logo 022-69032946

PRIVACY POLICY

1. Introduction

Shriram Credit Company Limited (“SCCL”, “the Company”, “we”, “us” or “our”) is a Non-Banking Financial Company registered with the Reserve Bank of India (“RBI”), with its registered office at Shriram House, No.-4, Burkit Road, T. Nagar, Chennai – 600 017, Tamil Nadu, India. This Privacy Policy (“Policy”) explains how we collect, use, process, disclose share, retain, secure and protect any information provided by the Customer (“you/yours” or the “user/customer/visitor/subscriber/client” your when you access our website https://www.shriramcredit.in and our digital lending applications (together, the "Platform") and avail our Loan Against Mutual Funds and related services (the "Services").

This Policy is published in compliance with, and is to be read with, the following, as amended from time to time:

  • the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 ("DPDP") to the extent applicable and in force from time to time;
  • the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
  • the RBI Digital Lending Directions and the RBI Key Facts Statement circular;
  • the Aadhaar Act, 2016 and UIDAI regulations; and other Applicable Law.

Please read this Policy carefully. By continuing to use the Services, you agree to this Policy. If you do not agree, please do not use the Platform.

2. Acknowledgment and Consent

Based on the Services you avail or intend to avail, the Company shall collect data from you for the purpose of meeting the Client's needs in respect of the provision of the services. Upon visiting the website, you agree that you will provide information while availing the Services, and you hereby agree and acknowledge that you submit your information to the Company.

Kindly review this Privacy Policy thoroughly. Therefore, by engaging with our website or utilizing any service or product, you hereby provide your unconditional consent or agreement to SCCL, and you acknowledge and confirm that you have (i) completed 18 years of age;(ii) not disqualified under Applicable Law. (iii) resident of India. You acknowledge and confirm that you are eligible to avail the relevant Services, are not disqualified from doing so under Applicable Law and satisfy any applicable residency, KYC and product eligibility requirements. You confirm that any information that you have provided that may describe you and your identity is true and complete. By using this website and services herein, you agree and consent to the collection, use, storage, processing, sharing, transfer, and disclosure of your personal and sensitive information as described and collected by us in accordance with this policy and any other policies references herein. If you do not agree with this policy, kindly do not access the website and Services. You acknowledge that you possess all legal rights and lawful authority to share the information with us. Where you provide Personal Data relating to any other individual, you represent that you are authorised or otherwise legally permitted to provide such information to SCCL and that SCCL may process such information for the purposes described in this Policy. Furthermore, you recognize that by collecting, sharing, processing, and transferring information provided by you, it shall not cause any loss or wrongful gain to you or any other person. You agree not to provide any information that is unlawful, misleading, fraudulent, unauthorised or that infringes the rights of any third party. SCCL shall be entitled to rely upon the information provided by you, subject to its verification processes and Applicable Law.

3. Definitions

  • "Personal Data" means any data about you that identifies you, directly or indirectly, or is capable of identifying you, whether directly or in combination with other information, and includes sensitive personal data or information as defined under Applicable Law.
  • "Data Principal" means you, the individual to whom the Personal Data relates.
  • "Data Fiduciary" means SCCL, which determines the purpose and means of processing your Personal Data.
  • "Data Processor" means a person or entity that processes Personal Data on behalf of SCCL, as applicable under Applicable Law.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, sharing, disclosure, retention and erasure.
  • "Applicable Law" means all applicable laws, statutes, rules, regulations, notifications, circulars, directions, guidelines, orders, standards and regulatory requirements applicable to SCCL, the Platform, the Services or the processing of Personal Data, including those issued by the RBI, UIDAI, SEBI, CERT-In and other competent authorities, as amended or replaced from time to time.

4. Information we collect

Guided by the principle of data minimisation, we collect only the information reasonably necessary for the Services. We indicate mandatory and optional fields, and you may choose not to provide information by not using a particular feature.

In connection with providing the Services, the personal data we collect from you may be classified into:

(a) Information you provide

Name, date of birth, contact details (mobile, e-mail, address), PAN, KYC documents / identifiers, bank account details, mutual fund folio / holding details, income or employment information where required, and any information you submit through forms or in support of your application.

(b) Information collected automatically

When you use the Platform we may collect technical and usage data such as IP address, device type and identifiers, operating system, browser type, network information, and details of your interactions (pages viewed, features used, access times), including through cookies and similar technologies. We may also collect application, transaction, security and diagnostic logs, including information reasonably necessary to authenticate users, secure the Platform, detect unauthorised access, investigate fraud or security incidents, maintain audit trails and comply with Applicable Law.

(c) Information from third parties

With your consent or as permitted by law, we may receive information from credit information companies / bureaus, account aggregators, RTAs / depositories (CAMS, KFintech, CDSL, NSDL), KYC registries, and our service providers and partners, for identity verification, fraud prevention, collateral verification and credit assessment. The service providers and Lending Service Providers we work with are listed on our Partners page at https://www.shriramcredit.in/our-partners.

(d) Vendors / service providers we work with

The table below sets out, by function, the third-party vendors and service providers who process information on our behalf for the Services.

Function / Purpose Category of Partner SCCL Partner / Vendor Name
PAN validation Verification Service Provider Digio
eKYC via DigiLocker DigiLocker Requester Entity Digio
eAgreement (e-Signing of loan documents) Digital Signature / e-Sign Service Provider Digio
Bank account verification (penny drop) Bank Account Verification Partner Digio / Cashfree
eNACH mandate registration Payment / Mandate Processing Partner Digio
Credit bureau / credit assessment Credit Information Company Experian (Digitap)
MF-NAV fetch Mutual Fund Data / NAV Service Provider Global Data Feeds / Value Research
Repayment payment gateway — UPI Payment Aggregator Cashfree
Repayment payment gateway — Net Banking Payment Aggregator Cashfree
Repayment payment gateway — Debit Card Payment Aggregator Cashfree
SMS / OTP delivery Communication Service Provider ValueFirst
Mutual fund portfolio fetch Account Aggregator / Portfolio Data Provider MF Central
CKYC record fetch / upload KYC Registry Service Provider Digio
Liveliness check / selfie & photo match Fraud & Risk Analytics Provider Digio
Digital signature certificate issuance Digital Signature Certifying Authority Capricorn
Lending Service Provider(s) for the LAMF product Lending Service Provider (LSP) https://www.shriramcredit.in/our-partners

5. Lawful grounds for processing

We process your Personal Data on one or more of the following grounds under Applicable Law:

  • your consent, given for a specified purpose (separate, explicit consent is taken for direct marketing, which you may opt in or out of);
  • performance of the contract (the loan) with you;
  • compliance with our legal and regulatory obligations; and
  • other legitimate uses permitted by law.

Where applicable, processing may also be undertaken where the Personal Data has been voluntarily provided by you for a specified purpose, where processing is necessary for compliance with a legal obligation or lawful order, for prevention, detection or investigation of offences or fraud, for protection of SCCL's rights and interests, or pursuant to any other lawful ground or legitimate use recognised under Applicable Law.

You may withdraw consent at any time (see Section 11). Withdrawal of consent shall not affect the lawfulness of any processing carried out prior to such withdrawal and shall not apply to any processing of Personal Data that is necessary for compliance with Applicable Law, performance of the contract, protection of our legitimate interests or any other lawful basis permitted under Applicable Law. Withdrawal for essential data — such as KYC or collateral information — may affect your ability to avail or continue the Services; in such circumstances, we may be unable to provide or continue providing the Services or may take such other action as may be permitted under Applicable Law. We will inform you of such implications at the point of withdrawal.

6. KYC, execution and device permissions

With your explicit consent captured in the digital journey, we facilitate KYC through the Central KYC Registry (CKYC/CERSAI), Aadhaar-based eKYC/OKYC (UIDAI, voluntary, with an Officially Valid Document alternative), DigiLocker and PAN validation. Your Aadhaar number and core biometrics are used only as permitted by law. SCCL shall not store or collect core biometric information except where expressly permitted under Applicable Law. Aadhaar-related information may be disclosed or shared with authorised entities, service providers, regulators, governmental authorities or other persons only where permitted or required under Applicable Law and, where required, with appropriate consent. We also process the data needed to execute your loan documents electronically (e-Sign) and to register your auto-debit mandate (e-NACH / NACH).

Where the Platform requests access to device features, such access is taken only once during the onboarding journey, for a stated purpose, and only with your explicit consent:

Permission Purpose
Camera / microphone One-time access to capture a selfie and scan/photograph KYC documents, for identity verification and auto-filling fields.
Location One-time access to verify your location and geo tagging, for KYC and service-eligibility purposes.
SMS / financial data (if enabled) If and only to the extent enabled with your consent, one-time access to financial/transaction SMS to assess income and creditworthiness. Personal SMS is not read; the data is encrypted and is not shared with third parties.
Call recording Calls made to or received from our customer support, verification or collections teams may be recorded and monitored for quality assurance, staff training, dispute resolution and fraud prevention, in accordance with Applicable Law.

You may deny or later withdraw these permissions through your device settings. Withdrawal or denial of any such permission may affect our ability to process your application, assess your eligibility, provide or continue the Services, or perform certain functions of the Platform. We do not collect biometric data except as permitted under Applicable Law, and we do not access your contacts or personal media except as expressly stated above for document upload or where otherwise permitted or required under Applicable Law. Any access to camera, microphone, location or other device functionality permitted under the RBI Digital Lending Directions shall be limited to what is necessary for onboarding/KYC or another expressly permitted purpose, shall be one-time where required, shall be subject to explicit consent and shall be maintained with an appropriate audit trail.

7. How we use your information

We use your information for the following core purposes:

  • verifying your identity and completing KYC;
  • assessing your creditworthiness, eligibility and collateral, and processing, disbursing and servicing your loan;
  • lien-marking, monitoring and, where required, invoking the pledge on your mutual fund units;
  • fraud prevention, security and risk management;
  • customer support and service-related communications; and
  • complying with legal, regulatory and audit obligations.

Secondary purposes include improving our products and services, and analytics and research (generally using anonymised data). We will not use your Personal Data for a materially new purpose without your renewed, explicit consent.

8. Sharing and disclosure

We share your information strictly on a need-to-know basis and under confidentiality obligations, with:

  • regulated financial partners, banks / NBFCs and credit bureaus, for loan processing, disbursement and credit reporting;
  • Lending Service Providers, RTAs / depositories, and service providers who assist with KYC, verification, hosting, analytics, payments, customer support and collections;
  • governmental, regulatory, law-enforcement or judicial authorities, where required by Applicable Law or legal process; and
  • a successor entity in the event of a merger, acquisition or restructuring, which will remain bound by this Policy.

We may also share information with Data Processors, technology providers, cloud and hosting providers, payment and mandate service providers, KYC and authentication providers, fraud-prevention service providers, collection/recovery service providers and other persons engaged by SCCL where such sharing is reasonably necessary for the Services, permitted or required under Applicable Law, or undertaken pursuant to your consent where consent is required. The current list of Lending Service Providers and partners with whom your information may be shared is maintained on our Partners page at https://www.shriramcredit.in/our-partners. We do not sell your Personal Data. We do not share your government identifiers (PAN, Aadhaar, VID) with unauthorised third parties, and your Aadhaar number is never disclosed except to the extent permitted or required under Applicable Law.

Where the Platform integrates a third-party software development kit (SDK), the SDK provider may collect limited technical data on our behalf — such as device identifiers, in-app workflow status and location — which is used solely for analytics, fraud prevention and delivering personalised in-app notifications. Any such SDK provider is contractually bound to protect this data and to use it only for the stated purposes; we do not permit such provider to use the Personal Data for the purposes unrelated to the Services, including independent advertising or profiling, except where separately permitted by Applicable Law and where required, based on separate consent.

We do not currently engage third-party advertising companies or ad agencies to serve targeted advertisements on the Platform. Should this change, we will update this Policy in advance and provide you with a clear opt-out mechanism before any such use begins.

9. Data localisation

Your Personal Data is stored on servers located in India. Where any processing by a service provider involves storage outside India, we ensure appropriate safeguards consistent with Applicable Law; in all cases, storage and processing comply with RBI and DPDP requirements.

10. Retention and erasure

We retain your information only for as long as necessary for the purpose for which it was collected, or as required under Applicable Law (including PMLA and RBI record-keeping requirements), whichever is longer. Indicatively:

  • non-personally-identifiable and transaction-SMS data: retained for about one (1) year or for such longer period as may be necessary or required under Applicable Law or for the purposes set out in this Policy;
  • core loan, KYC and servicing data: retained for a minimum of five (5) years from closure of the relationship, or such longer period as Applicable Law requires or as needed to defend legal claims.

Notwithstanding the above indicative periods, SCCL may retain Personal Data, records, logs, communications and related information for longer periods where required or permitted under Applicable Law, including requirements relating to KYC, AML/CFT, PMLA, RBI directions, taxation, accounting, audit, dispute resolution, litigation, investigation, fraud prevention, enforcement of contractual rights or establishment, exercise or defence of legal claims. Where different laws prescribe different retention periods, the longer or otherwise applicable statutory/regulatory retention period shall apply.

When the purpose is served and no legal requirement to retain remains, we erase or securely destroy the data (including copies) in accordance with our data retention and disposal policy and the erasure requirements under DPDP.

11. Your rights as a Data Principal

Subject to Applicable Law, you have the right to:

  • Access obtain a summary of the Personal Data we hold about you and how it is processed;
  • Correction and updation have inaccurate, incomplete or outdated data corrected or updated;
  • Erasure request deletion of your data, and to have the app "delete / forget" your data, subject to legal retention requirements;
  • Withdraw consent previously given — through the in-app privacy settings (as easily as it was given) or by writing to the contact in Section 14 — and manage or revoke device permissions through your device settings;
  • Grievance redressal readily register a grievance with us (see Section 14); and
  • Nominate another individual to exercise your rights in the event of death or incapacity, as provided under DPDP.

To exercise these rights, or to restrict sharing of your information with third parties (other than statutory / regulatory authorities), write to us at the contact in Section 14. All consent and withdrawal actions are securely logged for audit and compliance.

12. Cookies

We use cookies and similar technologies to operate the Platform, remember your preferences, analyse usage and improve our Services. You can control cookies through your browser settings; disabling some cookies may limit certain features. Cookies do not by themselves identify you unless you provide identifying information.

Where the Platform integrates any Google API-based service or SDK (such as Google Sign-In, Maps or Analytics), our use and transfer of information received through those Google APIs, we will handle such information in accordance with Applicable Law, and the terms applicable to the relevant Google service, including its Limited Use requirements, where applicable.

13. How we keep your data secure

We apply reasonable physical, administrative and technical safeguards consistent with Applicable Law and industry standards, including:

  • encryption of Personal Data in transit using Transport Layer Security (TLS 1.2 or above), and encryption at rest;
  • firewalls, access controls, authentication procedures (including OTP), and restriction of access to authorised personnel under confidentiality obligations;
  • monitoring, intrusion detection and secure hosting through our service providers.

No system can be completely secure. In the event of a personal-data breach, we follow our incident-management process and comply with the notification requirements of the DPDP Rules, CERT-In and RBI, including notifying the Data Protection Board and affected Data Principals within the timelines prescribed.

Your login password is stored using industry-standard encryption such that it cannot be retrieved or viewed in readable form, even by our own personnel. Backup drives and storage media containing your information are similarly encrypted. You are responsible for keeping your login credentials confidential and must not share them with any third party; please contact our Grievance Redressal Officer immediately (see Section 14) if you suspect unauthorised access to or use of your account.

14. Grievance redressal and contact

In according with the data privacy laws as applicable for any question, request or complaint about your Personal Data or this Policy, contact our Grievance Redressal Officer:

Name Grievance Redressal Officer
Address Shriram Credit Company Limited, Shriram House, No.-4, Burkit Road, T. Nagar, Chennai – 600 017, Tamil Nadu, India
E-mail grievanceredressal@shriramcredit.in
Phone 022-69032946

The Grievance Redressal Officer shall address complaints relating to digital lending, privacy and data processing in accordance with Applicable Law and SCCL's applicable grievance redressal mechanism. Where a complaint relates to a Lending Service Provider or Digital Lending App operated by an LSP, SCCL shall remain responsible for addressing the complaint in accordance with applicable RBI requirements.

If your complaint is not resolved within the timelines prescribed by RBI / DPDP, you may escalate to the RBI under the Reserve Bank – Integrated Ombudsman Scheme via the Sachet portal (https://sachet.rbi.org.in), or to the Data Protection Board of India as provided under DPDP.

You must provide the following information in customer's complaint:

  • Identification of the information provided by Customer.
  • Clear statement as to the information concerned.
  • User address, telephone number or e-mail address.

You may also be required to provide sufficient details to enable SCCL to identify the relevant account, application, transaction or processing activity and to verify your identity.

15. Children

The Platform and Services are not intended for, and SCCL does not knowingly provide lending Services to, individuals below 18 years of age. SCCL shall not knowingly process Personal Data of a child except where such processing is permitted or required under Applicable Law and, where applicable, after obtaining verifiable parental consent in the manner prescribed by Applicable Law.

16. Changes to this Policy

We may update this Policy from time to time. The current version is published on the Platform, and material changes will be notified as required by Applicable Law. Please revisit this page periodically. Your continued use of the Services confirms your acceptance of the updated Policy. This Policy is reviewed at least annually or as required.