Privacy Policy
Effective Date: 15 March 2026 | Last Updated: 15 March 2026
Finnid is a product of Leg-IT Collective, headquartered in Lucknow, Uttar Pradesh, India.
This Privacy Policy explains how Finnid ("we", "us", "our") collects, uses, stores, and protects your
personal data when you use our SaaS platform for FPO/MSME ERP, market linkage, agri-tech solutions,
and related services at finnid.in.
By using Finnid, you agree to the practices described in this policy. If you do not agree, please do
not use our services.
1. Data We Collect
We collect the following categories of information:
- Account & Identity Data: Name, email address, mobile number, organisation name, business constitution, sector, industry, state, city, and KYC documents (PAN, GSTIN, registration certificates) provided during registration.
- Transaction Data: Subscription plans, payment amounts, payment method details (processed by CashFree; we do not store card/UPI details), invoice history, and wallet balances.
- Usage Data: Pages visited, features used, session duration, IP address, browser type, device type, and referring URLs.
- Market Linkage Data: Commodity listings, RFQ submissions, buyer/seller profiles, live mandi prices, and supply interest forms.
- Communication Data: Contact form submissions, demo booking details, partnership enquiries, OTP verification records, email/SMS/WhatsApp message logs, and support chat transcripts.
- AI Interaction Data: Queries and prompts submitted to our Groq-AI-powered features for generating insights, recommendations, or content.
2. How We Use Your Data
- To create and manage your Finnid account and ERP workspace.
- To process subscriptions, payments, refunds, and commissions.
- To provide market linkage services including live mandi prices, RFQ matching, and buyer-seller connections.
- To send transactional notifications via email, SMS, and WhatsApp (demo confirmations, OTPs, payment receipts).
- To improve our platform through analytics, usage patterns, and AI-driven insights.
- To comply with legal and regulatory requirements applicable in India.
- To detect and prevent fraud, abuse, or security threats.
3. Cookies & Tracking
Finnid uses the following cookies and similar technologies:
- Essential Cookies: Session cookies, authentication tokens, anti-forgery tokens, and OTP verification cookies (e.g., DEMO_OTP, CONTACT_OTP, PARTNER_OTP, GLOBAL_REQ_OTP, INTEREST_OTP). These are strictly necessary for platform functionality and cannot be disabled.
- Analytics Cookies: Google Analytics (gtag.js) to understand traffic sources, page views, and user engagement. You can opt out via your browser settings or the Google Analytics Opt-out Browser Add-on.
- Third-Party Widgets: Tawk.to live chat widget and Google Translate widget, which may set their own cookies.
4. OTP Handling
We use One-Time Passwords (OTPs) for email and mobile verification during registration, demo booking,
contact form submissions, partnership enquiries, and supply interest forms. OTPs are:
- Generated as random 6-digit codes on the server.
- Stored temporarily as Base64-encoded values in HTTP-only cookies with a validity of 10 to 15 minutes.
- Sent to you via email (using our email service) or SMS (via Fast2SMS).
- Automatically deleted from cookies upon successful verification or expiry.
- Never stored permanently in our database in plain text.
5. Third-Party Services
Finnid integrates with the following third-party services that may process your data:
| Service |
Purpose |
Data Shared |
| CashFree Payments |
Payment processing for subscriptions and transactions |
Name, email, phone, payment amount, order ID |
| Fast2SMS |
Transactional SMS (OTPs, demo confirmations, alerts) |
Mobile number, message content |
| Mixis WhatsApp |
WhatsApp notifications (demo bookings, RFQ updates) |
Mobile number, template variables (name, date, time) |
| Groq AI |
AI-powered insights, content generation, and recommendations |
User prompts and contextual data required for AI processing |
| data.gov.in |
Live mandi/commodity price data aggregation |
No user data shared; we consume public API data |
| Google Analytics |
Website traffic and usage analytics |
Anonymised usage data, IP address, device info |
| Tawk.to |
Live chat support |
Chat messages, optional name/email if provided |
Each third-party service operates under its own privacy policy. We encourage you to review them.
6. Data Retention
- Account Data: Retained for as long as your account is active, plus 3 years after deletion to comply with Indian tax and business regulations.
- Transaction & Payment Data: Retained for 8 years as required under the Income Tax Act, 1961 and GST regulations.
- Usage & Analytics Data: Retained for 26 months (aligned with Google Analytics default retention).
- Communication Logs (OTP, SMS, Email, WhatsApp): Retained for 1 year for audit and dispute resolution purposes.
- Market Linkage Data (RFQs, price snapshots): Retained indefinitely as aggregated market intelligence; personal identifiers are anonymised after 2 years of inactivity.
- Cookies: Session cookies expire when you close your browser. OTP cookies expire within 10-15 minutes. Analytics cookies follow Google's retention policy.
7. Data Security
We implement industry-standard security measures including:
- HTTPS/TLS encryption for all data in transit.
- HTTP-only, SameSite cookie flags for session and OTP tokens.
- Role-based access controls across all dashboard tiers (Admin, Distributor, Sub-Distributor, Subscriber, Employee).
- Regular security audits and dependency updates.
- Encrypted storage for sensitive credentials and API keys.
8. Your Rights under the Digital Personal Data Protection (DPDP) Act, 2023
As a data principal under the DPDP Act, 2023, you have the following rights:
- Right to Access: You may request a summary of your personal data processed by us and the processing activities undertaken.
- Right to Correction & Erasure: You may request correction of inaccurate data or erasure of data that is no longer necessary for the purpose it was collected, subject to legal retention requirements.
- Right to Grievance Redressal: You may raise a grievance with our Data Protection Officer. If unsatisfied with our response, you may approach the Data Protection Board of India.
- Right to Nominate: You may nominate another individual to exercise your data rights in the event of your death or incapacity.
- Right to Withdraw Consent: You may withdraw consent for data processing at any time. Withdrawal does not affect the lawfulness of processing done prior to withdrawal. Note that withdrawing consent may limit your ability to use certain platform features.
9. Children's Privacy
Finnid is designed for businesses (FPOs, MSMEs, cooperatives, agri-entrepreneurs) and is not intended
for individuals under 18 years of age. We do not knowingly collect personal data from children. If we
become aware that we have collected data from a minor, we will delete it promptly.
10. Cross-Border Data Transfers
Your data is primarily stored on servers in India. Certain third-party services (Google Analytics,
Groq AI, Tawk.to) may process data outside India. Such transfers are made in compliance with the
DPDP Act, 2023 and applicable regulations regarding permissible jurisdictions.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email
or a prominent notice on our platform. The "Last Updated" date at the top reflects the most recent revision.
Continued use of Finnid after changes constitutes acceptance of the revised policy.
12. Contact Us
For any privacy-related queries, data access requests, or grievances, please contact:
- Data Protection Officer: Finnid (Leg-IT Collective)
- Email: welisten@finnid.in
- Address: Leg-IT Collective, Lucknow, Uttar Pradesh, India
We aim to respond to all data-related requests within 30 days.