Legal

Privacy Policy

Last updated: February 27, 2026

This Privacy Policy describes how Kredixa ("we", "us", or "our") collects, uses, and protects your information when you use our peer-to-peer lending platform.

1. Information We Collect

Personal Information

When you register and use Kredixa, we collect the following personal information:

  • Phone number (used for account registration and OTP-based authentication via Firebase Phone Auth)
  • Full name and profile details you provide
  • Profile photograph (optional)

Location Data

Kredixa is a location-based platform. We collect:

  • Your geographic location (latitude and longitude) when you enable location services
  • Address information you provide in your profile
  • Location data is used for proximity-based matching with nearby lenders or borrowers

Financial Information

To facilitate lending transactions, we collect:

  • Loan request details (amount, interest rate, duration, collateral type)
  • Lending capacity and terms (for lenders)
  • Transaction history and repayment records

Communication Data

We store messages exchanged through the in-app chat system, including text messages and shared files or images, to facilitate communication between lenders and borrowers.

Device Information

We collect device tokens for push notifications via Firebase Cloud Messaging (FCM) to send you important updates about your loans, messages, and account activity.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Account creation, authentication, and identity verification
  • Location-based matching to connect borrowers with nearby lenders
  • Facilitating loan requests, offers, and transaction management
  • Enabling real-time communication between users via in-app chat
  • Sending push notifications for loan updates, messages, and important alerts
  • Platform improvement, analytics, and troubleshooting
  • Fraud prevention and security enforcement
  • Customer support and dispute resolution

3. Data Storage and Security

Where Your Data is Stored

Your data is stored securely using industry-standard infrastructure:

  • Account data, loan records, and chat messages are stored in MongoDB Atlas with encryption at rest
  • Uploaded files (such as chat attachments and profile photos) are stored in Amazon Web Services (AWS) S3 with server-side encryption (region: ap-south-1)
  • Authentication is handled via Firebase with secure token-based verification

Security Measures

We implement the following security measures to protect your data:

  • JWT-based authentication with token expiry
  • Encrypted data transmission over HTTPS/TLS
  • Secure OTP-based phone authentication (no passwords stored)
  • Pre-signed URLs with limited expiry for file access
  • Role-based access controls for admin operations
  • Regular security audits and monitoring

4. Information Sharing

We do not sell your personal information. We may share your information in the following limited circumstances:

  • With other users: Your profile information (name, location, lender/borrower status, ratings) is visible to other users for the purpose of facilitating loan transactions
  • With service providers: We use third-party services (AWS, Firebase, MongoDB Atlas) for infrastructure, and they process data on our behalf under strict data protection agreements
  • For legal compliance: We may disclose information when required by law, court order, or government regulation
  • For safety: We may share information to prevent fraud, protect user safety, or enforce our terms of service

5. Your Rights

As a Kredixa user, you have the following rights regarding your personal data:

  • Access: You can view your personal information through your profile at any time
  • Correction: You can update your profile information through the app
  • Deletion: You can request deletion of your account and associated data by contacting our support team. Note that some data may be retained for legal and regulatory compliance
  • Data Portability: You can request a copy of your personal data in a structured format
  • Withdraw Consent: You can withdraw consent for location tracking or push notifications through your device settings

6. Data Retention

We retain your data for the following periods:

  • Account data: Retained for as long as your account is active, plus 5 years after account deletion for regulatory compliance
  • Loan transaction records: Retained for 8 years after loan completion as per financial record-keeping requirements
  • Chat messages: Retained for 2 years after the last message in a conversation
  • Push notification tokens: Deleted when you uninstall the app or revoke notification permissions

7. Cookies and Tracking

The Kredixa mobile application does not use browser cookies. However, we use the following technologies:

  • AsyncStorage on your device to store authentication tokens and app preferences locally
  • Firebase Analytics may collect anonymized usage data to help us improve the platform
  • The Kredixa admin dashboard (web application) may use cookies for session management

8. Children's Privacy

Kredixa is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we discover that we have collected data from a minor, we will promptly delete that information.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of significant changes through in-app notifications or push notifications. Your continued use of Kredixa after changes are posted constitutes your acceptance of the updated policy.

10. Platform Disclaimer

Kredixa is solely a technology platform that connects lenders and borrowers. Important disclaimers:

  • Kredixa is NOT a bank, non-banking financial company (NBFC), or money lending institution
  • The owners, operators, and developers of Kredixa are not responsible for any financial loss, non-repayment, fraud, or disputes arising from transactions between users
  • All lending and borrowing transactions are conducted directly between users at their own risk
  • Kredixa does not guarantee the repayment of any loan, the creditworthiness of any user, or the outcome of any transaction
  • Users are solely responsible for evaluating risks, verifying counterparties, and making informed financial decisions
  • By using Kredixa, you acknowledge and accept that the platform bears no liability for any monetary losses incurred through transactions facilitated on the platform

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: