Privacy Policy
Comprehensive framework detailing how Golden Bag Capital Services collects, safeguards, and processes your personal and financial data in strict adherence to Indian laws.
Last Updated & Effective Date: September 2026
1. INTRODUCTION & REGULATORY COMMITMENT
Golden Bag Capital Services(“Golden Bag Capital,” “Firm,” “we,” “us,” or “our”) is an established wealth advisory and financial services firm headquartered in Chomu (Jaipur), Rajasthan, India. We operate as an AMFI-Registered Mutual Fund Distributor (MFD) committed to safeguarding the confidentiality, integrity, and privacy of the personal and financial information entrusted to us by our clients, investors, and website visitors (“you” or “your”).
Our relationship is built upon unwavering trust and faith. In the course of utilizing our website (www.goldenbagcapital.com), mobile interfaces, wealth calculators, or availing investment distribution services, we may become privy to confidential personal data. This Privacy Policy outlines our data governance standards in strict compliance with applicable Indian legislations, including:
- The Digital Personal Data Protection Act, 2023 (DPDP Act) and its rules;
- The Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules);
- Regulatory master circulars and directives issued by the Securities and Exchange Board of India (SEBI), the Association of Mutual Funds in India (AMFI), and the Reserve Bank of India (RBI);
- The Prevention of Money Laundering Act, 2002 (PMLA) and statutory KYC/AML guidelines.
This Policy should be read in conjunction with our Cookie Policy Charter and statutory disclosures. By accessing our platform or providing information, you consent to the practices outlined herein.
2. CATEGORIES OF INFORMATION WE COLLECT
To fulfill regulatory Know-Your-Customer (KYC) obligations, execute financial transactions, and provide seamless wealth advisory services, we collect and process specific categories of personal and financial information:
2.1 Identity, KYC & Verification Data
Mandatory information required by SEBI, AMFI, and Central KYC Registry (CKYCR) to verify your identity prior to processing financial transactions:
- Full legal name, father's name, spouse's name, gender, and date of birth
- Permanent Account Number (PAN) and tax residency status
- Proof of Identity and Address documentation (Voter ID, Passport, Driving License, or masked Aadhaar/DigiLocker verification in strict compliance with UIDAI circulars)
- Signature, photograph, and Central KYC (CKYC) identification number
- FATCA / CRS declarations and Politically Exposed Person (PEP) self-certifications
2.2 Financial & Banking Information
Information essential for facilitating investments, redemption payouts, and portfolio aggregation:
- Bank account number, bank branch name, account type, and IFSC code
- Cancelled cheque leaf or bank statement copies for account verification
- Mutual fund folios, depository participant (DP) details, and investor client codes
- SIP / NACH / e-Mandate registration records and transaction confirmation logs
- Investment preferences, risk tolerance score, and gross annual income bracket
2.3 Contact & Nominee Information
- Personal mobile number, alternate phone, and verified email address
- Residential, permanent, and communication postal addresses
- Nominee details (nominee legal name, relation, date of birth, and guardian details for minor nominees) as statutorily required under mutual fund regulations
2.4 Technical, Device & Portal Log Data
When you access our digital portal, we automatically record technical parameters to ensure system security and prevent fraudulent access:
- IP address, device hardware identifiers, and browser type/version
- Session timestamps, authentication logs, and portal feature interactions
- Essential session cookies for maintaining authenticated states (refer to our Cookie Policy)
3. HOW WE USE THE INFORMATION WE GATHER
Golden Bag Capital Services processes personal and financial data exclusively for lawful, specified purposes aligned with our role as a financial advisory and mutual fund distributor:
Facilitating centralized KYC verification with SEBI-registered KRAs (CVL, KFintech, CAMS, NDML, DotEx) and CKYCR as legally mandated.
Transmitting transaction requests, SIP registrations, and switch/redemption instructions to Asset Management Companies (AMCs) and RTAs.
Generating comprehensive valuation reports, asset allocation overviews, capital gain statements, and performance insights for client review.
Maintaining audit trails, compliance registries, and transaction histories required under SEBI guidelines, PMLA mandates, and tax laws.
We may periodically send communications regarding your investments, transaction status, or market updates to your registered email or phone. You may opt out of non-transactional informational updates at any time by contacting us.
4. DATA SHARING & STATUTORY DISCLOSURES
Your information is disclosed strictly on a need-to-know basis to authorized entities within the Indian financial infrastructure to fulfill your investment requests:
- Asset Management Companies (AMCs) & Mutual Fund Houses: To establish your investor folios and process unit allotments.
- Registrar and Transfer Agents (RTAs): CAMS, KFintech, and Franklin Templeton RTA for investor records maintenance and corporate actions.
- Transaction & Order Routing Platforms: BSE StAR MF, NSE NMF II, and MF Central for secure execution and banking reconciliation.
- Banking & Payment Gateways: Scheduled commercial banks, NPCI (for NACH / UPI mandates), and authorized payment aggregators (e.g., Razorpay) to process direct account debits and refunds.
- KYC Registration Agencies (KRAs): To verify and validate identity documents as mandated under SEBI KRA Regulations.
- Statutory, Regulatory & Judicial Bodies: We may be legally compelled to disclose your information to Government agencies, Courts, Judicial forums, the Securities and Exchange Board of India (SEBI), Reserve Bank of India (RBI), Income Tax Department, or the Financial Intelligence Unit (FIU-IND) under the requirements of any binding law.
5. DATA SECURITY & TECHNICAL SAFEGUARDS
As a financial services provider trusted with client wealth, we recognize the paramount importance of cybersecurity. We have implemented rigorous physical, electronic, and managerial safeguards in accordance with the IT SPDI Rules, 2011 and industry benchmarks:
6. HYPERLINK POLICY & THIRD-PARTY WEBSITES
Our platform may contain hyperlinks to external internet sites (such as mutual fund AMC portals, SEBI, AMFI, or payment gateways) for your convenience and transaction fulfillment. Any hyperlink to external sites is accessed at your own risk. The contents, opinions, and security measures of such external websites are not verified, monitored, or endorsed by Golden Bag Capital Services in any manner.
Once you leave our domain, we do not have control over external websites and cannot be held responsible for the protection and privacy of information you provide while visiting such sites. You are advised to review the respective privacy statements of any third-party websites you visit.
7. DATA RETENTION & STATUTORY RECORD-KEEPING
Personal and financial information is retained only as long as necessary to achieve the business purposes for which it was gathered and to satisfy statutory retention obligations under Indian law:
- PMLA Mandate: Under the Prevention of Money Laundering Act, client identification records and transaction records must be maintained for a statutory period of at least five (5) to eight (8) years following the termination of an investment account or business relationship.
- SEBI & Tax Obligations: Transaction logs, commission statements, and dispute documentation are preserved to meet SEBI audits, Income Tax assessments, and judicial requirements.
Upon expiry of statutory retention periods and resolution of all regulatory requirements, records are securely purged or permanently anonymized.
8. YOUR RIGHTS UNDER THE DPDP ACT, 2023
Under the Digital Personal Data Protection Act, 2023, you hold recognized rights as a Data Principal regarding your personal data:
To exercise your rights, please submit a written request to our designated Grievance Officer at info@goldenbagcapital.com. We will respond within thirty (30) days as stipulated by law.
9. MINORS' PRIVACY & GUARDIAN CONSENT
In accordance with the DPDP Act, 2023 and SEBI regulations, investments made in the name of a minor can only be initiated through their natural or legal guardian. We do not knowingly track, profile, or collect personal data directly from minors without verifiable parental or guardian consent. All account statements and correspondence for minor folios are dispatched exclusively to the registered guardian.
10. GRIEVANCE REDRESSAL MECHANISM
In accordance with Rule 5(9) of the IT SPDI Rules, 2011 and Section 13 of the Digital Personal Data Protection Act, 2023, Golden Bag Capital Services has designated an official Grievance Officer to address any data protection concerns, discrepancies, or queries:
Designated Grievance Officer
Data Protection & Investor Grievance Cell
11. REGULATORY DISCLOSURES & RISK FACTORS
Risk Factors: Investments in Mutual Funds are subject to Market Risks. Read all scheme related documents carefully before investing. Mutual Fund Schemes do not assure or guarantee any returns. Past performances of any Mutual Fund Scheme may or may not be sustained in the future. There is no guarantee that the investment objective of any suggested scheme shall be achieved.
Regular Plans & Commission Disclosure: We deal in Regular Plans only for Mutual Fund Schemes and earn a Trailing Commission on client investments. Disclosure for Commission earnings is made to clients at the time of investments. The option of a Direct Plan for every Mutual Fund Scheme is available to investors, offering the advantage of a lower expense ratio. We are not entitled to earn any commission on Direct plans; hence, we do not deal in Direct Plans.
Golden Bag Capital Services reserves the right to update this Privacy Policy from time to time to reflect enhancements in technology, business practices, or statutory revisions under the DPDP Act. The revised policy will always be published on this page with an updated effective date.