Legal
Privacy Policy
TrustRails Technologies Private Limited operates the Le'Udhaar platform. This policy explains what personal data we handle, why we hold it, who else processes it, and what you can ask us to do with it.
Last updated 3 August 2026
01
Scope
This policy covers the TrustRails website and the applications we operate, including Le’Udhaar. It applies to borrowers, lenders, merchants, and anyone who contacts us.
Where we decide why and how your data is used, we are the data fiduciary. Where a bank, payment aggregator, or eSign provider handles your data under its own licence, that entity is responsible for that processing under its own policy.
02
Information we collect
You give us
- Identity and contact details: name, mobile number, email address, date of birth
- KYC information required to document a transaction, including identity document references
- Bank account or UPI details used for disbursal and repayment
- Loan details you enter: amount, tenure, agreed terms, counterparty
We generate or receive
- Transaction and mandate records, including successful and failed debit attempts
- Signed agreements and the audit trail of the eSign or OTP that executed them
- Reminder, call, and support interaction logs, which exist to evidence the recovery standard we commit to in the terms
- Device, app version, IP address and log data used for security and fraud prevention
03
Why we use it
- To create and operate your account
- To document a loan between two users and produce the agreement
- To set up, run, and retry auto-debit mandates
- To send repayment reminders and provide recovery support
- To detect and prevent fraud, misuse, and money laundering
- To meet statutory, tax, and regulatory obligations
- To respond to your questions and grievances
We do not sell personal data. We do not use your loan data to serve third-party advertising.
04
Payment data handling
Payment mandates and auto-debit processing are facilitated via regulated third-party payment aggregators and banking partners. The Company does not directly store full card or bank credentials.
What we retain is the reference needed to identify a mandate and its status, not the underlying credential.
05
Aadhaar and eSign handling
Aadhaar-based eSign services are provided via licensed eSign Service Providers. Aadhaar information is processed in accordance with applicable Indian regulations.
We do not store your Aadhaar number in our own systems. The eSign flow runs with the licensed provider, and what returns to us is the signed document and its audit trail.
06
Who else sees your data
- The counterparty to your loan sees what the agreement requires them to see: your name, the agreed terms, and repayment status. They do not see your full bank credentials.
- Payment aggregators and banks, to set up mandates and move funds
- Licensed eSign Service Providers, to execute agreements
- Cloud hosting, communication, and analytics providers acting on our instructions
- Legal and recovery partners, where Le'Legally enforcement has been activated at a lender's request
- Courts, regulators, and law enforcement, where we are legally required to disclose
We require our service providers to protect your data and to use it only for the purpose we engaged them for.
07
Data retention
Loan agreements and mandate records may be retained for statutory compliance and dispute resolution purposes.
Closing your account does not delete records we are required to keep, or records tied to an obligation that is still live. Once no legal, tax, or dispute reason to keep something remains, we delete it or reduce it to anonymised aggregates.
08
Security
Data is encrypted in transit and at rest. Access inside the Company is limited to people who need it to do their job, and that access is logged. Sensitive credentials sit with our regulated payment and eSign partners rather than in our systems.
No system is absolutely secure. If a breach occurs that is likely to affect you, we will notify you and the relevant authority as required by law.
09
Your rights
- Access a copy of the personal data we hold about you
- Correct data that is inaccurate or out of date
- Withdraw a consent you previously gave, including a micro-debit authorisation, subject to obligations already in force
- Ask us to erase data we no longer have a legal reason to keep
- Nominate someone to exercise these rights if you are unable to
- Raise a grievance about how we handled your data
Write to the address in clause 12 to exercise any of these. We may need to verify your identity before acting. Withdrawing a consent that a live loan depends on may prevent you from continuing to use parts of the platform.
10
Communications and call records
Repayment reminders are sent by SMS, WhatsApp, in-app notification, email, or phone call. Support and recovery calls may be recorded so that we can evidence the communication standard set out in our terms. Service messages tied to a live loan are not marketing and cannot be opted out of while that loan is outstanding.
11
Cookies and this website
This website is a static marketing site. It does not set advertising or cross-site tracking cookies. Any analytics we run is aggregate and does not identify you.
12
Contact and grievance officer
For any question about this policy, or to exercise a right under it, write to daya@trustrails.in. We acknowledge grievances within 48 hours and aim to resolve them within 30 days.
TrustRails Technologies Private Limited
Navi Mumbai, Maharashtra, India
We may update this policy as the product and the regulatory position change. Material changes will be notified in the application or by email before they take effect.