Account and registration data: name, email, phone number, company name, business type, location (country/state/city), PAN/GST details where provided, passwords (stored in hashed form), and authentication logs.
Customer Data (processed on behalf of subscribers): pledge records, customer and employee party details, transaction and accounting data, documents, images, voice inputs where enabled, and operational metadata you upload or generate in the Service.
Payment data: billing contact details and transaction references. Card and UPI details are processed by payment partners; we do not store full payment card numbers on our servers.
Technical and usage data: IP address, device and browser type, operating system, access times, pages viewed, feature usage, error logs, and cookies or similar technologies (see Section 9).
Communications: support requests, emails, and feedback you send to us.
Depending on context, we rely on: performance of a contract (providing the Service you requested); legitimate interests (security, improvement, analytics in accordance with this Policy); consent (where required for marketing cookies or optional features); and legal obligation (tax, regulatory, or law enforcement requests).
For personal data processed on behalf of our business customers, the customer determines the lawful basis for collecting end-customer data; we process it under their instructions and our agreement.
Your data may be stored or processed in India and other countries where we or our providers operate. Where required, we implement appropriate safeguards for cross-border transfers consistent with applicable law.
We retain account data for as long as your subscription is active and for a reasonable period afterward to comply with law, resolve disputes, and enforce agreements. Customer Data retention while subscribed is controlled by your organization; upon account termination, data may be deleted or anonymized per our retention schedule and your export requests, unless longer retention is required by law.
Backup copies may persist for a limited period before automatic deletion.
We implement administrative, technical, and organizational measures designed to protect personal data, including access controls, encryption in transit (HTTPS/TLS), secure authentication, and monitoring. No method of transmission or storage is completely secure; you are responsible for safeguarding credentials and configuring roles within your organization appropriately.
Subject to applicable law (including India's Digital Personal Data Protection Act, 2023, where applicable), you may have the right to access, correct, delete, withdraw consent, restrict or object to certain processing, and lodge a complaint with a supervisory authority.
To exercise rights relating to data we control directly, contact privacy@codingroof.com. For data your employer or gold loan business holds about you as their customer, please contact that organization first; we will assist them as their processor where appropriate.
We will verify requests before responding and may decline requests that are manifestly unfounded or excessive.
The Service is intended for business use and is not directed to children under 18. We do not knowingly collect personal data from children. If you believe we have done so, contact us to request deletion.
The Service may link to third-party sites or services. Their privacy practices are governed by their own policies; we are not responsible for them.
We may update this Privacy Policy from time to time. We will post the revised version on https://goldloan.codingroof.comand update the "Last updated" date. Material changes may be communicated by email or in-product notice.
Your use of the Service is also governed by our Terms of Service.
If you have concerns about our processing of personal data, you may contact our Grievance Officer at privacy@codingroof.com. We will acknowledge complaints within a reasonable timeframe and work to resolve them in accordance with applicable law.