Privacy Policy
Last updated: 23 August 2026
Finumph Pvt (hereinafter referred to as "Company") establishes and presents the privacy policy as follows, in order to protect the personal information of data subjects who use "NinFin", hereby referred as "Application", and resolve any relevant complaint.
1. Purpose of Processing Personal Information
Company collects and uses personal information for the following purposes.
- Membership registration and management: confirmation of membership intent, identification/authentication, maintenance and management of membership, prevention of illegal use of services, sending various notices, etc.
- Provision of goods or services: provision of service, delivery of contract/invoice, provision of basic service and customized service, verification of identity, age verification, bill payment and settlement, debt collection, etc.
- Managing consumer complaints: identification of the data subject, confirmation of complaints, contact/notification for fact-finding, and notification of processing results.
- Marketing and Advertising: provision of customized advertisements, opportunities to participate in events, statistics on the use of services by data subjects, etc.
- Improvement of existing services and development of new and customized services.
- Processing of pseudonymized information for statistical preparation, scientific research, and preservation of records in accordance with the DPDP Act.
2. Items of Personal Information Processed
Company collects and processes the following personal information of users of Application.
Information collected through membership registration (obligatory)
Email, password, first name, phone number, date of birth.
Information collected when using paid service
- When paying by credit card: payment information such as the name of the card company and card number.
- In case of bank transfer: payment information such as the name of the account holder, account number, and bank holding the account.
- When paying by mobile phone number/UPI: payment information such as phone number, VPA ID and telecommunication company.
Information collected automatically through use of the Application
Information is collected through the user's input, the user's receiving of text messages or Application notices, or the user's reconnection to the Application. The received SMS is used for automatic entry of household account details. If you sign up as a member, it will be sent to the server for synchronization and storage.
Information collected on Android devices: received SMS content (sender details, transaction details), received date and time, local storage access, Android device ID, notification access, etc.
When using the service, the following personal information items are automatically created and collected: cookies, service use records (user behaviour, user data logging), device information (mobile phone model name, OS name, and version information), self identifiers (Android ID, device ID), etc.
For managing consumer complaints
Collects and processes necessary information among the above from the user.
3. Period of Retention and Use for Personal Information
Company retains and uses the user's personal information while the user uses services as a member, and when either the user requests withdrawal from membership, deletion of account or Company achieves the purpose of collection and use of personal information, the Company will immediately destroy the relevant personal information. However, if the Company terminates the service use contract according to the Terms of Use, the relevant personal information will be preserved for one year to prevent unauthorized re-registration and use of service, and the information is deleted immediately after the end of the relevant period.
Notwithstanding the foregoing, the following information is retained for the period specified for the following reasons.
- Personal information related to use of service (log records): until the end of the tenure of the services of the Application.
- Records on withdrawal of contract or subscription, and records on payment and supply of goods: 1 year.
4. Provision of Personal Information to Third Parties
- The Company may provide personal information to third parties only to the extent of authentication or hosting of the Application, or when there are special provisions required by the law.
- The Company may provide pseudonymized information to a third party, and in that case, the Company shall comply with Indian regulations.
5. Processing Personal Information Subsequent to Outsourcing of Work and Overseas Transfer
The Company entrusts the following personal information processing tasks to consignees who use servers located overseas, for smooth personal information processing.
Google Inc. (Google Firebase)
- Personal information transferred: app store/version used, country of residence, mobile number, email, name, language setting, device model information, time of accessing the service/history of use, etc.
- Country: United States of America.
- Date and method of transfer: transfer through the network when using the service.
- Consignee's purpose of use: authentication of users.
- Period of retention and use: until user account deletion.
Amazon Web Services
- Personal information transferred: transaction details, user behaviour, profile information.
- Country: United States of America.
- Date and method of transfer: transfer through the network when using the service.
- Consignee's purpose of use: hosting of the Application backend.
- Period of retention and use: until user account deletion.
6. Use and Provision of Personal Information within the Scope Reasonably Related to the Purpose of Collection
The Company may use or provide personal information to a third party without the consent of the data subject, considering each of the following criteria within a reasonable scope and the original purpose of collection.
- Whether the interests of the data subject are unreasonably infringed: judgment based on whether the interests of the data subject are substantially infringed in relation to the additional purpose of use and whether the infringement of the interests is unreasonable.
- Whether measures necessary to secure safety, such as pseudonymization or encryption, have been taken: judgment by considering whether safety measures are taken in consideration of the possibility of infringement.
7. User's Rights and Methods for Exercising the Rights
- The user can exercise the right to read, correct, delete and suspend processing his or her personal information against the Company at any time.
- The exercise of these rights can be made to the Company by making changes via the Application, or by e-mail, and the Company will take action without delay.
- The exercise of these rights may be done through an agent such as a legal representative of the data subject or a person who has been delegated. In this case, a power of attorney must be submitted to the Company.
- In accordance with relevant laws, the exercise of the user's right to access, correct, delete, or suspend the processing of personal information may be restricted.
- Request for correction and deletion of personal information cannot be requested if the information is required to be collected according to other laws.
8. Destruction Procedures and Methods for Personal Information
- The Company destroys the personal information without delay when the personal information becomes unnecessary, such as in the cases of the expiration of the personal information retention period, or achievement of the purpose of processing.
- If personal information needs to be preserved in accordance with the laws and regulations even when the personal information retention period agreed by the user has elapsed or the purpose of processing has been achieved, the personal information will be moved to a different place or stored in a separate database.
Destruction procedures and methods
- Destruction procedures: the Company selects the personal information that needs to be destroyed, and destroys it with the approval of the Company's personnel for management of personal information.
- Destruction method: the Company destroys personal information recorded and stored in electronic file format using technical methods so that the information cannot be reproduced, and personal information recorded and stored in paper documents is destroyed by crushing or incineration with a shredder.
9. Technical and Administrative Measures to Ensure Safety of Personal Information
For users' personal information, Company is taking the following technical and administrative measures to ensure safety so that personal information is not lost, stolen, leaked, altered, or damaged.
- Administrative measures: establishment and implementation of internal management plans for personal information, regular employee training, etc.
- Technical measures: password and data encryption, security program installation, etc.
10. International Transfer of Personal Information
The Company may store, process, and transmit personal information in India or any other location as required by the third party integrations. Data may also be stored locally on the devices the user uses to access the service. When the Company transfers personal information outside India, the Company will ensure that a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- The Company will only transfer personal information to countries that have been deemed to provide an adequate level of protection for personal data.
- Where the Company uses certain service providers, we may use specific contracts which give personal data the same protection it has in India.
11. Protection of Personal Information of Children
Our service is not directed at children. The Company does not knowingly collect personal information of children under the age of 13 or an equivalent minimum age as prescribed in the laws of the relevant jurisdiction.
12. Personnel for Management of Personal Information
The Company has designated the person in charge of personal information management and handling complaints about personal information, and the contact information is as follows.
- Name: Irfan Modak
- Affiliation: Director
- Contact: support@finumph.com
The user can inquire about all personal information protection-related inquiries, handling complaints, damage relief, etc. that occurred while using the Company's service to the person in charge of personal information protection and the department in charge. The Company will respond and handle the inquiries without delay.
13. Amendment
If there are any additions, deletions, or changes to the contents of this Privacy Policy, we will notify users in advance through a notice on the website at least 7 days prior to the revision.
Questions about this policy can be sent to support@ninfin.app.