Legal · for businesses
Partner Terms
Draft of 11 August 2026 · An effective date will be set when these terms are executed in final
form.
They govern use of FinLens by a business. They are not the terms your customer
agrees to.
The agreement between Value Garage Private Limited and the business that integrates FinLens: what we deliver and how long you have to collect it, the Google restrictions that travel with the documents into your systems, what you become responsible for the moment they arrive, and what happens when either of us stops.
- Which document this is
- What FinLens delivers, and when
- Google Limited Use, flowed down to you
- Your data-protection obligations
- What you represent on every session
- Credentials
- Prohibited uses
- The pull window is the retention window
- What we do not promise
- Suspension & termination
- Confidentiality & intellectual property
- Commercial terms
- Limitation of liability
- Indemnity
- Governing law & jurisdiction
- Changes to these terms
- Contact
1. Which document this is
FinLens is a product of Value Garage Private Limited (CIN U66190DL2025PTC453505), a company incorporated in India with its registered office at Flat no. 26, Vandana Apartment, East Delhi, Delhi — 110092 ("FinLens", "we", "us"). These terms are an agreement between us and the business that integrates FinLens ("you", "the client"). "You" here is a company, never a consumer.
There are two agreements. Confusing them is the mistake this section exists to prevent.
This page governs your integration: the API, the credentials, the documents we hand you and what you may do with them.
Terms of Service is a different document with a different counterparty — the individual whose mailbox is read. Google links to it from its own consent screen, and your customer accepts it by continuing through the FinLens connection flow. It says at §14 that it is not the agreement a business integrates under, and points here.
Neither document gives the other's counterparty a right under it. Your customer is not a party to this page and cannot enforce it. You are not a party to Terms of Service and acquire nothing under it. Where the two describe the same mechanism — the three-hour window, what we cannot recall — they are written to agree. If they ever do not, tell us rather than choosing the reading you prefer.
Our Privacy Policy describes what we do with your customer's data and is what they read. It is not a data-protection agreement between you and us; see §4 for what is and is not in place there.
These terms take effect when the first credential is issued to you, or when you first call the API, whichever is earlier. A written order form or agreement signed by both parties prevails over this page where the two conflict — but nothing in an order form waives §3, because those obligations are not ours to waive.
2. What FinLens delivers, and when
FinLens collects financial documents from your customer's Gmail, with their permission, and hands them to you. In order:
- You create a session — POST /v1/sessions — with your own reference for the customer, the document types you need, a return URL, and exactly four identity fields: name, PAN, date of birth and mobile. Nothing else is accepted. You receive a link.
- Your customer opens it and grants Google gmail.readonly access on Google's own screen. Declining ends the session.
- They then see a FinLens page that names you by your registered name, lists the document types you asked for, and states how far back we will look. Nothing is fetched until they approve it.
- We fetch PDF attachments from registered financial senders only, after checking each message authenticates as genuinely coming from the institution it claims. 18 months by default, unbounded for institutions you named at intake and for insurers.
- We attempt to open protected documents using the identity you supplied, extract text in our own containers with no person reading it, and make the results available to you.
- Your registered webhook endpoint is notified. You then pull from GET /v1/sessions/:id/documents.
Each document reaches you either as extracted — the original PDF plus machine-read JSON — or as delivered_unparsed, the original PDF with a specific reason naming the identifier that would have opened it. A document we could not open is still a document you asked for, so it ships either way. The interface is described in full in the integration documentation, which is part of these terms to the extent it describes behaviour, and is not a promise of future behaviour.
The webhook notifies; it does not deliver. A webhook outage costs you nothing, because the artifacts are still there to pull — but the window in §8 runs from the moment they exist, not from the moment you were told.
Your registered name is load-bearing and is not correctable. The name you give us at onboarding is the string your customer reads in the sentence asking them to hand over their Gmail, so it must be your registered name exactly as it appears on the contract. There is no rename path anywhere in the platform. Getting it wrong means being provisioned again as a new client and abandoning the old one, including its credential.
3. Google Limited Use, flowed down to you
Document content genuinely reaches you, so Google's restrictions travel with it. Most vendors in this space hand over a derived signal, and can argue about where Google's policy stops. We cannot. You receive the PDF your customer received, and the data read out of it. That content is information obtained from Google APIs, and it does not stop being that when it lands in your systems.
So this clause is not a formality. Our access to Gmail exists under the Google API Services User Data Policy and its Limited Use requirements. What you do with the documents is conduct Google holds us answerable for. That is why a breach of this clause is treated more severely than any other obligation on this page.
Everything in §3 applies to every document and every extracted field we deliver to you, and to anything you derive from either.
3.1 The one use you are permitted
You may use what we deliver to provide and improve the user-facing feature your customer approved on the FinLens consent page — the purpose they were shown, by name. Not a different purpose you form later. Not a purpose you would have to explain to them afterwards. That single sentence is the whole of the permission; §3.2 is what falls outside it.
3.2 What you must not do
- Do not transfer the documents onward. Four exceptions, and no others: where a transfer is necessary to provide or improve that same approved feature; for security purposes; to comply with applicable law; or as part of a merger or acquisition, after your customer has been notified and has consented. Anyone who receives documents under one of those exceptions is bound by this clause exactly as you are.
- Do not use them for advertising. That includes personalised, retargeted, interest-based and look-alike advertising. It also includes building, selling, licensing or sharing an audience segment, a profile or a dataset about an individual.
- Do not sell them.
- Do not let a person read them, except where your customer has affirmatively agreed to that specific access, where it is necessary for security, abuse investigation or legal compliance, or where the law requires it. Where a person does read one under an exception, record why.
- Do not train models on them. You will not use them to develop, train, fine-tune, evaluate or improve any generalised or non-personalised artificial-intelligence or machine-learning model, and you will not supply them to a third party that would.
- Do not re-identify, enrich or combine them with other sources for a purpose your customer was never told about.
3.3 Three things this clause does not bend to
Consent does not waive it
These are obligations we owe Google, not protections we hold for the individual. No consent you collect from your customer releases you from any of them.
It flows down
It binds your affiliates, agents, contractors and sub-processors. You are responsible for what they do with the documents as if you had done it yourself.
It survives termination
It applies for as long as you hold anything we delivered, or anything derived from it — after this agreement ends, and whichever party ended it.
3.4 What a breach costs
A breach of this clause is a material breach, and we may suspend you immediately on discovering one (§10) rather than after a cure period. That looks disproportionate and is deliberate: a Limited Use breach by one client is a risk to the Google verification the whole platform runs on, and therefore to every other client's customers.
You will cooperate promptly with any Google enquiry, assessment or audit that touches data we delivered to you, and give us the information we reasonably need to answer one.
4. Your data-protection obligations
This clause is where every data-protection duty between us is written down. Nothing about data-protection roles or duties is threaded through the rest of the page.
4.1 Who is what
FinLens takes your customer's permission directly. We decide how the mailbox is queried, what is extracted, and how long anything is kept, and we ask the individual for that permission on our own page. So we act as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("the Act") for the collection — not as a processor acting on your documented instructions.
When the documents reach you, you determine the purpose and the means of everything that happens next. You are a separate Data Fiduciary in respect of it. Your duties attach at that moment and they are yours alone. Ours describe what we do and stop at delivery.
4.2 What that makes you responsible for
- Notice. Tell your customer what you do with the documents, and keep that accurate.
- A lawful basis for your own processing, which you also represent to us on every session (§5).
- Purpose limitation, accuracy and reasonable security safeguards over your copy.
- Your own retention rules, and erasure when your purpose is served or consent is withdrawn.
- Responding to requests from the individual about your copy, and publishing a grievance route they can reach.
- Breach notification. A personal data breach affecting your copy is notified to the Board and to the affected individuals by you, as the Act requires of you.
- Your own privacy policy, published and maintained — covering what you do with the documents and extracted data we deliver, how long you keep them, and how an individual reaches you about them. It must be accurate and it must be reachable by your customer. You may not present ours as covering your handling, and you may not tell a customer that FinLens's retention answers a question about your copy.
4.3 What neither of us can undo
We cannot recall a delivered document, and neither can your customer through us. Our copy is destroyed within three hours regardless; yours is not affected by that. Where an individual asks us to erase what we hold after delivery, we destroy our copy, tell them plainly that you hold one, and point them at you. You must not obstruct or discourage a withdrawal or an erasure request, and you must act on one under your own policy.
There is no separate notification channel for this. What you see is the session's terminal state (integration docs §7) — a declined or stopped request reads as one. A client that treats a terminal state as a transient failure and mints a new session is asking a person who declined to decline again.
4.4 What is not in place, said rather than implied
There is no data processing agreement attached to this page, and none is being claimed. "We process only on your documented instructions" does not describe this architecture and would be the wrong instrument. The precise characterisation of each party under the Act, and whether what is required between us is a data-sharing agreement, a processing agreement or neither, are [counsel to confirm]. The reading above follows the architecture and is recorded as a legal conclusion nobody has yet signed off.
We publish no sub-processor register today, because the only sub-processor we anticipate is cloud infrastructure and nothing is provisioned yet. Trust page §12 records that, and the commitment to publish a register before any partner goes live. No document reaches a third party: extraction runs in our own containers.
5. What you represent on every session
We rely on you for the things only you can know. On each session you create, you represent and undertake that:
- The person is your customer and has asked you for this. A session exists because a real individual is in a real dealing with you and needs to give you documents. You do not create one speculatively, on a prospect who has not asked, or on anyone else's behalf.
- You hold your own lawful basis for collecting and processing what we deliver, independent of the permission your customer gives us (§4).
- You have established who they are, and that they are 18 or older. There is no age check anywhere in the connection flow, and we would rather say so than let you assume one — Terms of Service §4 says the same to the individual. We rely on your onboarding.
- The identity you send is accurate. The four fields are your assertion. We do not verify them against any authority; we use them to build the scan and to derive document passwords.
- The return URL is one you control, and the registered name is truly yours.
6. Credentials
Access to the API is a key id and an API secret, issued to you by an operator. There is no self-serve signup and no way to mint your own.
The API secret is displayed exactly once, at the moment it is created, and is not recoverable afterwards. Not by re-running the provisioning command, not from the database, not from a log, and not by us. What we store is ciphertext sealed under the deployment's key-management service and bound to the key's own id — the property that makes a stolen database insufficient to forge requests as you.
If it is lost, the credential is revoked and another is issued. That is the whole of the recovery procedure, and it is not a limitation we can lift on request.
Your obligations, and ours:
- You hold the secret. Store it as you would a production database password. Do not embed it in a mobile or browser client, do not commit it, do not send it over a channel you would not send a password over, and do not share it with a third party or let another business create sessions under it.
- Everything done with your credential is attributed to you, and is your act for the purposes of these terms.
- Rotation is yours to request. Ask us, and we issue a second credential and show it once. Your existing one keeps working, so you cut over on your own clock. We revoke the old one only when you confirm you have cut over. Nothing expires it on its own, so an unfinished rotation leaves two live credentials until somebody finishes it — tell us when you are done.
- Tell us immediately if a credential is exposed or you suspect it is. We may revoke a credential without notice where we reasonably believe it is compromised.
- Your webhook signing secret is handed over on the same terms — once, in the response to POST /v1/webhooks, which you call yourself. It is not recoverable either; losing it means rotating the endpoint.
- Revocation and suspension are two different levers. Revoking a credential disables that credential. Suspension acts on you as a client and leaves your credentials untouched (§10).
You sign every request; the scheme is in integration docs §4. Clock skew beyond ±5 minutes is rejected, so run NTP. Every authentication failure returns the same 401 with the same message, deliberately — quote the request id to us and you will get a real answer.
7. Prohibited uses
In addition to §3, which stands on its own, you must not:
- create a session in respect of a person who has not asked you for the service it delivers, or for a mailbox you do not believe belongs to that person;
- disclose a delivered document, or extracted data from one, to any party other than the individual it concerns and those permitted under §3;
- resell, syndicate or otherwise make the FinLens service available to another business, whether as a reseller, a white label or an intermediary, without a written agreement with us that says so;
- attempt to reach another client's sessions, documents or webhooks, or to establish whether a given session id exists on another client's account;
- probe, scan, overload or interfere with the service, or circumvent a security control, rate limit or the window in §8;
- present a delivered document or extracted field as verified, certified, attested or assessed by FinLens. We authenticate the message that carried a document. We do not certify the document's contents, and we produce no score, rating or opinion about any individual;
- state or imply that FinLens has evaluated your customer, or attribute a decision of yours to us;
- use the FinLens or Value Garage names, marks or design in your product, marketing or documentation without our written permission.
Security researchers acting in good faith within the scope on our trust page are not caught by the interference bullet. Write to security@finlenstech.com first, and never test against a real person's mailbox.
8. The pull window is the retention window
Derived artifacts — the PDF and its extracted JSON — exist for at most three hours from the scan, encrypted at rest, and are then hard-deleted. Source email content is never stored at all.
There is no archive, no re-fetch, no re-delivery and no way to extend the window. After it closes, the mailbox grant is destroyed too, so the same documents cannot be produced again without a fresh consent from your customer — which costs them an interaction they should not have had to repeat. A nightly batch job built against this API will find nothing.
What follows from that, contractually rather than as advice:
- Collection is your responsibility. Pull on notification, or poll and pull promptly. artifactsExpireAt and each document's expiresAt are the deadline, and the session.ready event carries the deadline with it.
- A document you pulled and then lost is not recoverable from us. Once the window closes there is nothing to serve. After it, the session reports purged rather than 404, so you can tell "your three hours are up" from "you have the wrong id".
- Your retention is your decision and your obligation. The three hours is a fact about our systems and says nothing about how long you keep your copy. That is governed by §4, your own policy and your own regulator.
- We have no ability to recall, retrieve, alter or delete a document once it has left us. This is not a limitation we chose to impose. It is what handing something over means.
Whether a fresh session made necessary by a missed window is chargeable is a commercial question and is §12.
9. What we do not promise
The service is provided as is. The disclaimers below are specific rather than boilerplate, because each one is something you would otherwise discover in a trial:
- No service level, no uptime commitment, no completion-time commitment and no support commitment. None exists, in this agreement or anywhere else, and nothing on this site creates one by implication.
- No security certification. No CASA, ISO 27001 or SOC 2, and no third-party penetration test. Trust page §11 records that, and §14 tabulates every control a security page is commonly expected to assert that is not true here yet.
- No sandbox, no test mode and no fixture data.
- No guarantee that a document exists, is found, or can be opened. We read only PDF attachments from registered senders whose messages authenticate. Where a statement's password is keyed to a customer ID, a card number or a policy number, no combination of the four identity fields will produce it, and those arrive unopened with the reason named.
- The sender registry is only partly verified — 11 of 187 entries, with the rest emitting no queries at all — so a live scan today can complete correctly and return nothing. We would rather you read that here than find it in a pilot.
- Extraction is machine-read and can be wrong. Where the extracted data and the PDF disagree, the PDF governs; we deliver both so the original is always available to check against. It is not analysis, scoring or opinion, and no person at FinLens reads it.
- Gmail only. No other mailbox provider is supported.
- Field names and shapes can still change before the first production integration. After that, a change becomes a coordinated breaking change across two companies and will be handled as one.
To the fullest extent permitted by law we exclude implied warranties of merchantability, fitness for a particular purpose and non-infringement. What we do warrant is that we will provide the service with reasonable skill and care.
10. Suspension & termination
We can suspend a client, and it is a mechanism rather than a sentence in an agreement. The gateway reads your client record on every authenticated request and caches nothing, so a suspension takes effect on your next call: it is refused with client_suspended (403). No new FinLens consent page will name you.
It is not revocation. The credentials you hold are untouched, and reinstating you needs no key material and no change on your side. Two honest properties: scans already in flight finish, and documents already produced remain pullable until their three-hour deadline. Suspension stops new work, not work that is already your customer's.
We may suspend you where we reasonably believe there has been a material breach of these terms — immediately and without a cure period in the case of §3 or §7 — where a credential of yours is or may be compromised, where we are required to by law or by Google, where continued provision would put end users at risk, or for non-payment once commercial terms exist and remain unpaid after notice. We will tell you why, at the address you gave us.
You may stop at any time by ceasing to create sessions. There is nothing to cancel and no minimum commitment on this page.
Either party may terminate on notice of [counsel to confirm], or immediately for a material breach not cured within [counsel to confirm] of written notice. Both periods are figures a lawyer sets against the commercial arrangement, and neither has been invented here.
There is nothing for us to return or delete at termination, and that is a property of the design rather than a concession. Derived artifacts are gone within three hours of the scan that produced them, and source email content was never stored. What survives is an append-only ledger and audit log recording that acts happened — not document content. Your credentials are revoked.
What you hold is unaffected by termination. It stays governed by §3, §4 and your own policy, for as long as you hold it.
Sections 3, 4, 7, 8, 11, 13, 14, 15 and this sentence survive termination.
Two operator acts do not exist anywhere in the platform, and you should plan around their absence: there is no rename and no de-provision. A client whose registered name is wrong is provisioned again as a new client. A client that leaves is suspended and has its credentials revoked rather than deleted, because a delete would cascade to that client's sessions and grants and there is a ledger reason not to do that.
11. Confidentiality & intellectual property
Credentials are confidential without qualification: your API secret, your webhook signing secret and your key id. Beyond those, each party protects the other's confidential information with at least reasonable care, uses it only to perform this agreement, and returns or destroys it on termination — excluding information that is public, independently developed, or lawfully obtained elsewhere.
Ours stays ours. The FinLens platform, the API and its contracts, the sender registry, the extraction templates, the connection flow, this website and the FinLens and Value Garage names and marks are our property or licensed to us. You are granted a non-exclusive, non-transferable right to use the service for its purpose during the term, and nothing more. No licence is granted by implication.
Your customer's documents are your customer's. Neither of us acquires ownership of them. We acquire no rights beyond collecting, opening, reading and delivering them for the one request they approved, and we do not keep them. You acquire what your own agreement with your customer gives you, and no more than that.
12. Commercial terms
Fees are agreed per client, in writing, during onboarding. There is no published price list and nothing on our site is an offer or a quotation. The unit of pricing, the rate, the currency, the treatment of taxes including GST, invoicing frequency and payment terms are all [to be confirmed] and belong in the executed order form rather than on this page.
One thing you are entitled to know before you rely on any of it: the platform contains no billing system. Nothing meters, counts or invoices. There is no per-client tally of sessions or delivered documents anywhere in it. Any usage-based charge therefore has no system of record behind it today, and would be reconciled by hand until one exists.
We would rather write that down than let an order form imply a counter that is not there. The pricing page says the same thing at greater length and puts a marker against every figure.
We do not charge your customer anything. The commercial relationship is with you. Terms of Service §1 tells them so directly, and nothing agreed between us may contradict it — you may not present a FinLens fee to the individual whose mailbox is read.
Sections 13, 14 and 15 are incomplete on purpose, as are the two periods in §10, the characterisation in §4 and the notice period in §16. They are the points a lawyer must settle rather than a draftsman, and they appear here so the page is whole rather than silently short. Each is marked [counsel to confirm] rather than invented.
Only some are figures. §13 needs a cap — and note that the conventional formula, a multiple of fees paid in the preceding twelve months, is not computable here: nothing has been billed, and §12 explains why there is no system that could compute it. §14 is a judgement about scope and mutuality, and §4 is a legal characterisation with no number in it at all. Nothing on this page is legal advice, and a placeholder is not a term you are agreeing to.
13. Limitation of liability
To the extent permitted by law, and subject to the paragraph at the end of this section:
- Neither party is liable for indirect, incidental, special or consequential loss, or for loss of profit, revenue, business, goodwill or anticipated savings.
- We are not liable for a document that could not be found, opened or read (§9), for an error in machine-read data where the source PDF was delivered alongside it, or for a document you did not collect inside the window (§8).
- We are not liable for what you do with documents after they are delivered to you, for decisions you take on them, or for your handling, retention or disclosure of them.
- Our total aggregate liability to you, for all claims arising out of or relating to these terms, is limited to [counsel to confirm]. A figure has not been chosen, and the usual fees-based formula does not yet resolve to a number (§12).
- Whether your breach of §3 or §7 sits outside that cap is [counsel to confirm]. It is the position most worth taking deliberately on this page, because the harm a Limited Use breach causes is to our standing with Google rather than to a sum of money we can point at.
Nothing in these terms limits or excludes any liability that cannot be limited or excluded under Indian law — including liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, and any liability arising under the Digital Personal Data Protection Act, 2023.
14. Indemnity
You agree to indemnify us against claims, losses and reasonable costs arising from your breach of §3, §5 or §7 — in particular from a session created in respect of a person who did not ask for it, and from a use of delivered data that Google's Limited Use requirements do not permit.
The precise scope of this indemnity, whether it is mutual, whether it is capped and where it sits against §13, are [counsel to confirm]. So is one specific question worth naming rather than burying: whether the indemnity should reach a suspension, restriction or termination of our Google project caused by your conduct — a harm that is real, foreseeable and not naturally expressed as a fee multiple, and which [counsel to confirm]. Nothing here extends to anything arising from our own breach, negligence or unlawful act.
15. Governing law & jurisdiction
These terms are governed by the laws of India.
The forum is [counsel to confirm]: whether disputes go to the courts at Delhi, as Terms of Service §15 provides for the individual, or to arbitration, and if arbitration then the seat, the rules and the number of arbitrators. We have not named a venue or a forum, because we will not put one in front of you before counsel has advised that it is appropriate and enforceable.
If you have a complaint, raise it with us first (§17).
16. Changes to these terms
We may update these terms. Any revised version is posted on this page with a new date, and the version in force when a session is created governs that session — we do not apply a later version to something already delivered.
Material changes are notified to you in advance, at the address you gave us. The length of that notice period is [counsel to confirm]. A change to §3 required by a change in Google's own policy may have to take effect on Google's timetable rather than ours, and that possibility is part of what counsel is being asked to settle.
The text your customer is shown on the consent page is versioned separately. A change to what they are being asked to agree to always produces a new approval request — never a silent widening of one already given.
17. Contact
Partnerships and this agreement · partners@finlenstech.com
Integration and API access · developers@finlenstech.com
Security reports · security@finlenstech.com
Privacy questions · privacy@finlenstech.com
Grievance officer (DPDP) · Suraj Agarwalla
— suraj@maximoney.in
Value Garage Private Limited · CIN U66190DL2025PTC453505
Registered office: Flat no. 26, Vandana Apartment, East Delhi, Delhi, India — 110092
Before you integrate, read the integration documentation for what the API does and does not do, the trust page for what is built and what is not, the Privacy Policy your customers will read, and pricing for how a commercial conversation actually starts.