Privacy Policy
How Transure collects, uses, and protects your personal and financial data when you use our financial operations platform, website, and related services.
01Overview
Transure (“we”, “us”, “our”) operates a financial operations platform that helps businesses manage payments, treasury, expenses, and cash flow. This Privacy Policy explains how we handle information collected through our platform, website, and related services.
By accessing or using Transure, you agree to the practices described in this policy. This policy applies to all users including company administrators, finance team members, and authorised approvers.
Transure complies with the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000, as applicable to entities operating financial services platforms.
02Data We Collect
Account & Identity Information
- Full name, work email address, and phone number.
- Designation, department, and role within your organisation.
- Login credentials (passwords stored in hashed form only).
- KYC documents as required for payment processing (PAN, GST, CIN).
Business & Financial Information
- Company name, registered address, and business type.
- Bank account details linked for NEFT / RTGS / IMPS payments.
- Transaction records, invoices, expense reports, and approval histories.
- Cash flow data, treasury positions, and forecasting inputs.
Usage & Technical Information
- IP address, browser type, and device identifiers.
- Pages visited, features used, and session duration.
- API access logs and integration activity.
- Error logs and performance diagnostics.
03How We Use Your Data
We use collected data for the following purposes:
- Providing and improving the Transure platform and its features.
- Processing and reconciling payments via regulated banking rails.
- Generating financial reports, forecasts, and audit trails.
- Enforcing maker-checker workflows and approval policies.
- Detecting and preventing fraud, unauthorised access, and policy violations.
- Sending transactional alerts, payment confirmations, and security notifications.
- Complying with applicable laws including RBI guidelines, GST regulations, and the IT Act.
04Sharing of Data
Transure does not sell your personal or business data. We share data only in the following circumstances:
Banking & Payment Partners
Account and transaction data is shared with partner banks (ICICI, IDFC First) and payment processors (Cashfree, Razorpay) solely to execute authorised transactions.
Legal & Regulatory Obligations
We may disclose information to regulatory authorities, courts, or law enforcement agencies when required by law, including responses to RBI audit requests or statutory investigations.
Service Providers
Trusted sub-processors who assist in operating our infrastructure are bound by data processing agreements and are prohibited from using your data for any other purpose.
05Data Storage & Residency
All financial and personal data of users is stored within data centres located within the sovereign boundaries of the Republic of India, in compliance with RBI data localisation guidelines.
No financial transaction data or KYC records are transferred to or stored in servers outside India.
06Data Retention
We retain different categories of data for the periods set out below:
- Transaction records — minimum 8 years from the date of transaction.
- Audit logs — 7 years from the date of the logged event.
- KYC documents — 5 years after the termination of the business relationship.
- Account information — duration of active subscription plus 2 years.
- Support communications — 3 years from the date of resolution.
07Your Rights
Under the DPDP Act, 2023, you have the following rights:
- Right to Access — request a summary of personal data we hold about you.
- Right to Correction — request correction of inaccurate or incomplete data.
- Right to Erasure — request deletion of your personal data, subject to legal retention requirements.
- Right to Grievance Redressal — raise complaints regarding the processing of your data.
08Security Measures
- AES-256 encryption at rest and TLS 1.3 in transit for all data.
- Role-based access control with maker-checker enforcement.
- Immutable audit logs for all access and modification events.
- Real-time anomaly detection across payment rails (NEFT, RTGS, IMPS).
- Regular vulnerability assessments and penetration testing.
- Incident response protocols aligned with CERT-In reporting timelines.
09Cookies & Tracking
Transure uses essential, functional, and analytics cookies. We do not use cookies for advertising or cross-site tracking. You can manage cookie preferences through your account settings. For full details, see our Cookie Policy.
10Policy Changes
We may update this Privacy Policy from time to time. For material changes, we will notify account administrators at least 14 days before the changes take effect.
11Contact Us
For any questions about this policy or to exercise your rights, please reach our Data Protection Officer:
Questions about your privacy?
Our Data Protection Officer is happy to help with any data or privacy request.