Back to App
Garage HiFiLegal & Privacy
Get Started
Institutional Data Safeguards

Privacy Policy & Data Notice

This Privacy Policy explains how Garage HiFi collects, protects, utilizes, and processes personal data across our alternative asset investment platform, escrow facilities, and distributed verification infrastructure.

Last UpdatedAugust 28, 2026
Effective DateAugust 1, 2026
Compliance StandardISO/IEC 27001 & SOC2

End-to-End Encryption

AES-256 at rest and TLS 1.3 in transit

Strict Confidentiality

We never sell or rent your personal information

Audited Escrow Custody

Statutory trustees & multi-sig wallet oversight

Regulatory Compliance

KYC/AML verification conforming to financial regulations

1

Introduction & Scope

Welcome to Garage HiFi ("we", "our", "us", or the "Platform"). We operate an institutional-grade investment platform facilitating secondary market assets, debt syndication, tokenized yields, and escrow-backed venture structures.

This Privacy Policy governs the manner in which Garage HiFi collects, uses, maintains, and discloses information collected from users, accredited investors, institutional partners, and corporate entities. By accessing our platform, registering an account, completing KYC verification, or funding an investment tranche, you acknowledge and agree to the data handling practices described herein.

Important Scope Notice: In certain circumstances where investments are structured under specific statutory SPVs or regulated escrow partners, additional deed-specific disclosures may apply. Those terms supplement this policy.
2

Information We Collect

To fulfill regulatory mandates, execute legally binding investment deeds, and ensure escrow safety, we collect and process several categories of information:

A. Identity & Contact Data

  • Full legal name and date of birth
  • Residential address & proof of domicile
  • Verified email address and phone number
  • Corporate registration / Entity certificates (if investing via entity)

B. KYC / AML & Regulatory Data

  • Permanent Account Number (PAN) / Tax ID
  • Government photo ID (Passport / Aadhaar / Driver's License)
  • Biometric / Liveness facial verification checks
  • Politically Exposed Person (PEP) declaration logs

C. Banking & Financial Data

  • Bank account numbers and IFSC / routing codes
  • Cancelled cheque copies and bank statements for verification
  • Accreditation status, net worth thresholds, and source of funds
  • Virtual Escrow Account identifiers and payout preferences

D. Blockchain & Technical Telemetry

  • Public cryptographic wallet addresses
  • On-chain smart contract transaction hashes
  • IP address, browser user-agent, and session identifiers
  • Audit logs of digital signature execution timestamps
3

How We Use Your Information

We adhere strictly to data minimization principles. We only process your information for legitimate business operations and legal compliance:

Executing Investment Applications: Generating investment agreements, executing digital signatures, assigning fractional units, and routing funds into regulated escrow accounts.
Automating Yields & Settlements: Calculating real-time accrued returns, managing coupon distributions, processing wallet credits, and remitting payouts to your registered bank account.
Statutory AML/CFT Compliance: Cross-referencing sanction lists, verifying tax residency, validating bank account ownership (penny drop checks), and filing regulatory reports.
Platform Security & Fraud Prevention: Authenticating login sessions via OTP verification, detecting anomalous login behavior, and maintaining tamper-evident audit trails.
4

Data Sharing & Third-Party Disclosure

We do not sell, rent, or trade your personal data. We disclose your data solely to trusted infrastructure partners under strict confidentiality agreements:

  • Regulated Escrow & Banking Partners: ICICI Bank, Yes Bank, or appointed statutory escrow trustees who safeguard funds during investment lifecycles.
  • Accredited KYC & Verification Providers: Third-party verification engines (such as IDfy, Signzy, or Digio) for PAN verification, Aadhaar XML checks, and digital document signing.
  • Auditors & Legal Trustees: Appointed independent auditors, debenture trustees, and legal advisors managing asset registers and SPV compliance.
  • Regulatory & Law Enforcement Bodies: SEBI, RBI, FIU, or judicial bodies when compelled by applicable court orders or anti-money laundering investigations.
5

Data Security & Storage Architecture

We maintain bank-grade physical, electronic, and procedural safeguards designed to protect personal and financial information against unauthorized access, destruction, or disclosure:

AES-256

Storage Encryption

TLS 1.3

In-Transit Encryption

24/7 SOC

Threat Monitoring

All sensitive documents (PAN cards, bank proofs, signatures) are stored in secure, permission-scoped cloud vaults with immutable access logs and automatic tokenization of account identifiers.

6

Your Privacy Rights & Choices

Depending on your jurisdiction, you possess specific legal rights regarding your personal information:

Right to Access & Portability

You may request a machine-readable export of all holding records, transaction history, and submitted KYC records.

Right to Rectification

You can update or correct outdated bank details, contact addresses, or authorized signatory profiles via your Settings dashboard.

Right to Restriction & Erasure

You may request account closure, subject to mandatory financial record retention periods (e.g. 5-8 years under AML rules).

Right to Withdraw Consent

Opt-out of non-essential marketing emails, product announcement digests, or analytical telemetry at any time.

7

Cookies & Tracking Technologies

We use secure session cookies, local storage tokens, and essential telemetry to maintain persistent user authentication, remember filter preferences, and safeguard CSRF tokens. We do not use third-party ad-tracking cookies.

8

Data Retention & Cross-Border Transfers

We retain investment records, executed deeds, KYC artifacts, and transaction receipts for as long as your account remains active and for the minimum statutory period required by applicable financial regulatory frameworks (typically 7 years post-maturity of an investment instrument).

9

Updates to This Privacy Policy

We may update this policy periodically to reflect evolving regulatory frameworks or platform enhancements. Material changes will be communicated via email or through prominent notifications inside your investor dashboard prior to the change taking effect.

10

Contact Our Data Protection Officer (DPO)

If you have any questions, concerns, or requests regarding your personal data, you can reach out to our dedicated compliance team:

privacy@garage.co / dpo@garage.co

Attn: Data Protection Officer & Compliance Office
Garage HiFi Technologies Inc.
Financial District, Building 4B, Level 12