By visiting this Cashmama mobile application (“App”) (collectively, the “Platform”) and availing the services
By mere access to the Platform or any part thereof, you expressly consent to Cashmama (“we” or “our” or “us” or
“Onion credit private limited”) use and disclosure of your personal information in accordance with this Privacy
using Services or accessing our Platform (“user” or “you” or “your”).
If you do not agree to this Policy or any part thereof, please do not use or access our Platform or any part
COLLECTION OF PERSONALLY IDENTIFIABLE INFORMATION
When you use our Platform, whether our Website or our App, we collect and store your information (personal
information) which is provided by you from time to time by explicitly seeking permissions from YOU to get the
required information. Our primary goal in doing so is to provide you a safe, efficient, smooth and customized
experience and services. This allows us to provide services and features that meets your needs, and to customize
our Platform to make your experience safer and easier and to improve the services provided by us. More
importantly, we collect personal information from you that we consider necessary for achieving the
In general, you can browse the Website or App without telling us who you are or revealing any personal
information about yourself. However, to create an account on the Website or App, you must provide us with
certain basic information required to provide customized services. The information we collect from you, inter
a. your full name;
c. mailing address;
d. postal code;
e. family details;
f. university/college details;
g. phone number;
h. Permanent Account Number (PAN);
i. Academic records and certificates.
Where possible, we indicate the mandatory and the optional fields. You always have the option to not provide your
personal information by choosing not to use a particular service or feature on the Platform. We also collect
other identifiable information (your payment card details and transaction histories on the Platform) from you
when you set up a free account with us as further detailed below. While you can browse some sections of our
Platform without being a registered member as mentioned above, certain activities (such as availing of loans
from the third party lenders on the Platform) requires registration and for you to provide the above details.
The Platform shall clearly display the personal information it is collecting from you, and you have the option
to not provide such personal information. However, this will limit the services provided to you on the
COLLECTION OF MOBILE NUMBER AND EMAIL ADDRESS
When you sign up with us, we collect your mobile number and email address to uniquely identify you. This helps us
ensure that no unauthorised device or person is acting on your behalf.
COLLECTION OF CONTACT
Our app requires this permission to detect references and to auto fill the data during your loan application process for seamleass user journey.
COLLECTION OF LOCATION
We collect and monitor the information about the location of your device to provide serviceability of your loan
application, to reduce risk associated with your loan application and to provide pre-approved customised loan
offers. This also helps us to verify the address, make a better credit risk decision and expedite your KYC
COLLECTION OF INSTALLED APPLICATIONS
We collect a list of the installed applications’ metadata information which includes the application name,
package name, installed time, updated time, version name and version code of each installed application on your
device to assess your credit worthiness and enrich your profile with pre-approved customized loan offers.
We require the storage information permission that allows the App to enable you to upload photos and/or documents
to complete the application form during your loan application journey.
We require the camera information permission to provide you an easy/smooth experience and to enable you to click
photos of your KYC documents along with other requisite documents and upload the same on the App during your
loan application journey.
COLLECTION OF OTHER NON-PERSONAL INFORMATION
We automatically track certain information about you based upon your behaviour on our Platform. We use this
information to do internal research on our users' demographics, interests, and behaviour to better understand,
protect and serve our users and improve our services. This information is compiled and analysed on an aggregated
basis. We also collect your Internet Protocol (IP) address and the URL used by you to connect your computer to
the internet, etc. This information may include the URL that you just came from (whether this URL is on our
Website or not), which URL you next go to (whether this URL is on our Website or not), your computer browser
information, and your IP address.
to other lending websites / apps and online marketplace websites / apps. Use of this information helps Us
identify You in order to make our Website more user friendly. Most browsers will permit You to decline cookies
but if You choose to do this it might affect service on some parts of Our Website.
If you choose to make a purchase through the Website, we collect information about your buying behaviour.
We retain this information as necessary to resolve disputes, provide customer support and troubleshoot problems
as permitted by law.
If you send us personal correspondence, such as emails or letters, or if other users or third parties send us
correspondence about your activities or postings on the Website, we collect such information into a file
specific to you.
COLLECTION OF DEVICE INFORMATION
The information the App collects, and how that information is used, depends on how you manage your privacy
controls on your device.
When you install the App, we store the information we collect with unique identifiers tied to the device you’re
We collect information from the device when you download and install the App and explicitly seek permissions from
YOU to get the required information from the device.
The information we collect from your device includes the unique ID i.e. IMEI number, information on operating
system, SDK version and mobile network information including carrier name, SIM Serial and SIM Slot, your profile
information, list of installed apps, wi-fi information.
We collect information about your device to provide automatic updates and additional security so that your
account is not used in other people’s devices. In addition, the information provides us valuable feedback on
your identity as a device holder as well as your device behaviour, thereby allowing us to improve our services
and provide an enhanced customized user experience to you.
USE AND DISCLOSURE OF YOUR PERSONAL AND OTHER INFORMATION
We access, store and use the information we collect from to provide our Services, to research and develop new
We use personal information to provide the services you request, to customize your user experience and to improve
our services. To the extent we intent to use your personal information to market any product to you, we will
provide you the ability to opt-out of such uses.
We use your personal information to:
a. resolve disputes;
b. troubleshoot problems;
c. help promote a safe service;
d. analytical analysis;
e. measure consumer interest and satisfaction in our products and services;
f. inform you about online and offline offers, products, services, and updates;
g. customize your experience;
h. detect and protect us against suspicious or illegal activity, fraud and other criminal activity
i. enforce our terms and conditions;
j. improvement of our services and as otherwise described to you at the time of collection
In our efforts to continually improve our product and service offerings, we collect and analyze demographic and
profile data about our users' activity on our Website.
USE OF YOUR DEVICE INFORMATION
We use the information provided by You in the following ways:
a. to establish identity and verify the same;
b. monitor, improve and administer our Website / Platform;
c. provide our service i.e. perform credit profiling for the purpose of facilitating loans to You.
d. design and offer customized products and services offered by our third party financial partners;
e. analyse how the Website is used, diagnose service or technical problems and maintain security;
f. send communications notifications, information regarding the products or services requested by You or process
queries and applications that You have made on the Website;
g. manage Our relationship with You and inform You about other products or services We think You might find of
h. conduct data analysis in order to improve the Services / Products provided to the User;
i. use the User information in order to comply with country laws and regulations;
j. to conduct KYC for our third party lending partners based on the information shared by the User;
k. use the User information in other ways permitted by law to enable You to take financial services from our
We will use and retain Your information for such periods as necessary to provide You the Services on our Website,
to comply with our legal obligations, to resolve disputes, and enforce our agreements.
DISCLOSURE TO THIRD PARTIES
We will share Your information with only our registered third parties including our regulated financial partners
for provision of services on the Website and/or for facilitation of a loan / facility to a User. We will share
Your information with third parties only in such manner as described below:
a. We disclose and share Your information with the financial service providers, banks or NBFCs and Our third
party partners for facilitation of a loan or facility or line of credit or purchase of a product;
b. We share Your information with our third party partners in order to conduct data analysis in order to serve
You better and provide services or Products on our Website;
c. We may disclose Your information, without prior notice, if We are under a duty to do so in order to comply
with any legal obligation or an order from the government and/or a statutory authority, or in order to enforce
protect the rights, property, or safety of Us, Our users, or others. This includes exchanging information with
other companies and organizations for the purposes of fraud protection and credit risk reduction.
d. We will disclose the data / information provided by a User with other technology partners to track how the
User interact with Website on Our behalf.
e. We and our affiliates may share Your information with another business entity should we (or our assets) merge
with, or be acquired by that business entity, or re-organization, amalgamation, restructuring of business for
continuity of business. Should such a transaction occur than any business entity (or the new combined entity)
receiving any such information from Us shall be bound by this Policy with respect to your information.
f. We will disclose the information to our third party technology and credit partners to perform credit checks
and credit analysis like Credit Bureaus or third party data source providers;
g. We will share Your information under a confidentiality agreement with the third parties and restrict use of
the said Information by third parties only for the purposes detailed herein. We warrant that there will be no
unauthorised disclosure of your information shared with third parties.
h. By using the Platform, you hereby grant your consent to the Company to share/disclose your Personal
Information (i) To the concerned third parties in connection with the Services; and (ii) With the governmental
authorities, quasi-governmental authorities, judicial authorities and quasi-judicial authorities, in accordance
with applicable laws of India.
In case we use or disclose your information for any purpose not specified above, we will take your explicit
LINK TO THIRD-PARTY SDK
Our application has a link to a registered third party SDK which collects data on our behalf and data is stored
to a secured server to perform a credit risk assessment. We ensure that our third party service provider takes
extensive security measures in order to protect your personal information against loss, misuse or alteration of
Our third-party service provider employs separation of environments and segregation of duties and have strict
role-based access control on a documented, authorized, need-to-use basis. The stored data is protected and
stored by application-level encryption. They enforce key management services to limit access to data.
Furthermore, our registered third party service provider provides hosting security – they use industry-leading
anti-virus, anti-malware, intrusion prevention systems, intrusion detection systems, file integrity monitoring,
and application control solutions.
posted, those changes are effective immediately, unless stated otherwise. We encourage you to periodically
review this page for the latest information on our privacy practices. Continued access or use of the Services
ACCESSING YOUR INFORMATION / CONTACTING US
At any point of time Users can choose to edit/modify or delete/withdraw any Personal Information shared for use
of the Platform. Please note that deleting or withdrawing information may affect the Services we provide to you.
In case of modification of Personal Information, Users will be required to furnish supporting documents relating
to change in Personal Information for the purpose of verification by the Company.
YOUR PRIVACY CONTROLS
You have certain choices regarding the information we collect and how it is used:
a. Device-level settings: Your device may have controls that determine what information we collect. For example,
you can modify permissions on your Android device for access to Camera or Audio permissions.
b. Delete your entire App account.
c. You can also request to remove content from our servers based on applicable law or by writing to our Grievance
The Website/App intends to protect your personal information and to maintain its accuracy as confirmed by you. We
implement reasonable physical, administrative and technical safeguards to help us protect your personal
information from unauthorized access, use and disclosure. For example, we encrypt all sensitive personal
information when we transmit such information over the internet. We also require that our registered third party
service providers protect such information from unauthorized access, use and disclosure.
Our Platform has stringent security measures in place to protect the loss, misuse and alteration of information
under control. We endeavour to safeguard and ensure the security of the information provided by you. We use
Secure Sockets Layers (SSL) based encryption, for the transmission of the information, which is currently the
required level of encryption in India as per the law.
We blend security at multiple steps within our products with the state of the art technology to ensure our
systems maintain strong security measures and the overall data and privacy security design allow us to defend
our systems ranging from low hanging issue up to sophisticated attacks.
In addition, the Website and App have been certified for the following security certifications:
a. ISO 9001: being the international standard that details requirements for a quality management system (QMS).
Organizations use the standard to demonstrate the ability to consistently provide products and services that
meet customer and regulatory requirements with the requisite security protections.
b. ISO 27001 (formally known as ISO/IEC 27001:2005): is a specification for an information security management
system (ISMS) and is the suggested level of certification required under the Information Technology Act, 2000.
An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls
involved in an organization’s information risk management processes.
We work hard to protect from unauthorized access, alteration, disclosure or destruction of information we hold,
a. We use encryption to keep your data private while in transit;
b. We offer security feature like an OTP verification to help you protect your account;
c. We review our information collection, storage, and processing practices, including physical security measures,
to prevent unauthorized access to our systems;
d. We restrict access to personal information to our employees, contractors, and agents who need that information
in order to process it. Anyone with this access is subject to strict contractual confidentiality obligations and
may be disciplined or terminated if they fail to meet these obligations.
e. Compliance & Cooperation with Regulations and applicable laws;
g. Data transfers
We or our affiliates maintain your information on servers located in India. Data protection laws vary among
countries, with some providing more protection than others. We also comply with certain legal frameworks
relating to the transfer of data as mentioned and required under the Information Technology Act, 2000.
When we receive formal written complaints, we respond by contacting the person who made the complaint. We work
with the appropriate regulatory authorities, including local data protection authorities, to resolve any
complaints regarding the transfer of your data that we cannot resolve with you directly.
h. Bureau Enquiry
We will enquire with one or more Credit Bureaus on one or more affiliate National Banking Financial Company’s
(NBFC) behalf to provide you with your loan amount.
LINKS TO OTHER SITES
Our Website links to other websites that may collect personally identifiable information about you. We are not
responsible for the privacy practices or the content of those linked websites. With this Policy we’re only
addressing the disclosure and use of data collected by Us. If You visit any websites through the links on the
Website, please ensure You go through the privacy policies of each of those websites. Their data collection
practices, and their policies might be different from this Policy and We do not have control over any of their
policies neither do we have any liability in this regard.
By using the Website/App and/ or by providing your information, you consent to the collection and use of the
of what information we collect, how we use it, and under what circumstances we disclose it.
In accordance with Information Technology Act 2000 and rules made there under, the name and contact details of
the Grievance Officer are provided below:
Name: Mr. Sharat Konatham
Address: 1/1, Trillion Co-working, Madhuranagar, Hyderabad - 500032, India
Time: Mon - Sat (9:30 - 18:30)