Privacy Policy
Last updated · October 2026 · agreement 3.3 · 2026-10-03
This policy is the data part of the MNHA Financials user agreement, shown here word for word. Every user reads it, and gives separate consents, before an account is used. It is also available in हिन्दी and ગુજરાતી on the agreement page.
Who we are
MNHA Financials (“MNHA”, “we”) provides the software at mnhafinancials.com and is responsible for your personal data under this agreement (the Data Fiduciary). Contact and grievances: support@mnhafinancials.com. MNHA is independent and is not affiliated with, sponsored by or endorsed by Groww.
Information we collect
Account: your email address (confirmed with a one-time code we email you) and your password (stored only as a salted hash). Identity verification on this page: a selfie and a photo of your PAN or Aadhaar, and the details in them — used only to verify that you are the person opening the account, to keep evidence that you personally completed this agreement, and to protect account integrity. You can take them on your phone by scanning a QR code: that link works for 15 minutes and can only upload these two photos to your account. They are stored as soon as you upload them, even before you sign. If you also complete MNHA's optional verification, we collect your full name, PAN, date of birth, postal address, a selfie and an ID document, and may hold a live video call with you; PAN and date of birth are stored encrypted. Identity images are stored as files on our server, outside public access. We treat all of these as sensitive.
Connecting your Groww account
Connecting Groww is a separate step. You sign in on Groww's own website and create the API key and TOTP secret there; we never ask for, receive or see your Groww password, PIN or one-time OTP. We verify the key live with Groww and store it encrypted (AES-256). With it, MNHA only reads: your Groww client code and enabled segments, balance, holdings, positions, order book and fills, and the live quotes and option chains shown on your desk — to show your desk and to work out round-trip analysis from your actual fills. Adding MNHA's static server IP to your key is optional: a static IP is required only for orders sent through the API.
Why we use your information
Only for the purposes in this agreement: creating, securing and running your account; signing you in; verifying your identity and recording your acknowledgement; connecting Groww when you ask and reading the permitted information; showing your desk and your analysis; keeping the service secure; meeting legal obligations; and handling your requests and grievances.
Where your data is stored, and who processes it
Your data is stored on our servers, run by our hosting provider (Hostinger) in the United States, so it is processed outside India. Groww supplies the account data you ask us to read; public market data also comes from other market-data sources, and no personal data is sent to them. Account emails, such as your sign-up code, are sent through Google's Gmail service, which receives your email address and the message. If a live verification call is arranged, it takes place on the video-meeting service named in the invitation, and MNHA does not record it. If recorded read-aloud is switched on, only the text of this agreement is sent to Microsoft Azure to make the audio. We use no third-party analytics, advertising or marketing-email services today, and we do not sell your personal data.
How long we keep it
Your account details, identity materials (selfie, ID photo) and verification details: until you delete your account. Your Groww key and client code: until you disconnect Groww or delete your account, whichever comes first. The rest of your Groww account data is not stored — it is read live each time you open a page. Your consent records and notifications: until you delete your account. Membership invoices, if any: kept after account deletion as billing records, used only for accounting and legal purposes. Server logs used for security and troubleshooting rotate out automatically.
Your rights and choices
You may ask what personal data we process and how; access it; correct or update it; have it erased when it no longer needs to be kept; withdraw a consent; and raise a grievance. Withdrawing a consent does not undo processing that was lawful before it, and withdrawing a required consent may mean we cannot continue that part of the service.
Withdrawing consent, disconnecting and deleting
In Settings → Privacy & consents you can switch optional consents off at any time — as easily as you gave them. Settings → Disconnect broker removes your stored Groww key at once and records the withdrawal of your Groww consent; you can also revoke the key on Groww. Settings → Delete account erases your account and personal data immediately — everything except billing records and server logs, including the backup copies our software keeps (an active membership must be left, and any unpaid invoice settled, first). Settings stays open to you even before you sign this version or connect Groww. You can also write to support@mnhafinancials.com.
Marketing, analytics and cookies
Marketing messages (email, SMS or WhatsApp) and non-essential analytics or cookies are optional, separate, and only for users who opt in; refusing or withdrawing them never limits the core service. Today we send no marketing and use no analytics tools or non-essential cookies — only a strictly necessary sign-in cookie (valid for eight hours) and a display-theme setting stored in your browser.
Your consent record
We keep evidence of your consent: the agreement version and its fingerprint, every language you viewed, each box you ticked, your typed signature, the date and time, your IP address and device, your selfie and ID photo, and any later change or withdrawal.
Questions and grievances
For questions, data requests or grievances, write to support@mnhafinancials.com. We aim to respond within a couple of business days. Where the Digital Personal Data Protection Act applies, you may also use the remedies it gives a Data Principal, including a complaint to the Data Protection Board of India.