Abhicash Infotech Private Limited (LSP) · Lending Partner: CNMP Investments Private Limited (NBFC) · https://abhimoney.in ·
This Privacy Policy is framed in light of Section 43A of the Information Technology Act, 2000 read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; the Digital Personal Data Protection Act, 2023; and in compliance with the Reserve Bank of India (Digital Lending) Directions, 2025 and other applicable RBI directions. It governs how personal information (including sensitive personal data or information) is collected, received, stored, used, disclosed and protected in connection with the AbhiMoney platform.
Who operates AbhiMoney
“AbhiMoney” is a brand. The AbhiMoney website and mobile application (the “Platform” / “DLA”) are owned and operated by Abhicash Infotech Private Limited (the “LSP”, “we”, “us”, “our”), which acts as a Lending Service Provider and authorised agent of the lender.
Loans are provided, and all lending decisions are taken solely, by the lending partner. Our current lending partner is CNMP Investments Private Limited (the “NBFC” / “Lender”), a company incorporated under the Companies Act, 2013 and registered with the Reserve Bank of India as a Non-Banking Financial Company, CIN U74899DL1983PTC016061, having its registered office at . The LSP does not itself lend, take deposits or make credit decisions. Responsibility for data privacy and security of the borrower’s personal information on an ongoing basis rests with the NBFC as the Regulated Entity.
The AbhiMoney DLA is reported on the RBI’s Centralised Information Management System (CIMS) and listed on the RBI’s public database of digital lending apps. The name of the Lender and a link to the Lender’s website (where the LSP is named as its authorised agent) are displayed on the Platform.
We are committed to protecting the personal information, including sensitive personal and financial information, that you submit to us, and to using it only for the purposes described here. This Policy explains how your data is collected, stored, used and shared. Please read it carefully. By using the Platform, you consent to the collection, use and disclosure of your personal information in accordance with this Policy. If you do not agree, you may refrain from using our services. For any question, contact care@abhimoney.in.
We collect only need-based information, with your prior and explicit consent and an audit trail, as required under the RBI (Digital Lending) Directions, 2025. We may collect:
4.1 Information you provide by filling in forms on the Platform — name, email, mailing address, phone number, and financial and employment details.
4.2 KYC information as required under the RBI Know-Your-Customer norms — KYC documents (PAN, Aadhaar as permitted, photograph), contact details, and bank details (account number, IFSC) — collected on behalf of the Lender for identity verification and underwriting.
4.3 Account-registration information such as name, address, email and telephone number, and basic, non-sensitive device metadata (device model, operating-system version, app version, IP address, and crash/diagnostic logs) used solely for security, fraud prevention and service improvement.
4.4 Information from third parties such as credit information companies and identity-verification services, used for credit assessment.
4.5 One-time access for onboarding / KYC (RBI-permitted): with your explicit consent, the app may take a one-time access to your device camera, microphone and location, solely for the purpose of onboarding / KYC (for example, a live-photo/video KYC and address/serviceability verification), as expressly permitted under the RBI (Digital Lending) Directions, 2025. This access is limited to the KYC purpose and is not used for any continuous tracking.
4.6 Bank-account verification through an RBI-authorised Account Aggregator, with your consent, to obtain the financial information required for underwriting for the duration of the loan-application and decisioning process.
4.7 Information you provide when interacting with our customer-support team, and testimonials you voluntarily provide (displayed only with your consent).
4.8 Server log files that your browser sends automatically (IP address, browser type, referring/exit pages, pages viewed), used to analyse trends and administer the Platform.
4.9 SMS metadata (business-instructed): with your explicit, just-in-time consent, we may read the headers of SMS to identify the sender type and read indicative SMS content from 6-digit alphanumeric (transactional) senders for verification. Information such as sender name, indicative content and timestamp may be collected to verify financial statistics such as income and spending patterns for credit evaluation and fraud prevention, and may be transmitted to our service providers. We do not read personal or OTP messages, other than OTPs sent by us.
4.10 Installed-application list (business-instructed): with your explicit consent, we may collect metadata about applications installed on your device (application name, package name, install/update time, installer source, version) for identity verification, fraud detection and underwriting, and may share this with our device-intelligence service provider. Collection is initiated only after your consent.
4.11 Location (business-instructed, beyond one-time KYC): with your consent, we may collect and monitor your device location to determine serviceability, reduce credit risk, assist address verification and provide pre-approved offers.
4.12 Device / phone-state (business-instructed): with your consent, we may request Phone State permission to verify the device’s active SIM and network status at onboarding and disbursement, to confirm the transaction corresponds to the rightful customer and is not spoofed. We do not collect IMEI or device serial numbers.
The one-time camera / microphone / location access described in clause 4.5 is taken only for onboarding / KYC, only with your explicit consent, and can be declined or revoked (which may affect your ability to complete KYC).
To the extent clauses 4.9 to 4.12 apply, any access to SMS, installed-application lists, location or device/phone-state is taken only with your explicit, just-in-time consent, is limited to the stated verification, fraud-prevention and credit-assessment purposes, and can be revoked. We do not access your files, media, photo gallery, contacts / phone book or call logs, and do not read personal or OTP messages (other than OTPs sent by us).
We do not collect permanently identifiable device identifiers such as IMEI or device serial number. We do not collect or store biometric data except as permitted by law. All data is stored on servers located in India.
We use the information collected to:
We do not use your data for purposes unrelated to the original consent unless required by law or with your renewed consent. We do not sell, lease or trade your personal data.
We share your personal data only to the extent necessary, and only with: the Lender (and other regulated lending partners); credit information companies; third-party service providers under confidentiality obligations (e.g. e-KYC, e-sign, account aggregators, payment gateways); and government / regulatory / law-enforcement bodies where required by law. Such parties may use the information only for the stated purpose and must protect it under strict confidentiality. Data sharing with third parties requires your consent except where disclosure is for legal or regulatory reasons. The list of third parties collecting information through the Platform is available on the website and updated from time to time.
Like most websites, we use cookies and similar technologies to recognise repeat users, maintain session integrity during login, personalise content, support security and analyse usage to improve the Platform. Information collected is stored in secured databases and treated as confidential. We do not track users across third-party websites, and we do not allow third-party behavioural-advertising tools on our lending app or website.
We have implemented reasonable security practices and procedures commensurate with the information protected, including role-based access controls, encryption, firewalls, anti-malware controls, intrusion detection, vulnerability assessments and secure coding practices, and we apply data-minimisation. You are responsible for maintaining the confidentiality of your account credentials; we are not liable for unauthorised use resulting from your failure to do so.
We retain personal information only for as long as necessary for the purposes for which it was collected and for the statutory retention period thereafter (for KYC records, the period prescribed under the RBI KYC Directions / PML Rules). The Lender may retain your information during the loan tenure and thereafter to meet legal and regulatory obligations, resolve disputes and prevent fraud. As the LSP, we do not store your personal information except basic minimal data (such as name, address and contact details) required to carry out our functions under our agreement with the Lender. On expiry of the retention period, data is deleted or anonymised. You may contact our Grievance Officer to access, correct or request deletion of your data.
The Platform may contain links to third-party websites or services not operated by us. Inclusion of a link is not an endorsement. We do not control and are not responsible for the privacy practices or content of such third parties; their own policies apply. Please review them before submitting any information.
The Platform is intended only for persons who are 18 years or older. We do not knowingly collect personal data from children. As part of KYC, documentary age verification is carried out at onboarding. If we become aware that we have inadvertently collected data from a person below 18, we will delete or anonymise it. By using our services, you affirm that you are at least 18 years old and competent to contract under Indian law.
By accessing, registering or using the Platform, you give your free, informed, specific and unambiguous consent to the collection, processing, storage, use and disclosure of your personal data as described in this Policy, in accordance with the Digital Personal Data Protection Act, 2023 and the applicable RBI framework. You may withdraw consent at any time by writing to our Grievance Officer; on withdrawal we will stop processing for the relevant purpose unless processing is required to comply with law, to service an active loan, or to establish or defend legal claims. Withdrawal of consent for essential data (e.g. KYC, repayment details) may affect your ability to use certain services. You may also request deletion of data no longer required to be retained under law.
Grievance Officer (LSP): Komal bisht, Abhicash Infotech Private Limited — gro@abhimoney.in ·8448161354 · 3rd Floor Building No. 56/6, Block C, Sector 62 Noida, Gautam buddha Nagar, Uttar Pradesh- 201309.
Nodal Grievance Redressal Officer for Digital Lending: appointed by the Lender; name and contact details are displayed on the Platform, in the app and in the KFS. If a complaint is not resolved within 30 days, you may escalate it to the RBI under the Reserve Bank – Integrated Ombudsman Scheme through the RBI Complaint Management System portal (https://cms.rbi.org.in), or report unauthorised/illegal lending activity on the RBI SACHET portal (https://sachet.rbi.org.in).
We may amend this Policy from time to time; changes are effective prospectively and will be communicated through the Platform. This Policy is governed by the laws of India, and disputes are subject to the exclusive jurisdiction of the courts at [●], Haryana. If any provision is held invalid, the remainder continues in effect. The Company (as Data Fiduciary) and the LSP (as Data Processor) process borrower personal data under the DPDP Act, 2023 in accordance with that Act, the RBI (Digital Lending) Directions, 2025 and this Policy. In case of conflict of interpretation, the English version prevails.
This Policy is subject to review at least annually, and upon any change in applicable law or regulation, with modifications approved by the Board of the Lender. The most recent version is always available on the Platform.
