Cookie & Digital Identifiers Policy

Welcome to Fin 100X.AI — India’s First Protocol-Governed AI Financial Operating System. By using our app or platform, you agree to the following terms:

Fin 100X.AI – Cookie & Digital Identifiers Policy Effective Date: [Insert Date]Last Updated: [Insert Date]

  1. Introduction This Cookie & Digital Identifiers Policy (“Policy”) explains how Fin 100X.AI Technologies Private Limited (“Fin 100X.AI”, “we”, “our”, “us”) uses cookies, SDKs, and other digital identifiers on our website, mobile application, and WhatsApp onboarding flow. We are committed to ensuring that your personal data is protected and handled in compliance with the: Digital Personal Data Protection Act, 2023 (DPDP Act) Information Technology Act, 2000 and its rules CERT-IN Cybersecurity Directions, April 28, 2022 RBI, SEBI, and IRDAI circulars relating to data protection and digital security

By continuing to use our website, mobile app, or WhatsApp services, you consent to our use of cookies and identifiers in accordance with this Policy.


  1. Scope & Applicability This Policy applies to all users of: Fin 100X.AI Website (any browser) Fin 100X.AI Mobile App (Android & iOS) Fin 100X.AI WhatsApp onboarding & engagement services

This Policy does not apply to: Third-party websites, SDKs, or services not controlled by us. Licensed financial partners (banks, insurers, mutual funds, MFIs, PFRDA providers) who may apply their own cookie and privacy rules.


  1. Types of Cookies & Identifiers We Use a) Strictly Necessary / Essential Required for login, OTP verification, and navigation. Enable security features against CSRF, XSS, and fraud attempts. These cannot be disabled and do not require consent.

b) Functional Save your language preference (EN, HI, MR). Remember personalization settings (themes, financial dashboard layout). Facilitate smooth movement across modules (Fin AI → Fin Score → SIP Planner).

c) Analytics & Performance Firebase SDK, Google Analytics. Track aggregated, anonymized usage: e.g., number of SIP planner opens, time spent in Fin AI. We enforce data minimization to prevent personal identification.

d) Security & Fraud Prevention Identifiers Device fingerprinting, IP logging, behavioural anomaly detection. Logs stored for minimum 180 days per CERT-IN directive. Supports RBI digital lending fraud guidelines.


  1. Consent Mechanism We comply with DPDP Act, 2023, Section 6, which requires free, informed, specific, and unambiguous consent. Website: First-time users see a banner requesting cookie consent. Mobile App: Consent screen during initial setup for functional/analytics cookies. WhatsApp: Explicit consent message before enabling tracking identifiers.

Users can withdraw consent at any time via app or browser settings. Withdrawal will not affect prior lawful usage.


  1. How We Use Cookies & Identifiers Authentication: To maintain secure sessions and avoid repeated OTPs. Fraud Prevention: Detect suspicious logins and fraudulent activities. Analytics: Improve Fin 100X.AI services by studying aggregated usage. Personalization: Remember your language and preferences.

We do not use cookies or identifiers for: Behavioural advertising Selling user data Third-party profiling


  1. Third-Party SDKs & APIs We integrate third-party SDKs for functionality and analytics, including but not limited to: Firebase Analytics & Crashlytics (Google) Google Analytics (Web usage) Partner APIs (CRIF, DigiLocker, IRDAI PoSP)

All partners are contractually bound to comply with: DPDP Act, 2023 RBI, SEBI, IRDAI obligations CERT-IN log & security directives


  1. Data Retention & Deletion Session Cookies: Deleted when you log out or close browser. Functional Cookies: Retained for up to 12 months. Analytics Identifiers: Stored for 90 days, then anonymized. CERT-IN Logs: Retained for a minimum of 180 days.

After expiry, data is securely deleted unless required by law.


  1. User Controls You have full control over cookies and identifiers: In-App Settings: Toggle on/off non-essential cookies. Browser Controls: Chrome, Safari, and Firefox allow cookie management. WhatsApp: Send “STOP” to withdraw consent.

Note: Disabling certain cookies may limit personalization but core financial services will remain available.


  1. Children’s Protection For users under 18 years: No analytics or behavioural cookies stored. Only essential cookies required for login and security. Parental consent required under DPDP Section 9.

  1. Updates to This Policy We may update this Policy from time to time. Material changes will be notified 15 days in advance via app, website banner, and WhatsApp message. Continued use after update implies consent.

  1. Dispute Resolution & Governing Law This Policy is governed by the laws of India. Disputes shall be resolved by arbitration under the Arbitration & Conciliation Act, 1996. Jurisdiction: Mumbai, Maharashtra.

  1. Annexures Annexure A – Table of Cookies & Identifiers Name Purpose Essential/Optional Duration Retention Basis SessionID Secure login & session Essential Until logout IT Act + CERT-INLangPref Save language choice Functional 12 months User preferenceFirebaseID Usage analytics Optional 90 days DPDP Sec. 6DeviceFP Fraud prevention Essential 180 days CERT-IN, RBI

Annexure B – Sample Consent Banner (Website)

“We use cookies to improve your experience. Some cookies are essential, while others help us understand usage. By clicking ‘Accept’, you consent to functional & analytics cookies. You may withdraw consent anytime.”

Annexure C – CERT-IN Reference Cybersecurity Directions, 28 April 2022: Log retention minimum 180 days, reportable incidents within 6 hours.