1. Who this applies to
CapitalHope Facilitation Management System ("CapitalHope FMS", "the System", "we") is an internal, invitation-only platform used to record loan facilitation claims, calculate vendor payouts, and manage approvals. It is not a public consumer product — access is limited to individuals given an Admin, Worker, or Vendor account by the operating organisation.
This policy explains what information the System holds about the people who use it, why it's held, and how it's protected. It does not cover the loan products themselves, which are governed separately by the lending banks and NBFCs involved in each transaction.
2. Information we collect
The System collects only what's needed to record claims, calculate payouts, and verify identity before approval. No online payment processing takes place on this platform, so no card, UPI, or wallet details are ever collected.
| Category | Examples | Collected from |
|---|---|---|
| Account details | Name, email, phone number, role, password (stored as a hash) | Provided at account creation by an Admin |
| Vendor business details | Company name, PAN, bank account number, IFSC code | Entered by Admin during vendor onboarding |
| Claim & loan records | Borrower name, loan type, loan amount, bank, disbursement date | Entered by Workers or imported from Book3.xlsx |
| Payout figures | Vendor rate, gross payout, TDS%, net payout, carry-forward balance | Calculated by the System from claim data |
| Verification logs | OTP requests, timestamps, IP address, device signal | Generated automatically at login and approval |
| Activity records | Who changed what, and when, on every record | Generated automatically (audit trail) |
3. Aadhaar & DigiLocker data
Where a vendor's identity is verified through DigiLocker, the process runs through India's official MeitY-approved eKYC flow. A few important points:
- The vendor authenticates directly with DigiLocker using their own Aadhaar credentials — CapitalHope FMS never receives, sees, or stores the Aadhaar number itself.
- Only the fields released by DigiLocker after consent — name, date of birth, gender, and address — are stored against the vendor's profile.
- Verification is entirely optional per vendor and is only triggered when an Admin initiates it with the vendor's knowledge.
- A "DigiLocker Verified" status and date are shown on the vendor's record once complete; the underlying eKYC data is visible only to Admin and the vendor themselves.
4. How information is used
- To record and track loan facilitation claims from entry through to payout.
- To calculate gross payout, TDS, net payout, and carry-forward balances accurately.
- To verify identity before login (OTP) and before a payment is approved (OTP).
- To confirm a vendor's identity through DigiLocker where verification is requested.
- To maintain an audit trail of who did what, for internal accountability and dispute resolution.
- To send SMS notifications relevant to a user's own account — a login OTP, an approval OTP, or a payout confirmation.
Information is never used for advertising, profiling, or any purpose unrelated to running the claims and payout process.
6. How data is protected
- Every screen and every API response is restricted by role — a Worker's session cannot retrieve columns marked Admin-only, even by direct request.
- All traffic runs over HTTPS; sessions use secure, same-site cookies and expire automatically after 30 minutes of inactivity.
- Login is protected by rate limiting (5 attempts before a 15-minute lockout) and OTP verification on new devices.
- Payout approvals require a fresh OTP — a session being open is not sufficient to approve a payment.
- Every create, edit, and status change is written to an audit log with a before/after record, the acting user, and their IP address.
- Passwords are never stored in plain text and are never visible to any user, including Admins.
7. Data retention
Claim and payout records are retained for as long as the vendor relationship is active and for a reasonable period afterward to satisfy audit, tax, and reconciliation needs. OTP codes themselves expire within minutes and are not retained beyond their audit log entry. Where an Admin deactivates a user or vendor, their historical claim and payout records are retained for audit continuity, but their active account access is removed immediately.
8. Your rights
Any user of the System — Admin, Worker, or Vendor — can request to:
- See what personal information is held about them.
- Correct inaccurate account or profile details.
- Ask that their DigiLocker verification be re-run or removed, where it is no longer required.
- Raise a concern about how their information has been handled.
Requests can be made through the Admin of your organisation, or directly to the grievance contact below.
10. Grievance officer
In line with India's IT Rules, 2021, questions or complaints about this policy can be directed to the designated Grievance Officer for CapitalHope FMS:
Email: [add grievance officer email]
Response time: within 30 days of a written request
11. Changes to this policy
This policy may be updated as the System's features change — for example, if a new verification method or reporting feature is added. The effective date at the top of this page will be updated whenever a material change is made, and users will be notified through an in-app notice for significant changes.