YELOW PAYMENTS PRIVATE LIMITED including our subsidiaries and affiliates (“YELOW”, “we”, “our” or “us”), puts great efforts in communicating our data practices and in making sure that the data we process is safe and used properly. This Privacy Policy (“Policy”) describes how we collect, store, use and disclose the following types of personal data:
(i) Prospect data concerning our prospective partners, customers or website visitors, who visit or engage with our websites (such as https://autofin.yelow.club and their subdomains), social media pages, blogs, or other similar forums, online ads and content, emails or other communications under our control (collectively, the “Sites”), or participate in events or webinars that we organize or take part in (collectively, “Prospects”).
(ii) Customer data concerning automotive dealerships (“Customers”) and their authorized sales representatives (“Users”) who have engaged with us, including account, contact, and activity data relating to their use of the YELOW Platform and other tools and features provided by us as part of the services (the “Platform”, and together with the Site, the “Services”);
(iii) Consumer data concerning the customers of our Customers who have implemented YELOW’s services on their websites and internal systems (“Consumers”).
1. Controllers of Personal Information
Your Personal data information will be collected and stored at servers located in India by Yelow Payments Private Limited\ (including its, representatives, affiliates, and its business partners).
2. What Personal Information we gather about you
The information we learn from customers helps us personalize and continually improve your experience at the Website. Here are the types of information we gather.
We receive and store any information or document you enter or upload on our Website or give us in any other way, in line with the product or service opted by you and as required by us or our business partners, including your personal information like first name, last name, email address, date of birth, residence city etc. You can choose not to provide certain information but then you might not be able to take advantage of many of our services and features. We neither collect nor store your biometric information.
We may also have one time access to your camera, microphone, location and mobile device and store such information only for the purpose of onboarding or KYC requirements of us or our Partner with your explicit consent. in accordance with the Digital Lending guidelines issued by RBI and as amended from time to time
We might receive information about you from other sources and add it to our account information.
3. Cookies and tracking technologies
We and our Service Providers use “cookies” and other technologies for performance, tracking, analytics and personalization purposes and in order to provide you with a better experience. We may share non-identifiable/aggregated extracts of such information with our partners for our legitimate business purposes.
- Cookies: cookies are small text files that are stored through the browser on your computer or mobile device (for example, Google Chrome or Safari) when you visit a website. Some cookies are removed when you close your browser session – these are the “session cookies”. Some last for longer periods and are called “persistent cookies”. We use both types of cookies to facilitate the use of the Services’ features and tools. Whilst we do not change our practices in response to a “Do Not Track” signal in the HTTP header from a browser or mobile application, you can manage your cookies preferences, including whether or not to accept them and how to remove them, through your browser settings. Please bear in mind that disabling cookies may complicate or even prevent you from using the Services.
- Google Analytics: we use Google Analytics to collect information about the use of our Services. Google Analytics collects information such as how often you visit the Services, which pages you visited when doing so, and which other sites they used prior to coming to our Services. We do not merge the information collected through the use of Google Analytics with personally identifiable data. Google’s ability to use and share information collected by Google Analytics about your visits to and use of the Services is restricted by the Google Analytics Terms of Service and the Google Privacy Policy. You can learn more about how Google collects and processes data specifically in connection with Google Analytics here. Further information about your option to opt-out of these analytics services is available here
4. How do We Use The Information
Yelow collects your information when you register for an account when you use its products or services, visit its Website's pages. When you register with Yelow, you are asked for your first name, last name, state and city of residence, email address, date of birth, and sex. Once you register at the Website and sign in, you are not anonymous to us. Also, you are asked for your contact number during registration and may be sent SMS notifications about our services to your wireless device. Hence, by registering, you authorize Yelow (including its business partners and affiliates) to send texts and email alerts to you with your login details and any other service requirements, including promotional mail and SMS, even if you have registered yourself under DND or DNC or NCPR services. Your authorization shall be valid as long as your account is not deactivated or unless you withdraw your consent Yelow Website may, based on your consent, also access your mobile device, including a camera, for the purpose of service facilitation and ease of access to our Website for the various services opted by you and in compliance with applicable laws.
Purpose for collecting information: - Assist us or our business partners in facilitating and delivering services to you, process payments and your applications, communicate with you about products, services and promotional offers.
- Respond to queries, or requests submitted by you, and resolve your grievances/issues/problems with any services supplied to you.
- Administer or otherwise carry out our obligations in relation to any agreement with our business partners.
- Send you information about special promotions or offers. We might also tell you about new features or products/services. These might be our own offers, products/services, or third-party offers or products/services with whom Yelow has a tie-up.
- Use your information for internal analysis and to provide you with location-based services, such as advertising, search results, and other personalized content.
- Use this information to improve our platform, prevent or detect fraud or abuses of our Website and enable third parties to carry out technical, logistical, or other functions on our behalf. We may combine information we get from you with information about you we get from third parties.
- Send you notices, communications, and recommend services that might be of interest to you update our records and generally maintain your accounts with us, display content, and customer reviews.
- When you provide your contact details, we will use it to send you general notices or important news about your account, request your feedback or opinions and provide updates on special deals and offers that might interest you.
- File storage permissions on Android/iOS and Website for uploading customer documents are obtained for the purpose of processing customer applications by our Partners. Yelow Website may, based on your consent, also access your mobile device, including camera for the purpose of service facilitation, ease of access, and logging in to our Website for the various services opted by you.
- As otherwise provided in this Privacy Policy and in compliance with the applicable laws.
Some features of this Website or our Services will require you to furnish your personally identifiable information as provided by you under your account section on our Website.
5. Disclosure to Third Parties
Yelow will not sell or rent or otherwise disclose your information for commercial purposes to anyone in a way that is contrary to the commitments made and/or other than as set forth in this Privacy Policy. Notwithstanding the foregoing, we may share your information to third parties including our group Company, employees, agents, business partner (Banks/NBFCs),CICs, Payment Aggregator and Service Providers we have a tie up with and any of our affiliates, for the purposes as set out in this Privacy Policy.
These third parties are required to handle your information using the same level of care and confidentiality as is followed by Yelow and any accessing or processing of your information by these third parties is in accordance with contractual terms, applicable laws and our instructions and subject to your consent. For the purposes of this paragraph, “Affiliate” shall mean, as to any Person, any other Person that, directly or indirectly, controls, or is controlled by, or is under common control with, such Person. (The term “control” (including, with its correlative meanings, “controlled by” and “under common control with”) shall mean the possession, directly or indirectly, of the power to direct or cause the direction of management or policies of a Person, whether through the ownership of securities or partnership or other ownership interests, by Contract or otherwise. The term "Person" includes any natural person, corporation, partnership, limited liability company, trust, unincorporated association, or any other entity).
Yelow may also share, and or transfer your personally identifiable information to any successor-in-interest as a result of a sale of any part of Yelow business or upon the merger, reorganization, or consolidation of it with another entity on a basis that it is not the surviving entity.
We limit the collection and use of your personal information. We may make anonymous or aggregate personal information and disclose such data only in a non-personally identifiable manner. Such information does not identify you individually. Access to your Account information and any other personal identifiably information is strictly restricted and used only in accordance with specific internal procedures, and for the purposes set out in this Privacy Policy, in order to operate, develop or improve our services. We may use third party service providers to enable you to provide with our services and we require such third parties to maintain the confidentiality of the information we provide to them,under our contracts with them.
We may also share your information, without obtaining your prior written consent, with government agencies mandated under the law to obtain information for the purpose of verification of identity, or for prevention, detection, investigation including cyber incidents, prosecution, and punishment of offences, or where disclosure is necessary for compliance of a legal obligation. You agree and consent for the Website to disclose your information, if so required, under applicable law.
There are number of products/services such as loans offered by third Parties on the Website, such as lenders, banks. If you choose to apply for these separate products or services, disclose information to these providers, then their use of your information is governed by their privacy policies in addition to the Privacy Policy of the Website. Yelow is not responsible for their privacy policies. We encourage you to visit and read about the privacy notices and procedures adopted by these third parties/providers, when you apply for their products or services. Yelow holds no responsibility for the content of the privacy policies or terms of use etc. of these third party websites.
Roles and responsibilitiesCertain data protection laws and regulations, typically distinguish between two main roles for parties processing personal data: the “business”, who determines the purposes and means of processing; and the “service provider”, who processes the data on behalf of the business. Below we explain how these roles apply to our Services, to the extent that such laws and regulations apply.
(i) With respect to Prospect data, YELOW assumes the responsibilities of a “business” (solely to the extent applicable under law), as set forth in this Privacy Policy. In such instances, our Service Providers processing such data will assume the role of “service providers”.
(ii) With respect to User data, YELOW assumes the responsibilities of both a “business” and a “service provider”. Such data is partially processed by YELOW for its own purposes (as described in Section 2 above), as a “business” whilst other aspects of Users’ data will be processed by us on our Customer’s behalf, as a “service provider”.
(iii) With respect to Consumer data, YELOW assumes the responsibilities of a “service provider”, processing the data on behalf of our Customer (the “business”). In such instances, our Service Providers processing such data will assume the role of “third-parties”.
Accordingly, YELOW processes Consumers personal data strictly in accordance with such Customer’s reasonable instructions and as further stipulated in our DPA and other commercial agreements with such Customer. The Customer, as controller of such data, will be responsible for meeting any legal requirements applicable to business. For the avoidance of doubt, each Customer is solely responsible for providing adequate notice to their Users and Consumers whose personal data may be processed – including sufficient reference to the processing of their personal data via the Services, and any other information necessary to comply with all applicable privacy and data protection laws; and to obtain all approvals and consents from such individuals as required under such laws.
6. Data Storage
We and our authorized Service Providers (defined below) maintain, store and process personal data in india, United States and other locations as reasonably necessary for the proper performance and delivery of our Services, or as may be required by law. While privacy laws may vary between jurisdictions, YELOW and its affiliates and Service Providers are each committed to protect personal data in accordance with this Privacy Policy, customary industry standards, and such appropriate lawful mechanisms and contractual terms requiring adequate data protection, regardless of any lesser legal requirements that may apply in the jurisdiction to which such data may be transferred.
7. What Is Your Control Over Your Personal Information That’s Collected And Used Online
It's important to note that the information we use about you helps us provide you with products, services and experiences that benefit you. You have the ability to control how your non-personal information is collected and used online.
You also have the ability to choose what personal information, including what sensitive personal information (i.e. your financial information) you provide to us, restrict disclosure of your information to third parties, however, please note that this may affect your seamless access to such product/ service as opted by you. However, if you choose not to provide all of the mandatory information and data that is requested of you, we may not be able to provide you with the Services that you have subscribed to.
We believe you should be able to choose what kinds of information you receive via email/SMS. If you do not want to receive marketing materials by email/SMS, just indicate your preference on the contact information for your account or the 'opt-out' or unsubscribe link provided in our marketing emails and you can also write to us at support@yelow.club. Please note that it may take about 10 days to process your request. Please keep in mind that we will continue to notify you by email /SMS/via phone calls regarding your services with us, even after you have opted out.
You can review the information that you have provided to us by logging into your account at the Website and correct or amend any personal information or sensitive personal data or information to ensure that the information or data you provided us is accurate and/or not deficient. Yelow is not responsible for the authenticity of any personal information or sensitive personal data or information supplied to it by you or any third party.
8. Revocation of Consent
If you feel that we do not require the retention of your personal information or if you ask us to delete or remove your personal data where you think we do not have the right to process it we shall destroy or delete such Customer information. You may, at any time while availing of our Services or otherwise, withdraw the consent given earlier to us to collect and use your sensitive personal data or information by writing to us at support@yelow.club. However, in the case of you withdrawing such consent, Yelow shall have the option to stop providing you the Services for which the information was sought. You will not be eligible for a refund of any fees paid for any service in such event and you agree that the Website shall not be liable to you for the same in any manner whatsoever.
The data may be required to be retained for the purpose of Product servicing, repayment etc. by us and/or our Partners and also as required under any applicable laws. We assure that such retained information shall be protected following all cyber security norms.
9. Log Files
Like most standard websites, we use log files. This information may include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, platform type, date/time stamp, and number of clicks to analyze trends, administer the site, track user's movement in the aggregate, and gather broad demographic information for aggregate use. We may combine this automatically collected log information with other information we collect about you. We do this to improve the services we offer to you, to improve marketing, analytics or site functionality.
10. Changes in this Privacy Policy
Yelow reserves the right to change this policy from time to time, at its sole discretion. We may update this privacy policy to reflect changes to our information practices. We encourage you to periodically review. Checking the effective date below allows you to determine whether there have been changes since the last time you reviewed the statement.
11. Data Purging Policy
PurposeThe purpose of this Data Purging Policy is to establish guidelines and procedures for the secure and efficient removal of data that is no longer necessary for operational, legal, or regulatory purposes. This policy aims to protect the integrity of the organization’s data and reduce risks associated with data retention.
ScopeThis policy applies to all employees, contractors, and third-party service providers who manage, store, or access data on behalf of the organization. It covers all data types, including but not limited to electronic records, databases, and physical documents.
Definitions- Data Purging: The process of permanently deleting data that is no longer needed.- Retention Period: The duration for which data is kept before it is eligible for purging.- Sensitive Data: Information that requires special protection due to its confidential nature (e.g., personal information, financial records).
Data Retention Guidelines1. Establish Retention Periods:- Identify the types of data and assign appropriate retention periods based on legal, regulatory, and operational requirements.- Review and update retention schedules annually or as required by changes in laws or business practices.2. Criteria for Data Purging:- Data that has reached its retention period.- Data that is deemed obsolete, redundant, or irrelevant.- Data that has been replaced or superseded by more recent information.
Data Purging Procedures1. Approval Process:- All data purging actions must be approved by the Data Management Team or designated authority.- Document the rationale for purging decisions.2. Methods of Data Purging:- Electronic data should be permanently deleted using secure deletion methods to prevent recovery.- Physical documents must be shredded or otherwise destroyed in a manner that ensures confidentiality.3. Documentation and Record Keeping:- Maintain records of data purging activities, including data types, quantities, methods used, and approval details. - Ensure documentation is retained for a minimum of three years after the purging date.
Compliance and Audit- Regular audits will be conducted to ensure adherence to this policy and the effectiveness of data purging practices.- Non-compliance may result in disciplinary action, up to and including termination of employment or contract.
Review and UpdatesThis policy will be reviewed annually and updated as necessary to reflect changes in regulations, technology, or business operations.
Note : We retain your Personal Data as long as the purpose for its usage exists and once the user is deactivated for more than 60 days we store it for 6 months , after which the same is disposed off by us except for any record retention required as per Master Direction on Issuance and Operation of RBI
Chapter VII on Record Management of Master Direction - Know Your Customer (KYC) Direction, 2016 (Updated as on April 20, 2020)
(https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566) require your transaction logs to be stored for atleast 5 years and PPI guidelines -para 6, sub-clause no. 6.3
(https://rbi.org.in/ScriptS/BS_ViewMasDirections.aspx?id=11142) require your transaction logs to be stored for atleast 10 years post the deletion of an account. In the event of the pendency of any legal/regulatory proceeding or receipt of any legal and/or regulatory direction to that effect, we may be suggested by the law of the land to retain your Personal Data for longer periods.