Privacy Policy

findit is built around one promise: your phone number is not given to anyone until you decide it should be. This policy explains what we collect, why we hold it, who it reaches, and how to get it back or get rid of it.

Effective 9 August 2026 Data Fiduciary under the DPDP Act, 2023 Data stored in India

1Who we are

findit is an intent marketplace operated in India. When a customer posts a requirement, we send it to a small number of matching businesses who respond with real options. We act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) in respect of the personal data described below.

This policy covers the findit customer app and PWA, the findit for Business app and panel, and the findit API. It does not cover what a business does with your details after you have chosen to share them with that business — at that point they are an independent Data Fiduciary for their own use of your data, bound by the Terms of Service and the Community Guidelines.

2What we collect

If you are a customer

DataWhy we need it
Mobile numberIt is your account. There are no passwords in findit; you sign in with your number and a one-time code
NameShown to a business only when you share your contact with them
Date of birthAge determines eligibility for loan, insurance and credit-card requirements. We store the date and derive age rather than storing an age that quietly goes stale
City and localitiesMatching. A requirement is matched to businesses covering your city, and scored against the areas you picked
Requirement detailsBudget, category and the answers to the category's questions — this is what gets matched and what businesses respond to
Reference photosOptional, and only if you attach them
Device push tokenTo notify you when a response arrives. Optional; declining notifications does not affect anything else
Consent recordsEvery time you share your contact, we store what you agreed to, the version of that wording, and when
Technical logsRequest timestamps, error diagnostics and coarse device information, used to keep the service working and to investigate abuse

If you are a business or a sales user

  • Your mobile number, name, and whether you are a registered business or self-employed.
  • Your business's legal name, city, and the service categories you claim.
  • Business identifiers such as GSTIN or PAN, and a logo, if you provide them after approval.
  • Your inventory listings, the responses you send, photos you upload, and your response history.
  • Contact details of customers who have chosen to share them with you.
We do not collect

Location tracking, contact lists, call logs, SMS, browsing history outside findit, advertising identifiers, or biometric data. We do not buy personal data from third parties, and we do not run third-party advertising or tracking pixels.

3How we use it

  • To run the marketplace — matching a requirement to businesses, delivering their responses to you, and recording the contact share when you make one.
  • To notify you of responses and of things that happen on your account.
  • To review businesses before they are allowed to receive leads, and to investigate reports about them afterwards.
  • To keep the service safe — detecting duplicate accounts, spam, bait listings and misuse of contact data.
  • To improve the product using aggregate patterns, such as which categories get responses and how quickly.
  • To meet legal obligations, including retaining consent records and responding to lawful requests.

We do not use your data to build advertising profiles, and we do not sell personal data to anyone, in any form, for any price.

4Your phone number, specifically

The rule the product is built on

A business receives your name and number only after you tap to share them on one specific response. Before that, your contact details are not merely hidden from the business — they are absent from the data the business receives at all.

When you share your contact with a business:

  • We record the exact consent wording shown to you and its version, so that a later change to our wording cannot alter the record of what you actually agreed to.
  • That business receives your name and number, and you receive theirs. The exchange is mutual.
  • The share applies to that business and that response only. Sharing with one business tells the other four nothing.
  • You can withdraw the share. Withdrawal stops further access through findit and is logged. It cannot un-know a number the business has already seen, which is why the tap comes first — but a business that keeps contacting you afterwards is in breach and will be removed.

Your number is never displayed on a requirement, never included in a business's lead inbox, and never exposed by the API to any business-facing endpoint.

5Who your data reaches

RecipientWhat they see
Matched businesses
up to 5 per requirement
The requirement — category, budget, areas, your answers and any photos. No name, no number, no date of birth. Your identity only after you share it
Businesses you share contact with Additionally your name and mobile number
Cloud infrastructure
Microsoft Azure
Hosting, database and photo storage. Processors acting on our instructions, not for their own purposes
Authentication and messaging
Google Firebase
Your mobile number, to send the one-time code, and a device token to deliver notifications
findit staff Access on a need-to-know basis for support, review and abuse investigation. Every administrative action on customer or business data is written to an audit log
Authorities Only where required by law, and only what is required

We do not share personal data with advertisers, data brokers, or lead-generation networks. There is no such arrangement and there will not be one.

6How we protect it

  • All traffic is over HTTPS. The service refuses plain HTTP.
  • Photos live in private storage. They are served through short-lived signed links that expire; there is no publicly readable photo container.
  • Business accounts are scoped server-side to their own business on every query. A business cannot request another business's leads by changing an identifier — the request returns nothing.
  • Customer contact fields are excluded from business-facing responses at the data-transfer layer, so a leak cannot happen by someone forgetting to strip a field.
  • Secrets and connection strings are held in managed key storage, never in application code.
  • Administrative access is key-protected and audit-logged.
Beta status — please read

findit is currently a limited beta in Bengaluru. During the beta the platform is being actively developed and hardened, and you should not treat it as you would a mature service. Do not enter data you would not want in a pre-production system, and do not send identity documents, account numbers or financial statements through it. No system is perfectly secure; we will tell you promptly if something goes wrong.

7How long we keep it

DataKept for
Your account and profileUntil you delete it, or after a long period of inactivity following notice
Requirements and responsesUntil you delete them; a requirement stops matching once closed or after it expires
Consent and contact-share recordsRetained after deletion where we need them to evidence a consent that was given, as the DPDP Act requires
PhotosDeleted with the requirement or listing they belong to
Audit and security logsA limited period, for abuse investigation and legal obligations

When you delete a requirement, it disappears from your view. A business that already responded to it keeps its own record of the response it sent, because that is their business record — but it no longer carries your contact details unless you had shared them, and it stops being visible to you.

8Your rights

Under the DPDP Act, 2023, you may:

  • Access a summary of the personal data we hold about you and who we have shared it with.
  • Correct data that is inaccurate, and complete data that is incomplete — most of it is editable directly in the app.
  • Erase your data and delete your account, subject to what we must retain by law.
  • Withdraw consent, including withdrawing a contact share, as easily as it was given.
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
  • Complain to the Grievance Officer, and afterwards to the Data Protection Board of India.

To exercise any of these, use the account settings in the app or write to privacy@getfindit.online from your registered mobile number's associated account. We respond within 30 days. Withdrawing consent for the processing that findit depends on — your number, your name, your requirement — means we can no longer operate the account, and it will be closed.

9Children

findit is not for anyone under 18. We do not knowingly collect data from children, and the requirement categories we operate in — property, vehicles, loans, insurance and credit cards — are not available to minors. If we learn that an account belongs to someone under 18, we close it and delete the data.

10Where your data is stored

Personal data is stored in India. Some infrastructure components used to operate the service may be located elsewhere; where that is the case, the data involved is protected by contract and transferred only in line with the DPDP Act and any restrictions notified by the Central Government. We are consolidating all processing into Indian regions.

11Grievance Officer

If you have a concern about how your personal data has been handled, contact our Grievance Officer. We acknowledge every grievance and aim to resolve it within 30 days.

Grievance Officer

[Name of Grievance Officer]
Email: grievance@getfindit.online
Address: [Registered office address], Bengaluru, Karnataka, India
Response time: acknowledgement within 72 hours, resolution within 30 days

If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India.

12What we do not control

findit is a matching medium. It introduces two sides and gets out of the way. The limits that follow are a consequence of that, and they are stated plainly here rather than buried in a clause elsewhere.

Media uploaded by others

We do not pre-screen, verify, or actively monitor all media, images, or documents uploaded by businesses or users. We assume zero liability for offensive, inappropriate, or unethical images shared by third-party businesses. If inappropriate content is reported, we will investigate and remove it within a commercially reasonable timeframe, but we are not liable for its initial visibility.

Report anything of this kind from within the app, or as described in Community Guidelines §7. Reports that carry a reference code are actioned considerably faster.

Contact information you disclose yourself

Your contact information is protected within our system interface until you explicitly choose to share it or reveal it to a business. We are not responsible or liable if you voluntarily disclose your personal data directly to a business, or if a business obtains your information through external, non-platform channels. We act solely as a matching medium and cannot guarantee the downstream privacy practices of independent third-party vendors.

Responses, listings and transactions

We do not guarantee that every requirement posted will receive a response, nor do we guarantee the accuracy, completeness, or legitimacy of property listings or requirements posted by either party. We provide a connection platform only and are not a party to any rental, lease, or commercial transaction negotiated between users and businesses.

Availability and security

The platform is provided on an "as-is" and "as-available" basis without warranties of any kind. We are not responsible for temporary service interruptions, data loss, delayed push notifications, or technical glitches caused by third-party infrastructure providers. We do not guarantee absolute protection against unauthorised access to our servers, though industry-standard security measures are maintained — those measures are set out in §6.

Money

We are not responsible for financial transactions, token payments, deposits, brokerage fees, or agreements made directly between users and businesses outside of our official platform payment gateway. Any financial disputes must be resolved independently between the involved parties.

Identity and background checks

We do not independently background-check every individual user or business entity. We are not liable for any misrepresentation, fraud, or damages arising from interactions between users who met through the platform. Users and businesses agree to interact at their own risk.

Business accounts are reviewed by a person before they can receive requirements, and a business can be suspended or removed for what it does afterwards — but that review establishes that an applicant plausibly operates in the category they claimed. It is not a background check, and it is not a warranty of anyone's conduct.

What these limits do not touch

None of the above reduces our obligations as a Data Fiduciary under the DPDP Act, 2023 for the personal data we ourselves hold — the consent, access, correction, erasure and grievance rights in §8 and §11 stand regardless. Nor does anything here exclude liability that cannot lawfully be excluded. These are limits on what we can promise about other people's conduct and about infrastructure we do not own; they are not a disclaimer of our own duties to you.

13Changes to this policy

We will update this policy as the product changes. Material changes — new categories of data, new recipients, or a change in how your contact data is treated — are notified in the app before they take effect, and where the law requires it we will ask for fresh consent rather than assume it. The effective date at the top of this page is always the version in force.