Privacy Policy

Privacy Policy | LoanPayBima
Home  /  Privacy Policy
Master Privacy Document

Privacy Policy

This master policy explains how LoanPayBima collects, uses, shares, protects, retains and deletes personal information. It also incorporates our earlier Data Retention and Data Deletion policy subjects into one clear document.

Effective: 26 July 2026 HRK Enterprises Karanja, District Washim, Maharashtra
LoanPayBima is a technology, CRM, lead-generation, document-assistance and customer-support platform. It is not an insurer, insurance broker, bank, NBFC, lender or financial institution.
One master policyPrivacy, retention and deletion combined.
Purpose-limited useInformation is used to support requested services and lawful operations.
Deletion requestsRequests are reviewed subject to legal, fraud-prevention and record-keeping needs.

1. Overview and commitment

LoanPayBima is operated by HRK Enterprises. We value privacy and aim to handle personal information fairly, transparently and securely.

This Privacy Policy applies to information handled through loanpaybima.in, customer forms, partner dashboards, CRM systems, telephone calls, WhatsApp, email, support channels, advertisements, offline assistance and related services controlled by us.

Our handling of digital personal data is intended to align with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and related rules or notifications as brought into force from time to time, along with other applicable information-technology, consumer-protection and sector-specific requirements.

Important legal positionThis policy describes our current operating practice. It does not make LoanPayBima an insurer, broker, bank, NBFC, lender, regulated entity or financial institution, and it does not replace the privacy notices of third-party providers.

2. Scope of this policy

This policy applies to customers, prospective customers, website visitors, partners, agents, leads, service applicants, authorised representatives and people who contact us. It covers personal data collected digitally and information first collected offline and later entered into a digital system.

It does not govern information independently collected and controlled by an insurer, bank, NBFC, lender, payment provider, KYC utility, analytics provider, hosting provider or another third party. Such organisations may act under their own legal obligations and privacy notices.

Website visitorsInsurance customersLoan applicantsPartnersSupport usersBusiness leads

3. Information we may collect

3.1 Identity and contact information

  • Full name, mobile number, WhatsApp number and email address.
  • Address, city, state, PIN code and communication preferences.
  • Date of birth, gender or other identity details when needed for a requested service.

3.2 Insurance and vehicle information

  • Vehicle registration number, vehicle type, make, model, fuel type and registration details.
  • Existing or previous policy details, insurer, policy number, expiry date, claim history and selected insurance type.
  • RC copy, previous policy, inspection images or other records requested by an authorised provider.

3.3 Loan, banking and financial-assistance information

  • Employment, occupation, income, business, loan requirement and repayment-related information.
  • Bank statements, account-related documents, credit-related information supplied by you and application status.
  • PAN, KYC documents and details needed to route or support an application with an authorised provider.

3.4 Partner information

  • Education, occupation, experience, city, KYC status, lead details and platform activity.
  • Commission records, wallet balance, payout details, bank account information and tax-related records.
  • Training, support, compliance, audit, complaint and disciplinary records.

3.5 Technical and usage information

  • IP address, browser, device, operating system, referral URL, pages viewed and time of access.
  • Login records, form submissions, consent logs, error logs, security events and cookie identifiers.
  • Approximate location inferred from IP or device settings where permitted and relevant.

3.6 Communication records

  • Emails, WhatsApp messages, chat conversations, call notes, complaint records and support tickets.
  • Call recordings only where recording is enabled and an appropriate notice or consent is provided.

4. KYC documents, bank statements and document passwords

Depending on the service requested, you may voluntarily upload or send Aadhaar, PAN, RC, previous insurance policy, bank statement and other supporting records. We seek these documents to assist with an application, verification, provider submission, customer support, fraud prevention or record management.

Document / informationTypical purposeHandling principle
AadhaarIdentity/address support where lawfully accepted by the relevant provider.Use only for the stated process. A masked Aadhaar may be accepted where sufficient for the relevant purpose/provider.
PANKYC, taxation, financial application or provider verification.Restricted access and purpose-limited sharing.
RC and old policyVehicle and insurance details, quotation or renewal assistance.Shared with authorised providers or operational personnel as required.
Six-month bank statementLoan eligibility, income/cash-flow review or provider documentation.Not used to operate your bank account; access limited to the requested process.
PDF passwordOpening a password-protected bank statement or policy file supplied by you.Used only to access that file for the requested process; avoid reusing your banking password.
Never share these credentialsDo not provide ATM PIN, UPI PIN, CVV, net-banking password, OTP or card PIN to LoanPayBima. A PDF-opening password may be requested only when required to open a document you voluntarily supplied.

Where practical, we encourage customers to submit only the minimum document needed and to use masked or redacted copies when accepted by the relevant provider. Please ensure documents belong to you or that you have lawful authority to provide them.

5. How we receive information

  • Directly from you: through forms, calls, WhatsApp, email, uploads, dashboards or offline interactions.
  • From a partner or authorised representative: where you asked that person to assist you or where the partner confirms a lawful lead source.
  • From service providers: such as insurers, banks, NBFCs, lenders or technology providers that return application status, quotation or servicing information.
  • Automatically: through cookies, server logs, analytics, security tools and device/browser data.
  • Public or permitted sources: where lawful and reasonably necessary for verification, fraud prevention or business communication.

6. How we use personal information

We may process information for the following purposes:

  1. To register accounts, manage profiles and operate customer or partner dashboards.
  2. To understand service requirements and assist with insurance, loan, credit-card, bank-account or related enquiries.
  3. To collect, organise, check and transmit documents to a selected or relevant authorised third-party provider.
  4. To provide quotations, reminders, application updates, support and complaint handling.
  5. To verify identity, prevent duplicate applications, detect fraud and protect platform security.
  6. To calculate partner commissions, wallet balances, payouts and compliance records.
  7. To improve forms, website usability, CRM workflows, service quality and training.
  8. To send marketing or promotional communication where permitted, with an available opt-out.
  9. To establish, exercise or defend legal claims and comply with lawful requests.
  10. To create aggregated or anonymised business analytics that do not reasonably identify an individual.

We do not sell a person's KYC documents as a standalone commercial product. Information may, however, be shared with relevant providers and operational vendors as described below to fulfil the requested service.

8. When we may share information

8.1 Authorised financial and insurance providers

We may share relevant information with insurers, insurance intermediaries, banks, NBFCs, lenders, credit-card issuers, bank-account providers, TPAs, surveyors, inspection vendors or other authorised entities to obtain a quotation, submit an application, complete KYC, process a request or provide support.

8.2 Technology and operational vendors

We may use hosting, CRM, cloud storage, email, SMS, WhatsApp, analytics, cybersecurity, call-management, payment, document-processing and professional-service vendors. They receive information only to the extent reasonably necessary for their role and subject to applicable contractual or legal safeguards.

8.3 Partners and authorised personnel

Information may be visible to a partner, employee, contractor or support representative responsible for the lead or request. Access should be role-based and limited to operational need.

8.4 Legal and safety disclosures

We may disclose information to courts, regulators, police, government authorities, auditors, advisers or other persons where required by law, lawful order, investigation, fraud prevention, platform security or protection of rights and safety.

8.5 Business restructuring

If the business, platform or relevant assets are reorganised, merged, transferred or acquired, information may be transferred with appropriate confidentiality and continuity safeguards, subject to law.

9. LoanPayBima's platform role

LoanPayBima provides technology, CRM, lead generation, document assistance and customer support. Final product terms, eligibility, underwriting, KYC acceptance, pricing, approval, rejection, disbursal, policy issuance, claims and servicing decisions are made by the applicable authorised provider.

A third-party provider may independently determine why and how it processes information submitted to it. You should read that provider's privacy notice before completing an application. LoanPayBima is not responsible for independent processing that falls outside our control, although we may help you identify the relevant provider or support channel.

10. Data security and access controls

We use reasonable administrative, technical and organisational safeguards proportionate to the nature of our operations. Measures may include:

  • Role-based access and account authentication.
  • HTTPS encryption in transit and secure hosting configurations.
  • Restricted document access, logging and periodic permission review.
  • Backups, malware protection, security updates and vulnerability management.
  • Partner and staff confidentiality obligations, training and incident escalation.
  • Data minimisation, deletion workflows and secure disposal practices.

No internet, email, cloud or storage system can be guaranteed completely secure. Users should keep account credentials confidential, avoid sending documents in public groups and promptly report suspicious activity.

11. Data retention

We retain information only for as long as reasonably necessary for the purpose collected, the customer or partner relationship, operational needs, legal compliance, audit, tax/accounting, fraud prevention, dispute handling and enforcement of agreements. Actual periods may vary based on the provider, record type and applicable law.

Record categoryIndicative retention approachMain reason
Basic enquiry and lead detailsNormally retained while the enquiry is active and for a reasonable follow-up period; older inactive records may be deleted or anonymised.Customer follow-up, service history, duplicate prevention.
KYC and application documentsRetained during processing and afterwards only as reasonably required for proof, support, compliance, dispute or provider coordination.Application support, audit, fraud prevention.
Issued policy / completed service recordsMay be retained for the relationship, renewal/support cycle and applicable limitation, tax or regulatory periods.Servicing, renewal, complaint and legal records.
Unsuccessful or abandoned applicationsReviewed periodically; unnecessary documents may be deleted earlier than core audit or consent records.Follow-up, fraud control and proof of instructions.
Partner KYC, leads, commissions and payoutsDuring the partnership and for applicable accounting, tax, audit, dispute and compliance periods after closure.Payment proof, reconciliation and compliance.
Consent and communication logsFor as long as needed to prove consent, opt-out, instructions or complaint history.Accountability and dispute resolution.
Security and server logsUsually for a limited security cycle, unless retained longer for investigation or legal hold.Cybersecurity and abuse prevention.
BackupsRemoved through normal backup rotation; immediate deletion from every backup may not be technically possible.Business continuity and disaster recovery.

When a retention purpose ends, information may be securely deleted, de-identified, aggregated or archived with restricted access. We may keep a minimal suppression record—such as a phone number or email in an opt-out list—to ensure you are not contacted again against your preference.

No universal fixed periodBecause LoanPayBima supports multiple product categories and third-party providers, a single fixed retention period cannot accurately apply to every record. We review necessity according to purpose, status, risk and legal requirements.

12. Data deletion and account closure

12.1 How to request deletion

You may request deletion, account closure or withdrawal of consent by emailing support@loanpaybima.in. Include your full name, registered mobile number or email, the service used and a clear description of the request. Do not email full Aadhaar or bank statements merely to prove identity unless specifically and securely requested.

12.2 Identity verification

To protect against fraudulent deletion, we may verify your request through the registered phone/email, OTP, account login, limited identity details or another proportionate method.

12.3 What deletion may include

  • Closing the LoanPayBima account or partner profile.
  • Removing unnecessary uploaded documents from active systems.
  • Deleting or anonymising inactive lead and marketing records.
  • Restricting processing while a complaint or verification is pending.
  • Requesting a relevant processor to delete data controlled on our behalf.

12.4 When immediate or complete deletion may not be possible

We may refuse, limit or postpone deletion where information is reasonably necessary for:

  • A completed transaction, policy, payout, invoice, tax or accounting record.
  • Compliance with law, regulatory direction, court order or lawful investigation.
  • Fraud prevention, security, duplicate-account control or platform abuse records.
  • A complaint, dispute, chargeback, claim, audit, legal hold or enforcement of rights.
  • Records already submitted to an independent third-party provider.
  • Backup rotation, where data is isolated from normal use and removed on schedule.

Where full deletion is not possible, we may restrict use to the permitted purpose and explain the reason, subject to legal limitations.

12.5 Third-party deletion

A request to LoanPayBima does not automatically delete records controlled by an insurer, bank, NBFC, lender or other independent provider. You may need to contact that organisation directly. We may assist with provider identification but cannot guarantee deletion by another controller.

13. Cookies and similar technologies

Our website may use essential, preference, analytics and marketing cookies or similar technologies. Essential cookies support security, forms, sessions and basic functionality. Analytics cookies help us understand website performance. Marketing technologies may measure campaigns or support relevant advertising where permitted.

You may manage non-essential cookies through an available consent banner or browser settings. Blocking cookies may affect login, forms or other website features. More detail may be provided in our separate Cookie Policy; where there is overlap, this Privacy Policy governs the broader handling of personal data.

14. Your privacy rights and choices

Subject to applicable law and verification, you may request:

  • Information about personal data we process and the main processing purpose.
  • Correction, completion or updating of inaccurate or outdated information.
  • Deletion of personal data no longer required for a lawful purpose.
  • Withdrawal of consent for future consent-based processing.
  • Opt-out from promotional communication.
  • Grievance redressal concerning our handling of personal data.
  • Nomination or other rights that become applicable under law.

We may need enough information to locate the relevant record. Requests are handled within a reasonable period and according to applicable statutory timelines once effective. Repetitive, manifestly unfounded or identity-unverified requests may be limited as permitted by law.

Fastest way to stop marketingReply “STOP” to a supported promotional message, use the unsubscribe link in email, or contact support with your registered number. Service messages related to an active request may continue until that request is closed.

15. Children's privacy

LoanPayBima's financial and insurance assistance services are generally intended for adults capable of entering into relevant transactions. We do not knowingly seek to create independent customer or partner accounts for children.

Information concerning a child may be processed only where relevant to a lawful product or service—such as a health or life insurance proposal—and where provided or authorised by a parent, lawful guardian or authorised provider. If you believe a child submitted information without appropriate authority, contact us for review.

16. Third-party websites, APIs and services

Our platform may contain links, buttons, embedded forms, payment pages or integrations operated by third parties. Their collection and use of information is governed by their own terms and privacy notices. We recommend reviewing those notices before submitting information.

We are not responsible for the security or privacy practice of a third-party site merely because it is linked from LoanPayBima. However, please report suspicious links or impersonation so we can investigate our platform and communication channels.

17. Data storage, service locations and transfers

Information may be stored or processed on systems operated by us or our vendors in India or other permitted locations, depending on the hosting, CRM, communication and provider services used. Where cross-border processing occurs, we aim to use appropriate contractual, security and legal safeguards and comply with restrictions notified under applicable law.

Third-party financial or insurance providers may maintain their own systems and retention locations independently of LoanPayBima.

18. Security incidents and personal data breaches

If we become aware of a personal data breach affecting information under our control, we will assess its nature, scope, likely impact and required containment. We may reset access, restrict systems, preserve logs, engage technical specialists and notify affected individuals or authorities where required by applicable law.

Users should immediately report unauthorised account access, suspicious document requests, fake payment demands or impersonation of LoanPayBima.

19. Changes to this policy

We may update this policy to reflect legal developments, new services, operational changes, security practices or provider requirements. The revised version will display a new effective or last-updated date. Material changes may also be communicated through the website, account, email, WhatsApp or another suitable channel.

Your continued use after an update does not replace consent where fresh consent is legally required.

20. Frequently asked questions

Is this policy also the Data Retention and Data Deletion Policy?

Yes. The master Privacy Policy now includes detailed retention and deletion sections, so separate pages are not necessary for ordinary website use.

Does LoanPayBima sell my Aadhaar, PAN or bank statement?

No. We do not sell KYC documents as standalone data products. Relevant information may be shared with authorised providers and operational vendors to support the service you requested.

Why is a bank statement PDF password requested?

Some bank statements are password protected. The password is used only to open the file you supplied for the requested application. Never provide an ATM PIN, UPI PIN, OTP, CVV or net-banking password.

Can I use a masked Aadhaar?

A masked Aadhaar may be accepted where it provides enough information for the relevant purpose and the receiving provider accepts it. Some regulated processes may require a different legally permitted KYC method.

Will deleting my LoanPayBima account cancel an insurance policy or loan application?

No. Account deletion does not automatically cancel a product, application or contract with an independent provider. Contact the provider or our support team for the applicable cancellation process.

How long will deletion take?

We first verify identity and review legal or operational exceptions. Active-system deletion is handled within a reasonable period, while backup copies are removed through scheduled rotation.

Can a partner keep customer documents on a personal phone?

Partners should use approved workflows, avoid unnecessary local copies and delete temporary copies after secure submission unless retention is specifically authorised for a lawful purpose.

Who decides whether my policy or loan is approved?

The relevant authorised insurer, intermediary, bank, NBFC, lender or product provider makes the final decision. LoanPayBima only provides platform and assistance services.

21. Privacy contact and grievance support

For access, correction, consent withdrawal, deletion, account closure, marketing opt-out or privacy grievances, contact us with your registered details and a clear description of the request.

LoanPayBima — HRK Enterprises

In Front of the Bus Stand, Karanja, District Washim, Maharashtra – 444105

+91 77209 56108

support@loanpaybima.in

https://loanpaybima.in

Include in your request
  • Full name
  • Registered mobile number or email
  • Relevant service or application
  • Specific privacy request
  • Preferred response method

For security, do not send OTP, PIN, CVV or net-banking credentials.

© 2026 LoanPayBima, operated by HRK Enterprises. All rights reserved. This document should be reviewed by a qualified legal professional before final publication.
Scroll to Top
WhatsApp