This Policy explains in clear language what personal data we process, why we process it, who may receive it, how long we keep it and the choices available to you when you use the InstaLock EMI Locker ecosystem.
Overview
InstaLock (“InstaLock”, “we”, “us” or “our”) provides a connected technology platform for the protection and management of eligible financed devices. The ecosystem may include our public website, EMI Locker customer application, Distributor App, Retailer App, partner dashboards, APIs, support channels, notification systems and related technology services (together, the “Services”).
This Privacy Policy describes how we collect, use, disclose, retain and protect personal data when you visit our website, create or use an account, register or activate an eligible device, interact with an authorised distributor or retailer, receive an EMI-related notification, contact support or otherwise use the Services.
We seek to process digital personal data for lawful purposes while respecting the rights of individuals. This Policy should be read with our Terms and Conditions and any notice shown at the point where information is collected. If a partner, lender, retailer, distributor, payment provider or device seller gives you a separate privacy notice, that notice governs its own processing activities.
Scope and our privacy roles
This Policy applies to personal data processed by InstaLock through the Services. Depending on the activity, InstaLock may determine the purpose and means of processing or may process information on documented instructions from an authorised business partner. The relevant role may affect which organisation responds to a request or complaint.
For example, a retailer or finance partner may decide which customer and finance-plan details are entered into the platform, while InstaLock provides the technical infrastructure to securely process those details. In other situations, such as operating our website, managing our own partner accounts, preventing platform abuse or responding to a direct support enquiry, InstaLock may determine how the information is used.
This Policy does not govern independent websites, payment gateways, lenders, device manufacturers, app stores or other third parties that we do not control. We encourage you to review their privacy notices before providing information.
Personal data we collect
The information we collect depends on your role, the Services you use, the device and finance arrangement, and the permissions granted. We aim to collect only information reasonably necessary for the relevant purpose.
Information you or a partner provides
This may include your name, mobile number, email address, postal address, preferred language, account credentials, role, organisation, retailer or distributor details, store information, support messages and verification records. Where required for an authorised activation or finance workflow, the information may also include customer identifiers, KYC references, finance-plan identifiers, device-purchase details and acknowledgements or consents.
Device and technical information
We may process device brand, model, serial number, IMEI or other hardware identifiers, operating-system version, app version, device registration status, activation state, protection-policy state, network information, IP address, timestamps, crash data, security signals and diagnostic logs. We do not use device controls outside the functionality authorised for the EMI Locker service.
Finance and payment-status information
We may receive or display a finance-plan reference, instalment schedule, due date, repayment status, outstanding-status indicator, payment confirmation, reconciliation reference or completion status. InstaLock generally does not need full card or bank credentials. If a payment facility is offered, sensitive payment credentials are ordinarily handled by an authorised bank or payment service provider under its own privacy and security practices.
Usage and interaction information
We may record login times, dashboard actions, activation steps, retailer onboarding activity, feature usage, notification delivery, consent or acknowledgement records, support interactions and audit trails. These records help us operate the Services, resolve errors, prevent unauthorised actions and maintain accountability.
Approximate location and permissions
If a feature requires it and you grant permission, an application may use approximate or precise location for fraud prevention, store verification, authorised field activity or device registration. Camera access may be used to scan a device identifier or upload a permitted document. Notification permission may be used for security, activation and EMI-status alerts. You can control device permissions through your operating-system settings, although disabling a required permission may prevent the relevant feature from working.
Where personal data comes from
We may receive personal data directly from you, from an authorised distributor or retailer, from your organisation, from an authorised finance or technology partner, from a payment-status integration, from the device or application you use, or from service providers supporting identity verification, communications, cloud hosting, analytics, security and customer support.
Business users must ensure that they are authorised to submit personal data and that they have given required notices or obtained required consent. If you believe information was submitted without authority, please contact us promptly so that we can investigate with the relevant partner.
We may also derive limited operational information, such as whether an account appears at risk, whether an activation step failed, or whether a record needs reconciliation. We do not purchase unrelated consumer-marketing databases for the purpose of operating EMI Locker.
How and why we use personal data
We use personal data to provide and administer accounts; verify authorised users and partners; register eligible devices; support EMI Locker activation and completion; display relevant finance and payment-status information; send operational alerts; manage distributor and retailer networks; provide customer support; and keep accurate security and audit records.
We also use information to prevent fraud, impersonation, unauthorised access, tampering and misuse; diagnose technical problems; maintain compatibility; monitor availability; enforce our Terms; protect customers and partners; comply with lawful requests; establish or defend legal claims; and meet applicable legal, accounting and regulatory obligations.
We may analyse aggregated or de-identified usage patterns to understand feature performance, improve workflows, plan capacity, improve security and develop better products. We do not attempt to re-identify properly de-identified information except where necessary to test whether the de-identification remains effective.
Where processing is based on consent, the notice presented at collection should describe the information and purpose in clear language. You may withdraw consent through the method communicated to you. Withdrawal will not affect processing already lawfully completed, and it may mean that a consent-dependent feature can no longer be provided. Certain processing may continue where it is necessary for another lawful purpose, such as security, legal compliance, dispute handling or fulfilling an existing request.
Operational and promotional communications
We may send one-time passwords, login alerts, activation confirmations, device-status notifications, EMI reminders, service announcements, security notices, support responses and other messages necessary to operate the Services. These operational communications may be delivered by app notification, SMS, email, telephone or another channel associated with your account.
We will send promotional communications only in accordance with applicable requirements. Where an opt-out is available, you can use the unsubscribe instruction or contact us. Opting out of promotions will not stop essential operational or security communications.
Data location and cross-border processing
Our Services may rely on cloud and technology providers that operate infrastructure in India or other permitted locations. Where personal data is processed outside the place where it was collected, we take reasonable steps to use contractual, organisational and technical safeguards and to comply with applicable restrictions.
Business partners must not export, replicate or make personal data accessible in another jurisdiction through the Services without appropriate authority and safeguards. The actual storage architecture may change as we improve resilience, security and service delivery.
How long we retain information
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, complete the device or EMI journey, maintain security and audit records, resolve disputes, enforce agreements and comply with legal or accounting obligations.
Retention periods vary by data type. Active account and device records may be retained while the account, partner relationship or finance journey remains active. After completion or closure, essential transaction, consent, security, support and audit records may be retained for an appropriate limitation, regulatory or dispute period. Temporary logs and diagnostics may be retained for shorter periods unless needed for an investigation.
When information is no longer required, we take reasonable steps to delete, anonymise or securely isolate it. Deletion from active systems may not immediately remove information from encrypted backups; backup data is protected and removed or overwritten according to scheduled cycles. A partner may have an independent retention obligation for information it controls.
How we protect personal data
We use a combination of administrative, technical and organisational safeguards designed for the nature of the Services. Measures may include access controls, role-based permissions, authentication, encryption in transit, secure development practices, system monitoring, audit logs, vulnerability management, backups, incident-response procedures, employee confidentiality commitments and service-provider reviews.
Security is a shared responsibility. You should use a strong and unique password, keep one-time passwords private, protect your phone and email account, install updates, review account activity and promptly report suspicious messages or actions. Business administrators should remove former users, review roles and limit access to those with a genuine need.
No method of transmission or storage is completely secure. If we become aware of a personal-data breach, we will assess it, take reasonable containment and remediation steps, preserve necessary evidence and provide notifications to affected persons or authorities where required by applicable law.
Your privacy rights and choices
Subject to applicable law and verification, you may ask for information about the personal data being processed and the processing activities, request correction or completion of inaccurate information, request erasure where retention is no longer necessary, withdraw consent for consent-based processing, or raise a grievance about our handling of your data.
You may also nominate another individual to exercise applicable rights in the event of death or incapacity where the law provides such a right. A request should identify the relevant account, mobile number, device, retailer or transaction so that we can locate the correct record without collecting unnecessary information.
We may need to verify identity and authority before acting on a request. If InstaLock processes the information only on behalf of a partner, we may forward the request to that partner or explain how to contact it. We may retain limited information where necessary for security, legal compliance, fraud prevention, the establishment or defence of claims, or another lawful purpose.
To exercise a privacy right, email info@instalock.co.in with the subject “Privacy Request”. We will acknowledge and handle the request within the period required by applicable law. You are expected to provide authentic information, avoid impersonation and not suppress material information in a request or grievance.
Children and guardian-authorised use
The Services are intended primarily for adults and authorised business users. We do not knowingly create an independent EMI Locker account for a child without the involvement and verifiable authorisation of a parent or lawful guardian where required.
Business partners must not submit a child’s personal data unless the collection and processing are lawful, necessary and supported by required parental or guardian authorisation. The Services must not be used in a manner that causes detrimental effects on a child’s well-being or unlawfully tracks, monitors or targets a child.
If you believe a child’s information has been submitted improperly, contact us so that we can investigate and take appropriate action with the relevant partner.
Automated signals and important decisions
The Services may use automated rules to identify unusual logins, failed activations, inconsistent device information, overdue-status signals or events requiring review. Such automation is primarily used for workflow, security and operational support.
InstaLock does not independently decide whether a person receives credit or determine the commercial terms of a loan unless this is expressly disclosed in a separate product notice. Lending, repayment enforcement and customer-support decisions remain subject to the responsibilities and processes of the relevant authorised partner. If you believe an automated status is incorrect, contact the retailer, finance provider or InstaLock support with supporting information.
Responsibilities of distributors and retailers
Authorised partners using InstaLock must handle personal data responsibly. They must provide clear notices, collect only necessary information, use data only for authorised purposes, protect login credentials, restrict staff access, keep information accurate, respond to customer questions, report incidents and comply with applicable privacy, consumer and cybersecurity requirements.
Partners must not download, copy, disclose or use customer information for unrelated marketing, personal benefit, harassment, unauthorised collection or any unlawful purpose. InstaLock may restrict access, investigate activity or preserve relevant records where we reasonably suspect misuse.
Changes to this Privacy Policy
We may update this Policy when the Services, our practices or applicable requirements change. The current version will be posted with a revised “Last updated” date. If a change materially affects how we use personal data, we will use reasonable efforts to provide additional notice through the website, app, account or registered contact details. Where fresh consent is required, we will request it through an appropriate process.
We encourage you to review this page periodically. Previous versions may be made available where appropriate.
Privacy and grievance contact
For a privacy request, correction, erasure request, consent withdrawal, security concern or grievance, contact the InstaLock Privacy & Grievance Team. Please do not send passwords or one-time passwords.
Important: This policy is a detailed operational draft. Before production reliance, InstaLock should have Indian privacy counsel verify the exact company identity, registered address, data flows, service providers, retention schedule, consent screens, partner contracts, grievance process and technical behaviour.