Effective date5 July 2026
Version1.0
Applies tohttps://wingzman.com/, the Wingzman mobile application, and any other Digital Lending Application operated by the Company

1. Who we are and what we do

The Company is a Lending Service Provider (“LSP”) engaged by one or more Regulated Entities (“REs”) — banks and non-banking financial companies licensed by the Reserve Bank of India. We are not a lender. We do not sanction loans, set pricing, or take credit decisions.

Our current lending partners are listed at https://wingzman.com/lending-partners.

In relation to personal data, the RE that extends or is considering extending your loan is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 for data processed for lending purposes. The Company processes such data as a Data Processor on that RE’s instructions, under a written agreement. Where we process data for our own purposes — for example, operating and securing our platform — we act as Data Fiduciary and this Policy governs that processing.

2. Personal data we collect

We collect only data that is need-based for a specified purpose, with your prior and explicit consent.

CategoryExamplesWhy we collect it
IdentityName, date of birth, gender, PAN, Aadhaar-based verification resultKYC and identity verification on behalf of the RE
ContactMobile number, email address, residential addressCommunication, servicing, statutory notices
FinancialBank account details, income information, bank statement data, credit bureau dataCredit assessment by the RE, disbursal and repayment set-up
EmploymentEmployer name, employment type, work emailIncome verification
TransactionLoan account activity, repayment historyServicing and account management
Device and technicalDevice model, OS version, IP address, app version, device identifiersFraud prevention, security, and app functionality
UsagePages viewed, features used, session dataProduct improvement and error diagnosis

2.1 Device permissions

We request the following permissions, each with your explicit consent, and each on a one-time basis for the stated purpose only:

PermissionPurposeBasis
CameraOne-time capture of KYC documents and live photographOne-time, at your action
LocationOne-time capture at onboarding for regulatory address verificationOne-time, at your action
MicrophoneVideo KYC session, where applicableOne-time, at your action

We do not access your contacts list, call logs, SMS messages, or device file and media storage. Access to these is not required for our services, and we will not request it.

You may deny or later withdraw any permission through your device settings. Denying a permission may prevent completion of a step that legally requires it, and we will tell you clearly when that is the case.

2.2 Biometric data

We do not collect or store biometric data except where expressly permitted or required under applicable law, and never for purposes beyond that permission.

3. Consent

We collect personal data only with your prior, explicit and informed consent, given through a clear affirmative action. Consent is:

  • Specific — sought separately for each distinct purpose, not bundled;
  • Granular — you may consent to some purposes and decline others;
  • Recorded — every grant, denial, and withdrawal is logged with a timestamp in an auditable trail;
  • Revocable — withdrawable at any time through the Wingzman app or by writing to the Grievance Officer named in section 11.

Withdrawal of consent operates prospectively. It does not affect processing already carried out, and it does not extinguish any obligation you owe under a loan agreement or any obligation the RE has to retain records under law.

4. How we use your data

We use personal data to: verify your identity and eligibility; transmit your application to the relevant RE; present loan offers; facilitate disbursal and repayment instructions between you and the RE; service your account and respond to your queries; detect and prevent fraud; comply with legal, regulatory and audit obligations; and improve and secure our platform.

We do not sell personal data. We do not use personal data for purposes unrelated to those disclosed to you at the time of collection.

5. Who we share your data with

Recipient categoryWhat is sharedWhy
Regulated Entities (our lending partners)Application, KYC, financial and servicing dataSo the RE can assess, sanction, disburse and service your loan
Credit Information CompaniesAs mandated by our NBFC partnersStatutory reporting, at the RE's direction
KYC and verification service providersAs mandated by our NBFC partnersIdentity, address, and document verification
Payment and account-aggregation partnersAs mandated by our NBFC partnersDisbursal and repayment set-up
Cloud hosting and infrastructure providersEncrypted stored dataHosting and processing, on servers located in India
Fraud prevention and analytics providersAs mandated by our NBFC partnersFraud detection
Regulators, courts, law enforcementAs lawfully requiredLegal compliance

Every third party is bound by a written agreement restricting use to the disclosed purpose, imposing security obligations, and prohibiting onward transfer.

6. Storage, localisation and retention

All personal data is stored on servers located in India.

Where any processing is undertaken outside India, the resulting data is deleted from servers outside India and brought back to India within 24 hours of processing, in accordance with the DL Directions.

We retain personal data only for as long as necessary for the purpose for which it was collected, or for the period required by applicable law, the RE’s regulatory retention obligations, or to establish or defend legal claims — whichever is longer. Specific periods:

DataRetention period
KYC recordsAs mandated under applicable KYC and PMLA requirements
Loan account and transaction records5 years from closure of the loan
Consent and audit logs5 years from closure of the loan
Applications that did not proceed to sanction2 years from closure of the loan
Complaint records5 years from closure of the loan

On expiry of the retention period, data is securely and irreversibly destroyed. Our destruction protocol is cryptographic erasure of storage keys followed by overwrite, with a certificate of destruction retained.

7. Security

We maintain reasonable security safeguards including encryption in transit and at rest, role-based access control, network segregation, logging and monitoring, periodic vulnerability assessment and penetration testing, and annual third-party security audit, consistent with the cybersecurity standards specified by the Reserve Bank of India.

8. Data breaches

In the event of a personal data breach, we will notify the affected individuals and the Data Protection Board of India in the manner and within the timelines prescribed under the Digital Personal Data Protection Act, 2023 and the rules made under it, and will notify each affected RE without delay so that the RE can meet its own reporting obligations to the Reserve Bank of India.

9. Your rights

Subject to applicable law, you may:

  • Access — obtain a summary of the personal data we process about you and the identities of those with whom it has been shared;
  • Correct — have inaccurate or incomplete data corrected, and have data updated;
  • Erase — request deletion of data no longer necessary for the purpose for which it was collected, subject to statutory retention obligations;
  • Withdraw consent — at any time, as described in section 3;
  • Restrict or deny disclosure of specific data to third parties;
  • Port your data — obtain data in a portable form, and request its transfer, where the DL Directions or applicable law provide for this;
  • Nominate — appoint a person to exercise your rights in the event of your death or incapacity;
  • Complain — to our Grievance Officer, and thereafter to the Data Protection Board of India.

To exercise any right, contact the Grievance Officer named in section 11. We will respond within 30 days. We may need to verify your identity before acting.

10. Cookies and similar technologies

We keep this deliberately minimal. The website sets no cookies at all unless you agree to analytics cookies, and it works exactly the same either way.

WhatPurposeCookies?Needs your consent?
Your cookie choiceRemembers whether you accepted or declined analytics, so we stop askingNo — stored in your browser’s local storageNo, it is strictly necessary
Cloudflare Web AnalyticsCounts page views and referrers so we know which pages are usefulNo — it is a cookieless measurement tool and does not fingerprint youNo
Google Analytics 4More detailed analysis of how the site is usedYes — sets cookies beginning _gaYes — it stays switched off until you accept

We do not use advertising or cross-site tracking cookies, and we do not sell or share your browsing data with advertisers.

Changing your mind. Choose “Cookie settings” at the bottom of any page to accept or decline at any time. If you withdraw consent we switch Google Analytics off and delete the cookies it set. You can also block or delete cookies through your browser settings.

11. Grievance Officer and Data Protection contact

NameArpit Narang
DesignationGrievance Officer / Data Protection Officer
Emailarpit.narang@wingzman.com
Telephone+91 90535 83590
Postal addressPlot 23, Sector 18, Maruti Industrial Development Area, Gurugram, Haryana 122015
Response time30 days

For complaints relating to digital lending conduct generally, please also see our Grievance Redressal Policy, which sets out the escalation path to the relevant Regulated Entity and thereafter to the Reserve Bank of India.

Complaints regarding personal data may be escalated to the Data Protection Board of India after exhausting the above.

12. Children

Our services are not offered to persons below 18 years of age, and we do not knowingly collect personal data of children.

13. Changes to this Policy

We may update this Policy. Material changes will be notified to you through in-app notification and email at least 15 days before they take effect. The current version and its effective date always appear at the top of this page.