Privacy Policy

1. Introduction

TartanHQ Solutions Private Limited, is a private limited company with its registered office at Flat No C 1504, GreenWorld, Gut No 242, Hiss Navi Mumbai, Digha Thane 400708, operating under the brand name “Tartan HQ” (“Tartan”, “we”, “us”, “our” or “Company”). We own the domain name tartanhq.com and its related sub domains, sites and tools.

We, at Tartan, are committed to protecting the privacy and security of its users. This Privacy Policy (“Privacy Policy”) applies to all the products and services made available by Tartan through the use of its Application Programming Interface (“API”) or Website or otherwise (“Services”). This Privacy Policy explains how we collect, use, process, disclose, and safeguard your information when you use our Services or our website [https://www.tartanhq.com] (“Website”) or our API through the mobile application/ website of our Customers (as defined below). Website and the API are collectively referred to as the “Platform”. This Privacy Policy applies to anyone who uses the Platform or the Services.

1.1 Applicable Laws

We adhere to the requirements of the data protection laws and regulations (as amended from time to time) established in India and this Privacy Policy is published in accordance with:

  • Information Technology Act, 2000 (“IT Act”);
  • Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the “SDPI Rules”); and
  • Rule 3 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

1.2 Personal Information

The term "Personal Information" means information that you provide to us which personally identifies you such as your name, phone number, email address, and any other data that is tied to such information. “Personal Information” also includes “Sensitive Personal Information” which consists of information relating to your medical history, financial information, password, biometric information etc. You may be required to provide certain Sensitive Personal Information like your bank account details and your user ID and password for your account with the Information Provider (as defined below) or with us, as the case may be. Our practices and procedures in relation to the collection and use of Personal Information have been set-out below in order to ensure safe usage of the Platform by you. Please read this Privacy Policy carefully to understand our policies and practices regarding your Personal and non-personal information and how we will treat it. At times, you may be accessing our website or using our API through the mobile application of a third party. We will recommend that prior to accessing our website or using our API, you read this privacy policy carefully and pursuant to your satisfaction give consent to the transmission of information. By accessing the Platform or using our services, directly or indirectly, you agree to accept all the terms contained in this Privacy Policy and acknowledge and agree with the practices described herein.

1.3 Binding Nature

This Privacy Policy is a legally binding document and does not require any signing or execution. If you do not agree with the terms of this Privacy Policy, please do not access and use our Platform or the Services being provided by us.

The Services, being provided by Tartan, are not intended for the use of any person under the age of 18. If you are under 18, please do not share your information using the Platform.

1.4 Third Party Information/Website

This Privacy Policy describes our privacy practices for the Platform and Services that are being provided by us. However, this Privacy Policy does not apply to those affiliates, agents and partners that have their own privacy policy. We use third party vendors for hardware, software, networking, storage, and/or ancillary technology required to provide the Services like AWS. In such situations, we recommend that you read the privacy policy on the applicable website.

If you provide Tartan with Personal Information about someone else, you confirm that they are aware that you have provided their information and they have consented to Tartan’s use of their information according to the Privacy Policy. This Privacy Policy applies to all the current and former visitors, users and others who access our website or use our API for any purpose or use the information obtained using our Services.  

This privacy policy shall be deemed to be an integral part of the terms of service and words not defined herein shall have the meaning ascribed to it in the Terms of Service.

2. Consent

By using the Platform and by providing your information to us or access to the information with the Information Provider (as defined below), you consent to the collection, transmission, storage and use of such information in accordance with this Privacy Policy. You consent that all information is being provided by you voluntarily. You specifically agree and consent to us collecting, storing, processing and sharing information (including Personal Information) related to you with Customers (as defined below), third parties, service professionals or to registered business partner/users and in accordance with the terms as set out in this Privacy Policy.  

The Personal Information that is collected by us from the end users is done for the benefit and on behalf of our Customers who are required to take your explicit consent before you share any data with us or before you provide us any access to your personal data. The obligation and responsibility of taking necessary consent from the End User is on the Customer. You acknowledge that Tartan will not be liable for any action or omission of the Customer with respect to the Personal Information and the utilization of such Personal Information by the Customer.  

You shall have the right to withdraw the consent at any time by communication in writing addressed at support@tartanhq.com.  

3. Collection of Information

3.1 How and what we collect

Our Services are aimed at, inter alia, providing the Customers with connectivity to the payroll system, financial information of the End User through a single API. Our Services, inter alia, enable individuals (“End Users”) to connect to payroll systems, financial accounts and related platforms offered by third parties, including but not limited to payroll providers and employers (each an “Information Provider”) and provide user data to our customers, such as financial institutions and fintech entities who are intending to provide certain products and services to the End Users (“Customers”). If you provide your third-party account credentials to us, you understand that access to such platform of the Information Provider may be provided to the Customer through the API as well as content and information in those accounts may be transmitted to the account of the Customer which may be hosted by us or otherwise transmitted to the Customer. We may also require you to manually upload your payslip and similar documents which will then be transmitted to the Customer. You understand that the data provided by you or the Information Provider may be transmitted to the Customer in the same or different format and that information transmitted shall be covered by this Privacy Policy. We may provide the information one time or continuously on a real time basis, depending on the requirement of the Customer and your consent. We may also collect information through your communications with our customer-support team if you contact us for support. We may use and store your information obtained from you or the Information Provider only for purposes as have been detailed in this Privacy Policy.  

When you use our Platform, we may require you amongst other things to fill in the name of your employer, your User ID and password for the payroll system to integrate the platform of the Information provider with our API to collect your Personal Information. This information will include the data that is available with the Information Provider and may include your full name, mobile number, email address, password, photograph, date of birth, gender, Permanent Account Number (PAN), passport details other identification proof, date of joining, promotion date, bank account number and details, salary related information etc. We may also ask the End User to provide directly any other personal/financial information as may be required by the Customer for providing you the products and services. The specific pieces of Personal information we collect from you or the Information Provider will depend on the requirements of the Customer.

Further, when you as a Customer or End User or internet surfer, communicate with us or visit our Website or use our API, we may log and store certain non-personal information such as your IP address, cookie information, browser type, mobile operating system, manufacturer and model of your mobile device, geolocation, preferred language, access time and time spent. We will also collect information about the pages you view within our sites and other actions you take while using the Platform. Cookies are files that are placed in your computer’s browser. If you do not want us to place a cookie on your device, you may be able to turn that feature off on your device. Please note that if you delete or choose not to accept cookies from our Platform, you may not be able to utilize the features of our Platform to their fullest potential.

3.2 Liability

All such information described above, shall be deemed to be transmitted/given access to or uploaded willingly and without any coercion. No liability of any form pertaining to the authenticity/genuineness/misrepresentation/fraud/negligence, etc. of any information provided by you or as available in the payroll system of the employer, shall be on the Company, nor will the Company be in any way responsible to verify any information obtained from the End User and it shall always be the responsibility of the Customer/End User to verify/review the data. Also, you understand that the use of your personal information by the Customer will depend on your agreement with the Customer and the same is not controlled by Tartan. The Company shall also not be liable to End User for any action or omission of the Customer or the Information Provider.

The Platform may be linked to third-party websites/apps (“Third-Party Sites”) that may collect your personal information. The Company is not in any manner responsible for the security of such Third-Party Sites or their privacy practices or content. Such Third-Party Sites may have their own privacy policies governing their storage and retention of your information that you may be subject to. This Privacy Policy does not govern any information provided to, stored on, or used by such Third-Party Sites or third-party providers and we recommend that you review the applicable privacy policy when you enter a Third-Party Site. You agree and acknowledge that the Company is not liable for the information published by any Third-Party Site.

4. Disclosure of the information

  1. We are appointed by the Customer to provide your Personal information to the Customer through our Platform and therefore, we disclose your personal information as obtained from you or the Information Provider to the Customer. At times, we may also host such information on our API for review by the Customer and provide them such information in such format as may be required by them. We may disclose the Personal information one time or continuously on a real time basis, depending on the requirement of the Customer and your consent as given to the Customer.  
  1. We may be required to disclose your Personal Information and non-Personal Information to the extent necessary to statutory and regulatory authorities to comply with applicable laws and to respond to lawful requests and due legal process.
  1. We will be disclosing your information to employees, agents, officers, third party partners, legal advisors or auditors but only on a need to basis and in accordance with the provisions of this Privacy Policy.
  1. We may also disclose your information to protect the rights, property and safety of the Company, our business and services partners and the users, including to enforce the Terms of Service, Privacy Policy or for any dispute resolution.
  1. We do not publish sensitive personal information.

5. Storage and other utilization of the information

  1. We may use and store the information provided by you or obtained through the Information Provider or any non-personal information for the following purpose:
  1. To improve and personalise your experience of the use of the Platform;
  1. For our own analysis, product development, improving existing products and services;
  1. To resolve disputes, provide customer/end user support and troubleshoot problems;
  1. To advertise, promote and market our products and services;
  1. To contact you including for informing you about online and offline offers, campaigns, programs, products, services and/or updates;
  1. To customise your experience on the Platform;
  1. To detect, prevent and protect the Company from any errors, frauds, and other criminal or prohibited activity;
  1. To communicate important notices or changes in the Services offered by the Company, use of the API and website, and the terms/policies which govern the relationship between you and the Company and with our affiliates;
  1. For any other purpose, for which you have granted consent.
  1. We may use your data to create aggregate or statistical information that does not directly identify a specific person, and we may share that information with third parties.

Where we have no continuing legitimate business or need to store your Personal Information, we will either delete or anonymize it or, if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is made possible. However, we may continue to retain the non-personal information.

6. Deletion of Information

If required by you, Tartan will delete the Personal Information provided by you, subject to applicable laws. You can always refuse to supply your Personal Information to us. However, this may restrict you from using the products and services that are being provided by the Customer. Further, we are not liable for the deletion/non deletion of the Personal Information provided to the Customer by us based on your consent.

7. Information Security

  1. We use reasonable security measures to protect information from unauthorized access, maintain data accuracy as required under applicable laws. These safeguards take into account the sensitivity of the information that we collect, process, transmit and store and the current state of technology. We follow generally accepted industry standards to protect the Personal information submitted to us, both during transmission and once we receive it. We host the API in a secure server environment that uses advanced technology to prevent interference or access from outside intruders.  
  1. Our security practices and procedures limit access to personal information on need-only basis.
  1. Tartan will strive to protect information and privacy, however, it takes no guarantee of absolute security when information is transmitted to the Customer. Tartan will not be responsible under any circumstance for any loss or theft of information due to unauthorised access to your device through which you visit website or use the API or any other reasons not attributable directly to Tartan. Tartan will not be responsible for any breach of security due to any actions or events of any third parties including Customer and Information Provider which are outside its reasonable control including but not limited to computer hacking, government acts, computer crashes etc.

8. Governing Law

This Privacy Policy will be governed by and construed in accordance with the laws of India. You agree that any legal action or proceedings arising out of your use may be brought exclusively in to the jurisdiction of such courts/ tribunals as mentioned in the Terms of Service.

9. Changes in the Privacy Policy

We reserve the right, at our sole discretion, to revise, change or modify this Privacy Policy from time to time.  We urge you to review the Privacy Policy periodically to ensure that you agree with our latest information on our privacy practices.

10. Redressal of Grienvances

  1. Any queries, complaints, abuse or concerns with regard to any content, comments or breach of this Privacy Policy or any other matter pertaining to our Platform shall be immediately addressed to the designated Grievance Officer as mentioned below via in writing or through email:

Name of Grievance Officer: Meet Semlani  

Email: support@tartanhq.com  

Registered address: ___________________________________.

  1. We shall acknowledge the complaint within 24 hours of the receipt of any complaint.  
  1. We may reach out to you for further information and details on receipt of the complaint/queries/concerns by the Company. We will make all endeavours to resolve the complaint as soon as possible.

Ready to get started?