INTRODUCTION
1.1 Data Protection Commitment
SUGAM SURAKSHA SARTHI INDIA PRIVATE LIMITED (“Company”, “We”, “Us”) is committed to protecting your privacy and personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable data protection laws.
1.2 Scope of Policy
This Privacy Policy applies to the Drivergill mobile application and all related services. It explains how we collect, use, store, share, and protect your personal data.
1.3 Data Controller
The Company acts as the data fiduciary (controller) for personal data collected through the App/website.
DATA COLLECTION
2.1 Personal Information Collected
We collect the following categories of personal data:
Account Information:
- Name, phone number, email address
- Profile picture (optional)
- Date of birth (for age verification)
- Government ID details (for verification)
- Location Data:
- Pickup and drop-off locations
- Real-time GPS location during trips
- Approximate location for service availability
- Vehicle Information
Payment Information:
- Credit/debit card details (tokenized)
- Digital wallet information
- UPI IDs and transaction history
- Billing addresses
- Device Information:
- Device type, operating system
- App version and usage analytics
- IP address and device identifiers
- Push notification tokens
Communication Data:
- Customer support interactions
- In-app messages with drivers
- Call logs for safety purposes
2.2 Data Collection Methods
Data is collected through:
- Direct input during registration
- Automatic collection during app usage
- Third-party integrations (payment gateways, maps)
- Cookies and tracking technologies
LEGAL BASIS FOR PROCESSING
We process personal data based on:
3.1 Consent
- Marketing communications
- Location tracking (beyond service requirements)
- Optional features and services
- Data sharing with third parties for non-essential services
3.2 Contractual Necessity
- Service provision and trip facilitation
- Payment processing
- Account management
- Customer support
3.3 Legitimate Interest
- Fraud prevention and security
- Service improvement and analytics
- Safety monitoring
- Business operations
3.4 Legal Compliance
- Regulatory reporting
- Law enforcement requests
- Tax and financial compliance
- Dispute resolution
USE OF DATA
4.1 Primary Uses
Service Provision:
- Connecting passengers with drivers
- Route calculation and navigation
- Trip tracking and completion
- Payment processing
Safety and Security:
- Identity verification
- Fraud detection and prevention
- Emergency response
- Incident investigation
Customer Support:
- Query resolution
- Complaint handling
- Service improvement
- Technical support
4.2 Secondary Uses (with consent)
Marketing and Communications:
- Promotional offers and updates
- New feature announcements
- Surveys and feedback requests
- Personalized recommendations
Analytics and Improvement:4.2 Secondary Uses (with consent)
Marketing and Communications:
- Usage pattern analysis
- Service optimization
- App performance monitoring
- Business intelligence
DATA SHARING
5.1 Sharing with Drivers
- Limited data shared with assigned drivers:
- First name and phone number
- Pickup and drop-off locations
- Trip-specific information
- Rating and feedback (anonymized)
5.2 Service Providers
- Data shared with trusted third parties:
- Payment processors (for transaction processing)
- Map and navigation services
- Cloud storage providers
- Customer support platforms
- Analytics and marketing tools
5.3 Legal Authorities
- Data may be shared with:
- Law enforcement agencies (upon legal request)
- Regulatory authorities (for compliance)
- Courts and tribunals (pursuant to legal orders)
- Tax authorities (for financial compliance)
5.4 Business Transfers
In case of merger, acquisition, or business transfer, data may be transferred to the new entitywith appropriate safeguards.
5.5 No Sale of Personal Data
We do not sell, rent, or trade personal data to third parties for their marketing purposes.
DATA SECURITY
6.1 Security Measures
We implement industry-standard security measures:
Technical Safeguards:
- End-to-end encryption for sensitive data
- Secure data transmission-HTTPS/TLS
- Regular security audits and penetration testing
- Access controls and authentication
- Data anonymization and pseudonymization
Organizational Safeguards:
- Employee training on data protection
- Data processing agreements with vendors
- Privacy by design principles
- Incident response procedures
- Regular security policy updates
6.2 Data Breach Response
In case of data breaches:
Immediate containment and assessment
Notification to authorities within 72 hours
User notification for high-risk breaches Remedial measures and monitoring Regular breach response drills
DATA RETENTION
7.1 Retention Periods
Active User Data: Retained while account is active
Trip Data: 2 years (for legal and regulatory compliance)
Payment Data: As per RBI guidelines and tax requirements
Support Communications: 1 years
Marketing Consents: Until withdrawn
7.2 Deletion Procedures
Data deletion through:
- Automated deletion after retention period
- User-initiated account deletion
- Data subject erasure requests
- Secure deletion methods for all copies
7.3 Legal Retention Requirements
Some data may be retained longer for:
- Legal proceedings
- Regulatory investigations
- Tax and financial audits
- Fraud prevention
USER RIGHTS
8.1 Right to Access
Under the DPDP Act, you have the following rights: Request information about:
- Personal data we hold about you
- Purposes of processing
- Categories of recipients
- Retention periods
8.3 Right to Erasure
Request deletion of personal data when:
- No longer necessary for original purpose
- Consent is withdrawn
- Data has been unlawfully processed
- Required for legal compliance
8.4 Consent Management
- Withdraw consent at any time
- Granular consent controls
- Easy consent modification options
COOKIES AND TRACKING
9.1 Types of Cookies
Essential Cookies:
- App functionality
- Security features
- User preferences
Analytics Cookies:
- Usage statistics
- Performance monitoring
- Error tracking
Marketing Cookies:
- Personalized content
- Advertising optimization
- Cross-platform tracking
9.2 Third-Party Analytics
- We use third-party services like:
- Google Analytics (with data anonymization)
- Firebase Analytics
- Custom analytics platforms
9.3 Opt-Out Options
- Users can control tracking through:
- App settings
- Device privacy settings
- Cookie preferences
- Marketing communication preferences
INTERNATIONAL TRANSFERS
10.1 Data Localization
- In compliance with RBI requirements:
- Payment data stored within India
- Primary user data stored locally
- Copies may be transferred abroad with safeguards
10.2 Transfer Safeguards
- When data is transferred internationally:
- Adequacy decisions by Indian authorities
- Standard contractual clauses
- Corporate binding rules
- Explicit user consent
10.3 Vendor Compliance
All international vendors must:
- Provide adequate data protection
- Sign data processing agreements
- Comply with Indian data protection standards
- Enable data localization when required
CHILDREN'S PRIVACY
11.1 Age Restrictions
Our service is not intended for users under 18 years of age.
POLICY UPDATES
12.1 Amendment Process
This policy may be updated to:
- Comply with new laws and regulations
- Reflect changes in our practices
- Improve clarity and transparency
- Add new features and services
12.2 Notification of Changes
Policy updates will be communicated through:
- App notifications
- Email notifications
- Website banner notices
- Push notifications for material change
12.3 Continued Use
Continued use of the App after policy updates constitutes acceptance of the revised policy.
CONTACT AND GRIEVANCES
13.1 Data Protection Queries
For privacy-related questions: Email: support@sugamsarthi.com
13.2 Grievance Redressal
Internal Process:
- Submit complaint through app or email
- 48-hour acknowledgment
- 30-day resolution timeline
- Escalation to senior management(if required)
13.3 Response Timeline
- Query acknowledgment: Within 48 hours
- Simple queries: Resolved within 1-2 business days
- Complex investigations: Up to 30 days
Regular status updates provided This Privacy Policy is effective from September 2025 and was last updated on September 12,2025.