Privacy Policy
How Vistarkriya collects, uses, shares, and protects your information
Your Consent Matters
By using Vistarkriya, you consent to the collection, use, and sharing of your data as described in this Privacy Policy.
Quick Navigation
Introduction & Scope
Welcome to Vistarkriya, operated by VistarKriya Marketings Private Limited ("Company", "we", "us", "our"). This Privacy Policy ("Policy") explains how we collect, use, disclose, store, and safeguard your information when you use our SaaS platform, website, mobile applications, APIs, and all related services (collectively, the "Service" or "Platform").
Who This Policy Covers
This Policy applies to all users of our Platform:
- Tenants/Admins: Businesses that subscribe to our platform
- B2B Partners: Business customers of our Tenants
- B2C Users: Individual end users
- Visitors: Anyone browsing our website
- Lead Subjects: Individuals whose data is submitted through leads
IMPORTANT: Consent to Data Processing
BY ACCESSING OR USING VISTARKRIYA, YOU EXPRESSLY CONSENT TO THE COLLECTION, USE, STORAGE, AND SHARING OF YOUR INFORMATION AS DESCRIBED IN THIS PRIVACY POLICY.
If you do not agree to this Policy, you must immediately stop using our Platform and services.
This Policy is a legally binding agreement between you and VistarKriya Marketings Private Limited. It forms part of and should be read together with our Terms of Service.
Information We Collect
We collect various types of information to provide and improve our services. The information collected includes but is not limited to:
🏢 For Tenants/Admins (Business Subscribers)
Registration & Identity Information
- Full legal name, business name, and trade name
- Email address and mobile phone number
- Physical address and business address
- PAN Card number and details
- Aadhaar number (via DigiLocker verification)
- GST registration number and certificate
- Business registration documents (Shop Act, MSME, etc.)
- Photographs and identity proofs
- Date of birth and gender
Financial Information
- Bank account details (account number, IFSC, branch)
- UPI IDs and payment preferences
- Transaction history on our platform
- Wallet balances and withdrawal history
- Invoice and billing information
Platform Usage Data
- Leads created, managed, and submitted
- Chapters subscribed and features used
- Customer data uploaded to your account
- Documents uploaded and processed
- Service requests and communications
- Login history, IP addresses, and session data
- Device information and browser details
👥 For B2B Partners & B2C Users
- Name, email, phone number
- Business information and registration details
- KYC documents (PAN, Aadhaar)
- Service requests and documents submitted
- Communication history
- Transaction and payment history
📋 Lead Data (Customer Information Submitted by Tenants)
- Full name and contact details of lead subjects
- Employment and income information
- Loan requirements and financial needs
- KYC documents (PAN, Aadhaar, address proof)
- Bank statements and financial documents
- Property documents (for secured loans)
- Business documents (for business loans)
- Any other information required for loan processing
🌐 Automatically Collected Information
- IP address and geolocation data
- Browser type, version, and settings
- Device type, operating system, and unique identifiers
- Pages visited, time spent, and navigation patterns
- Referral URLs and exit pages
- Cookies and similar tracking technologies
Document Collection
All documents we collect are standard, publicly-available identity and business documents required for KYC compliance, regulatory requirements, and service delivery. By uploading documents, you confirm their authenticity and grant us permission to process, store, and share them as necessary.
How We Use Your Data
We use the collected information for various purposes, including but not limited to:
🔧 Service Delivery & Operations
- Providing, operating, and maintaining our Platform
- Creating and managing your account
- Processing transactions and payments
- Delivering requested services and features
- Processing and routing leads to appropriate partners
- Generating reports (CIBIL, verification, etc.)
🔐 Verification & Compliance
- KYC verification and identity authentication
- Fraud prevention and security monitoring
- Compliance with legal and regulatory requirements
- Responding to legal requests and court orders
📧 Communication
- Sending transactional notifications and updates
- Providing customer support and responding to inquiries
- Sending service-related announcements
- Marketing communications (with consent)
- Promotional offers and newsletters
📊 Analytics & Improvement
- Analyzing usage patterns and platform performance
- Improving our services and user experience
- Developing new features and products
- Conducting research and analytics
- Training machine learning models (anonymized data)
🤝 Business Operations
- Facilitating partnerships and integrations
- Processing commissions and payouts
- Business planning and reporting
- Merger, acquisition, or sale of business assets
Legal Basis for Processing
We process your data based on: (a) your explicit consent, (b) performance of contract with you, (c) compliance with legal obligations, and (d) legitimate business interests that do not override your rights.
Data Sharing & Disclosure
We may share your information with third parties in the following circumstances:
🏦 Banks, NBFCs & Financial Institutions
Lead data and supporting documents are shared with banks, NBFCs, and other lending institutions for the purpose of processing loan applications and financial services requested through our Platform.
📊 Credit Bureaus
We share data with credit bureaus (CIBIL, Experian, Equifax, CRIF High Mark) for credit report generation and verification services.
🔌 API Partners & Service Providers
We share data with our technology partners including:
- Payment gateway providers (for transaction processing)
- Cloud hosting providers (for data storage)
- KYC verification providers (Aadhaar, PAN verification)
- Email and SMS service providers (for communications)
- Analytics providers (for platform improvement)
- CDN providers (for content delivery)
👨💼 Professional Service Providers
For Associate Services chapter, data may be shared with Chartered Accountants, Company Secretaries, Tax Consultants, and Legal professionals to deliver requested services.
🏛️ Government & Legal Authorities
We may disclose your information when required by law, court order, regulatory authority, or government agency. This includes:
- Responding to legal process and government requests
- Compliance with RBI, SEBI, and other regulatory requirements
- Tax authorities and GST compliance
- Law enforcement agencies investigating fraud or illegal activities
🏢 Business Transfers
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred to the acquiring entity or successor.
Sharing for Service Purposes
By using our Platform and submitting data, you expressly consent to the sharing of your information with banks, NBFCs, credit bureaus, and other partners as necessary to process your requests and deliver services. This sharing is essential to our service delivery and cannot be opted out of while using our Platform.
Purpose-Limited Sharing
We share data ONLY for the specific purpose for which it was collected. Loan lead data is shared with lenders for loan processing. CIBIL requests are shared with credit bureaus. We do not sell your personal data to third parties for unrelated marketing purposes.
Lead Data, Third-Party Sharing & Consent
CRITICAL: Lead Data Processing
Vistarkriya is a CRM platform that facilitates the collection and routing of leads to banks, NBFCs, and other service providers. When you submit a lead (whether your own application or on behalf of a customer), you acknowledge and consent to the following:
📤 What Happens to Lead Data
- Collection: Lead data is collected through our CRM platform
- Storage: Data is stored on our secure servers
- Processing: Data is processed to match with appropriate lenders/partners
- Sharing: Data is shared with one or more banks, NBFCs, or partners for service fulfillment
- Multiple Sharing: A single lead may be shared with multiple partners to maximize approval chances
✅ Your Consent Obligations (For Tenants/Admins)
If you submit leads on behalf of your customers, you REPRESENT AND WARRANT that:
- You have obtained explicit consent from each individual whose data you submit
- You have informed them that their data will be shared with banks/NBFCs/partners
- You have the legal authority to submit their data on their behalf
- All information submitted is accurate and authentic
- You will indemnify us against any claims arising from unauthorized data submission
🏦 Third-Party Data Handling
Once data is shared with banks, NBFCs, or other partners:
- That data becomes subject to their respective privacy policies
- We have no control over how they use, store, or process the data
- They may contact the lead subject directly
- They may share data with their own partners as per their policies
- We are not responsible for their data handling practices
No Control Over Third-Party Actions
Vistarkriya is not responsible for the privacy practices, data handling, or actions of any bank, NBFC, or third-party partner. Once data is transmitted to these entities, their privacy policies govern the use of that data. We recommend reviewing the privacy policies of any financial institution you engage with.
📞 Our Right to Contact Lead Subjects Directly
Vistarkriya, its authorised personnel, sub-processors, and technology partners may contact any lead subject, borrower, applicant, or customer whose data is submitted through the Platform ("Lead Subject") directly — via voice call, IVR, WhatsApp, RCS, SMS, email, or in-app notification — for processing, verification, fulfilment, quality, fraud-prevention, support, recovery, and transactional purposes connected with the lead or service requested.
Consent Covers Direct Platform Contact
Where a Tenant or other user submits a Lead Subject's data, that user represents and warrants that the consent obtained from the Lead Subject expressly authorises VistarKriya Marketings Private Limited and its partners to contact the Lead Subject directly through the channels stated above for the stated purposes. By submitting data, the submitting user confirms that no separate or additional consent is required for such contact. Responsibility for obtaining valid, DPDP- and TRAI/TCCCPR-compliant consent rests entirely with the submitting user, who shall indemnify us against any claim arising from its absence or inadequacy.
Data Protection Roles under DPDP Act, 2023
(a) Data Fiduciary — Platform Data
VistarKriya Marketings Private Limited is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 for personal data collected directly from Tenants during registration, KYC verification, and account management. This data is collected solely for the purposes of identity verification, age and eligibility confirmation, regulatory compliance (including under the Income Tax Act, 1961, the Goods and Services Tax Acts, the Companies Act, 2013, and the Information Technology Act, 2000), fraud prevention, contractual performance, and legal protection.
This data is retained for as long as required by applicable law. The Platform's obligation to comply with statutory retention requirements under tax, corporate, and information technology laws shall override any erasure request to the extent permitted by Section 17(2) of the Digital Personal Data Protection Act, 2023.
(b) Data Processor — Tenant Customer Data
For personal data of Tenants' customers, borrowers, lead subjects, and end users submitted by Tenants through the Platform, the Tenant is the Data Fiduciary. VistarKriya Marketings Private Limited acts solely as a Data Processor, processing such data on the Tenant's behalf and in accordance with these Terms. All obligations towards the data principal — including obtaining valid consent, responding to access and erasure requests, and handling grievances — rest exclusively with the Tenant as Data Fiduciary. The Tenant shall indemnify VistarKriya Marketings Private Limited against any claim, penalty, or loss arising from the Tenant's failure to discharge its Data Fiduciary obligations. Except that, with respect to de-identified, aggregated, and Derived Data that the Platform independently creates and owns under Terms of Service §16, the Platform acts as a Data Fiduciary in its own right.
(c) Breach Notification
In the event of a personal data breach:
- For data where Vistarkriya is the Data Fiduciary: Vistarkriya shall notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act, 2023 and rules made thereunder.
- For data where the Tenant is the Data Fiduciary: Vistarkriya shall notify the Tenant without undue delay upon becoming aware of the breach. The Tenant, as Data Fiduciary, is solely responsible for notifying the Data Protection Board and affected Data Principals. Vistarkriya shall provide reasonable cooperation to the Tenant in investigating and remediating the breach.
(d) Designated DPDP Contact
For all matters relating to the Digital Personal Data Protection Act, 2023, the designated contact is:
Name: Ankit Arora
Designation: Director & Grievance Officer
Email: ankit@vistarkriya.com
Data Retention
We retain your data for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
📅 Retention Periods
- Active Account Data: Retained for the duration of your account and thereafter as required by applicable law
- Transaction Records: Retained as required by applicable tax laws
- KYC Documents: Retained as required by applicable regulatory and KYC laws, and as evidentiary proof of identity, eligibility, and consent
- Lead Data: Retained as required by applicable law and for legitimate business, compliance, and dispute-resolution purposes
- Communication Records: Retained as required by applicable law
- Log Files & Analytics: Retained as required by applicable law
- Backup Data: Retained as required by applicable law and our standard backup cycle
Post-Account Deletion
After you request account deletion, your active data will be removed from our primary systems within 30 days. However, certain data will be retained in archives as required by applicable law for legal, regulatory, tax, and compliance purposes. Backup copies may persist for the duration of our standard backup cycle.
Legal Holds: If we receive a legal request, litigation hold, or regulatory inquiry, we may retain data beyond the normal retention periods as required.
Data Security
We implement industry-standard security measures to protect your information:
SSL/TLS Encryption
All data in transit is encrypted
Secure Hosting
Enterprise-grade cloud infrastructure
Access Controls
Role-based access permissions
Monitoring
24/7 security monitoring
Firewalls
Network-level protection
Backups
Regular encrypted backups
Security Disclaimer
While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data. You acknowledge and accept this inherent risk when using our Platform. You are responsible for maintaining the security of your own account credentials.
Breach Notification: In the event of a data breach that affects your personal information, we will notify you as required by applicable law and take appropriate remedial measures.
Your Rights & Choices
Subject to applicable law and certain limitations, you may have the following rights regarding your data:
- Access: Request information about what personal data we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Portability: Request a copy of your data in a portable format
- Opt-out: Unsubscribe from marketing communications
- Withdraw Consent: Withdraw consent for specific processing activities
Limitations on Rights
Your rights are subject to certain limitations:
- Deletion requests may not be fulfilled if we need to retain data for legal, regulatory, or legitimate business purposes
- Lead data already shared with third parties cannot be recalled or deleted from their systems
- Transaction records must be retained as per tax and financial regulations
- KYC documents must be retained as per RBI and regulatory requirements
- Exercising certain rights may result in inability to use our services
To exercise your rights, contact us at hello@vistarkriya.com. We will respond within 30 days. We may require identity verification before processing your request.
Cookies & Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience:
🍪 Types of Cookies We Use
- Essential Cookies: Required for platform functionality (login, security, preferences)
- Analytics Cookies: Help us understand usage patterns and improve services
- Preference Cookies: Remember your settings and preferences
- Marketing Cookies: Used to deliver relevant advertisements
📡 Other Tracking Technologies
- Pixel tags and web beacons
- Local storage and session storage
- Device fingerprinting
- Log file analysis
Managing Cookies: You can manage cookie preferences through your browser settings. However, disabling certain cookies may affect platform functionality and your ability to use our services.
Do Not Track: Our Platform does not currently respond to "Do Not Track" signals from browsers.
Third-Party Links & Services
Our Platform may contain links to third-party websites, applications, and services including banks, NBFCs, and partner platforms. These third parties have their own privacy policies.
Third-Party Disclaimer
We are not responsible for the privacy practices, content, or data handling of any third-party website or service. When you click on third-party links or use third-party services accessed through our Platform, you are subject to their terms and privacy policies. We encourage you to review the privacy policies of any third party before sharing your information.
Children's Privacy
Our Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at hello@vistarkriya.com.
If we discover that we have collected personal information from a child under 18, we will take steps to delete such information promptly.
Changes to This Policy
VistarKriya Marketings Private Limited reserves the absolute right to modify, amend, update, or replace this Privacy Policy at any time without any prior notice, as the Company deems fit and necessary. Changes become effective immediately upon posting to our Platform.
Notification of Changes
For significant changes, we may notify you via email or prominent notice on our Platform. However, it is your responsibility to review this Policy periodically. Continued use of our Platform after changes constitutes your acceptance of the modified Policy.
The "Last Updated" date at the top of this Policy indicates when it was last revised.
Legal Provisions & Dispute Resolution
⚖️ Governing Law & Jurisdiction
This Privacy Policy and any disputes arising out of or in connection with it shall be governed by and construed in accordance with the laws of India. Subject to the arbitration clause below, the courts of Dehradun, Uttarakhand shall have exclusive jurisdiction over any legal proceedings arising from this Policy.
🤝 Dispute Resolution & Arbitration
(a) Good-Faith Negotiation: Any dispute shall first be attempted to be resolved through good-faith negotiation for a period of thirty (30) days from written notice of the dispute.
(b) If unresolved, the dispute shall be referred to binding arbitration under the Arbitration and Conciliation Act, 1996 (as amended).
- (c) Number of Arbitrators: One (1), mutually appointed by the parties. If the parties cannot agree within fifteen (15) days, the appointment shall be made in accordance with the Arbitration and Conciliation Act, 1996.
- (d) Seat and Venue: Dehradun, Uttarakhand, India.
- (e) Language: English or Hindi.
- (f) Arbitration Fees: To be borne by the losing party unless otherwise determined by the arbitrator.
- (g) The arbitrator's decision shall be final and binding.
🌪️ Force Majeure
Vistarkriya shall not be liable for any failure or delay in performing its obligations where such failure or delay results from circumstances beyond our reasonable control, including but not limited to:
- Acts of God, natural disasters, earthquakes, floods, fire
- War, terrorism, riots, civil unrest
- Government actions, new regulations, or restrictions
- Pandemic, epidemic, or public health emergencies
- Power outages, internet disruptions, server failures
- Third-party API failures, bank system outages
- Strikes, labor disputes
- Any other events beyond our reasonable control
✂️ Severability
If any provision of this Policy is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, or if modification is not possible, shall be severed from this Policy. The remaining provisions shall continue in full force and effect and shall not be affected or impaired in any way.
📄 Entire Agreement
This Privacy Policy, together with our Terms of Service and Refund Policy, constitutes the entire agreement between you and VistarKriya Marketings Private Limited regarding data privacy and supersedes all prior agreements, representations, and understandings.
Registered Office
VistarKriya Marketings Private Limited
(VistarKriya Marketings Private Limited)
3rd Floor, Shree Jee Plaza, New Road,
Dalanwala, Dehradun, Uttarakhand 248001
Branch Office:
55, 3rd Floor, Westend Marg, Saidullajab,
Near Saket Metro, New Delhi 110030
Contact Us
If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about our data practices, please contact us:
VistarKriya Marketings Private Limited
Data Protection Contact:
Email: hello@vistarkriya.com
Phone: 8766268711
Correspondence Address:
55, 3rd Floor, Westend Marg, Saidullajab,
Near Saket Metro, New Delhi 110030, India
Registered Office:
3rd Floor, Shree Jee Plaza, New Road,
Dalanwala, Dehradun, Uttarakhand 248001
Grievance Officer
In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Consumer Protection (E-Commerce) Rules, 2020, and the Digital Personal Data Protection Act, 2023, the Grievance Officer for VistarKriya Marketings Private Limited is:
Name: Ankit Arora
Designation: Director & Grievance Officer
Company: VistarKriya Marketings Private Limited
Email: ankit@vistarkriya.com
Phone: 8766268711
Address: 55, 3rd Floor, Westend Marg, Saidullajab, Near Saket Metro, New Delhi 110030
We will acknowledge a grievance within 24 hours and endeavour to resolve it within 15 days of receipt, or within the timeline mandated by applicable law.
We will respond to your inquiries within 30 days. For formal complaints that remain unresolved, you may have the right to lodge a complaint with the appropriate data protection authority.
Acknowledgment & Acceptance
By Using Our Platform, You Acknowledge:
- You have READ and UNDERSTOOD this entire Privacy Policy
- You CONSENT to the collection, use, and sharing of your data as described
- You UNDERSTAND that lead data will be shared with banks, NBFCs, and partners
- You ACCEPT that data shared with third parties is governed by their policies
- You AGREE to the data retention periods specified
- If submitting others' data, you have obtained their CONSENT
- You will INDEMNIFY us for any claims related to unauthorized data submission
Questions About Privacy?
VistarKriya Marketings Private Limited
Correspondence Address:
55, 3rd Floor, Westend Marg, Saidullajab, Near Saket Metro, New Delhi 110030
Registered Office:
3rd Floor, Shree Jee Plaza, New Road, Dalanwala, Dehradun, Uttarakhand 248001