some profile fields are controlled through Findoly’s CRM and may require verification before update.
We may request evidence to prevent unauthorised changes. Correcting a display field does not require alteration of historical transaction records that were accurate when created.
Back to contents22. Access, correction, erasure and other rights
Subject to applicable law and its commencement, you may request information about personal data processed by Findoly, correction of inaccurate or incomplete data, erasure of data no longer required, and grievance redressal. You may also have rights concerning consent withdrawal or nomination where provided by law.
Requests must be sent from a verifiable channel and include enough detail to identify the account and request. We may ask for reasonable verification, reject fraudulent or excessive requests, redact another person’s data, and retain information where processing is required by law, contract, security, payment reconciliation or legal claims.
Back to contents23. Account closure and deletion requests
A request to close a Provider account may stop future access but does not automatically erase all records. Findoly may preserve transaction, invoice, credit, lead-unlock, complaint, security and audit records for legal, accounting, fraud-prevention and dispute purposes.
Where deletion is appropriate, Findoly may delete or de-identify data after completing verification and any required retention. Closure does not convert credits into cash or change the Refund Policy.
Back to contents24. Children and authorised business use
The Provider Portal is for adults acting for service businesses and is not intended for children. You must not create an account for a child or submit a child’s personal data unless there is a lawful, necessary and properly authorised reason.
If we learn that a child’s data was submitted contrary to this rule, we may restrict the account and take reasonable steps to remove or protect the information, subject to legal retention.
Back to contents25. Processing and transfers across locations
Findoly and its service providers may process information in locations where they operate infrastructure or support services. Any transfer outside India will be handled subject to applicable restrictions, contractual protections and government directions in force at the relevant time.
We do not promise that every vendor or data copy is located in a particular city or state unless a specific written agreement says so.
Back to contents26. Third-party sites and services
Links to Razorpay, WhatsApp or other third-party services are provided for convenience. Their privacy policies govern information they collect directly. Findoly does not control their independent processing and you should review their terms before use.
This Policy does not cover a Provider’s own website, CRM, messaging, call-recording or customer database.
Back to contents27. Policy changes
We may update this Policy for legal, security, vendor or product changes. The revised date will be displayed. Material changes may also be notified through the Platform or registered contact details. Where law requires fresh consent, we will request it before the relevant processing.
Back to contents28. Privacy questions and grievances
Send privacy requests and questions to support@findoly.com with the subject “Privacy Request”. Include the registered mobile number, the right or issue involved and sufficient detail to verify and locate the information.
The Grievance Redressal Policy explains escalation and response handling.
Back to contents