Stack security policy cover image

Privacy policy

We are always committed to keeping your data secure, your private information private, and maintaining transparency regarding our practices.

Invacia Labs Private Limited operate mobile applications and website under brand names Stack Finance. Stack Finance is committed to operating its website and mobile applications with the highest ethical standards and required internal controls. We take your privacy extremely seriously. Your privacy is important to us and maintaining your trust is imperative. This Policy forms part and parcel of the Terms of Use and other terms on the Stack Finance Platform ("Terms of Use"). The Privacy Policy should always be read in conjunction with the Terms and Conditions

This Privacy Policy is applicable to a User who avails the Services. The term "User" for the purposes of this Privacy Policy shall mean You, in the capacity of an individual, a guest user, browser and/ or representative of an entity, who visits, accesses, uses, downloads, deals with, avails Services and/ or transacts through Stack Finance Platform. For the purpose of this Policy, wherever the context so requires "You" or "Your" shall mean User and the term "We", "Us", "Our" shall mean Company.

In case You do not wish to provide any information, including personal or personally identifiable information, or in the event You do not agree to any or all the clauses of the Terms of Use, Privacy Policy and product specific Terms and Conditions, then Company may not be in a position to offer You all or some of the product/Services, including without limitation, certain features of the Stack Finance Platform, and may even restrict (partially or fully) the User from accessing the Stack Finance. Further, if You do not agree to this Privacy Policy, Terms of User and/ or product specific Terms and Conditions, You may also not register on Stack Finance Platform, not avail Our Services and/or deregister from Stack Finance Platform and stop using Our products/Services. We shall not be held responsible and/ or liable for any denial of Service due to User not providing the required information. Stack Finance does not knowingly collect or solicit personal information from anyone under the age of 18. If you are under 18, please do not attempt to register for the Services or send any personal information about yourself to Stack Finance. If Stack Finance learns that we have collected personal information from a person under age 18, we will delete that information as quickly as possible. If you believe that a person under 18 may have provided us with personal information, please contact us at

1. Information received, collected and stored by the company

While registering on /accessing Stack Finance Platform or while using Our Services, You may be required to provide some information about yourself, on a voluntary basis. We may also ask You to provide certain additional information from time to time or retrieve information about You from third parties. All information disclosed by You shall be disclosed willingly on a voluntary basis and without any coercion. Also, in some instances You might have to provide certain information on a mandatory basis (such as KYC information).

A. Information supplied by users
The Company shall collect Personal Information about the User, including, without limitation, at the time of:

  1. registering /setting up an account on Stack Finance;
  2. while filling up forms;
  3. browsing/accessing the Stack Finance;
  4. while availing any product/services.

Users may be required to provide certain personal information for the registration process that may include but not limited to:

  1. Name;
  2. PAN;
  3. email id;
  4. mobile number;
  5. marital status;
  6. bank account number;
  7. address;
  8. credit card numbers;
  9. medical records and history;
  10. nominee details;
  11. date of birth;
  12. Signatures;
  13. Income Details;
  14. Documents (like Address proof or Bank Statements) and other related information.

The Company shall also collect non-personal information pertaining to the behaviour of the User (Behavioural information), while using/browsing the Stack Finance Platform, messages posted by the User on Stack Finance Platform etc.

When You register using Your other accounts like on Facebook, Twitter, Gmail etc. We shall retrieve Information from such accounts to continue to interact with You and to continue providing the Services.

Any personally identifiable information provided by You will not be considered as sensitive if it is freely available and / or accessible in the public domain like any comments, messages, blogs, scribbles available on social platforms like Facebook, twitter etc. Further, any posted/uploaded/conveyed/communicated by users on the public sections of the Sites becomes published content and is not considered personally identifiable information subject to this Privacy Policy. The Company/its partners/vendors/ service providers etc. may also contact You from time to time through any mode of communication about updating Your personal information in order to provide the Users with such features that We believe may benefit / interest You.

The Personal Information, any non-personal information and behavioural information (collectively called as Information) is stored by the company on servers owned by its or its group companies or by third parties in India. Only on your explicit consent Stack Finance collects account information from respective institutions [as selected by you], by providing your account details and the corresponding password. The credentials are dual-encrypted, first by a unique-to-user key pair and second by our master key. These credentials are then passed to the institutions to screen scrape the data from the institutions website/platform. Data in transit is also encrypted using TLS and bank-grade public-private key exchange. This will enable Stack Finance to consolidate accurate information and present the same to you.

Investments information: We provide the following options for you to update your investment information in a secure manner :

(i) Upload your investment statements in PDF or Excel versions.
These are investment statements that you get from depositories or brokers or Registrar & Transfer Agents such as Computer Age Management Services, Karvy Fintech Private Limited, National Securities Depositories Limited, Central Depositories Services Limited, etc.

You provide explicit consent to Stack Finance to fetch these statements from and

(ii) Enter the information manually
You provide investment details like scheme name, investment type, investment date and investment value by manually entering the data.

Voluntary information:
We may collect additional information at other times, including but not limited to, when You provide feedback, comments, change Your content or email preferences, respond to a survey, or any communications with Us. However, in the event You wish to provide Us with Your Aadhar card information, You hereby agree and acknowledge that You are providing the same to Us purely on a voluntary basis only.

B. Information automatically collected/tracked while navigation

Cookies & Third Party Analytics Services
We use Local Storage Objects (LSOs) to store content information, preferences and to keep you signed-in. We identify the user’s signed-in state with a token which has encoded a user identifier. The LSO token expires when a user logs out of our website or mobile application.We do not collect any information about your online activity when you sign-out and/or leave our services.We use third party analytics services in order to better understand user engagement with the Services. When a user browses or uses the Services, these third party analytics services may collect the user’s IP address, browser type, and approximate location (based on the IP address). They may also use web logs or web beacons and may set and access cookies on your computer or other device.These third party analytics services may deploy cookies on your browser. Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services that you do not wish such operators to track certain of your online activities over time and across different websites. Do Not Track signals are set on a browser-by-browser basis, so you must set them on every browser you use if you do not wish to be tracked.

Log File Information
We automatically collect limited information about Your computer's connection to the Internet, mobile number, including Your IP address, when You visit Our site, application or service. Your IP address is a number that lets computers attached to the Internet know where to send You data -- such as the pages You view. We automatically receive and log information from Your browser, including but not limited to Your IP address, Your computer's name, Your operating system, browser type and version, CPU speed, and connection speed. We may also collect log information from Your device, including Your location, IP address, Your device's name, device's serial number or unique identification number (e.g.. UDiD on Your iOS device), Your device operating system, browser type and version, CPU speed, and connection speed etc.

2. Information from other Sources:

Demographic and other information:
We may reference other sources of demographic and other information in order to provide You with more targeted communications and promotions. We use Google Analytics, among others, to track the user behaviour on Our Sites. Google Analytics specifically has been enabled to support display advertising towards helping Us gain understanding of Our users' demographics and interests. The reports are anonymous and cannot be associated with any individual personally identifiable information that You may have shared with Us. You can opt-out of Google Analytics for display advertising and customize Google Display Network ads using the Ads Settings options provided by Google.

Links to third party sites/Ad-servers:
The Sites may include links to other websites or applications. Such websites or applications are governed by their respective privacy policies, which are beyond Our control. Once You leave Our servers (You can tell where You are by checking the URL in the location bar on Your browser), use of any information You provide is governed by the privacy policy of the operator of the application, you are visiting. That privacy policy may differ from Ours. If You can't find the privacy policy of any of these sites via a link from the application's homepage, You should contact the application owners directly for more information. We do not provide any personally identifiable Information to third party websites/ application/ advertisers/ ad-servers without Your consent except in the circumstances mentioned in Information Sharing section.

When We present Information to Our advertisers -- to help them understand Our audience and confirm the value of advertising on Our Sites -- it is usually in the form of aggregated statistics on traffic to various pages / content within Our Sites. We use third-party advertising companies to serve ads when You visit Our Sites. These companies may use Information (excluding Your name, address, email address or telephone number or other personally identifiable information) about Your visits to this and other websites or application, in order to provide advertisements about goods and services of interest to You. We do not provide any personally identifiable information to third party websites/advertisers/ad-servers without Your consent.

Information use by the company
The Personal information provided by the User is used by the Company for the purposes, including, without limitation:

  • provide a smooth, safe and customized experience to the User on Stack Finance Platform;
  • provide/promoting its products and services on the Stack Finance Platform- general as well as customized and improve the same from time to time;
  • provide You the most user-friendly experience and for developing new services;
  • analyse flow, track user trends, measure promotional effectiveness;
  • provide additional features on the Stack Finance Platform through Cookies;
  • protect the safety and integrity of the Stack Finance Platform, information and maintain the confidentiality of the User and their data;
  • Ensure smooth execution of transaction and payments;
  • Maintain, improve and provide Service (including personalization of Stack Finance Platform);
  • Inform the User about new/change in products/services/offers/updates/reminders, billing information, customer service(s) etc.;
  • To detect and/or prevent any fraudulent/criminal/prohibited activity on Stack Finance Platform;
  • To process Your request or respond to Your queries/grievances/comments;
  • Send customized messages/notifications to You;
  • Communicate any change in Our services/products/Terms and Conditions/Privacy policy;
  • Marketing and commercial communications regarding services/products;
  • Analyse Your behaviour on Stack Finance Platform;
  • Facilitate Company's marketing, advertising and educational activities/initiatives;
  • Auditing and investigation purposes;
  • Updated regarding third party services and products and products and services offered on other Sites;
  • Data analysis/analytics;
  • Pre-filling of various forms;
  • Maintain User Account;
  • Provide general information/updates.

We may also use Your email address or other personally identifiable information to send commercial or marketing messages about Our Services and/or such additional updates and features about third parties' products and services with an option to subscribe / unsubscribe. We may, however, use Your email address for non-marketing or administrative purposes (such as notifying You of major changes, for customer service purposes, billing, etc.).

3. Information sharing

The Company may share Your Information with authorised third party without obtaining the prior consent of the User in the following circumstances but not limited to:

  • In order to provide seamless experience
  • To provide various services/products to the User of the Company as well as of the third parties
  • Customize offers/products/services based on the User needs or behavioural pattern
  • Ensure smooth execution of transaction and payments
  • to protect the rights and property of the Company
  • To initiate any investigate any complaints / claims / disputes
  1. When it is requested or required by law or by any court or governmental agency or authority to disclose, for the purpose of verification of identity, or for the prevention, detection, investigation including but not limited to cyber incidents, or for prosecution and punishment of offences. These disclosures are made in good faith and belief that such disclosure is reasonably necessary for enforcing these Terms or for complying with the applicable laws and regulations.
  2. The Company proposes to share such Information to conduct its business and to share such Information within its group companies and officers and employees of such group companies for the purpose of processing personal information on its behalf. We also ensure that these recipients of such Information agree to process such information based on Our instructions and in compliance with this Policy and any other appropriate confidentiality and security measures.
  3. The Company may present Information with third parties - to help them understand Our audience and confirm the value of advertising on Our Sites - however it is usually in the form of aggregated statistics on traffic to various pages within Our site. When We present Information to Our advertisers -- to help them understand Our audience and confirm the value of advertising on Our Sites -- it is usually in the form of aggregated statistics on traffic to various pages / content within Our Sites. We use third-party advertising companies to serve ads when You visit Our Sites. These companies may use Information (excluding Your name, address, email address or telephone number or other personally identifiable information) about Your visits to this and other websites or application, in order to provide advertisements about goods and services of interest to You. We also share User Personal Information with Our vendors/service providers -- to help Us understand about Our User Behaviour and/or to serve ads when You visit Stack Finance platform. These companies may use Information (excluding Your name, address, email address or telephone number or other personally identifiable information) about Your visits to this and other websites or application. We use third-party advertising companies to serve ads when You visit or use Our Sites or Services. These companies may use information (excluding Your name, address, email address or telephone number or any personally identifiable information) about Your visits or use to particular website, mobile application or services, in order to provide advertisements about goods and services of interest to You.
  4. The Company may share Your Information regarding Your activities on Sites with third party social websites to populate Your social wall that is visible to other people however You will have an option to set Your privacy settings, where You can decide what You would like to share or not to share with others.
  5. We may share Your Information to enforce or protect Our rights or any or all of its affiliates, associates, employees, directors or officers or when We have reason to believe that disclosing Information of User(s) is necessary to identify, contact or bring legal action against someone who may be causing interference with Our rights or Our Sites, whether intentionally or otherwise, or when anyone else could be harmed by such activities.
  6. We may share information with consultants/third parties/business partners/vendors for providing Our and/or their various products/ services. The handling of Your Information by such Consultants/third parties/business partners/vendors shall be as per the privacy policies of those consultants/ third parties/ business partners/ vendors. The Company shall not be responsible or liable for any action or omission of these consultants/ third parties/ business partners/ vendors with respect to Your Information.

4. Data accessed from Google

Your personal information with respect to connecting your Gmail account with Stack Finance Application: Compliance w.r.t. Google OAuth API Scopes (Restricted scopes)

We will never rent or sell your information or data to anyone. Stack Finance ensures that it is always in compliance with the restricted scope defined under Google OAuth API policies.

  1. Stack Finance limits use of data to providing or improving your user experience. Connecting your Gmail account with Stack Finance is completely optional and based on your explicit consent for only specific use cases as has been described in this Privacy Policy. You can choose to de-link your Gmail account with the application at any time and/ or you can delete your information by writing to
    Alternatively, you can remove access to Stack Finance from Google Mail’s permission settings located at:
  2. We only transfer the data to others if necessary to provide or improve user-facing features that are prominent in the requesting application's user interface. We may also transfer data as necessary to comply with applicable law or as part of a merger, acquisition, or sale of assets with notice to users. All other transfers or sales of the user data are prohibited
  3. We don't use or transfer the data for serving ads, including retargeting, personalized, or interest-based advertising and we do not allow and we prohibit access to any of the third party analytics providers.
  4. We don't allow humans to read the data, unless:
    • (a) We first obtain your affirmative agreement for specific messages;
    • (b) It is necessary for security purposes (such as investigating a bug or abuse);
    • (c) It is necessary to comply with applicable law; or
    • (d) Our use is limited to internal operations and the data (including derivations) have been aggregated and anonymize.

These prohibitions of user of data apply to the raw data obtained from Restricted Scopes and data aggregated, anonymized, or derived from them. Our employees, agents, contractors, and successors comply with the “Google API Services: User Data Policy”.

5. Accessing and updating personal information

When You use the Services or Sites (or any of its sub sites), We make good faith efforts to provide You, as and when requested by You, with access to Your personal information and shall further ensure that any personal information or sensitive personal data or information found to be inaccurate or deficient shall be corrected or amended as feasible, subject to any requirement for such personal information or sensitive personal data or information to be retained by law or for legitimate business purposes. We ask individual users to identify themselves and the information requested to be accessed, corrected or removed before processing such requests, and We may decline to process requests that are unreasonably repetitive or systematic, require disproportionate technical effort, jeopardize the privacy of others, or would be extremely impractical (for instance, requests concerning information residing on backup tapes), or for which access is not otherwise required. In any case, where We provide information access and correction, We perform this service free of charge, except if doing so would require a disproportionate effort. Because of the way We maintain certain services, after You delete Your information, residual copies may take a period of time before they are deleted from Our active servers and may remain in Our backup systems.

We encourage You to review, update and correct the personal information that We maintain about You, and You may request that We delete personal information about You that is inaccurate, incomplete or irrelevant for legitimate purposes, or are being processed in a way which infringes any applicable legal requirement.

Your right to review, update, correct etc. Your information is subject to Our records retention policies and applicable law, including any statutory retention requirements.

Retention of Data
We shall retain the records as per applicable laws and such other statutory / regulatory requirements from time to time. In the event any legal / regulatory proceeding is pending, we can retain records for a longer period.
We shall store the data in our database even if the User has chosen not to be contacted and/ or closed his/her account with the Company.
We shall store the data/information/records on a server owned by Us or its group companies in India.
We may keep Our records of the electronic instructions/transactions in any form as permitted under applicable Laws. In this regard, all records, whether in electronic form, magnetic form, documents or any other form with respect to electronic instructions/online transactions shall be conclusive evidence of such instructions/transactions and shall be binding on the User

6. Information Security

We take appropriate security measures to protect against unauthorized access to or unauthorized alteration, disclosure or destruction of data. These include internal reviews of Our data collection, storage and processing practices and security measures, including appropriate encryption and physical security measures to guard against unauthorized access to systems where We store personal data. All information gathered on Stack Finance is securely stored within the Company controlled database. The database is stored on servers secured behind a firewall; access to the servers is password-protected and is strictly limited. However, as effective as Our security measures are, no security system is impenetrable. We cannot guarantee the security of Our database, nor can We guarantee that information You supply will not be intercepted while being transmitted to Us over the Internet. And, of course, any information You include in a posting to the discussion areas is available to anyone with Internet access.

7. Updates / Changes

The internet is an ever-evolving medium. We may alter Our Policy from time to time to incorporate necessary changes in technology, applicable law or any other variant. In any case, We reserve the right to change (at any point of time) the terms of this Policy or the Terms of Use. Any changes We make will be effective immediately on notice, which We may give by posting the new policy on the Sites. Your use of the Sites or Services after such notice will be deemed acceptance of such changes. We may also make reasonable efforts to inform You via electronic mail. In any case, You are advised to review this Policy periodically on the Sites to ensure that You are aware of the latest version.

8. Changes to Privacy Policy

Stack Finance reserves the right to change this policy from time to time. Any changes shall be effective immediately upon the posting of the revised Privacy Policy. While we will make reasonable efforts to keep you posted on any updates to this privacy policy, to make sure that you are aware of any changes, we recommend that you review this policy periodically. If you are not comfortable with any of the changes to Privacy Policy you may choose to discontinue usage of Stack Finance website or mobile applications. You can also email us at to update or delete your personal information that Stack Finance has collected.

9. Privacy Questions and Access

If you have questions, concerns, or suggestions regarding our Privacy Policy, please contact us immediately at or In certain cases, you may have the ability to view or edit your personal information online. In the event your information is not accessible online and you wish to change or delete your personal information or other information that you may have provided, please contact us immediately at or

10. Security and Responsible Disclosure

We at Stack Finance are committed to our client's data and privacy. We blend security at multiple steps within our products with state of the art technology to ensure our systems maintain strong security measures. The overall data and privacy security design allows us to defend our systems ranging from low hanging issues up to sophisticated attacks.

If you are a security enthusiast or a researcher and you have found a possible security vulnerability on Stack Finance, we encourage you to report the issue to us responsibly.

You could submit a bug report to us at with detailed steps required to reproduce the vulnerability.