Legal
Privacy policy
Not published yet
A scaffold, not a policy. A lawyer must draft the real text against the Digital Personal Data Protection Act 2023 before Finhale accepts a single user's data. The headings below are what that draft has to cover.
01What we collect
Every field, itemised: account details, the financial data a user enters, device and usage data, and anything analytics records. A category omitted here cannot lawfully be collected.
02Why we collect it
The DPDP Act 2023 requires a stated purpose per category. 'To improve our services' is not a sufficient purpose on its own.
03Consent and notice
How consent is obtained, what the notice says at the point of collection, and how a user withdraws it. Withdrawal must be as easy as giving it.
04Who else sees it
Every processor by name: hosting, analytics, email delivery, error tracking, payments. Users are entitled to know the list, not a category.
05Where it is stored
Storage location, retention period per category, and exactly what happens to the data when an account is deleted.
06Security
The measures actually in place — encryption in transit and at rest, access control, and the breach notification process and timeline.
07Your rights
Access, correction, erasure and grievance redressal, plus the named Data Protection Officer or grievance officer with working contact details.
08Children
Processing the data of anyone under 18 requires verifiable parental consent under the DPDP Act. State the policy and how it is enforced at sign-up.
09Changes
How users are notified when this policy changes, and whether continued use constitutes acceptance.