1Fi Privacy Policy
Last Updated: 27 June 2026
This Privacy Policy explains how Fiquity Technology Private Limited, operating under the brand name "1Fi", collects, uses, stores, shares, discloses and protects personal data when you access or use the 1Fi website, mobile website, mobile application, checkout journey, digital lending application, APIs, customer support channels, WhatsApp/SMS/email communication channels and any other services offered by 1Fi.
For the purpose of this Privacy Policy, "1Fi", "we", "us" or "our" refers to Fiquity Technology Private Limited, having its registered address at 1090, Guru Haridas Road, Behind Medicity Hospital, Sector 38, Gurugram, Haryana 122001, CIN U66190HR2024PTC126813.
1Fi acts as a technology platform, checkout enablement partner, Lending Service Provider and/or Digital Lending Application partner for RBI-regulated lending partners, including Kalandri Capital Private Limited and/or such other regulated lending partners as may be onboarded from time to time. 1Fi is not itself a bank, NBFC or lender. Credit facilities, loans, purchase limits and drawdowns are sanctioned, disbursed and serviced by the relevant regulated lending partner, subject to the applicable Key Fact Statement, loan agreement, drawdown term sheet and other loan documents.
1. Scope of this Privacy Policy
This Privacy Policy applies to all users, visitors, customers, borrowers, prospective borrowers, merchants and other persons who access or use the 1Fi platform.
It covers personal data processed in connection with:
- account creation and login;
- eligibility checks for mutual-fund-backed purchase limits;
- KYC, identity and fraud checks;
- mutual fund holding discovery, verification, lien marking and release;
- Account Aggregator, bank account, repayment and mandate-related journeys;
- merchant checkout and no-cost EMI transactions;
- customer support, grievance handling and communications;
- servicing, collection and recovery-related communications on behalf of regulated lending partners;
- marketing and promotional communications, where permitted; and
- website analytics, security, diagnostics and product improvement.
This Privacy Policy should be read with the 1Fi Terms & Conditions, the relevant lender's Key Fact Statement, loan agreement, drawdown term sheet, borrower consent documents, and any separate consent or disclosure shown to you during the customer journey.
2. Our role and the lender's role
For certain platform activities, 1Fi may determine the purpose and means of processing personal data and may act as a Data Fiduciary under applicable data protection law.
For lending-related activities, the relevant regulated lending partner may independently act as a Data Fiduciary in respect of lending, underwriting, KYC, credit reporting, loan servicing, loan recovery, pledge enforcement, regulatory reporting and loan record retention. 1Fi may process personal data on behalf of the regulated lending partner as a service provider, Lending Service Provider, Digital Lending Application partner or Data Processor.
This means that, depending on the activity, your personal data may be processed by 1Fi, by the relevant lending partner, or by both 1Fi and the relevant lending partner in accordance with applicable law and contractual arrangements.
3. Personal data we collect
We may collect the following categories of personal data:
3.1 Identity and KYC information
This may include your name, date of birth, gender, photograph, video, PAN, masked Aadhaar or Aadhaar-based verification information, CKYC identifier, DigiLocker documents, identity proof, address proof, signature, e-signature, OTP verification logs and other KYC or due diligence information required by law or by a regulated lending partner.
Where Aadhaar-based verification is used, it will be conducted only through lawful and authorised eKYC, offline KYC, DigiLocker or other permitted verification flows. We do not require you to share Aadhaar information except where it is lawfully required or voluntarily provided through an authorised consent-based process.
3.2 Contact and profile information
This may include your mobile number, email address, residential address, communication address, employment details, occupation, income range, customer category, language preference and other profile details submitted by you.
3.3 Financial and bank account information
This may include your bank account number, IFSC, bank name, repayment account details, UPI ID, mandate details, NACH/eMandate/UPI AutoPay data, payment status, repayment history, transaction references, bank statement information obtained through Account Aggregator or other lawful means, and information required to process repayments, refunds, prepayments or loan closure.
3.4 Mutual fund and collateral information
This may include details of your mutual fund holdings, folios, schemes, asset management companies, registrar and transfer agent records, eligible and ineligible schemes, pledged units, lien-marked units, NAV, market value, LTV calculations, lien status, lien marking instructions, lien release instructions, MFCentral records, CAMS/KFintech or other MF-RTA records, and any related collateral or pledge information.
3.5 Credit and eligibility information
This may include credit bureau reports, credit scores, loan account data, existing borrowings, repayment conduct, defaults, overdue information, SMA/NPA classification, fraud checks, internal risk scores, eligibility decisions and information received from credit information companies, lenders, account aggregators or other permitted sources.
3.6 Transaction and merchant information
This may include merchant name, store name, product or service category, order value, advance payment, drawdown amount, tenure, EMI amount, purchase date, order ID, transaction status, refund status, cancellation status, delivery status, merchant confirmations and related checkout information.
3.7 Device, technical and usage information
This may include IP address, device ID, advertising ID, browser type, operating system, network information, location derived from device or IP, app version, session information, log files, crash logs, clickstream data, time stamps, pages viewed, referral source, and user actions on the platform.
3.8 Location information
We may collect approximate location based on IP address or precise location based on device permissions, where required for fraud prevention, service availability, merchant discovery, compliance, user experience or other disclosed purposes. Precise location will be collected only if you grant device-level permission or otherwise provide consent.
3.9 Communication and support information
This may include call recordings, support tickets, emails, chat messages, WhatsApp messages, SMS records, push notification logs, grievance records, customer feedback, survey responses and other communications between you and 1Fi, the lender, merchants or service providers.
3.10 Marketing and preference information
This may include your preferences for offers, campaigns, partner stores, product categories, communication channels, opt-in/opt-out choices and responses to promotions.
3.11 Data we do not ordinarily collect
Unless specifically disclosed and consented to in a permission prompt or required for a specific feature, we do not ordinarily collect your contact list, SMS inbox, call logs, microphone recordings, gallery files or unrelated photos/files from your device.
4. Sources of personal data
We may collect personal data from:
- you directly;
- your device, browser or app usage;
- Kalandri Capital Private Limited and other regulated lending partners;
- merchants and merchant platforms;
- MFCentral, CAMS, KFintech, MF-RTAs, AMCs and mutual fund-related platforms;
- Account Aggregators and their technology service providers;
- banks, NPCI, payment gateways, mandate service providers and repayment partners;
- CKYCR, DigiLocker, UIDAI-authorised KYC providers, PAN verification providers and other identity verification sources;
- credit information companies;
- fraud prevention, risk, analytics and verification service providers;
- government, regulatory, judicial or law enforcement authorities, where applicable; and
- publicly available sources and databases, where permitted by law.
5. Purposes for which we process personal data
We process personal data for the following purposes:
- to create, maintain and secure your 1Fi account;
- to verify your identity, age, address, PAN, bank account and other KYC information;
- to assess eligibility for a purchase limit or loan facility offered by a regulated lending partner;
- to retrieve and assess eligible mutual fund holdings;
- to calculate purchase limits, available limits, LTV, margin requirements and collateral value;
- to facilitate lien marking, pledge creation, pledge variation, pledge monitoring and lien release;
- to enable merchant checkout, loan drawdown, direct disbursement to merchants and no-cost EMI transactions;
- to generate and provide the Key Fact Statement, loan agreement, drawdown term sheet, repayment schedule and other transaction documents;
- to set up, verify and process NACH, eMandate, UPI AutoPay, repayment, refund, prepayment and foreclosure journeys;
- to service your loan, send reminders, provide statements and support customer requests;
- to assist regulated lending partners with repayment follow-up, collection and recovery communications;
- to report credit information and loan performance to credit information companies and regulatory systems, where required;
- to detect and prevent fraud, identity theft, unauthorised access, money laundering, misuse, cyber incidents and other unlawful activities;
- to comply with KYC, AML, CFT, credit reporting, RBI, SEBI, tax, audit, accounting, information security and other legal or regulatory obligations;
- to respond to customer queries, complaints, disputes and grievances;
- to improve our platform, product flows, user experience, technology, security and analytics;
- to send transactional, regulatory, service and account-related communications;
- to send marketing, promotional and partner-offer communications where permitted and subject to your opt-out rights;
- to enforce our terms, protect our rights and defend legal claims; and
- for any other purpose disclosed to you at the time of collection or permitted under applicable law.
6. Legal basis and consent
We process personal data based on your consent, where consent is required, and for other lawful purposes permitted under applicable law.
By using the 1Fi platform, submitting information, accepting consent screens, completing OTP verification, using e-signature, clicking "I Agree", "I Accept", "Confirm and Continue" or similar buttons, or continuing a checkout/loan journey, you consent to the collection, use, storage, disclosure and processing of your personal data in accordance with this Privacy Policy and the relevant consent presented to you.
Where processing is based on consent, you may withdraw consent by using the available platform controls or by contacting us. Withdrawal of consent will not affect processing already carried out before withdrawal. Withdrawal may also affect our ability, or the lender's ability, to provide or continue services, process eligibility, maintain a purchase limit, service loans, process repayments, release liens, handle refunds, comply with law or enforce legal rights.
If you have an active loan, outstanding amount, pending refund, pending dispute, lien-marked units, legal obligation or regulatory retention requirement, certain data may continue to be processed and retained even after consent withdrawal, account closure or deletion request.
7. Sharing and disclosure of personal data
We may share personal data with:
7.1 Regulated lending partners
We share data with Kalandri Capital Private Limited and/or other RBI-regulated lending partners for eligibility assessment, loan sanction, KYC, underwriting, documentation, disbursement, loan servicing, repayment, collection, recovery, credit reporting, pledge enforcement, regulatory reporting and legal compliance.
7.2 Mutual fund ecosystem participants
We may share data with MFCentral, CAMS, KFintech, other MF-RTAs, AMCs and related service providers for mutual fund holding verification, lien marking, lien release, pledge management, redemption upon enforcement, reconciliation and support.
7.3 Merchants and merchant platforms
We may share limited transaction information with merchants for order confirmation, merchant settlement, refund processing, cancellation handling, delivery coordination, dispute support and reconciliation.
7.4 KYC, verification and fraud prevention partners
We may share information with CKYCR, DigiLocker, UIDAI-authorised KYC providers, PAN verification providers, account aggregators, banks, fraud-control partners and other verification providers.
7.5 Payment and repayment partners
We may share data with banks, NPCI, payment gateways, UPI providers, NACH/eMandate service providers, payment aggregators and settlement partners for processing payments, mandates, EMIs, refunds, settlements, reconciliation and payment dispute resolution.
7.6 Credit information companies and regulators
The relevant lender may share loan and repayment information with credit information companies, RBI systems and other regulatory or supervisory systems. 1Fi may facilitate such reporting where authorised.
7.7 Service providers and vendors
We may share data with cloud infrastructure providers, hosting providers, analytics providers, customer support tools, SMS/email/WhatsApp providers, call centre providers, risk engines, document execution providers, e-sign vendors, legal advisors, auditors, consultants, security vendors and other technology or operations vendors.
7.8 Recovery agents and authorised representatives
Where permitted by law and disclosed by the lender, data may be shared with authorised recovery agents or collection representatives for repayment follow-up and recovery-related communication.
7.9 Assignees and financing counterparties
Data may be shared with actual or proposed assignees, transferees, securitisation counterparties, financing partners or similar persons in connection with assignment, transfer, securitisation, sale, restructuring or financing of loan receivables or lender rights, subject to confidentiality and applicable law.
7.10 Government and legal authorities
We may disclose data to courts, tribunals, regulators, law enforcement agencies, government authorities, tax authorities or other persons where required by law, legal process, regulatory direction or to protect rights and safety.
8. Cookies, analytics and tracking technologies
We may use cookies, pixels, SDKs, tags, local storage, device identifiers and similar technologies to:
- keep you signed in;
- remember preferences;
- secure the platform;
- measure website and app performance;
- understand user behaviour;
- diagnose errors;
- prevent fraud;
- personalise content and offers; and
- improve our products and services.
You may disable some cookies through your browser or device settings. However, certain platform features may not work properly without essential cookies or similar technologies.
9. Communications
You may receive communications through SMS, email, phone call, WhatsApp, push notification, in-app message, chatbot, post or other lawful modes.
These communications may include OTPs, KYC updates, loan status, lien status, drawdown confirmation, repayment reminders, refund updates, support messages, grievance updates, regulatory communications, service messages, product updates and marketing offers.
You may opt out of marketing communications at any time by using the unsubscribe option or by contacting us. Transactional, servicing, legal, collection, security and regulatory communications may continue even if you opt out of marketing.
10. Data security
We use reasonable technical and organisational safeguards to protect personal data against unauthorised access, misuse, loss, alteration, disclosure or destruction. These may include access controls, encryption, secure transmission, logging, monitoring, authentication controls, vendor controls, backup procedures, security reviews and incident response processes.
No digital system is completely secure. You are responsible for keeping your device, SIM card, email, passwords, PINs, OTPs and app credentials secure. You should immediately inform us if you suspect unauthorised access or misuse of your account.
11. Data retention
We retain personal data for as long as required for the purposes described in this Privacy Policy, including account operation, loan processing, loan servicing, lien release, repayment, dispute handling, legal compliance, audit, risk management, fraud prevention and enforcement of legal rights.
For lending, KYC, financial, accounting, audit and regulatory records, data may be retained during the customer relationship and for at least 5 years after loan closure or relationship termination, or for such longer period as may be required under applicable law, regulatory directions, lender policy, litigation hold, audit requirement or contractual obligation.
If you request deletion or erasure of data, we will process the request subject to active loans, pending transactions, unresolved disputes, legal retention requirements, regulatory reporting obligations, fraud prevention needs and enforcement of legal rights.
12. Cross-border processing
Your personal data may be processed, stored or accessed in India or outside India by our service providers, technology partners or group/business partners, subject to applicable law. We will take steps to ensure that such processing is subject to appropriate contractual, technical and organisational safeguards. We will comply with any restriction notified by the Government of India in relation to transfer or availability of personal data outside India.
13. Children's data
The 1Fi platform and lending services are intended only for individuals who are at least 18 years of age and legally competent to contract. We do not knowingly provide lending services to children or knowingly collect children's personal data for lending purposes.
If we become aware that personal data of a child has been collected without lawful basis, we will take reasonable steps to delete or restrict such data, subject to legal and regulatory requirements.
14. Your rights
Subject to applicable law, you may have the right to:
- access a summary of personal data being processed by us;
- know the identities of persons with whom your personal data has been shared, where required by law;
- correct inaccurate or misleading personal data;
- complete incomplete personal data;
- update outdated personal data;
- request erasure of personal data where retention is no longer necessary and no legal obligation requires retention;
- withdraw consent where processing is based on consent;
- register a grievance;
- nominate another individual to exercise your rights in the event of death or incapacity; and
- exercise any other right available under applicable law.
To exercise your rights, you may contact us using the details provided in this Privacy Policy. We may verify your identity before processing your request. We may reject, defer or partially fulfil a request where permitted by law, including where the request conflicts with legal retention, active loan servicing, fraud prevention, regulatory reporting, dispute resolution or enforcement of legal rights.
15. Your responsibilities
You agree to:
- provide accurate, complete and updated information;
- not impersonate any person;
- not submit false, forged, misleading or unauthorised documents;
- keep your device, SIM, email, passwords, OTPs and app credentials secure;
- promptly update your mobile number, email, address, bank account and KYC details;
- promptly report unauthorised transactions or account compromise;
- not misuse the platform or attempt unauthorised access; and
- use the platform only in accordance with law and the 1Fi Terms & Conditions.
16. Third-party websites and services
The 1Fi platform may contain links, redirects or integrations with third-party websites, merchant platforms, payment gateways, KYC providers, account aggregators, mutual fund platforms and other third-party services. These third parties may have their own terms and privacy policies. We are not responsible for their independent privacy practices, except to the extent required by applicable law or contractual arrangement.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, regulation, business practices, technology, lender arrangements or platform functionality.
The updated Privacy Policy will be made available on the 1Fi platform. Where required by law, we will notify you or seek fresh consent. Your continued use of the platform after the updated Privacy Policy becomes effective will be treated as acceptance of the updated Privacy Policy, subject to applicable law.
18. Contact us
For questions regarding this Privacy Policy or your personal data, please contact:
Fiquity Technology Private Limited / 1Fi
Email: [email protected]
Phone: +91 7303323443
Address: 1st Floor, Orchid Business Park, Sector 48, Gurugram