Shiprocket Limited, (previously known as Shiprocket Private Limited and originally known as Bigfoot Retail Solutions Private Limited (“BFRS”) (“We” or “Our” or “Us” or “Company” or “Shiprocket”) is a company duly incorporated under the provisions of the (Indian) Companies Act, 1956 (as amended from time to time), which provides end to end technology platform/services designed to enable e-commerce transactions and logistics, checkout, payments, financing (Only as Lending Service Provider), order fulfilment, cross-border trade, warehousing, and enabling merchants to carry out their online and offline sales through its digital platform, website and mobile application (“Services”) under the brand name ‘Shiprocket’.
This Privacy Policy (“Policy”) governs the collection, storage, processing, use, disclosure, and transfer of personal and financial information of Borrowers in connection with our Services and is framed in strict compliance with the RBI Digital Lending Guidelines, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the Digital Personal Data Protection Act, 2023 (“DPDPA”), and all other applicable laws in force.
By accessing or using our Platform (website, mobile application, or any other digital interface operated by the Company), You expressly consent to the terms of this Policy.
1. INTRODUCTION AND REGULATORY CONTEXT
As an LSP operating under the RBI Digital Lending Guidelines, the Company is bound by strict data governance obligations. Key regulatory requirements that shape this Policy include:
- LSPs shall not store borrower data other than for the purpose of facilitating lending transactions, unless explicitly consented to by the Borrower and permitted under applicable law.
- All data collected must be on a “need-to-know” basis and with explicit, informed, and purpose-specific consent of the Borrower.
- LSPs shall ensure that the data collected is only stored on servers located within India (data localisation requirement) and must not be shared with any entity without express borrower consent.
- LSPs are prohibited from accessing the mobile phone resources of the Borrower such as files, media, contact list, call logs, telephony functions, etc., except for OTP or device tokens required for specific financial transactions.
- The Borrower has the right to receive a Key Fact Statement (“KFS”) prior to execution of any loan contract.
This Policy must be read in conjunction with the Terms and Conditions of Use, the Key Fact Statement, and the Loan Agreement (as applicable) provided by the Company and the respective RE.
2. DEFINITIONS
For the purpose of this Policy, the following terms shall have the meanings assigned to them below:
- “Personal Information” means any data that relates to a natural person who is directly or indirectly identifiable by reference to such data, including name, address, date of birth, contact details, financial information, and other identifying details.
- “Sensitive Personal Data or Information (SPDI)” means Personal Information relating to password; financial information such as bank account, credit card, debit card, or other payment instrument details; physical, physiological, and mental health condition; sexual orientation; medical records and history; biometric information; and any other information designated as sensitive under applicable law.
- “Regulated Entity (RE)” means the bank, NBFC, or other RBI-regulated lending institution on whose behalf the Company operates as an LSP and in whose books the loan is ultimately originated.
- “Lending Service Provider (LSP)” means the Company acting as an agent of the RE to carry out activities pertaining to digital lending, including customer acquisition, credit assessment support, loan servicing, recovery, and related functions.
- “Digital Lending App (DLA)” means the Company’s mobile application or web-based platform used to deliver the Services to Borrowers.
- “Borrower” or “User” means any individual or entity accessing the Platform or availing of the Services, including visitors and prospective loan applicants.
- “KFS” means the Key Fact Statement, a standardised document containing key terms of the loan, including the Annual Percentage Rate (APR), fees, charges, and recovery mechanisms, as mandated by the RBI.
- “Platform” means the Company’s website, mobile application, DLA, and any other digital interface through which Services are accessed.
- “RBI Digital Lending Guidelines” means The Reserve Bank of India (Non-Banking Financial Company – Credit Facilities) Directions 2025 and as updated from time to time.
- “Third-Party Service Provider” means any entity engaged by the Company to assist in delivering Services, including credit bureaus, KYC verification agencies, payment aggregators, cloud service providers, and analytics firms.
- “Children’s Data” means Personal Information of a person who has not attained the age of 18 years.
3. CATEGORIES OF PERSONAL INFORMATION COLLECTED
Subject to applicable consents, the Company may collect the following categories of Personal Information from Borrowers to facilitate lending Services:
3.1 Identity & Contact Information
- Full name, date of birth, gender
- PAN Card, Aadhaar number (masked, as per UIDAI guidelines), Voter ID, Passport, Driving Licence, or any other Government-issued ID
- Residential and permanent address
- Email address and mobile number
3.2 Financial Information
- Bank account details (account number, IFSC, branch) for disbursement and repayment purposes
- Income details, salary slips, income tax returns, Form 16, and other income proof documents
- Bank statements and account aggregator (AA) data fetched through RBI-licensed Account Aggregator framework (with explicit consent)
- GST registration details (for business loan applicants)
- Credit bureau reports and credit scores fetched from CIBIL, Experian, Equifax, CRIF, or any other RBI-recognised credit information company
- Existing loan details and repayment history
3.3 Employment & Business Information
- Employer name, designation, and employment type
- Business registration documents (for self-employed or business loan applicants)
- Business vintage, turnover, and financials (for business loans)
3.4 Device & Technical Information
- Device identifier, device model, and operating system version
- IP address and approximate geographical location
- App version and usage logs (for fraud detection and system security only)
- One-Time Password (OTP) and device token for authentication purposes only
IMPORTANT NOTICE: In strict compliance with the RBI Digital Lending Guidelines, the Company does NOT and shall NOT access or collect data from the Borrower’s device resources including contacts list, call logs, gallery/media files, SMS (except for OTP auto-read with consent), microphone, or camera (except for KYC document capture with consent). Any permission sought beyond the above shall be optional and non-coercive.
3.5 Transaction Information
- Loan application data, disbursement records, repayment schedules, and transaction history
- Bounce and delinquency records (for credit risk assessment)
- Recovery communications and settlement records
3.6 Communications & Support Data
- Call recordings and chat transcripts with customer support teams (retained for quality and compliance purposes)
- Complaints, grievances, and feedback submitted through the Platform
Note: We do not collect and process any BIOMETRIC DATA under the Services.
4. CONSENT FRAMEWORK
In accordance with the RBI Digital Lending Guidelines and the DPDPA, the Company shall obtain free, specific, informed, unambiguous, and revocable consent from the Borrower prior to collecting, using, or sharing their Personal Information. The following principles govern our consent practices:
- Consent shall be obtained before or at the time of collecting any Personal Information.
- Consent shall be granular — separate consent shall be sought for each distinct purpose of data collection and processing.
- Borrowers shall not be required to provide blanket consent for data sharing as a pre-condition to receiving the Services, except where such sharing is necessary for the core lending activity.
- A summary of consented data items, the purposes for which they are used, and the entities with whom such data may be shared shall be made available to the Borrower in the KFS and within the Platform.
- Borrowers may withdraw consent at any time; however, withdrawal may result in discontinuation of Services for which the consent was required. Withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal.
- The Company shall maintain a time-stamped consent artefact (digital consent log) for all consents obtained, accessible to the Borrower upon request.
5. PURPOSES FOR WHICH PERSONAL INFORMATION IS USED
Subject to applicable laws, the Company processes Personal Information only for the following specified, lawful, and necessary purposes:
- To evaluate and process loan applications, conduct credit appraisal, and facilitate loan origination on behalf of the RE.
- To verify Borrower identity through KYC/e-KYC processes in compliance with RBI’s Master Direction on KYC, 2016 (as amended).
- To perform credit risk assessment using bureau data, bank statements, financial statements, and other credit scoring methodologies.
- To facilitate loan disbursement to the Borrower’s designated bank account.
- To generate and communicate the KFS, repayment schedules, loan agreements, and other contractual documents.
- To manage loan repayments, EMI collections, and settlement of dues via NACH, UPI, netbanking, and other RBI-approved payment mechanisms.
- To conduct fraud detection, anti-money laundering (AML) checks, and Know Your Customer (KYC) due diligence.
- To provide customer support, handle grievances, and ensure quality of service.
- To comply with legal, regulatory, and contractual obligations including reporting to credit bureaus, CERSAI, GSTN, income tax authorities, and other regulatory bodies.
- To send transactional communications, payment reminders, and service notifications.
- To send promotional communications with prior explicit consent, where permitted by law; Borrowers may opt out at any time.
- To perform analytics, reporting, and improvement of the Platform and Services in aggregated or pseudonymised form.
- To maintain audit trails, system logs, and operational diagnostics for security and regulatory compliance.
- To facilitate recovery proceedings as permitted by law in case of default, including lawful communications with Borrowers through RBI-compliant recovery agents.
We collect only such Personal Information as is strictly necessary for the purposes described above. Any processing beyond these purposes shall require separate, specific consent.
6. DATA LOCALISATION AND STORAGE
In full compliance with the RBI Digital Lending Guidelines and applicable data protection law:
- All Personal Information collected by the Company shall be stored exclusively on servers and data centres located within the territory of India.
- No Personal Information of Borrowers shall be transferred to, stored in, or processed from servers located outside India without express RBI approval and requisite Borrower consent.
- Cloud services used by the Company shall be compliant with MEITY and RBI’s data localisation requirements.
- The Company shall maintain adequate documentation of data storage locations and shall make such information available to the RE and RBI upon request.
7. DISCLOSURE AND TRANSFER OF PERSONAL INFORMATION
7.1 Disclosure to the Regulated Entity (RE)
The Company, in its capacity as an LSP, shall share Borrower data with the respective RE as required for loan origination, underwriting, disbursement, and servicing. Such sharing shall be in accordance with the data sharing agreement between the Company and the RE and shall be limited to the purposes outlined therein.
7.2 Disclosure to Third-Party Service Providers
The Company may share Personal Information with authorised third parties strictly on a need-to-know basis, including:
- Credit information companies (CIBIL, Experian, Equifax, CRIF) for credit bureau enquiries and reporting.
- KYC/e-KYC service providers and video KYC platforms authorised by the RE/RBI.
- Account Aggregators (AAs) licensed by RBI under the Account Aggregator Framework.
- Payment service providers, payment aggregators, and banking correspondents for disbursement and collection.
- Cloud infrastructure and technology service providers for Platform operations.
- Legal and compliance advisors on a confidential basis.
Details of our Partners/ Service Provider/ Third Party with whom the Company may share your information on a need to know basis:
| S. No. | Name of Partner/ Service Provider/ Third Party |
|---|---|
| 1. | Crif High Mark Credit Information Services Private Limited |
| 2. | Finezza Information Technologies Private Limited |
All third-party service providers engaged by the Company shall be contractually bound to maintain the confidentiality and security of the Borrower’s Personal Information and to comply with applicable laws.
7.3 Disclosure Due to Legal Requirements
The Company may disclose Personal Information to government authorities, courts, tribunals, law enforcement agencies, or regulatory bodies (including RBI) to the extent required by applicable law, court order, or regulatory direction.
7.4 Disclosure to Recovery Agents
In the event of default, the Company may share relevant Borrower data with RBI-compliant recovery agents. All such agents shall be bound by the Company’s code of conduct for debt collection, compliant with RBI’s Fair Practices Code and the extant guidelines on outsourcing. The Company shall not share Borrower data with unauthorised third-party apps or platforms for recovery purposes.
7.5 Prohibition on Unauthorised Sharing
The Company strictly prohibits and shall not engage in any of the following:
- Sale of Borrower data to any third party for marketing, profiling, or any non-lending purpose.
- Sharing of Borrower data with any entity not disclosed in this Policy or the consent artefact without express Borrower consent.
- Sharing of Borrower contact list, call log data, or other device-level data with any party under any circumstances.
8. PROCESSING OF CHILDREN’S AND PERSONS WITH DISABILITY’S DATA
The Company’s Services are intended exclusively for individuals who are 18 years of age or older. We do not knowingly provide loan services to, or process the Personal Information of, any person below the age of 18 years. If we become aware that we have inadvertently collected data of a minor, we shall promptly delete such information and reject the associated loan application.
For Persons with Disabilities who have lawful guardians, the Company shall ensure that verifiable consent of the guardian is obtained prior to processing such Person’s data, in accordance with applicable law.
9. SECURITY PRACTICES AND PROCEDURES
The Company implements industry-standard technical, operational, managerial, and physical security measures to protect Personal Information, including:
- End-to-end encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Multi-factor authentication (MFA) for access to internal systems and Borrower accounts.
- Role-based access controls (RBAC) ensuring that employees access only the data necessary for their designated functions.
- Regular penetration testing, vulnerability assessments, and security audits in compliance with RBI IT security guidelines.
- Incident response and breach notification procedures compliant with DPDPA and CERT-In requirements.
- Data masking and tokenisation for sensitive financial identifiers.
- Comprehensive audit logs maintained for all data access and processing activities.
Notwithstanding the above, due to the inherent risks of internet-based communications, the Company cannot guarantee absolute security of data transmitted over the internet. The Company shall not be liable for any breach arising solely from factors beyond its reasonable control.
10. RETENTION OF PERSONAL INFORMATION
Personal Information shall be retained as follows:
- The Company shall store basic minimal data (i.e., name, address, contact details of the customer, etc.) that may be required to carry out their operations.
- Where the Borrower withdraws consent or closes their account, the Company shall erase or anonymise Personal Information unless retention is required by law or for the protection of the Company’s legal rights.
The Company shall not retain Personal Information beyond the periods specified above or beyond the period for which the purpose of processing exists, whichever is earlier.
11. BORROWER’S RIGHTS
In accordance with the DPDPA, SPDI Rules, and RBI Digital Lending Guidelines, Borrowers have the following rights in respect of their Personal Information:
- Right to Access: You may request a copy of the Personal Information held by the Company about you.
- Right to Correction: You may request correction, completion, or updating of any inaccurate, incomplete, or outdated Personal Information.
- Right to Erasure: You may request deletion of your Personal Information, subject to applicable legal retention requirements.
- Right to Withdraw Consent: You may withdraw your consent for processing of your Personal Information at any time. Such withdrawal shall not affect any processing already carried out prior to withdrawal.
- Right to Portability: Where technically feasible and legally permissible, you may request the Company to provide your Personal Information in a structured, commonly used, and machine-readable format.
- Right to Grievance Redressal: You have the right to file complaints and receive timely resolution through the Company’s Grievance Redressal Mechanism (as detailed in Section 13 of this Policy).
- Right to Specific Data and Data Retention: You have the right to restrict the usage and sharing of your data with Third Party.
To exercise any of the above rights, Borrowers may write to the Company’s Grievance Officer at the contact details provided in Section 13.
12. PROHIBITED CONDUCT ON THE PLATFORM
Borrowers shall not use the Platform to upload, transmit, or share any information that:
- Belongs to another person without their consent or legal authority.
- Is false, misleading, fabricated, or fraudulent, including misrepresentation of identity or financial status.
- Infringes any intellectual property rights, privacy rights, or other rights of any third party.
- Constitutes identity theft or impersonation of another person.
- Violates any applicable law, including laws related to anti-money laundering, counter-terrorism financing, or financial fraud.
- Contains malicious code, viruses, or any software designed to disrupt, damage, or impair the Platform.
13. GRIEVANCE REDRESSAL
In accordance with the RBI Digital Lending Guidelines, the Company has designated a Nodal Grievance Officer to address complaints and concerns related to this Privacy Policy and data processing practices:
Ashish Sabharwal
Email id: [email protected]
The Grievance Officer shall acknowledge receipt of complaints within 5 (five) business days and endeavour to resolve them within 30 (Thirty) calendar days of receipt. If a Borrower is not satisfied with the resolution, they may escalate their complaint to the RE or to the RBI Integrated Ombudsman Scheme (RBI-IOS) at https://rbi.org.in.
14. COOKIES AND TRACKING TECHNOLOGIES
The Platform may use essential cookies strictly necessary for the technical functioning of the Platform, including session management and security. The Company does not use tracking cookies for behavioural advertising or third-party analytics without Borrower consent. Borrowers may control cookie preferences through their device or browser settings; however, disabling essential cookies may affect the functionality of the Platform.
15. LINKS TO THIRD-PARTY PLATFORMS
The Platform may contain links to third-party websites or applications operated independently by the RE or other partners. The Company is not responsible for the privacy practices or content of such third-party platforms. Borrowers are advised to review the privacy policies of such third parties before providing any Personal Information.
16. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time and shall notify you regarding the Policy as well as any such changes periodically and at least once a year. However, you are advised to review this page/policy periodically for any changes. Your continued usage of the Services shall constitute your acceptance of the amended/updated Privacy Policy.
17. GOVERNING LAW AND JURISDICTION
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Gurugram, Haryana, India.