LEGAL & PRIVACY

Privacy Policy

Effective date: 22 July 2026Last updated: 22 July 2026
Your privacy matters to InstaLock.

This Policy explains in clear language what personal data we process, why we process it, who may receive it, how long we keep it and the choices available to you when you use the InstaLock EMI Locker ecosystem.

01

Overview

InstaLock (“InstaLock”, “we”, “us” or “our”) provides a connected technology platform for the protection and management of eligible financed devices. The ecosystem may include our public website, EMI Locker customer application, Distributor App, Retailer App, partner dashboards, APIs, support channels, notification systems and related technology services (together, the “Services”).

This Privacy Policy describes how we collect, use, disclose, retain and protect personal data when you visit our website, create or use an account, register or activate an eligible device, interact with an authorised distributor or retailer, receive an EMI-related notification, contact support or otherwise use the Services.

We seek to process digital personal data for lawful purposes while respecting the rights of individuals. This Policy should be read with our Terms and Conditions and any notice shown at the point where information is collected. If a partner, lender, retailer, distributor, payment provider or device seller gives you a separate privacy notice, that notice governs its own processing activities.

02

Scope and our privacy roles

This Policy applies to personal data processed by InstaLock through the Services. Depending on the activity, InstaLock may determine the purpose and means of processing or may process information on documented instructions from an authorised business partner. The relevant role may affect which organisation responds to a request or complaint.

For example, a retailer or finance partner may decide which customer and finance-plan details are entered into the platform, while InstaLock provides the technical infrastructure to securely process those details. In other situations, such as operating our website, managing our own partner accounts, preventing platform abuse or responding to a direct support enquiry, InstaLock may determine how the information is used.

This Policy does not govern independent websites, payment gateways, lenders, device manufacturers, app stores or other third parties that we do not control. We encourage you to review their privacy notices before providing information.

03

Personal data we collect

The information we collect depends on your role, the Services you use, the device and finance arrangement, and the permissions granted. We aim to collect only information reasonably necessary for the relevant purpose.

Information you or a partner provides

This may include your name, mobile number, email address, postal address, preferred language, account credentials, role, organisation, retailer or distributor details, store information, support messages and verification records. Where required for an authorised activation or finance workflow, the information may also include customer identifiers, KYC references, finance-plan identifiers, device-purchase details and acknowledgements or consents.

Device and technical information

We may process device brand, model, serial number, IMEI or other hardware identifiers, operating-system version, app version, device registration status, activation state, protection-policy state, network information, IP address, timestamps, crash data, security signals and diagnostic logs. We do not use device controls outside the functionality authorised for the EMI Locker service.

Finance and payment-status information

We may receive or display a finance-plan reference, instalment schedule, due date, repayment status, outstanding-status indicator, payment confirmation, reconciliation reference or completion status. InstaLock generally does not need full card or bank credentials. If a payment facility is offered, sensitive payment credentials are ordinarily handled by an authorised bank or payment service provider under its own privacy and security practices.

Usage and interaction information

We may record login times, dashboard actions, activation steps, retailer onboarding activity, feature usage, notification delivery, consent or acknowledgement records, support interactions and audit trails. These records help us operate the Services, resolve errors, prevent unauthorised actions and maintain accountability.

Approximate location and permissions

If a feature requires it and you grant permission, an application may use approximate or precise location for fraud prevention, store verification, authorised field activity or device registration. Camera access may be used to scan a device identifier or upload a permitted document. Notification permission may be used for security, activation and EMI-status alerts. You can control device permissions through your operating-system settings, although disabling a required permission may prevent the relevant feature from working.

04

Where personal data comes from

We may receive personal data directly from you, from an authorised distributor or retailer, from your organisation, from an authorised finance or technology partner, from a payment-status integration, from the device or application you use, or from service providers supporting identity verification, communications, cloud hosting, analytics, security and customer support.

Business users must ensure that they are authorised to submit personal data and that they have given required notices or obtained required consent. If you believe information was submitted without authority, please contact us promptly so that we can investigate with the relevant partner.

We may also derive limited operational information, such as whether an account appears at risk, whether an activation step failed, or whether a record needs reconciliation. We do not purchase unrelated consumer-marketing databases for the purpose of operating EMI Locker.

05

How and why we use personal data

We use personal data to provide and administer accounts; verify authorised users and partners; register eligible devices; support EMI Locker activation and completion; display relevant finance and payment-status information; send operational alerts; manage distributor and retailer networks; provide customer support; and keep accurate security and audit records.

We also use information to prevent fraud, impersonation, unauthorised access, tampering and misuse; diagnose technical problems; maintain compatibility; monitor availability; enforce our Terms; protect customers and partners; comply with lawful requests; establish or defend legal claims; and meet applicable legal, accounting and regulatory obligations.

We may analyse aggregated or de-identified usage patterns to understand feature performance, improve workflows, plan capacity, improve security and develop better products. We do not attempt to re-identify properly de-identified information except where necessary to test whether the de-identification remains effective.

Where processing is based on consent, the notice presented at collection should describe the information and purpose in clear language. You may withdraw consent through the method communicated to you. Withdrawal will not affect processing already lawfully completed, and it may mean that a consent-dependent feature can no longer be provided. Certain processing may continue where it is necessary for another lawful purpose, such as security, legal compliance, dispute handling or fulfilling an existing request.

06

Operational and promotional communications

We may send one-time passwords, login alerts, activation confirmations, device-status notifications, EMI reminders, service announcements, security notices, support responses and other messages necessary to operate the Services. These operational communications may be delivered by app notification, SMS, email, telephone or another channel associated with your account.

We will send promotional communications only in accordance with applicable requirements. Where an opt-out is available, you can use the unsubscribe instruction or contact us. Opting out of promotions will not stop essential operational or security communications.

07

Website cookies and similar technology

Our website and dashboards may use cookies, local storage, software development kits, pixels or similar technology to maintain a session, remember settings, protect login flows, understand performance and improve user experience. Strictly necessary technology supports essential features such as authentication, security and load balancing.

Analytics technology may help us understand which pages or features are used, how long they take to load and where errors occur. Where required, optional technology will be used only after an appropriate choice is provided. You can control cookies through browser settings, but blocking necessary cookies may prevent a login or dashboard from functioning correctly.

We do not knowingly use the EMI Locker platform to sell personal data or create advertising profiles based on sensitive device-finance activity.

08

When we share personal data

We may share personal data with the authorised distributor, retailer, finance partner, device seller or organisation connected with the relevant account or device journey. Access is intended to be role-based so that each participant receives information reasonably necessary for its function.

We may use carefully selected service providers for cloud infrastructure, data storage, communications, identity or business verification, customer support, analytics, cybersecurity, app distribution, professional advice and system maintenance. They may process information only for contracted purposes and are expected to apply appropriate confidentiality and security safeguards.

If you use a payment link or third-party integration, necessary information may be exchanged with the relevant provider to initiate, reconcile or confirm the transaction or service. The provider’s own privacy policy may apply to information it controls.

We may disclose information where reasonably necessary to comply with applicable law, a court order or a lawful governmental request; respond to an emergency; protect rights, safety and security; investigate fraud or misuse; enforce agreements; or establish and defend legal claims. We assess requests and disclose only information reasonably required, where permitted.

If InstaLock is involved in a merger, financing, acquisition, reorganisation, sale of assets or business transfer, personal data may be reviewed or transferred subject to confidentiality and applicable law. We will take reasonable steps to ensure continued protection and provide notice where required.

09

Data location and cross-border processing

Our Services may rely on cloud and technology providers that operate infrastructure in India or other permitted locations. Where personal data is processed outside the place where it was collected, we take reasonable steps to use contractual, organisational and technical safeguards and to comply with applicable restrictions.

Business partners must not export, replicate or make personal data accessible in another jurisdiction through the Services without appropriate authority and safeguards. The actual storage architecture may change as we improve resilience, security and service delivery.

10

How long we retain information

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, complete the device or EMI journey, maintain security and audit records, resolve disputes, enforce agreements and comply with legal or accounting obligations.

Retention periods vary by data type. Active account and device records may be retained while the account, partner relationship or finance journey remains active. After completion or closure, essential transaction, consent, security, support and audit records may be retained for an appropriate limitation, regulatory or dispute period. Temporary logs and diagnostics may be retained for shorter periods unless needed for an investigation.

When information is no longer required, we take reasonable steps to delete, anonymise or securely isolate it. Deletion from active systems may not immediately remove information from encrypted backups; backup data is protected and removed or overwritten according to scheduled cycles. A partner may have an independent retention obligation for information it controls.

11

How we protect personal data

We use a combination of administrative, technical and organisational safeguards designed for the nature of the Services. Measures may include access controls, role-based permissions, authentication, encryption in transit, secure development practices, system monitoring, audit logs, vulnerability management, backups, incident-response procedures, employee confidentiality commitments and service-provider reviews.

Security is a shared responsibility. You should use a strong and unique password, keep one-time passwords private, protect your phone and email account, install updates, review account activity and promptly report suspicious messages or actions. Business administrators should remove former users, review roles and limit access to those with a genuine need.

No method of transmission or storage is completely secure. If we become aware of a personal-data breach, we will assess it, take reasonable containment and remediation steps, preserve necessary evidence and provide notifications to affected persons or authorities where required by applicable law.

12

Your privacy rights and choices

Subject to applicable law and verification, you may ask for information about the personal data being processed and the processing activities, request correction or completion of inaccurate information, request erasure where retention is no longer necessary, withdraw consent for consent-based processing, or raise a grievance about our handling of your data.

You may also nominate another individual to exercise applicable rights in the event of death or incapacity where the law provides such a right. A request should identify the relevant account, mobile number, device, retailer or transaction so that we can locate the correct record without collecting unnecessary information.

We may need to verify identity and authority before acting on a request. If InstaLock processes the information only on behalf of a partner, we may forward the request to that partner or explain how to contact it. We may retain limited information where necessary for security, legal compliance, fraud prevention, the establishment or defence of claims, or another lawful purpose.

To exercise a privacy right, email info@instalock.co.in with the subject “Privacy Request”. We will acknowledge and handle the request within the period required by applicable law. You are expected to provide authentic information, avoid impersonation and not suppress material information in a request or grievance.

13

Children and guardian-authorised use

The Services are intended primarily for adults and authorised business users. We do not knowingly create an independent EMI Locker account for a child without the involvement and verifiable authorisation of a parent or lawful guardian where required.

Business partners must not submit a child’s personal data unless the collection and processing are lawful, necessary and supported by required parental or guardian authorisation. The Services must not be used in a manner that causes detrimental effects on a child’s well-being or unlawfully tracks, monitors or targets a child.

If you believe a child’s information has been submitted improperly, contact us so that we can investigate and take appropriate action with the relevant partner.

14

Automated signals and important decisions

The Services may use automated rules to identify unusual logins, failed activations, inconsistent device information, overdue-status signals or events requiring review. Such automation is primarily used for workflow, security and operational support.

InstaLock does not independently decide whether a person receives credit or determine the commercial terms of a loan unless this is expressly disclosed in a separate product notice. Lending, repayment enforcement and customer-support decisions remain subject to the responsibilities and processes of the relevant authorised partner. If you believe an automated status is incorrect, contact the retailer, finance provider or InstaLock support with supporting information.

15

Responsibilities of distributors and retailers

Authorised partners using InstaLock must handle personal data responsibly. They must provide clear notices, collect only necessary information, use data only for authorised purposes, protect login credentials, restrict staff access, keep information accurate, respond to customer questions, report incidents and comply with applicable privacy, consumer and cybersecurity requirements.

Partners must not download, copy, disclose or use customer information for unrelated marketing, personal benefit, harassment, unauthorised collection or any unlawful purpose. InstaLock may restrict access, investigate activity or preserve relevant records where we reasonably suspect misuse.

16

Changes to this Privacy Policy

We may update this Policy when the Services, our practices or applicable requirements change. The current version will be posted with a revised “Last updated” date. If a change materially affects how we use personal data, we will use reasonable efforts to provide additional notice through the website, app, account or registered contact details. Where fresh consent is required, we will request it through an appropriate process.

We encourage you to review this page periodically. Previous versions may be made available where appropriate.

17

Privacy and grievance contact

For a privacy request, correction, erasure request, consent withdrawal, security concern or grievance, contact the InstaLock Privacy & Grievance Team. Please do not send passwords or one-time passwords.

PHONE+91 99902 37356

EMAILinfo@instalock.co.in

OFFICENoida, Uttar Pradesh, India