Legal

Data Privacy Policy

How we collect, process, store and erase personal data under the DPDP Act, 2023.

Stride Fintree Private Limited (CarmaOne)Last updated: July 17, 2026

Stride Fintree Private Limited (“CarmaOne”, “Company”, “we”, “us”, “our”) is committed to the protection, confidentiality, and lawful processing of your personal data. This Privacy Policy outlines our strict protocols regarding the collection, processing, usage, storage, retention, and erasure of personal data belonging to our platform users and verified corporate directors (“Data Principals”, “you”, “your”). Your access to the services is subject to this Privacy Policy and our Terms of Service. By using the services or providing your information through our website, you consent to the practices described herein.

1.Categories of Personal Data Collected

We collect and process only the minimum necessary personal identifiers required to securely operate our Credit Insights portal, prevent unauthorized data harvesting, and maintain statutory audit logs:

  • User Authentication Identifiers: Mobile phone number, full legal name (where provided), and email address.
  • Corporate Verification Records: Mobile numbers of registered corporate Directors, and Permanent Account Numbers (PAN) strictly for corporate identity linking.
  • Session & System Metadata: IP addresses, browser fingerprints, cryptographic OTP transaction logs, date/time stamps of query execution, and network routing logs.
  • Financial Data: For payable services, we or our third-party payment gateways may collect payment instrument information to complete billing operations.
  • Cookies & Usage Data: The website may use cookies to store non-sensitive data for technical administration, research and development, and user administration.

2.Specific Purpose and Lawful Basis of Processing

Under Section 4 and Section 6 of the DPDP Act, 2023, personal data can only be processed based on an explicit, specific, clear, and unconditional consent provided by the Data Principal for a specified purpose. CarmaOne processes your data strictly for the following itemized operations:

  1. Authentication and Identity Mapping: Processing your mobile number to transmit an OTP code to establish your secure digital session.
  2. Statutory Consent Recording: Maintaining a secure, unalterable historical ledger of the exact individual and director who approved the extraction of corporate credit reports.
  3. Security Auditing & Anti-Fraud Protection: Analyzing network metadata and IP logs to identify brute-force attacks, automated scrapping vectors, and unauthorized corporate lookups.
  4. Service Administration: Processing transactions, subscriptions, and renewals, providing customer support, and notifying you about changes to our services.

We ensure that no user data is processed for hidden behavioral tracking, third-party monetization, advertising, or profiling.

3.Rights of Data Principals

The DPDP Act, 2023 grants you comprehensive statutory rights over your personal data. You are entitled to exercise the following rights directly via our designated channels:

  • Right to Access and Summary: The right to receive an itemized summary of your personal data currently being processed by us, along with descriptions of processing activities.
  • Right to Correction and Erasure: The right to rectify inaccurate or obsolete identifiers or command the complete systemic erasure of your personal records from our databases, provided such data is no longer required for active statutory audit compliance.
  • Right to Withdraw Consent: You possess an absolute, unconditional right to revoke your data processing consent at any point. The withdrawal mechanism mimics the ease of consent provision, accessible via your dashboard profile settings or by notifying our Grievance Redressal Officer.
  • Right to Grievance Redressal: The right to lodge a formal complaint regarding any data processing non-compliance, which must be resolved by our internal grievance architecture before escalation to the Data Protection Board of India.

4.Data Retention and Deletion Schedules

Personal data collected for user authentication, session logging, and temporary parsing is retained only for the duration required to satisfy the specific purpose of processing:

  • Session & Temporary Tokens: Automatically purged shortly after session termination.
  • Legal and Consent Audit Logs: Cryptographic logs linking a specific mobile number verification to an MCA or CIBIL pull are preserved for a mandatory period of 1 (one) year or for the duration required under applicable banking/credit regulatory audit cycles, after which they are irreversibly anonymized or securely erased from our active and backup data clusters.
  • Usage Data: Usage data may be retained for internal analysis and is generally kept for shorter periods unless needed to improve security, enhance service functionality, or comply with legal obligations.

5.Data Protection Architecture and Security

We implement enterprise-grade technical and organizational security measures to protect personal data against unauthorized breach, accidental loss, alteration, or disclosure. Our platform infrastructure is SOC 2 Type II Certified, utilizes 256-bit AES cryptographic encryption for all data-at-rest and TLS 1.3 transport security for data-in-transit, and maintains ISO 27001 compliance frameworks.

In the event of any accidental data breach, CarmaOne will immediately notify the Data Protection Board of India and all affected Data Principals as required under Section 8 of the DPDP Act, 2023. The Company is not responsible for the confidentiality, security, or distribution of your personal information by third parties outside the scope of our agreements, or for events beyond our reasonable control (including acts of government, hacking, unauthorized access, computer crashes, or internet/telecom issues).

6.Payments and Third-Party Gateways

For payable services, verification of financial/credit information is accomplished through the authentication process offered by third-party payment gateways. User card details are transacted on secure, encrypted sites of approved payment gateways. CarmaOne does not store card or bank account numbers on its portals, and is not responsible for issues, misuse, or fraud at third-party payment gateways.

7.Casual Visitors and Minors

No tool is deployed to automatically collect sensitive personal data from casual visitors who are merely browsing the website, though certain provisions of this Privacy Policy (such as cookie usage) still apply. If you willingly submit personal data, you will be treated as a user. Furthermore, although our website and services are not intended for minors, their privacy is respected. We encourage parents and guardians to supervise minors online.

8.Changes to this Privacy Policy

CarmaOne may change, modify, add, or delete portions of this Privacy Policy at any time at its sole discretion. When significant changes occur, the updated policy will be posted on the website. If you object to the changes, you must stop using the services and contact us to deactivate your account. Continued use of the platform after notice constitutes your consent to the updated terms.

9.Address for Privacy Questions

If you have any grievance or questions regarding our use of your information, or wish to exercise your rights, please contact our designated Grievance Redressal Officer at care@carmaone.ai.

Questions or concerns?

Reach our designated Grievance Redressal Officer for any data privacy request, consent withdrawal, or formal notice relating to the CarmaOne platform.

  • care@carmaone.ai
  • Block 3A, Ground Floor, DLF Corporate Park, DLF Phase III, Gurugram 122002, India