Privacy Policy

Introduction

This Privacy Policy (hereinafter known as “Policy”) sets out how the information provided to CARS24 Services Private Limited (hereinafter referred to as “CARS24”, “Company” “We”, “Us” and “Our”), its subsidiaries, affiliates, sister concerns, representatives, and contractors, in collecting, processing, protecting, storing, transferring, and utilizing the information that operates the Website https://www.cars24.com/ and https://www.loans24.co.in/ and any other websites and the corresponding domain, subdomain, mobile site and mobile application thereof, as well as the Google assistant bot (collectively, “Website”). ‘You’ or ‘Your’ or ‘Yourself’ or ‘User’ which term shall include persons who are accessing the website, mobile application, domain, subdomain and mobile site merely as visitors or undertaking any of the Services provided by CARS24 across all levels in addition to all the employees (permanent or contractual) or contractors, associates, and vendors. By accessing the website or using any of Our services, You agree to be bound by all the terms of this Policy.

CARS24 “affiliate” means any Person directly, or indirectly through one or more intermediaries, that i) controls, ii) is controlled by or iii) is under common control of CARS24. “Control” as used in the immediately preceding sentence, shall mean with respect to any person, the possession, directly or indirectly, of the power, through the exercise of voting rights, contractual rights or otherwise, to direct or control the decision-making of the management or policies of the controlled person. “Person” includes any natural person, corporation, partnership, Limited Liability Company, trust, unincorporated association, or any other entity.

The Company firmly believes in the highest standards of integrity in relation to the information provided by You at the time of interaction with the Company, and otherwise.

Scope of This Policy

This Policy has been designed and developed to help You to understand the following:

The type of Personal Data (including digital personal data or information and physical personal data uploaded digitally) that We collect from the User; The purpose of collection, means and modes of usage of such Personal Data by the Company; how and to whom the Company will disclose such information; how the Company will protect the Personal Data that is collected from the Users; and how Users may access and/or modify their Personal Data.

This Policy ensures compliance with privacy laws and regulations applicable to CARS24’s collection, processing, storage, use, transmission, disclosure to third parties and retention of Personal Data.

Types of Personal Data Collected by the Company

While using Our Services, We may collect the following categories of Personal Data from the Users: (i) Identity Information: Name, gender, age, photograph, and signature; (ii) Contact Details: Email ID, phone number, SMS and address (including country and ZIP/postal code); (iii) Authentication Data: Passwords and KYC documents (e.g., Aadhaar, PAN, driving license, GST certificate); (iv) Password chosen by the User; (v) Geolocation: IP-based geographical location; (vi) Financial Information: Bank account, credit/debit card details, tokenization, and transactional data; (vii) Dependent and Vehicle Details: Dependent information, vehicle registration, insurance policies & certificate, pollution certificate, transfer certificates, FASTag details (id, bank details including FASTag balance), insurance policies (current and previous)and challans; (viii) All other Personal Data as the User may share from time to time (including personally identifiable information/details).

We also keep records of telephone calls received and made for making inquiries, orders, or other purposes necessary for the administration of services.

In an attempt to improve Our Services, we may, from time to time, collect any information (other than what is mentioned above) from you through the Website. You may be assured that we do not share this data with any third party except in accordance with the terms of this Policy or applicable law.

In the ordinary course of the business, we may also use your email address and phone number without further consent for the purposes mentioned below under the Purpose of Information use (such as marketing, non-marketing, administrative purposes among others notifying you of major changes, for customer service purposes, providing information about updates to our Services, billing, etc.).

Any Information provided by you will not be considered as personal information if it is freely available and/or accessible in the public domain or is not deemed as personal information under the applicable law. Further, any reviews, comments, messages, blogs posted/uploaded/conveyed/communicated by users on the public sections of the Websites or an application store (like the App Store or Play Store) becomes published content and is not considered as personal information which is subject to this Policy.

Types of Other Data Collected by the Company

The Company may collect and process the following types of information: (i) Device and Usage Data: Internet connection, mobile device/application details, equipment used to browse the Website, operating system, IP details/address, your current and device location, communication information to provide customized offerings and usage details such as searches, browsing history, preferences (e.g., time zone, language), and online activities such as your searches, the results you selected from the search and other activities browsing length, automatically record when user’s website, browser type, referring/exit pages and URLs, number of clicks, domain names, landing pages, page viewed, details of online ads viewed by you, and other such information; (ii) Account and Transaction Data: User information provided during account creation or obtaining a quote (e.g., gender, searches, results, and transactional details); (iii) Cookies: Temporary cookies may be used for technical administration, research, development, and user personalization & administration; (iv) Additional Data: Information provided via surveys, contests, or optional requests to customize user experiences; (v) User-Generated Content: Content such as reviews, blogs, or testimonials is treated as Company property.

We may in the future include other optional requests for information from the User including through User surveys to help Us customize the platform to deliver personalized information to the User and for other purposes as mentioned herein. Such information may also be collected during surveys/contests conducted by Us. Any such additional Personal Data will also be processed in accordance with this Policy.

Please note that the above-mentioned list is only illustrative, and is by no means, exhaustive. Company may ask you for another information, where such information requirement has not been specified in the internal KYC Policy of the Company.

Purposes of Information Use

By providing Your information, You consent to its collection, sharing, disclosure, and use in accordance with this Policy. The information we collect may be utilized for various business, regulatory, and operational purposes, including but not limited to: (i) Improving Your Experience: Understanding how you interact with our Website and services, including your preferences, interests, and usage patterns, to improve features, personalize content, and provide tailored offerings; (ii) Service Delivery: Processing your transactions, queries, and requests, managing your account, sending periodic updates, and providing notifications about your vehicle, account, or scheduled appointments (e.g., self-inspections or home inspections); (iii) Communication: Contacting you and/or sending you notices about your account, marketing/promotional activities, updates in policies via email, SMS, telephone, or other means for product updates, promotional offers, surveys, or general inquiries about our services; (iv) Platform Management: Registering You on the Platform, performing technical administration, auditing, data analysis, and customization to enhance the platform’s functionality, security, and user experience; (v) Research and Market: Conducting surveys, research, analysis, business intelligence, reporting and improvement/development/advancement for the Company’s business, internal purposes, technical and administrative, operational purposes of the Company, and customization of the platform and/or the services and promotional activities; sending targeted and non-targeted advertisements; and analyzing user data to improve our services and develop new products in an effective manner; (vi) Compliance and Security: Verifying and identifying, preventing, detecting, and tackling fraud, money laundering, terrorism, and other crimes and political associations complying with legal obligations, investigating violations of terms, enforcing policies, and addressing disputes or security concerns; (vii) Legal and Administrative Purposes: Disclosing information to comply with legal requirements, court summons and orders, or law enforcement requests, and sharing data with authorized third parties for lawful purposes; (viii) Partnerships: Company is allowed to share the information, which You have shared on Our Website, with Our alliance partners/channel/business associates or affiliates (“Partners”). These alliances/partnerships are done to provide perks and convenience to You. By agreeing to this Policy, the Company and the Partners thereof, if any, will consider You as an interested user and will use the details submitted by You to contact You and give You a customized experience of Our services; (ix) Advertisement Personalization: Using your data to display advertisements aligned with your interests to relevant target audiences. While personal data is not disclosed without consent, interaction with ads may indicate alignment with advertiser criteria; (x) Operational Efficiency: Completing transactions with You effectively and billing for the products/services provided, Performing administrative tasks such as testing systems, recovering outstanding payments, and ensuring effective service delivery, Contact User as a survey respondent; (xi) Any other purpose that may be necessary to provide the services that You have opted for; the Company may use the information collected from You to enable the Company to display advertisements to its advertisers’ target audiences. Even though the Company does not disclose Your personal information for these purposes without Your consent, if You agree on, or otherwise interact with an advertisement, the advertiser may assume that You meet its target criteria.

This Policy covers the treatment of personal data gathered and used by Cars24 for lawful purposes and covers the personal data we share with authorized Third Parties or that Third Parties share with Us.

Cookies and Other Identifiers

To enable our systems to recognize your browser or device and to provide and improve Services, we use cookies and other identifiers. For more information about cookies and how we use them, please read our Cookies Policy. 

Legitimate Uses

Lawful purpose for processing of personal data includes obtaining consent of the User or for certain legitimate uses. These legitimate cases include: (i) Voluntarily provided personal data by User; (ii) User has not explicitly indicated that they do not provide consent to use personal data; (iii) By the state and any of its instrumentalities for any function under any law for the time being in force in India; (iv) For matters concerning public interest, e.g., medical emergency, judicial use; (v) For the purposes of employment or those related to safeguarding the employer from loss or liability.

Consent

By agreeing to this Policy and providing Your information, it is assumed that You have provided Your explicit consent to its collection, use, and sharing as described. If you do not agree, please refrain from using the website or app. Consent is obtained based on our relationship with you: for customers, through proposal forms or acceptance of terms on our app or website, and for prospects or leads, via third-party sources sharing such data. CARS24 ensures that consent is freely given, specific, informed, unambiguous, and obtained through a clear affirmative action. CARS24 reserves the right to continue lawful data collection, use, and disclosure where permitted by applicable laws. Users also confirm that the information they provide is lawful, accurate, and does not violate or infringe any laws. CARS24 assumes no liability for the authenticity, genuineness, or misrepresentation of the information provided and is not responsible for verifying the data obtained from users. You may withdraw your consent at any time by opting out by contacting us at privacy@CARS24.com. However, withdrawal of consent is not retroactive and does not apply to lawful data collection, use, or disclosure allowed under applicable laws. All consent-related actions, including withdrawal, will be appropriately documented.

Public Posts

As part of Our services, You may provide Your reviews, feedback, comments, ratings, photos, etc. on the public groups (“Post(s)”). The Company retains an unconditional right to remove and delete any Post or such part of the Post that, in the opinion of the Company, is false, malafide and misrepresenting. All Posts shall be publicly accessible and visible to all users and therefore, You should be careful about revealing any sensitive details about Yourself in such Posts. The Company reserves the right to use and reproduce Your Posts for lawful purposes. Further, the Company may share Your Posts with the service providers, businesses or any other third party for any such lawful purposes. If You delete Your Posts from any of the public groups, copies of such Posts may remain viewable in archived pages, or such Posts may have been copied or stored by any other user(s) of that public group.

Limiting Use, Disclosure and Transfer of Personal Data

We may need to disclose/transfer Personal Data to certain third-party service providers to provide the services they have opted for. We may need to disclose/transfer Personal Data to government and judicial institutions/authorities, to the extent required:

  • Under the laws, rules, and regulations and/or under orders of any relevant judicial or quasi-judicial authority
  • To protect and defend the rights or property of the Company
  • To fight fraud and credit risk
  • To enforce the Company's Terms of use (to which this Notice is also a part)
  • When the Company, in its sole discretion, deems it necessary to protect its rights or the rights of others

The Company may also make all Personal Data accessible to its employees and data processors/third party vendors only on a need-to-know basis and for the purposes set out in this Policy. The Company takes adequate steps to ensure that all the employees and data processors/third party vendors, who have access to, and are associated with the processing of Personal Data, respect its confidentiality and that such data processors/third party vendors adopt at least such reasonable level of security practices and procedures as required under applicable law. However, the Company does not disclose information, labelled, or aggregated, obtained through Marketplace application programming interface on behalf of a User, to other Users or any third parties, unless required by law.

Non-personally identifiable information may be disclosed to third party ad servers, ad agencies, technology vendors and research firms to serve non-targeted advertisements to the User. The Company may also share its aggregate findings (not specific information) in a non-personally identifiable form based on information relating to the User’s internet use (to the extent set out in this Notice) to prospective investors, strategic partners, sponsors, and others to help growth of the Company's business. We may also disclose or transfer the Personal Data, to another third party as part of reorganization or a sale of the assets or business of the Company. Any third party to which the Company transfers or sells its assets will have the right to continue to use.

User's Rights

  1. Right to information and access information
  2. Right to correction and erasure (“Right to be forgotten”)
  3. Right to rectification
  4. Right of grievance redressal
  5. Right to nominate – in the event of death or incapacity

Third Party Integration

You may access the Website through third-party Websites over which the Company has no control. You may optionally provide the Company with the information through third-party sign-in services such as Facebook, Pinterest, Twitter, Instagram, and Google, etc. In such cases, the Company fetches and stores whatever information is made available to the Company by you through these sign-in services. The Company reserves its rights to use information provided by you in consonance with all relevant laws and guidelines.

Further, it is clarified that while your usage of the Website, you might see the links to the third-party Websites / advertisements / electronic communication service, which are provided by the third parties. As operations of the third party are not under control of the Company, therefore the Company does not make any endorsement / guarantee of any service or product offered through such third-party Websites nor make any representation related to the privacy policy or other policies of such third party. Any usage of such third-party Website or availing any service or product through such third parties shall be at your risk and the Company is not responsible for any loss / damage or otherwise. It is recommended that you should review the terms & conditions of use and policy of such third-party Websites prior to using such Websites.

Disclosure to Third Parties

The links to third-party advertisements, third party websites or any third-party electronic communication services (referred to as “Third Party Links”) may be provided on the platform which are operated by third parties and are not controlled by, or affiliated to, or associated with the Company, unless expressly specified on the platform. If You access any such Third-Party Links, We request You to review the concerned website’s privacy Policy. We shall not be responsible for the policies or practices of such third parties.

Personal data shall be disclosed to third parties only for identified lawful purposes and after obtaining appropriate consent or requires otherwise.

  • Where reasonably possible, CARS24 shall ensure that third parties collecting, storing, or processing personal data on behalf of CARS24 have: (i) Signed agreements to protect personal data consistent with CARS24 Privacy Policy and information security practices or implemented measures as prescribed by law; (ii) Signed non-disclosure agreements or confidentiality agreements which includes privacy clauses in the contract; (iii) Established procedures to meet the terms of their agreement with CARS24 to protect personal data; and (iv) Any other purpose that may be necessary to provide the services that You.
  • Personal data may be transferred across geographies from where CARS24 operates for storage or processing where any of the following apply: (i) given consent to the transfer of information; (ii) transfer is necessary for the performance of a contract between the user and CARS24, or the implementation of pre-contractual measures taken in response to the user’s request; (iii) transfer is necessary for the conclusion or performance of a contract concluded in the interest of the User between CARS24 and a third party; (iv) transfer is necessary or legally required on important public interest grounds or for the establishment, exercise, or defense of legal claims; (v) transfer is required by law; (vi) transfer is necessary to protect the vital interests of the User; (vi) transfer is made under a data transfer agreement; (vii) The transfer is otherwise legitimized by applicable law.
  • Remedial action shall be taken in response to misuse or unauthorized disclosure of personal data by a third party collecting, storing, or processing personal data on behalf of CARS24.

Digital Lending Service Provider / Services Through Mobile App [Applicable if, Cars Financial Services Private Limited (CARS24 FSPL) or third party notified as Digital lender]

CARS24 FSPL will ensure that their Mobile App and Third Party Service Providers collect data only as needed with explicit borrower consent, avoid accessing mobile resources of the customers, provide options for data consent and revocation, disclose the purpose of consent at each stage as if required, and obtain explicit consent before sharing personal data with third parties unless legally required.

CARS24 FSPL will ensure that their Third Party Service Providers and Mobile Applications only store minimal necessary personal data, establish and disclose clear data storage policies, avoid storing biometric data unless permitted, and store all data on servers located within India, while maintaining responsibility for data privacy and security.

CARS24 FSPL will ensure their Third Party Service Providers and Mobile Applications have a publicly accessible, law-compliant privacy policy, detailing any third parties permitted to collect personal information.

Information Shared with Dealers and Franchise Partners

When you initiate a transaction, request services, or engage with offerings facilitated through our platform, certain information provided by you may be disclosed to authorized dealers or franchise partners to enable the processing of such transactions or services. This disclosure may include, but is not limited to, personal identifiers, contact information, payment details, preferences, and any other data required to facilitate and complete the requested transaction or service. In some cases, additional information, such as your transaction history, preferences, or data obtained from third-party sources, may also be shared with dealers or franchise partners to enhance the delivery of services.

If you provide a mobile number, dealers or franchise partners may contact you through text messages, calls, or other communication channels to provide updates regarding your transaction, service request, or delivery status. In certain instances, you may be required to furnish credit or debit card details to secure a reservation, transaction, or service request.

It is expressly stated that information shared with dealers or franchise partners may be used by them in accordance with their own policies and practices, which are beyond the control of the Company. The Company assumes no liability for the privacy practices of such dealers or franchise partners. For inquiries regarding their handling of your data, you are advised to contact the relevant dealer or franchise partner directly.

Permissible Age

The Services are not intended for users under the age of 18, unless permitted under applicable local laws (Permissible Age). We do not knowingly collect any personal information from users or market to or solicit information from anyone under the Permissible Age. If we become aware that a person submitting personal information is under the Permissible Age, we will delete the account and any related information as soon as possible. If you believe we might have any information from or about a user under the Permissible Age, please contact us at privacy@CARS24.com.

Job Applicants

If your information is submitted to us through our Service when applying for a position with our company, the information will be used to consider your application. We may retain your information for any period of time. This information may be shared with other companies for the purpose of evaluating your qualifications for the particular position or other available positions, as well as with third-party service providers retained by us to collect, maintain and analyze candidate submissions for job postings. For more details, please refer to the Applicant Privacy Policy at our Careers page.

Security Practices for Privacy

For the purpose of providing the services and for other purposes identified in this Policy, We are required to collect and host certain data and information from You. We are committed to protect Your Personal Data, and to that end, the Company adopts reasonable security practices and procedures to implement technical, operational, managerial, and physical security control measures in order to protect the Personal Data in its possession from loss, misuse and unauthorized access, disclosure, alteration, and destruction. While We try Our best to provide security that is commensurate with the industry standards, due to the inherent vulnerabilities of the internet We cannot ensure or warrant complete security of all information that is being transmitted to Us.

The Company takes adequate steps to ensure that third parties to whom the Personal Data may be transferred adopt at least such a reasonable level of security practices and procedures as required under applicable law to ensure security of Personal Data.

You hereby acknowledge that the Company is not responsible for any information sent via the internet that has been intercepted beyond Our control after having adopted reasonable security practices and procedures, and You hereby release Us from all claims arising out of or related to the use of intercepted information in any unauthorized manner.

Deletion and Retention of Records

CARS24 shall retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with applicable legal, regulatory, or contractual obligations. Upon withdrawal of consent by the data subject, or when it is reasonable to determine that the specified purpose for which the personal data was processed is no longer being served, the personal data shall be securely erased, unless its retention is required to comply with applicable laws or lawful obligations.

Disclaimer

In case any personal data is shared by You with Us, which is not requested by Us during registration, (whether mandatorily or optionally), We will not be liable for any personal data breach or disclosure in relation to such data. If You have any questions regarding this Policy or the protection of Your personal data, please contact us at privacy@CARS24.com.

Updates/Changes

We may alter Our Policy from time to time to incorporate necessary changes in technology, applicable law, or any other variant. In any case, We reserve the right to change (at any point of time) the terms of this Policy or the Terms of Use. Any changes We make will be effective immediately on notice, which We may give by posting the new policy on the Site. Your use of the CARS24 App Services after such notice will be deemed acceptance of such changes. We may also make reasonable efforts to inform You via electronic mail. In any case, You are advised to review this Policy periodically on the Site to ensure that You are aware of the latest version.

Contact Us/Questions/Grievance Redressal

In the event you have any complaints or concerns with respect to the Website or if you have any questions about this Policy, please feel free to contact Grievance Redressal Officer /Nodal Officer (“GRO”) our customer support at 1800 258 5656 or by mail at: privacy@CARS24.com with the following subject line: “Attention: Grievance Redressal Officer” or write to Cars24 FSPL at the following address: Address: 6th Floor, SAS Tower, Medicity Sector 38, Shivaji Nagar, Gurgaon - 122001, Haryana.

CARS24 will attempt to respond to all reasonable concerns or inquiries within 30 days of receipt of the email.