What they may do · DPDP §6(4)
What CRIF High Mark does with your data
A credit bureau whose board-approved policy confirms it discloses personal data to third parties and partner firms, and keeps information as long as it deems necessary or law requires, with no retention period stated. It says nothing about ads, tracking or AI.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
CRIF High Mark’s own policy says “CRIF HM shall disclose personal information to third parties / partner firms only for purposes identified in the privacy notice / contractual agreements.”
Our summary discloses personal information to third parties and partner firms for purposes set out in the privacy notice or contractual agreements, and to regulators, government and law enforcement authorities, courts, law firms and audit firms. The Purpose section separately describes member institutions (lenders) submitting borrower and guarantor data and querying prospective borrowers.
-
Keeps your records long-term
Held on after you stop using the service.
What this costs you. Years after you delete the app, the record is still sitting there — and every year it sits there is another year it can leak.
Show me where they say that
CRIF High Mark’s own policy says “Information will be retained for as long as necessary or any such period as required by law, to fulfil the purposes for which it was provided, including for the purposes of satisfying any legal, accounting, or reporting obligations, to resolve disputes, to enforce agreements and for such other purposes as are permitted under applicable law and aligned with CRIF HM’s Data Preservation and Destruction Policy.”
Our summary retention is open-ended and company-determined, tied to necessity, law and "such other purposes as are permitted under applicable law", with no maximum period or end date stated to the individual.
What the policy does not mention
These are uses CRIF High Mark’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Builds an advertising profile of you
- Follows you onto other websites and apps
- Processes your face or other biometrics
- Trains AI models on your content
CRIF High Mark is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does CRIF High Mark do with my personal data?
According to CRIF High Mark's own privacy policy, read on 2026-08-14, it discloses 2 of the six uses we track: shares your data with partners, keeps your records long-term.
Can I withdraw my consent from CRIF High Mark?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Every use above is one CRIF High Mark declared in its own published privacy policy, which we
read on 2026-08-14. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy