Privacy Policy
Last updated: May 23, 2026
This Privacy Policy describes how Xploreroots Private Limited, operator of the FinzPark brand (“FinzPark”, “we”, “us”), collects, uses, and protects your personal information when you use our mobile application and website. By using FinzPark, you agree to the practices described in this policy.
1. Information we collect
We collect information you provide directly - name, mobile number, email, PAN, Aadhaar (for KYC), bank details, and investment preferences. We also collect usage data such as in-app interactions, device identifiers, and IP addresses to improve platform performance and security.
2. How we use your information
Your information is used to: (a) provide and improve our services, (b) facilitate transactions where applicable, (c) comply with applicable laws and regulations, (d) personalise Avni AI insights, and (e) send important account notifications. We do not sell your personal data to third parties.
3. Data sharing
We share data only with: (a) authorised partners required to facilitate your transactions (payment gateways, gold custodians, KYC partners), (b) service providers bound by strict data processing agreements, and (c) regulators or law enforcement when required by law.
4. Data security
We use AES-256 encryption for data at rest, TLS 1.3 for data in transit, and JWT with short expiry tokens for authentication. We do not store card numbers or UPI credentials. All payment processing is handled by RBI-licensed payment gateways. We conduct regular security audits and penetration tests.
5. Your rights
You have the right to: (a) access the personal data we hold about you, (b) correct inaccurate data, (c) request deletion of your account and associated data (subject to regulatory retention requirements), (d) withdraw consent for non-essential communications. To exercise these rights, email privacy@finzpark.com.
6. Data retention
We retain personal data only as long as necessary to provide our services and to comply with applicable laws, including the Prevention of Money Laundering Act, 2002 (PMLA) and any future SEBI/AMFI/RBI requirements that may apply once relevant registrations are obtained. Retention periods may extend up to 5 years after the end of our relationship with you where mandated by law.
7. Cookies
Our website uses essential cookies for authentication and analytics cookies (with your consent) to understand usage patterns. We do not use cookies for cross-site advertising. You can manage cookie preferences in your browser settings.
8. Bot protection (Cloudflare Turnstile)
To protect our website forms from automated abuse and spam, we use Cloudflare Turnstile. Turnstile operates invisibly in the background and may collect limited technical data (such as browser attributes and interaction signals) to determine whether a visitor is human. No personally identifiable information is collected by Turnstile beyond what is necessary for this security check. For details on how Cloudflare processes this data, please refer to the Cloudflare Turnstile Privacy Addendum at https://www.cloudflare.com/trust-hub/turnstile-privacy-addendum/.
9. Children's privacy
FinzPark is not directed at persons under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us immediately.
10. Changes to this policy
We will notify registered users of material changes to this Privacy Policy via email and in-app notification at least 30 days before the changes take effect. Continued use of FinzPark after changes constitutes acceptance.
11. Contact us
For privacy-related queries, contact our Data Protection Officer at privacy@finzpark.com or write to: Xploreroots Private Limited, 1658, First Floor, 27th Main Rd, Sector 2, HSR Layout, Bengaluru – 560102.
