Legal

Privacy Policy

Last updated: April 26, 2026  ·  Effective immediately  ·  Version 1.0
IT Act 2000 DPDP Act 2023 DPDP Rules 2025 RBI Guidelines IT (SPDI) Rules 2011

FinMandi (finmandi.com) is committed to protecting your personal data and privacy. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDP Act), and the DPDP Rules, 2025. By using our website and submitting any personal information, you provide your free, specific, informed, and unambiguous consent to the practices described in this policy.

Table of Contents

  1. Who We Are
  2. Information We Collect
  3. Legal Basis for Processing
  4. How We Use Your Information
  5. Information Sharing & Disclosure
  6. Cookies & Tracking
  7. Data Security
  8. Data Retention
  9. Your Rights as a Data Principal
  10. Consent & Withdrawal
  11. Children's Privacy
  12. Cross-Border Data Transfer
  13. Data Breach Notification
  14. Grievance Redressal
  15. Changes to This Policy

1. Who We Are

FinMandi is an online financial information and comparison platform operated from India. We are a Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023, as we determine the purpose and means of processing your personal data.

Platform: finmandi.com
Nature: Financial product comparison, information, and lead generation
Contact: hello@finmandi.com

⚠️ Important: FinMandi is not a bank, NBFC, insurance company, or SEBI-registered investment advisor. We are an information and comparison platform. All financial decisions should be made after consulting with a qualified financial professional and verifying details directly with the respective institution.

2. Information We Collect

We collect only the minimum personal data necessary for the purpose stated. This includes:

We do not collect sensitive personal data such as Aadhaar numbers, PAN numbers, bank account details, passwords, biometric data, or credit/debit card information.

3. Legal Basis for Processing

Under the DPDP Act, 2023, we process your personal data on the following legal bases:

You have the right to withdraw your consent at any time. See Section 10 for details.

4. How We Use Your Information

Your personal data is used solely for the following stated purposes:

We do not use your data for automated decision-making that produces legal or similarly significant effects without human oversight.

5. Information Sharing & Disclosure

We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:

📋 We will never share your mobile number or email with lending partners without your explicit request and consent tied to a specific product enquiry.

6. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience. You may control these through your browser settings.

7. Data Security

We implement reasonable security practices as required under Section 43A of the IT Act, 2000 and the DPDP Act, 2023, including:

8. Data Retention

We retain your personal data only as long as necessary for the stated purpose or as required by Indian law:

9. Your Rights as a Data Principal

Under the DPDP Act, 2023, you have the following rights:

To exercise any right, contact us at hello@finmandi.com. We will respond within 30 days.

10. Consent & Withdrawal

Your consent is obtained when you submit our forms, use our tools, or continue to use FinMandi after being presented with this policy.

To withdraw consent: Email hello@finmandi.com with subject line "Withdraw Consent" along with your name and mobile number. We will process your request within 7 business days.

⚠️ Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal. It may limit certain services we can provide to you.

11. Children's Privacy

FinMandi is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. Under the DPDP Act, 2023, processing of children's data requires verifiable parental consent. If you believe a minor has submitted information without parental consent, contact us immediately at hello@finmandi.com and we will delete such data promptly.

12. Cross-Border Data Transfer

Your data is primarily stored and processed within India. Where we use third-party services such as Google Analytics and AdSense, data may be processed on servers outside India, subject to those providers' privacy policies and standard contractual safeguards. We do not transfer sensitive personal financial data outside India.

13. Data Breach Notification

In the event of a personal data breach, FinMandi will:

14. Grievance Redressal

In accordance with the IT Act, 2000 and the DPDP Act, 2023, we have designated a Grievance Officer to address privacy concerns:

Grievance Officer

DesignationGrievance Officer, FinMandi
PlatformFinMandi (finmandi.com)
Subject LineUse "Privacy Grievance" in your email subject
Response TimeWithin 30 days of receipt of complaint
Working HoursMonday to Friday, 10:00 AM – 6:00 PM IST

If you are not satisfied with our resolution, you may escalate your complaint to the Data Protection Board of India once fully operational under the DPDP Act, 2023.

15. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be posted on this page with a revised date. Continued use of FinMandi after changes constitutes acceptance of the updated policy. We recommend reviewing this page periodically.

Have a privacy question?

Our team is happy to help. We respond within 30 days as required by Indian law.

hello@finmandi.com