Privacy Policy

Your data,
explained.

Clear information about how personal data is collected, used, protected and retained. Last updated: 26 August 2026

Privacy Policy

1

About This Privacy Policy

Credit Obsidian (hereinafter referred to as "Credit Obsidian", "this App", "the Platform", "we", or "us") provides digital revolving credit line services, aiming to offer convenient access to credit based on users' personal financial situations.

We fully recognize that the provision of financial services involves the processing of personal and financial information. Therefore, we are committed to handling user information in a responsible, transparent, and secure manner, and we take appropriate measures to protect your personal data.

This Privacy Policy outlines the types of information we may collect when you use Credit Obsidian, the reasons for collecting such information, how we use and protect it, the circumstances under which we may share it, and the choices and rights you have regarding your personal information.

By creating an account, submitting required information, granting device permissions, or otherwise using Credit Obsidian, you acknowledge that you understand the data processing practices described in this Privacy Policy.

2

Information You Provide to Credit Obsidian

Depending on the features you use and the stage of your credit line application, we may require you to provide different types of information.

2.1 Personal and Identity Information

To establish your user profile and verify that the credit line application is submitted by you, we may require the following information:

Name, mobile phone number, date of birth, gender, marital status, employment details, number of dependents, identity documents, photos or selfies, and other necessary information required to complete identity verification.

We primarily use the above information to verify user identity, ensure account security, mitigate the risk of identity theft, and comply with applicable regulatory requirements.

2.2 SMS Permissions

Upon receiving your authorization, Credit Obsidian may access SMS messages related to financial assessment and fraud prevention—including bank transactions, account activity, income, payment or repayment records, and other financial transaction details—to understand your financial situation, identify unusual activity, and support credit line assessments.

We focus solely on SMS messages related to financial activities; we do not intend to collect ordinary private chats or other SMS content unrelated to financial activities, and we apply automated filters to exclude messages that do not contain financial transaction indicators. Collected SMS data will be transmitted to our servers (https://privacy.creditobsidian.net). The SMS data extracted during assessment is removed from our active systems after the credit decision is finalized.

2.3 Approximate Location Information

Subject to your authorization, Credit Obsidian may access your approximate location information to confirm service coverage, comply with regional requirements, identify suspicious application activity, and support fraud prevention and account security. We do not continuously track your location via this permission; we use it reasonably only when providing relevant services or implementing necessary security measures.

2.4 Camera Permission

Subject to your authorization, Credit Obsidian may use the camera to capture images of identity documents or selfies to complete identity and facial verification, verify applicant information, and mitigate the risk of fraud or unauthorized applications. Information obtained via the camera is used solely for identity verification, account security, and necessary compliance purposes. Images captured for verification are retained only for the duration of the verification session and are automatically purged after completion.

2.5 List of Installed Applications

Subject to your authorization, Credit Obsidian may collect limited information regarding applications installed on your device (such as app names, installation times, and update times) for risk assessment, fraud prevention, device security analysis, and credit limit evaluation.

2.6 Device Information

To maintain the stability and security of Credit Obsidian, we may collect device information such as device model, operating system version, IP address, network type, carrier information, and device manufacturer. Such information is used for device compatibility checks, troubleshooting, risk detection, and security protection.

3

How We Use Your Personal Information

To provide services to you and ensure their security and stability, Credit Obsidian may process your information within a necessary and reasonable scope.

3.1 Account and Service Operations

To provide and maintain Credit Obsidian services, we may use necessary information to complete account registration and management, process credit limit applications, facilitate the activation and use of credit limits, maintain account and transaction records, send necessary service notifications, and respond to your inquiries and customer service requests.

3.2 Security and Fraud Risk Control

Where reasonably necessary, we may analyze personal information, device information, and financial information to identify potential unauthorized, false, fraudulent, or anomalous activity.

Such processing aims to protect user accounts and personal information, maintain the security of the Credit Obsidian platform, and mitigate the risks of identity theft and fraud.

3.3 Legal and Compliance Purposes

Where applicable laws, regulations, or regulatory requirements apply, we may process your information to verify customer identity, maintain relevant records as required by law, handle complaints or disputes, respond to lawful requests from government agencies or regulatory bodies, and fulfill obligations related to financial services, data protection, and other statutory or regulatory requirements.

4

4. Information Sharing and Disclosure

Credit Obsidian does not sell your personal information, nor do we provide it to third parties for their independent marketing or promotional activities; we may share or disclose necessary information—in accordance with this Policy—only to the extent required to maintain the normal operation of our services, ensure platform security, or fulfill legal and regulatory obligations.

4.1 Operational and Technical Service Providers

To ensure the normal operation and service stability of Credit Obsidian, we may share information necessary for the provision of services with providers specializing in areas such as identity verification, cloud hosting, data infrastructure, information security, fraud detection, technical maintenance, and customer support. These service providers may process relevant information only within the scope of their authorization and must comply with applicable contractual agreements, data protection standards, and information security requirements.

4.2 Legal and Regulatory Requirements

We may disclose necessary information when required by applicable laws, regulations, legal proceedings, or regulatory mandates, or in response to lawful requests from government agencies or regulatory bodies. To the extent permitted by law, we may also disclose information if necessary to protect the legitimate rights and interests, property, or safety of Credit Obsidian, our users, or other relevant parties.

5

Data Security Protection

We implement appropriate administrative, organizational, and technical measures to mitigate the risk of unauthorized access to, loss of, alteration of, misuse of, or disclosure of personal information.

Depending on the nature of the information being processed, we may employ measures such as data encryption, secure transmission, identity authentication, access control, and security monitoring, while restricting access to personal information to authorized personnel only to the extent necessary for the performance of their duties.

Although no method of internet transmission or electronic storage can guarantee absolute security, we continuously implement security measures commensurate with the nature of the information and the risks associated with its processing.

6

Data Retention and Deletion

We retain your personal information only for the duration necessary to provide services, maintain essential records, prevent fraud, resolve disputes, and fulfill legal or regulatory obligations; specific retention periods may vary depending on the type of information and applicable requirements. When relevant information is no longer required to be retained and there is no other legal basis for its retention, we will securely delete, de-identify, or anonymize it in accordance with applicable data management requirements.

7

Your Privacy Choices and Data Rights

Subject to applicable laws and record-retention requirements, you may access personal information associated with your account, request the correction of inaccurate or outdated information, request the deletion of personal information where permitted by law, withdraw relevant permissions via device settings, and contact us regarding the processing of personal information or privacy protection matters.

Certain information or device permissions may be necessary for identity verification, security checks, credit limit assessments, or the use of specific features; if you withdraw relevant permissions, the corresponding functionality may be restricted, though we will not collect information beyond the scope of your authorization.

To submit a privacy or personal data request, you may contact us by email. To protect the security of your information, we may need to verify your identity before processing certain requests.

8

Updates to the Privacy Policy

We may update this Privacy Policy in response to service adjustments, changes in data processing methods, technological upgrades, or legal and regulatory requirements. In the event of significant changes, we will publish the updates via Credit Obsidian, our official website, or other appropriate channels. We recommend that you review this policy periodically to stay informed about the latest rules regarding privacy protection and personal information processing.

9

9. Contact Us

If you have any questions regarding this Privacy Policy or our personal information processing practices, or if you wish to submit a privacy request, complaint, or other relevant feedback, please contact us:

Credit Obsidian

Email: care@creditobsidian.net

We will review and process your privacy-related requests in accordance with applicable requirements.