Bachatt Logo
Loading...

Privacy Policy

Last Updated: 27 February 2026

At Bachatt, we value your privacy and are committed to protecting your personal information. This policy explains how we collect, use, and safeguard your data.

1. Introduction

1. Introduction

Trusave Fintech Private Limited and its subsidiaries (collectively "Bachatt") prioritizes safeguarding personal information and user trust. This policy outlines how personal data is collected, used, processed, and disclosed regarding Bachatt's products, services, website (bachatt.app), and mobile application. The policy does not apply to partners, who maintain separate privacy policies.

By using Bachatt's offerings, users acknowledge reading and agreeing to data processing per this policy and the Terms of Use.

1A. RBI Digital Lending Compliance

1A. RBI Digital Lending Compliance

This Privacy Policy is governed by and compliant with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the Digital Lending Guidelines as published and updated by the Reserve Bank of India ("RBI") from time to time, including the RBI circular on "Guidelines on Digital Lending" dated September 2, 2022 (RBI/2022-23/111 DOR.CRE.REC.66/21.07.001/2022-23).

Bachatt operates as a Lending Service Provider ("LSP") and Digital Lending Application ("DLA") in partnership with RBI-registered Regulated Entities ("REs") / Non-Banking Financial Companies ("NBFCs") for facilitating digital lending services. All lending activities facilitated through the Bachatt platform are conducted in full compliance with RBI's Digital Lending Guidelines.

2. Collection of Information

2. Collection of Information

User Provided Information

  • Registration requires personal details including name, mobile number, email, date of birth, gender, and address.
  • Additional services may require financial details, credit scores, card information, and official documents.
  • Refusing to share requisite data restricts certain features.
  • Device permissions (contacts, photos, camera, location, microphone, SMS, storage, calls, NFC) may be accessed with user consent, which can be revoked via device settings.

Marketing Communications Consent

  • Users may consent to contact via phone, SMS, WhatsApp, and email regarding promotional offers, product updates, investment opportunities, educational content, and partner offers.
  • Consent can be withdrawn by contacting [email protected].

Financial SMS Collection

  • Bachatt collects only financial SMS from six-digit alphanumeric senders to identify bank accounts, cash flow patterns, and transaction details for investment recommendations.
  • This data is not used for lending purposes.

Gmail Data for Mutual Funds

  • With explicit consent, Bachatt accesses Gmail in read-only mode to retrieve mutual fund statements from CAMS, KFintech, NSDL, and CDSL.
  • Only portfolio information is extracted and stored; original emails are not retained.

Application-Generated Information

  • Usage data includes services accessed, interactions, rewards claimed, transaction details, IP addresses, browser type, operating system, device model, geolocation, language preferences, and access duration.

Third-Party Information

  • Upon consent, Bachatt may request credit information from credit bureaus, conduct KYC verification, and share relevant customer and financial information with regulated entities and other authorized parties.
  • Such persons may independently undertake credit assessment activities (including credit bureau checks), fraud prevention checks, and other evaluations necessary for credit decisioning.

Lending-Specific Data Collection & Borrower Consent

  • For users availing lending services through the Bachatt platform, data collection is strictly need-based, with prior and explicit consent obtained from the borrower at each stage of the lending journey. All consent records are maintained in an auditable manner.
  • The following data may be collected for lending purposes, subject to explicit borrower consent:
  • Personal identification details (name, date of birth, gender, PAN, Aadhaar)
  • Contact information (mobile number, email address, residential address, pincode)
  • Financial information (income details, employment details, bank account information)
  • Credit information (credit score, credit history - obtained from credit bureaus with explicit consent, by the regulated entity)
  • KYC documentation (identity and address proof, as required by the RE)
  • Bank statement data (via Account Aggregator framework or manual upload, shared directly with the RE)
  • Any additional data points as required by the specific lending partner (RE)

Restrictions on Device Access for Lending Services

  • In compliance with RBI Digital Lending Guidelines, the Bachatt application (DLA) does not access mobile phone resources such as files and media, contact lists, call logs, or telephony functions for lending purposes. One-time access may be requested for:
  • Camera: For KYC verification, liveness check, and document capture during onboarding
  • Location: For address verification during onboarding/KYC
  • Microphone: Only if required for video KYC
  • Such access is requested only with the borrower's explicit prior consent, is limited to the specific onboarding/KYC purpose, and no persistent access is retained thereafter.

Borrower Rights Regarding Data

  • In accordance with RBI Digital Lending Guidelines, borrowers have the following rights:
  • Right to Provide or Deny Consent: Borrowers may choose to provide or withhold consent for the collection and usage of specific data points. Withholding consent for mandatory data points may affect eligibility for lending services.
  • Right to Restrict Disclosure to Third Parties: Borrowers may restrict the sharing of their personal data with third parties, except where mandated by regulatory or legal requirements.
  • Right to Know Data Retention Duration: Borrowers are entitled to be informed about how long their personal data will be retained.
  • Right to Revoke Consent: Borrowers may revoke previously granted consent at any time by contacting [email protected] or through the app settings. Revocation of consent may result in discontinuation of lending services.
  • Right to Data Deletion / Right to Be Forgotten: Borrowers may request the erasure or deletion of their personal data by writing to [email protected], subject to retention obligations arising from ongoing loan contracts, regulatory requirements, or legal proceedings.
3. Utilization of Information

3. Utilization of Information

Service Delivery and Personalization

  • Personal data executes service contracts, creates accounts, processes transactions, and conducts data analytics for improved user experience.
  • With consent, usage data supports promotional purposes.

Marketing Communications

  • Bachatt contacts users about promotional offers, new products, educational content, account updates, surveys, partner offers, and personalized recommendations through various channels.
  • All communications include opt-out mechanisms.

Security and Compliance

  • Data ensures payment service compliance, detects fraud and security threats, and assists customer support services.

Gmail Data Usage

  • Mutual fund data displays consolidated portfolios, provides analysis and performance tracking, and enables automated updates.
  • Not used for advertising, marketing, or third-party sharing.

Data Sharing

  • Partner products involve sharing of customer data with regulated entities and other third-party service providers for the purpose of providing lending and related services, subject to explicit customer consent.
  • Such sharing enables the regulated entities to undertake credit assessment, verification, and credit decisioning.
  • Any sharing with group entities or partners shall be undertaken only with explicit consent, unless required by law.
  • Gmail data for mutual funds is never shared with third parties.

Data Storage Policy

  • No biometric or mobile resource data is collected for L&T Finance Limited.
  • Bachatt adheres to RBI guidelines, respects the right to be forgotten unless legally required, and honors consent withdrawal requests sent to [email protected].
3A. Third-Party Disclosures for Lending Services

3A. Third-Party Disclosures for Lending Services

In compliance with RBI Digital Lending Guidelines, Bachatt discloses the following regarding third-party data collection and sharing in the context of lending services.

Third Parties Involved in Lending Data Processing:

  • Regulated Entities (REs) / NBFCs: Loan underwriting, credit assessment, disbursal, and servicing (e.g., Muthoot FinCorp Ltd, and other RBI-registered lending partners)
  • Credit Information Companies (CICs): Credit bureau checks and credit score retrieval (e.g., CIBIL/TransUnion, Experian, Equifax, CRIF High Mark)
  • Account Aggregator (AA) Framework: Fetching bank statement data with borrower consent via RBI-licensed Account Aggregators
  • KYC / Identity Verification Providers: Identity verification, Aadhaar authentication, PAN validation, and liveness detection
  • DigiLocker: Fetching verified documents with borrower consent (Government of India)
  • Payment / Mandate Partners: E-mandate registration and EMI collection, as specified by the RE
  • E-Sign / Agreement Partners: Digital agreement signing, as specified by the RE
  • Analytics Partners: App performance and user experience analytics (no lending-specific personal data shared)

Explicit Consents Obtained from Borrowers:

  • Credit Bureau Consent: Consent to fetch the borrower's credit score and credit report from one or more Credit Information Companies.
  • Mobile OTP Consent: Consent to verify the borrower's mobile number via OTP for authentication purposes.
  • Device Permissions Consent: Consent for one-time access to camera, location, or microphone for KYC/onboarding purposes only.
  • Data Sharing Consent: Consent to share the borrower's personal and financial data with the specific RE (lending partner) for loan processing.
  • DigiLocker Access Consent: Consent to fetch verified documents from DigiLocker, where applicable.
  • Bachatt Terms & Conditions and Privacy Policy Acceptance: Acknowledgment and acceptance of Bachatt's T&C and this Privacy Policy.
  • Aadhaar Sharing Consent: Consent to share Aadhaar details with the RE for identity verification and KYC purposes.
  • Bank Statement / Account Aggregator Consent: Consent to share bank account statement data with the RE via the Account Aggregator framework or manual upload.
  • Lender-Specific Consent: Any additional consent as required by the specific RE/lending partner.
  • All consents are recorded with timestamps and are auditable. Borrowers may view and manage their consent preferences through the Bachatt app or by writing to [email protected].
3B. Lending Data Handling & Security

3B. Lending Data Handling & Security

Types of Borrower Data Stored:

  • Personal identification details (name, date of birth, gender, PAN, contact information)
  • Loan application details (application ID, loan amount, loan type, application status)
  • KYC verification status and documents (as required for regulatory compliance)
  • Consent records (with timestamps for each consent obtained)
  • Loan transaction details (disbursal, repayment, EMI schedule)
  • Communication records related to lending services

Lending Data Retention:

  • Active loan accounts: Borrower data is retained for the duration of the loan and for 8 years from the date of loan closure or last transaction, whichever is later.
  • Rejected / Incomplete applications: Data is retained for a maximum of 3 years from the date of rejection or abandonment, after which it is securely destroyed.
  • Consent records: Retained for the duration of the business relationship and for a minimum of 5 years thereafter, as required for audit purposes.
  • Credit information: Retained for a maximum of 6 months from the date of retrieval or completion of the transaction, whichever is earlier, in compliance with CICRA requirements.

Restrictions on Data Usage:

  • Borrower data collected for lending purposes is used solely for the purpose for which consent was obtained.
  • No borrower data is used for cross-selling or marketing of unrelated products without separate explicit consent.
  • No borrower data is sold, rented, or traded to any third party.

Data Destruction Protocols:

  • Upon expiry of the applicable retention period, borrower data is permanently destroyed using secure deletion techniques, including data sanitization and secure erasure.
  • Credit information obtained from CICs is destroyed, purged, and erased immediately upon consent revocation or completion of the transaction, subject to the maximum retention period.
  • Destruction records are maintained for audit purposes.

Security Breach Handling:

  • Bachatt maintains an incident response plan for handling security breaches involving borrower data.
  • In the event of a data breach, Bachatt shall: immediately identify and contain the breach; notify affected borrowers and relevant regulatory authorities within legally prescribed timelines; conduct a thorough investigation; implement remediation measures to prevent recurrence; and maintain records of the breach and actions taken.

Biometric Data:

  • No biometric data is stored or collected by Bachatt or its DLA, unless explicitly permitted under extant statutory guidelines.
  • Where liveness verification is performed for KYC purposes, biometric data is processed in real-time and is not stored by Bachatt after verification is complete.
4. Communication Preferences and Consent Management

4. Communication Preferences and Consent Management

Communication Types:

  • Transactional: Essential service messages, security alerts, transaction confirmations, KYC notifications
  • Promotional: Marketing offers, product recommendations, investment opportunities
  • Service: Product updates, app announcements, customer support
  • Research: Surveys, feedback requests, market research

Communication Channels:

  • Voice calls, SMS, WhatsApp, email, push notifications, in-app messages, physical mail, and other emerging platforms (subject to consent).

Preferences Management:

  • Users manage settings through app settings, website accounts, or [email protected].
  • Opt-out preferences are processed within 3-5 business days.
  • Transactional communications continue after promotional opt-out.

Personalization:

  • Communications are targeted based on investment preferences, risk profiles, transaction patterns, and demographics, controllable through app privacy settings.
5. Cookies

5. Cookies

Cookies are small data blocks placed on user devices to analyze application services, user engagement, and promotional effectiveness. They reduce login frequency. Users may decline cookies, though this limits certain features.

6. Security

6. Security

Bachatt adopts reasonable physical, administrative, and technical safeguards protecting personal data from unauthorized access and disclosure.

Gmail Data Security:

  • Extracted data is encrypted at rest using industry-standard encryption.
  • Data transmission occurs over secure HTTPS connections.
  • Only extracted portfolio information is stored; original email content is never retained.

Third-party websites linked through the application are not Bachatt's responsibility. Security researchers should report vulnerabilities to [email protected].

7. Account Termination

7. Account Termination

Users may petition account deletion via the support section. All corresponding information is deleted upon request. Deletion may be unavailable if outstanding disputes, availed credit products, suspected fraudulent transactions, or unresolved claims exist.

Users may request account deactivation, inhibiting access until reactivation via [email protected].

Revoking Gmail Access:

  • Access is revoked via Google Account Permissions (https://myaccount.google.com/permissions) or Bachatt app settings.
  • All Gmail-derived data is deleted within 30 days of revocation.
8. Access and Queries

8. Access and Queries

Users may view or modify personal data online or request copies by contacting support. Identity validation may be required. Responses are provided within 30 days. Contact [email protected] for policy questions or concerns.

9. Data Retention

9. Data Retention

Personal data is retained only for necessary durations unless legally required or for legitimate business purposes.

Gmail Data Retention:

  • Mutual fund portfolio data is retained while accounts remain active and Gmail access is granted.
  • Data is deleted within 30 days of access revocation or account deletion.
  • Original email content is never stored.
10. Modifications to Privacy Policy

10. Modifications to Privacy Policy

Bachatt reserves modification rights at any time, effective immediately upon posting. Users are advised to periodically review the policy for updates.

11. Compliance

11. Compliance

Bachatt maintains privacy and information security policies and procedures. All payment data is stored within India per regulatory requirements, on cloud servers located in India.

Lending Data Localization:

  • All borrower data collected in connection with lending services is stored exclusively on servers located within India, in full compliance with RBI's data localization requirements. No borrower data related to lending services is transferred to or stored on servers outside India.

Telemarketing Compliance:

  • Bachatt complies with TRAI guidelines and telecom regulations, honoring Do Not Call registry requirements.
  • All marketing communications include sender identification and opt-out mechanisms.
  • Consent records are maintained per regulations.

Google API Services Compliance:

  • Bachatt's Google API usage adheres to Google's User Data Policy and Limited Use requirements.
  • Only minimum necessary data is accessed.
  • Gmail data is not shared with third parties, used for advertising, or accessed by humans.
12. Grievance Redressal Officer

12. Grievance Redressal Officer

For unresolved privacy concerns, users may contact the grievance officer:

13. Contact Us

13. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at: Email: [email protected]

Marketing Communications Management:

14. Grievance Redressal

14. Grievance Redressal

If issues remain unresolved after 14 days, escalate to the grievance officer (details in Section 12).

15. Experian Terms and Conditions

15. Experian Terms and Conditions

Users accessing Experian credit information consent to its provision by Experian to Bachatt using Experian tools and algorithms. Bachatt accesses credit data as an authorized representative for limited purposes related to availed services.

  • Credit information cannot be aggregated, retained beyond necessary periods (maximum 6 months), or shared with third parties.
  • Relationship governance follows Indian law; disputes fall under Delhi court jurisdiction.
16. Lending Partner & Regulatory Disclosures

16. Lending Partner & Regulatory Disclosures

In compliance with RBI's Digital Lending Guidelines, the following information is disclosed.

About Bachatt (LSP / DLA):

  • Legal Entity: Trusave Fintech Private Limited
  • Role: Lending Service Provider (LSP) operating a Digital Lending Application (DLA)
  • Website: https://bachatt.app
  • Customer Support: [email protected]
  • Grievance Officer: Ashutosh Kashyap | [email protected] | +91 79823 15462

Lending Partners (Regulated Entities):

  • Bachatt facilitates lending services in partnership with RBI-registered Regulated Entities (REs).
  • Muthoot FinCorp Limited (NBFC) — Insta Personal Loan (EDI)
  • For the most current list of partners, please visit https://bachatt.app/loans or contact [email protected].

Loan Product Details:

  • Loan Type: Insta Personal Loan with Equated Daily Instalments (EDI)
  • Ticket Size: ₹10,000 to ₹50,000
  • Tenure, Interest Rate, Processing Fees: As determined by the RE based on the borrower's credit profile.
  • A Key Fact Statement (KFS) containing the Annual Percentage Rate (APR), loan terms, fees, and charges is provided to the borrower prior to loan disbursal, as mandated by RBI.

Important Links:

  • RBI Sachet Portal: https://sachet.rbi.org.in
  • RBI Ombudsman for Digital Lending: https://cms.rbi.org.in
  • Bachatt Privacy Policy: https://bachatt.app/policies/privacy-policy
  • Bachatt Information Security Policy: https://bachatt.app/policies/information-security-policy

Disclaimer:

This policy is a general guideline and may be subject to change based on specific product or service offerings, regulatory requirements, or Bachatt's internal policies. Users are encouraged to review the specific terms and conditions associated with each service or product before use.


This document is an electronic record in terms of the Information Technology Act, 2000 and Rules made there under, and the amended provisions pertaining to electronic records.