Referral Feedback in Dhan App

There’s a privacy issue in the app which i would like to report.

When we tap on share referral code button, it asks for contacts permission & when we deny it doesnt let us share the link through any channel.

I understand contacts permission is required when Dhan wants to auto detect which contacts are already onboarded and which are left to onboard like it happens in Cred.

But if i just want to share the link to somebody on whatsapp, it doesnt make any sense to make the contacts permission mandatory. You can keep it recommendatory in nature when a user wants suggestion on which contact to send the link. But if i dont want your suggestion, then sharing the link on my own should be allowed without mandatory contacts permission.

There are many many many apps which allow the sharing of link , documents, etc without the need of contact permission.

I see it as a privacy issue & you all should do too.

2 Likes

Hi @krishag,

If you want to share the link, we’ve given the option to copy it easily by clicking on the “copy” button, you can refer the screenshot below.

1 Like

Hi @Champion_Trader,

We use multiple checks (sessions data, device binding etc) to understand the need of biometric on your device. Get in touch with us at help@dhan.co and we’ll be happy to assist you.

1 Like

Sir, copying the referal link and sending involves multiple clicks which has no sense.
Also, when click on refer & earn on the hamburger menu , it asks us for contact permission & if we deny then it will take us back.

Only if we visit the refer & earn section from inside the profile section, then it will allow us to copy the link.

if you can enable sharing the link directly from the app without contact permission it would be great. & you know thats very much possible.

Also, my question would be why do you need contacts permission? you dont process the contacts & give suggestion on which contact is not on dhan then whats the need of contacts permission ? why do u need this data ???

1 Like

Yes @Champion_Trader I agree with you.

If dhan uses Algorith to find out whether biometric is required or not then it should give us an option to use algorithm or every time biometric login as per our convenience.

If i am not wrong, there is a mandatory requirement by sebi as well to do 2FA & thats why you will see it mandatory under every broker.

even on indmoney, if you just open the app it won’t ask for biometric but if you want to access the stocks/mf section, then biometric is must.

i think that option to use biometric permanently or to use algo of dhan should be in the hands of the user.

and yes contact permission on refer & earn still seems unnecessary.

1 Like

Hi @Champion_Trader As long as the current session is valid and authenticated, the app will work. The moment it is invalidated, you will be asked to re-authenticate it.

Security of financial apps is important, we do all measures possible to ensure things are done right - you will be suprised to know how many requests we have got asking us to keep login with OTP only and we have struggled to communicate that these processes work as per regulations defined and not feedback we get.

1 Like

Well @krishag you do have option of sharing referral link without giving contacts permission - it is completely upto the user. And we continue to give referral credit to user even if the user has given contacts permission or not. It works both ways, for both set of users.

Yes, for authetication I have referred to in other response.

1 Like

sir you mentioned that when session is invalidated then we have to reauthenticate.

Does reauthenticate mean we have to use biometric login when invalidated ? or we have to login afresh ?

Also, when does a session is considered as invalidated ? when not used for 24 hrs ? or when ?

1 Like

But @PravinJ , you did not answer as to why contacts permission is asked in the first place ? What is the need ?

If we are sharing a file on whatsapp, messaging, etc , contacts permission is not mandatory if we talk abt any other app any category.

Then why contact permission is being made mandatory ? pls answer this.

1 Like

hi @krishag with contacts you will see who among your contacts is on Dhan and who is not. So you can refer only those who are not - it is a simple use-case.

2 Likes

Q1. when do u term a login session as invalidated ?

Q2. What happens when a login is invalidated ? login afresh or biometric authentication

1 Like

@Champion_Trader yes chief, it is about perspectives here. If I kept my laptop at home open, and let’s say my child comes and sends a message to my team at Dhan - I am declaring bonus to all of them, whom should I held responsible… :slight_smile: There are always going to be edge cases.

ps: my child does come by and plays videos on my laptop :slight_smile:

1 Like

Hi @krishag

Q1: Something proprietary to us. Can’t disclose. It’s like asking how do we processed our orders faster.
Q2: If it is partially invalidated and requires reauth - then by biometric (if you have set it) or fresh login if session is completely invalidated.

2 Likes

Agreed sir, but you can always give an option to the user if he wants biometric login each time the app is opened. This way the user can act on his requirement rather than depending on the perspective of anybody.

Making this thread private as it more like a conversation v/s a standalone post.

1 Like

ok but pls include an OPTION for compulsory biometric. Both set of users will be happy.

Thanks

1 Like

I dont think they will agree to this. Only the users feel the importance. In the interim, pls use phone’s app lock feature. There in almost all the models.

1 Like

We keep re-evaluating all our opinions from time to time. Dhan is built based on all feedback and suggestions we have got :slight_smile:

1 Like

@Champion_Trader One more use case is say i am sitting with my friends and they have my phone for playing music, then he can view my investments.

I trust that person that he wont place any transaction bcz i would only give my phone to somebody whom I trust. but it doesnt mean that i would like him to see my financial status. i like to keep it discreet from anybody.

1 Like