Shriram Credit Company Limited (“SCCL”, “the Company”, “we”, “us” or “our”) is a Non-Banking Financial Company registered with the Reserve Bank of India (“RBI”), with its registered office at Shriram House, No.-4, Burkit Road, T. Nagar, Chennai – 600 017, Tamil Nadu, India. This Privacy Policy (“Policy”) explains how we collect, use, process, disclose share, retain, secure and protect any information provided by the Customer (“you/yours” or the “user/customer/visitor/subscriber/client” your when you access our website https://www.shriramcredit.in and our digital lending applications (together, the "Platform") and avail our Loan Against Mutual Funds and related services (the "Services").
This Policy is published in compliance with, and is to be read with, the following, as amended from time to time:
Please read this Policy carefully. By continuing to use the Services, you agree to this Policy. If you do not agree, please do not use the Platform.
Based on the Services you avail or intend to avail, the Company shall collect data from you for the purpose of meeting the Client's needs in respect of the provision of the services. Upon visiting the website, you agree that you will provide information while availing the Services, and you hereby agree and acknowledge that you submit your information to the Company.
Kindly review this Privacy Policy thoroughly. Therefore, by engaging with our website or utilizing any service or product, you hereby provide your unconditional consent or agreement to SCCL, and you acknowledge and confirm that you have (i) completed 18 years of age;(ii) not disqualified under Applicable Law. (iii) resident of India. You acknowledge and confirm that you are eligible to avail the relevant Services, are not disqualified from doing so under Applicable Law and satisfy any applicable residency, KYC and product eligibility requirements. You confirm that any information that you have provided that may describe you and your identity is true and complete. By using this website and services herein, you agree and consent to the collection, use, storage, processing, sharing, transfer, and disclosure of your personal and sensitive information as described and collected by us in accordance with this policy and any other policies references herein. If you do not agree with this policy, kindly do not access the website and Services. You acknowledge that you possess all legal rights and lawful authority to share the information with us. Where you provide Personal Data relating to any other individual, you represent that you are authorised or otherwise legally permitted to provide such information to SCCL and that SCCL may process such information for the purposes described in this Policy. Furthermore, you recognize that by collecting, sharing, processing, and transferring information provided by you, it shall not cause any loss or wrongful gain to you or any other person. You agree not to provide any information that is unlawful, misleading, fraudulent, unauthorised or that infringes the rights of any third party. SCCL shall be entitled to rely upon the information provided by you, subject to its verification processes and Applicable Law.
Guided by the principle of data minimisation, we collect only the information reasonably necessary for the Services. We indicate mandatory and optional fields, and you may choose not to provide information by not using a particular feature.
In connection with providing the Services, the personal data we collect from you may be classified into:
Name, date of birth, contact details (mobile, e-mail, address), PAN, KYC documents / identifiers, bank account details, mutual fund folio / holding details, income or employment information where required, and any information you submit through forms or in support of your application.
When you use the Platform we may collect technical and usage data such as IP address, device type and identifiers, operating system, browser type, network information, and details of your interactions (pages viewed, features used, access times), including through cookies and similar technologies. We may also collect application, transaction, security and diagnostic logs, including information reasonably necessary to authenticate users, secure the Platform, detect unauthorised access, investigate fraud or security incidents, maintain audit trails and comply with Applicable Law.
With your consent or as permitted by law, we may receive information from credit information companies / bureaus, account aggregators, RTAs / depositories (CAMS, KFintech, CDSL, NSDL), KYC registries, and our service providers and partners, for identity verification, fraud prevention, collateral verification and credit assessment. The service providers and Lending Service Providers we work with are listed on our Partners page at https://www.shriramcredit.in/our-partners.
The table below sets out, by function, the third-party vendors and service providers who process information on our behalf for the Services.
| Function / Purpose | Category of Partner | SCCL Partner / Vendor Name |
|---|---|---|
| PAN validation | Verification Service Provider | Digio |
| eKYC via DigiLocker | DigiLocker Requester Entity | Digio |
| eAgreement (e-Signing of loan documents) | Digital Signature / e-Sign Service Provider | Digio |
| Bank account verification (penny drop) | Bank Account Verification Partner | Digio / Cashfree |
| eNACH mandate registration | Payment / Mandate Processing Partner | Digio |
| Credit bureau / credit assessment | Credit Information Company | Experian (Digitap) |
| MF-NAV fetch | Mutual Fund Data / NAV Service Provider | Global Data Feeds / Value Research |
| Repayment payment gateway — UPI | Payment Aggregator | Cashfree |
| Repayment payment gateway — Net Banking | Payment Aggregator | Cashfree |
| Repayment payment gateway — Debit Card | Payment Aggregator | Cashfree |
| SMS / OTP delivery | Communication Service Provider | ValueFirst |
| Mutual fund portfolio fetch | Account Aggregator / Portfolio Data Provider | MF Central |
| CKYC record fetch / upload | KYC Registry Service Provider | Digio |
| Liveliness check / selfie & photo match | Fraud & Risk Analytics Provider | Digio |
| Digital signature certificate issuance | Digital Signature Certifying Authority | Capricorn |
| Lending Service Provider(s) for the LAMF product | Lending Service Provider (LSP) | https://www.shriramcredit.in/our-partners |
We process your Personal Data on one or more of the following grounds under Applicable Law:
Where applicable, processing may also be undertaken where the Personal Data has been voluntarily provided by you for a specified purpose, where processing is necessary for compliance with a legal obligation or lawful order, for prevention, detection or investigation of offences or fraud, for protection of SCCL's rights and interests, or pursuant to any other lawful ground or legitimate use recognised under Applicable Law.
You may withdraw consent at any time (see Section 11). Withdrawal of consent shall not affect the lawfulness of any processing carried out prior to such withdrawal and shall not apply to any processing of Personal Data that is necessary for compliance with Applicable Law, performance of the contract, protection of our legitimate interests or any other lawful basis permitted under Applicable Law. Withdrawal for essential data — such as KYC or collateral information — may affect your ability to avail or continue the Services; in such circumstances, we may be unable to provide or continue providing the Services or may take such other action as may be permitted under Applicable Law. We will inform you of such implications at the point of withdrawal.
With your explicit consent captured in the digital journey, we facilitate KYC through the Central KYC Registry (CKYC/CERSAI), Aadhaar-based eKYC/OKYC (UIDAI, voluntary, with an Officially Valid Document alternative), DigiLocker and PAN validation. Your Aadhaar number and core biometrics are used only as permitted by law. SCCL shall not store or collect core biometric information except where expressly permitted under Applicable Law. Aadhaar-related information may be disclosed or shared with authorised entities, service providers, regulators, governmental authorities or other persons only where permitted or required under Applicable Law and, where required, with appropriate consent. We also process the data needed to execute your loan documents electronically (e-Sign) and to register your auto-debit mandate (e-NACH / NACH).
Where the Platform requests access to device features, such access is taken only once during the onboarding journey, for a stated purpose, and only with your explicit consent:
| Permission | Purpose |
|---|---|
| Camera / microphone | One-time access to capture a selfie and scan/photograph KYC documents, for identity verification and auto-filling fields. |
| Location | One-time access to verify your location and geo tagging, for KYC and service-eligibility purposes. |
| SMS / financial data (if enabled) | If and only to the extent enabled with your consent, one-time access to financial/transaction SMS to assess income and creditworthiness. Personal SMS is not read; the data is encrypted and is not shared with third parties. |
| Call recording | Calls made to or received from our customer support, verification or collections teams may be recorded and monitored for quality assurance, staff training, dispute resolution and fraud prevention, in accordance with Applicable Law. |
You may deny or later withdraw these permissions through your device settings. Withdrawal or denial of any such permission may affect our ability to process your application, assess your eligibility, provide or continue the Services, or perform certain functions of the Platform. We do not collect biometric data except as permitted under Applicable Law, and we do not access your contacts or personal media except as expressly stated above for document upload or where otherwise permitted or required under Applicable Law. Any access to camera, microphone, location or other device functionality permitted under the RBI Digital Lending Directions shall be limited to what is necessary for onboarding/KYC or another expressly permitted purpose, shall be one-time where required, shall be subject to explicit consent and shall be maintained with an appropriate audit trail.
We use your information for the following core purposes:
Secondary purposes include improving our products and services, and analytics and research (generally using anonymised data). We will not use your Personal Data for a materially new purpose without your renewed, explicit consent.
We share your information strictly on a need-to-know basis and under confidentiality obligations, with:
We may also share information with Data Processors, technology providers, cloud and hosting providers, payment and mandate service providers, KYC and authentication providers, fraud-prevention service providers, collection/recovery service providers and other persons engaged by SCCL where such sharing is reasonably necessary for the Services, permitted or required under Applicable Law, or undertaken pursuant to your consent where consent is required. The current list of Lending Service Providers and partners with whom your information may be shared is maintained on our Partners page at https://www.shriramcredit.in/our-partners. We do not sell your Personal Data. We do not share your government identifiers (PAN, Aadhaar, VID) with unauthorised third parties, and your Aadhaar number is never disclosed except to the extent permitted or required under Applicable Law.
Where the Platform integrates a third-party software development kit (SDK), the SDK provider may collect limited technical data on our behalf — such as device identifiers, in-app workflow status and location — which is used solely for analytics, fraud prevention and delivering personalised in-app notifications. Any such SDK provider is contractually bound to protect this data and to use it only for the stated purposes; we do not permit such provider to use the Personal Data for the purposes unrelated to the Services, including independent advertising or profiling, except where separately permitted by Applicable Law and where required, based on separate consent.
We do not currently engage third-party advertising companies or ad agencies to serve targeted advertisements on the Platform. Should this change, we will update this Policy in advance and provide you with a clear opt-out mechanism before any such use begins.
Your Personal Data is stored on servers located in India. Where any processing by a service provider involves storage outside India, we ensure appropriate safeguards consistent with Applicable Law; in all cases, storage and processing comply with RBI and DPDP requirements.
We retain your information only for as long as necessary for the purpose for which it was collected, or as required under Applicable Law (including PMLA and RBI record-keeping requirements), whichever is longer. Indicatively:
Notwithstanding the above indicative periods, SCCL may retain Personal Data, records, logs, communications and related information for longer periods where required or permitted under Applicable Law, including requirements relating to KYC, AML/CFT, PMLA, RBI directions, taxation, accounting, audit, dispute resolution, litigation, investigation, fraud prevention, enforcement of contractual rights or establishment, exercise or defence of legal claims. Where different laws prescribe different retention periods, the longer or otherwise applicable statutory/regulatory retention period shall apply.
When the purpose is served and no legal requirement to retain remains, we erase or securely destroy the data (including copies) in accordance with our data retention and disposal policy and the erasure requirements under DPDP.
Subject to Applicable Law, you have the right to:
To exercise these rights, or to restrict sharing of your information with third parties (other than statutory / regulatory authorities), write to us at the contact in Section 14. All consent and withdrawal actions are securely logged for audit and compliance.
We use cookies and similar technologies to operate the Platform, remember your preferences, analyse usage and improve our Services. You can control cookies through your browser settings; disabling some cookies may limit certain features. Cookies do not by themselves identify you unless you provide identifying information.
Where the Platform integrates any Google API-based service or SDK (such as Google Sign-In, Maps or Analytics), our use and transfer of information received through those Google APIs, we will handle such information in accordance with Applicable Law, and the terms applicable to the relevant Google service, including its Limited Use requirements, where applicable.
We apply reasonable physical, administrative and technical safeguards consistent with Applicable Law and industry standards, including:
No system can be completely secure. In the event of a personal-data breach, we follow our incident-management process and comply with the notification requirements of the DPDP Rules, CERT-In and RBI, including notifying the Data Protection Board and affected Data Principals within the timelines prescribed.
Your login password is stored using industry-standard encryption such that it cannot be retrieved or viewed in readable form, even by our own personnel. Backup drives and storage media containing your information are similarly encrypted. You are responsible for keeping your login credentials confidential and must not share them with any third party; please contact our Grievance Redressal Officer immediately (see Section 14) if you suspect unauthorised access to or use of your account.
In according with the data privacy laws as applicable for any question, request or complaint about your Personal Data or this Policy, contact our Grievance Redressal Officer:
| Name | Grievance Redressal Officer |
| Address | Shriram Credit Company Limited, Shriram House, No.-4, Burkit Road, T. Nagar, Chennai – 600 017, Tamil Nadu, India |
| grievanceredressal@shriramcredit.in | |
| Phone | 022-69032946 |
The Grievance Redressal Officer shall address complaints relating to digital lending, privacy and data processing in accordance with Applicable Law and SCCL's applicable grievance redressal mechanism. Where a complaint relates to a Lending Service Provider or Digital Lending App operated by an LSP, SCCL shall remain responsible for addressing the complaint in accordance with applicable RBI requirements.
If your complaint is not resolved within the timelines prescribed by RBI / DPDP, you may escalate to the RBI under the Reserve Bank – Integrated Ombudsman Scheme via the Sachet portal (https://sachet.rbi.org.in), or to the Data Protection Board of India as provided under DPDP.
You must provide the following information in customer's complaint:
You may also be required to provide sufficient details to enable SCCL to identify the relevant account, application, transaction or processing activity and to verify your identity.
The Platform and Services are not intended for, and SCCL does not knowingly provide lending Services to, individuals below 18 years of age. SCCL shall not knowingly process Personal Data of a child except where such processing is permitted or required under Applicable Law and, where applicable, after obtaining verifiable parental consent in the manner prescribed by Applicable Law.
We may update this Policy from time to time. The current version is published on the Platform, and material changes will be notified as required by Applicable Law. Please revisit this page periodically. Your continued use of the Services confirms your acceptance of the updated Policy. This Policy is reviewed at least annually or as required.