Loading InvoRush...
InvoRush Logo

Privacy Policy

Last updated: 14.08.2026
InvoRush (“InvoRush”, “we”, “us”, or “our”) is a working capital and supply chain finance marketplace operated by Sapphiro Consulting Solutions Pvt. Ltd. (“Sapphiro”, “Company”) that connects businesses with banks, non- banking financial companies (NBFCs), and payment and technology partners for B2B invoice discounting, supply chain finance (vendor finance), bulk payments, and structured financing with cards (the “Services”). This Privacy Policy explains how we collect, use, disclose, store, and protect information when you visit invorush.com and org.invorush.com (together, the “Platform”), register for or use the Services, or otherwise interact with us.

This Policy applies to visitors, prospective clients, registered business users, authorised signatories, directors and employees of client organisations, vendors, suppliers, and anchor partners who interact with our Platform (collectively, “you” or “Users”). By accessing the Platform or using the Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree with this Policy, please discontinue use of the Platform and Services.

This Policy is published in accordance with Rule 3(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, framed under the Information Technology Act, 2000, and reflects the requirements of the Digital Personal Data Protection Act, 2023 (“DPDP Act”). It will be updated as the DPDP Act's implementing rules come into force.

1. Scope of This Policy

This Policy covers personal data and business data collected through:

  • The InvoRush website, ROI/savings calculators, and lead, quote, or demo-request forms;
  • Onboarding, KYB (Know Your Business) and KYC (Know Your Customer) processes for the financing platform;
  • The InvoRush client dashboard at org.invorush.com and transaction workflows (invoice upload, financing requests, bulk payments, cards);
  • Customer support, sales, and account-management interactions (email, phone, chat, in-person meetings);
  • Cookies, analytics, and similar tracking technologies used on the Platform.

It does not cover the practices of third-party banks, NBFCs, payment gateways, or technology partners who process data under their own privacy policies once a transaction is routed to them; we encourage you to review those policies separately, and we identify categories of such partners in Section 6.

2. Information We Collect

2.1 Information you provide directly

  • Identity and contact details — name, designation, company name, business email, phone number, office address;
  • Business and financial information — GSTIN/PAN/CIN, bank account and payment details, receivables/payables data, invoice and transaction documents, credit and risk-assessment information submitted during onboarding or financing requests;
  • KYC documents — PAN, GST registration, certificate of incorporation, board resolutions, authorised- signatory identity proof, and other documents mandated by our lending partners or regulators;
  • Authentication data — login credentials, OTPs, and signatory authorisations;
  • Communications — information you provide when you request a demo, request a quote, use the ROI calculator's “email me the analysis” feature, submit the Contact form, or correspond with our sales and relationship teams;
  • Marketing preferences — details you provide when subscribing to Insights, newsletters, or event communications.

2.2 Information collected automatically

  • Device and usage data — IP address, browser type, device identifiers, pages viewed, referring URLs, and timestamps;
  • Log data — operating system, browser plug-ins, crash and system activity, and date/time of each request to the Platform;
  • Cookies and similar technologies — used for site functionality, analytics, and (where enabled) personalisation; see Section 5;
  • Platform activity logs — actions taken within the client dashboard, for security, audit, and fraud-prevention purposes.

2.3 Information from third parties

  • Verification data from credit bureaus, KYC/AML utilities, and government registries (e.g. GSTN, Ministry of Corporate Affairs) used to validate business identity and creditworthiness;
  • Data shared by partner banks, NBFCs, anchors, or corporate clients in connection with a financing programme you participate in;
  • Publicly available business information.

3. How We Use Your Information

We use the information described above to:

  • Create and administer accounts, and verify business and signatory identity (KYB/KYC and anti-money- laundering checks);
  • Evaluate and process financing, invoice discounting, supply chain finance, bulk-payment and card requests, including credit and risk assessment;
  • Facilitate transactions between you, anchor corporates, and our partner banks/NBFCs;
  • Operate, maintain, and improve the Platform, including the ROI calculator and dashboard;
  • Respond to enquiries, provide customer support, and send transactional communications;
  • Send product updates, Insights content, or marketing communications, where you have opted in or as otherwise permitted by law, with an option to opt out at any time;
  • Detect, investigate, and prevent fraud, security incidents, and misuse of the Services;
  • Comply with legal, regulatory, tax, and reporting obligations applicable to a financial services marketplace; and
  • Enforce our terms of use and this Policy.

4. Legal Basis for Processing

Where the DPDP Act or other applicable law requires a legal basis, we rely on one or more of the following: your consent (for example, when you submit a form or opt into marketing); performance of a contract with you or your organisation (for example, to process a financing request); compliance with a legal obligation (for example, KYC/AML and regulatory reporting); and our legitimate business interests, such as platform security, fraud prevention, and improving our Services, balanced against your rights.

5. Cookies and Tracking Technologies

We use cookies, web beacons, and similar technologies to operate the Platform, remember preferences, understand how visitors use our pages and tools (including the ROI calculator), and, where permitted, support marketing analytics. You can control cookies through your browser settings; disabling certain cookies may limit some Platform functionality. Where required by law, we will request your consent before setting non-essential cookies via a cookie banner or preference centre.

6. How We Share Information

We do not sell your personal data. We may share information with:

  • Partner banks and NBFCs to whom your financing request is routed, and anchor corporates participating in a relevant programme;
  • Payment, banking, and technology infrastructure partners that support onboarding, payments, and platform operations;
  • KYC/AML, credit bureau, identity-verification, and fraud-prevention service providers;
  • Cloud hosting, analytics, CRM, and customer-support vendors who process data on our behalf under contractual confidentiality and security obligations;
  • Professional advisors (legal, audit, compliance) and regulators, courts, or government authorities where required by law or to protect our rights;
  • Group companies and affiliates, including Sapphiro Consulting Solutions Pvt. Ltd., to support internal operations and business continuity;
  • A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to equivalent privacy protections.
  • Any third party that processes personal data on our behalf is required to use it only for the purposes we specify and to maintain appropriate security safeguards.

7. Data Storage, Security, Localisation and Retention

We use administrative, technical, and physical safeguards — including encryption in transit, access controls, and audit logging — designed to protect information from unauthorised access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Regulated customer data, financial information, and payment-related data collected in connection with the Services are stored and processed on servers located in India. Where any cross-border transfer is required, we take steps to ensure it does not restrict lawful regulatory or supervisory access, and that recipients maintain equivalent data-protection standards.

We retain personal and business data for as long as necessary to provide the Services, satisfy the purposes described in this Policy, and meet legal, regulatory, accounting, and reporting requirements applicable to financial intermediaries. Unless a longer period is mandated (for example, for tax or KYC records), our default retention period is six years from the last processing date, after which data is securely deleted or anonymised.

8. Your Rights

Subject to applicable law, including the DPDP Act, you have the following rights as a Data Principal:

RightWhat it means
Right to KnowKnow what personal data of yours we hold and why.
Right to AccessRequest a copy of the personal data we hold about you.
Right to CorrectionHave inaccurate, incomplete, or outdated data corrected or updated.
Right to ErasureRequest deletion of your data, subject to our legal, regulatory, and contractual retention obligations.
Right to Withdraw ConsentWithdraw consent for processing based on consent (e.g. marketing) at any time, without affecting prior lawful processing.
Right to Grievance RedressalRaise a complaint with our Grievance Officer and, if unresolved, escalate to the Data Protection Board of India.
Right of NominationNominate another individual to exercise these rights on your behalf in the event of death or incapacity.

To exercise any of these rights, contact our Grievance Officer using the details in Section 11. We will ask for reasonable proof of identity (and, if you are acting through an authorised agent, written proof of that authorisation) before actioning a request, and will respond within the timelines required by applicable law. Certain data — such as records required for regulatory, KYC, or tax purposes — may need to be retained even after a deletion request. You also have the right to lodge a complaint with the Data Protection Board of India if you are not satisfied with our response.

9. Identity Theft and Phishing

InvoRush will never ask you for sensitive information such as passwords, OTPs, or full bank account/card details over email, SMS, or unsolicited phone calls. If you receive a message that appears to be from InvoRush asking for such details, please do not respond, and report it to support@invorush.com immediately.

10. Children's Privacy

The Services are intended for use by businesses and their authorised representatives and are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it.

11. Third-Party Links

The Platform may contain links to third-party websites, including our banking, payment, and technology partners. This Policy does not apply to those websites, and we encourage you to review their respective privacy policies before providing any information.

12. Grievance Officer / Contact Us

If you have questions, concerns, or requests regarding this Policy or our data practices, or wish to raise a grievance, please contact:

Grievance Officer: Subhobroto Banerjee
Email: grievance@invorush.com
Phone: +91 966866 07030 (Mon – Sat, 9:30 AM – 6:30 PM)
Registered Address: Sapphiro Consulting Solutions Pvt. Ltd., Globsyn Crystals Building, 4th Floor, Salt Lake, Sector V, Kolkata, West Bengal 700091, India
Additional offices: Goregaon East, Mumbai, India | Janakpuri, New Delhi, India

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the revised Policy on this page with an updated “Last updated” date, and, where changes are material, provide additional notice as required by law.