top of page

PRIVACY POLICY

Arthashastra ePayLater Financial Private Limited

("AEFPL", "Company", "we", "us", "our")

A Non-Banking Financial Company registered with the Reserve Bank of India

[CIN: U65999HR2019PTC078016| RBI Registration No.: N-14.03518]

Effective Date: 1st April 2026

1. Introduction

Arthashastra ePayLater Financial Private Limited (“AEFPL”, “Company”, “we”, “us” or “our”) is a Non-Banking Financial Company (“NBFC”) registered with the Reserve Bank of India (“RBI”) under Section 45-IA of the Reserve Bank of India Act, 1934. AEFPL is committed to protecting the privacy and Personal Data of its customers, applicants, co-borrowers, guarantors and website/application users (collectively, “You” or “User”).

This Privacy Policy (“Policy”) is an electronic record within the meaning of the Information Technology Act, 2000 and the rules framed thereunder, and does not require any physical, electronic or digital signature. This Policy has been framed with reference to, and is intended to operate in compliance with, applicable Indian law including the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules made thereunder, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Reserve Bank of India (Digital Lending) Directions, 2025 (consolidating the erstwhile Digital Lending Guidelines), the RBI Master Direction – Reserve Bank of India (Co-Lending Arrangements) Directions, the RBI Master Direction – Know Your Customer (KYC) Direction, 2016 (as amended), the Credit Information Companies (Regulation) Act, 2005 and Rules, 2006, the RBI Master Direction – Reserve Bank of India (Non-Banking Financial Company – Scale Based Regulation) Directions, 2023, and the Fair Practices Code prescribed for NBFCs.

This Policy explains how AEFPL, in its capacity as a Regulated Entity (“RE”) and lender, collects, uses, stores, processes, shares, discloses and protects Personal Data in connection with lending and co-lending products offered directly by AEFPL or jointly with its co-lending partner banks/NBFCs, and in respect of loans originated through Lending Service Providers (“LSPs”) engaged by AEFPL, including Arthashastra Fintech Private Limited operating as “ePayLater” (“ePayLater” or the “LSP”).

This Policy must be read together with AEFPL's Terms and Conditions, the applicable Key Fact Statement (“KFS”), the Most Important Terms and Conditions (“MITC”), the loan agreement, sanction letter, and any customer consent declarations presented to You during onboarding or the lending journey. By accessing AEFPL's digital lending applications/website, applying for a loan, or otherwise providing Personal Data to AEFPL or its authorised LSP, You confirm that You have read, understood and agree to this Policy, and consent to processing of Your Personal Data as described herein, wherever such consent is legally required.


 

2. Definitions
 

  • “Personal Data” / “Personal Information” means any data about an individual who is identifiable by or in relation to such data, in accordance with the DPDP Act.

  •  “Data Principal” means the individual to whom the Personal Data relates – i.e., You, as an applicant, borrower, co-borrower, guarantor or User.

  • “Data Fiduciary” means AEFPL, which determines the purpose and means of processing Personal Data as the Regulated Entity/lender.

  • “Regulated Entity” or “RE” means AEFPL and any co-lending bank/NBFC partner, each of which is directly regulated by the RBI and is the lender of record for its respective share of the loan.

  • “Lending Service Provider” or “LSP” means an agent engaged by AEFPL under an outsourcing arrangement to carry out one or more of AEFPL's lender functions, such as customer acquisition, underwriting support, pricing support, disbursement, servicing, monitoring, recovery or providing KFS to borrowers on behalf of AEFPL, including ePayLater and any other LSP empanelled by AEFPL from time to time.

  • “Co-Lending Arrangement” or “CLM” means an arrangement between AEFPL and one or more partner banks/NBFCs for joint lending, undertaken in accordance with RBI's colending framework, under which each RE takes exposure on its share of the loan on its own books.

  • “Digital Lending App(s)” or “DLA(s)” means the mobile application(s) and website(s) owned and operated by AEFPL and/or its LSP(s) used to source and service digital loans (collectively the “Platform”).

  • “Consent Manager” has the meaning assigned under the DPDP Act – a person registered with the Data Protection Board who acts as a single point of contact for You to give, manage, review and withdraw consent.

  • “Processing” means any operation performed on Personal Data, including collection, recording, storage, use, retrieval, disclosure, sharing, erasure or destruction.
     

3. About AEFPL and Our Lending Model

 

AEFPL is the lender and Regulated Entity for loans originated on its own books, either independently or through a Co-Lending Arrangement with partner banks/NBFCs. AEFPL relies on outsourcing arrangements with LSPs, including ePayLater, to perform customer-facing and support functions such as sourcing, onboarding facilitation, collection of documents, technology hosting of the Platform, customer support and recovery assistance.

Where a loan is disbursed under a Co-Lending Arrangement, AEFPL and its co-lending partner each fund and record their respective share of the loan on their own books as per the RBI's colending framework, and each such Regulated Entity is independently responsible for regulatory compliance in respect of its share of the loan, including grievance redressal. AEFPL remains responsible for ensuring that any LSP engaged by it complies with applicable law, including the

RBI Digital Lending Directions and this Policy, in respect of Personal Data handled on AEFPL's behalf.

 

Notwithstanding the involvement of an LSP or a co-lending partner in the customer journey, AEFPL, as the Data Fiduciary and RE, remains accountable for the manner in which Your Personal Data is collected, used and protected in connection with products and services availed from AEFPL.

 

4. Scope and Consent

 

This Policy applies to Personal Data collected by AEFPL (i) through the Platform, whether operated by AEFPL or its LSP; (ii) during onboarding, application, underwriting, disbursement, servicing, collections and recovery of any loan or credit facility; (iii) through customer support interactions; and (iv) through any other touchpoint where AEFPL processes Your Personal Data as the lender.

Where AEFPL relies on Your consent as the legal basis for processing, such consent will be free, specific, informed, unconditional and unambiguous, obtained through a clear affirmative action, and limited to Personal Data necessary for the specified purpose, in accordance with the DPDP Act and the RBI Digital Lending Directions. Wherever digital lending regulations require explicit, itemised consent (for instance, before accessing specific device permissions or before sharing data with third parties for purposes beyond loan performance), AEFPL or its LSP shall seek such consent separately and shall not use “bundled” consent.

Where processing is necessary for the performance of the loan contract, compliance with a legal obligation (such as KYC/AML law, credit reporting or RBI directions), or other grounds recognised under the DPDP Act, AEFPL may process Personal Data on that basis and will indicate this clearly at the point of collection.

5. Personal Data We Collect

The Personal Data AEFPL collects depends on the product applied for and the stage of Your customer journey, and may include:

5.1 Identity and Contact Data

  • Name, date of birth, gender, photograph, live/video image captured for identity verification, and voice recordings taken for consent authentication.

  • Mobile number, email address, residential and/or business address, and communication preferences.
     

5.2 KYC Data

  • Officially Valid Documents (“OVDs”) recognised under RBI's KYC Master Direction, including PAN (or Form 60), proof of possession of Aadhaar (in masked/redacted form, as permitted), Passport, Driving Licence, Voter's ID Card, and other documents as prescribed by RBI from time to time.

  • CKYC records retrieved from the Central KYC Registry, where applicable.
     

5.3 Financial and Credit Data 

  • Bank account details, income, employment/occupation and business details, GST information (where applicable), assets and liabilities.

  • Credit history and credit score obtained from Credit Information Companies (“CICs”) such as CIBIL, Experian, Equifax or CRIF High Mark, with Your consent, for credit assessment.

  • Loan account information, repayment history, and information exchanged with co-lending partner REs relating to Your loan.
     

5.4 Technical and Usage Data

  • Device identifiers, IP address, operating system, application version, network information, session and diagnostic logs.

  • Usage patterns on the Platform, including app navigation, feature usage and interaction logs, collected to secure the Platform and improve services.
     

5.5 Data We Do Not Collect

  • In line with RBI's Digital Lending Directions, AEFPL and its LSPs do not access Your contact list, call logs, or personal SMS/message logs, and do not seek continuous or background access to camera, microphone or location. AEFPL does not collect biometric data for lending purposes, other than a live photograph/video used solely for identity verification with Your explicit consent. Where any specific device permission is required for a defined purpose (such as onetime location capture for fraud checks or camera access for document capture), it will be sought only at the relevant step, with a clear explanation of purpose, and You may decline such permission, subject to the consequence that the corresponding feature or service may not be available.
     

6. How We Collect Your Personal Data 
 

  • Directly from You: information You submit while applying for a loan, registering on the Platform, uploading documents, or corresponding with AEFPL or its LSP by email, chat, phone or in-app support. 

  • Automatically, through the Platform: technical and usage data collected via cookies, SDKs and similar technologies when You use the DLA or website.

  • From Your LSP: where an LSP such as ePayLater has facilitated Your onboarding, the information collected by the LSP on AEFPL's behalf and with Your consent is transmitted securely to AEFPL for underwriting and lending decisions.

  • From co-lending partner REs: information exchanged between AEFPL and its co-lending partners strictly for the purpose of jointly originating and servicing Your loan.

  • From authorised third parties: Credit Information Companies, Account Aggregators (with Your consent, under the RBI Account Aggregator framework), identity verification utilities (such as UIDAI, NSDL, CDSL, CKYCR/CERSAI), and other regulatory or public databases, as permitted by law.
     

7. How We Use Your Personal Data

AEFPL processes Personal Data only for purposes connected with the lawful exercise of its functions as a lender, including:

 

  •  Verifying Your identity, conducting KYC/CKYC checks and onboarding You for a loan or credit facility. 

  • Assessing creditworthiness, including through CIC credit reports and Account Aggregatorbased financial information, and making underwriting and pricing decisions, subject to any applicable Digital Lending Directions on algorithmic/automated decision-making disclosures. 

  • Disbursing, servicing, monitoring and recovering the loan, including in respect of AEFPL's share of a co-lent loan.

  • Generating and delivering the Key Fact Statement, sanction letter, loan agreement and other mandated disclosures.

  • Reporting to Credit Information Companies as required under the Credit Information Companies (Regulation) Act, 2005.

  • Complying with RBI directions, the Prevention of Money Laundering Act, 2002 and rules thereunder, tax laws, and other applicable statutory or regulatory obligations.

  • Fraud prevention, detection and investigation, cybersecurity and Platform integrity.

  • Customer support, grievance redressal, and service-related or transactional communication.

  • Improving the Platform's functionality and security based on aggregated or anonymised usage information. 

  • With Your separate, specific consent: marketing communications about AEFPL's or its partners' products, which You may opt out of at any time without affecting service-related communications.
     

AEFPL does not use Personal Data for any purpose incompatible with the purpose disclosed at the time of collection, and does not sell or rent Personal Data to third parties for their independent marketing purposes.

 

8. Disclosure and Sharing of Personal Data
 

8.1 With Co-Lending Partner REs


Where Your loan is originated under a Co-Lending Arrangement, AEFPL shares the minimum Personal Data necessary with the relevant co-lending partner RE(s) for joint underwriting, disbursement, servicing, regulatory reporting and grievance redressal in respect of their share of the loan. Each co-lending partner RE processes such Personal Data as an independent Data Fiduciary/Regulated Entity, subject to its own privacy policy and applicable law.

8.2 With Our LSP(s)

AEFPL shares Personal Data with its empanelled LSP(s), including ePayLater, strictly to the extent required for the LSP to perform the outsourced functions entrusted to it (such as sourcing, onboarding support, servicing or recovery assistance) on AEFPL's behalf, under a written outsourcing agreement that binds the LSP to confidentiality, security and purpose-limitation obligations at least as protective as this Policy.

8.3 With Credit Information Companies and Regulators

AEFPL reports credit information to CICs and shares information with the RBI, other financial sector regulators, courts, law enforcement and government authorities where required by law or pursuant to a lawful order or direction.

8.4 With Other Authorised Service Providers

AEFPL may engage service providers for cloud hosting, identity verification, payment processing, Account Aggregator connectivity, communications, analytics and customer support, each acting on AEFPL's instructions and under contractual confidentiality and security obligations, and processing Personal Data only for the services entrusted to them.

8.5 Business Transfers

In the event of a merger, acquisition, restructuring, assignment or sale of AEFPL's loan portfolio or business, Personal Data may be transferred to the successor entity, subject to that entity's obligation to continue to protect such data in a manner consistent with this Policy and applicable law.

8.6 Publicly Available Data

AEFPL does not control, and is not responsible for, Personal Data that You choose to make publicly available, including on public forums, application-store reviews or social media.

9. Data Localisation and Cross-Border Transfer

In accordance with RBI's Digital Lending Directions, Personal Data collected by AEFPL and its LSP(s) for the purposes of digital lending is stored and processed on servers located in India. Any cross-border flow of such data for processing (for example, to a cloud service provider with processing infrastructure outside India, where used) shall be limited to processing purposes only, shall not result in storage of the underlying data outside India except as strictly permitted by applicable RBI directions, and shall be subject to appropriate contractual and technical safeguards. AEFPL does not transfer Personal Data to any country restricted by the Central Government under the DPDP Act.

10. Cookies and Similar Technologies

The Platform may use cookies and similar technologies to maintain secure sessions, remember preferences, understand usage patterns and improve performance. You may manage or disable cookies through Your browser settings; disabling certain cookies may affect Platform functionality. The AEFPL/LSP mobile application does not rely on browser cookies but may use comparable technologies necessary for authentication, security and performance. AEFPL does not control cookies placed by independent third parties whose content may be accessible through the Platform.

11. Data Security

AEFPL implements reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and maintains a documented information security programme covering access controls, encryption of data in transit and at rest (where appropriate), network and application security testing, system monitoring, and incident response and breach-notification procedures aligned with RBI's cybersecurity and Digital Lending directions. Access to Personal Data is restricted to authorised personnel and service providers on a need-to-know basis.

You are responsible for safeguarding Your login credentials, passwords and one-time passwords (OTPs), and for not knowingly sharing them with any third party. You must notify AEFPL immediately at the contact details in Section 15 if You suspect unauthorised access to Your account.

12. Data Retention

AEFPL retains Personal Data only for as long as necessary to fulfil the purposes described in this Policy, including the tenure of the loan, statutory limitation periods, and record-retention requirements prescribed by the RBI (including under KYC and Digital Lending Directions), the Prevention of Money Laundering Act, 2002, and other applicable law. Where an LSP has temporarily processed Personal Data on AEFPL's behalf during onboarding, such data is retained by the LSP only for the period reasonably necessary to complete that operational purpose, after which it is securely deleted or anonymised in accordance with AEFPL's data retention schedule. Once the retention purpose ceases and no legal obligation requires continued storage, Personal Data is securely deleted or anonymised.

13. Your Rights as a Data Principal

Subject to the DPDP Act and its exemptions, You may exercise the following rights in relation to Your Personal Data held by AEFPL: 

  • Right to Access Information: to obtain a summary of the Personal Data being processed and the processing activities undertaken by AEFPL. 

  • Right to Correction and Erasure: to request correction of inaccurate or incomplete Personal Data, and updation or erasure of Personal Data that is no longer necessary for the purpose for which it was collected, subject to AEFPL's obligation to retain records required by RBI, tax or other law. 

  • Right to Grievance Redressal: to have Your complaint regarding processing of Personal Data addressed by AEFPL in a timely and effective manner. 

  • Right to Nominate: to nominate another individual to exercise these rights on Your behalf in the event of death or incapacity.

  • Right to Withdraw Consent: to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal; withdrawal may affect AEFPL's or a co-lending partner's ability to continue providing the loan or related services.
     

Requests may be sent to AEFPL's Grievance Officer/Data Protection Officer at the details in Section 15, along with sufficient information to verify Your identity and locate the relevant Personal Data. AEFPL will endeavour to respond within 30 (thirty) days, or such shorter period as may be prescribed under applicable law, and will notify You if additional time is required.

Where You have engaged a Consent Manager registered under the DPDP Act, You may also manage, review or withdraw consent given to AEFPL through such Consent Manager, once the relevant framework is operationalised by the Data Protection Board.
 

14. Children's Data
 

The Platform and AEFPL's lending products are not intended for use by individuals who are minors under applicable law. AEFPL does not knowingly collect Personal Data from minors. Parents and legal guardians are requested to ensure that minors do not submit Personal Data to AEFPL or its LSP.
 

15. Grievance Redressal and Contact Details
 

In accordance with the RBI Digital Lending Directions and the Fair Practices Code, AEFPL has appointed a Grievance Redressal Officer to address complaints relating to digital lending, including Personal Data handling. If You are not satisfied with the resolution provided by AEFPL's LSP, You may escalate the grievance directly to AEFPL using the details below.
 

 

 

 

 

 

 

 

 

 

 

 

​​

If Your grievance remains unresolved within the timelines prescribed by RBI, You may escalate the matter to the RBI Ombudsman for Digital Transactions/NBFCs, or approach the appropriate grievance redressal mechanism prescribed under the RBI Integrated Ombudsman Scheme, details of which are available at www.rbi.org.in.
 

16. Third-Party Links and Services
 

The Platform may contain links to third-party websites or services, including those of co-lending partners, payment gateways or CICs. This Policy governs only Personal Data collected by AEFPL and does not extend to the privacy practices of such third parties, which are governed by their own privacy policies. AEFPL encourages You to review those policies independently.
 

17. Limitation of Liability and Force Majeure
 

AEFPL shall not be liable for any loss, damage or misuse of Personal Data arising from events beyond its reasonable control, including natural disasters, war, civil unrest, industrial action, government action, or unauthorised third-party access despite reasonable security measures (“Force Majeure Event”). This limitation does not affect any non-excludable liability under applicable law.
 

18. Amendments to this Policy
 

AEFPL may revise this Policy periodically to reflect changes in its business, technology, or legal and regulatory requirements, including future RBI directions or amendments to the DPDP Act and rules thereunder. The updated Policy, with its revised effective date, will be published on the Platform, and, where required by law or where changes are material, You will be notified through appropriate channels. Continued use of the Platform or AEFPL's services after the revised Policy takes effect constitutes acceptance of the updated Policy, to the extent permitted under applicable law.
 

19. Governing Law and Jurisdiction

This Policy shall be governed by the laws of India. Subject to any dispute resolution or jurisdiction clause in the applicable loan agreement, the courts at Mumbai, India shall have exclusive jurisdiction over any disputes arising out of or in connection with this Policy.

bottom of page