Legal

Privacy Policy

Last updated 1 May 2026 · Version 1.0

1. Who we are

Swyft is operated by Tanvrit Pvt. Ltd., 168 Plot No 945, Gayatri Mandir se Purab, New Ariya, Sasaram, Bihar 821115, India. We are the data fiduciary for your ride and delivery data under India's Digital Personal Data Protection Act, 2023 (DPDPA).

2. Data Protection Officer

Vivek Singh, Founder, acting as Data Protection Officer until Tanvrit appoints a separate DPO. Reach the DPO at dpo@tanvrit.com. Response within 7 days; resolution within 30 days for any data principal request under DPDPA Section 11.

3. Personal data we collect (rider)

Account: name, email, phone (used for OTP authentication and account recovery). Location: precise GPS pickup and drop-off points — collected only during a ride request and for the duration of the ride. Background location is not collected. Payment: card tokens (via Stripe / Razorpay; we never see full PANs), UPI handles, wallet balance. Ride history: every ride's pickup, drop-off, vehicle type, fare breakdown, driver assigned, ratings. Communications: any chat between you and your driver during a ride; any message to support. Device & telemetry: device ID, OS version, IP address, crash logs, performance metrics.

4. Personal data we collect (driver)

Identity (KYC): full name, date of birth, photograph, mobile, email, residential address. Government IDs: driver's licence number + image, vehicle registration certificate (RC) image, PAN, Aadhaar (last 4 digits stored hashed only; never the full number unless mandated by the regulator), bank account number, IFSC. Location: real-time GPS during shifts when "online"; not collected when offline. Earnings: every ride payout, commission deducted, tips, daily/weekly/monthly aggregates, tax deductions. Background-check artefacts (where applicable): SARTHI verification result, criminal-record verification status.

5. Lawful basis (DPDPA Section 4 + 7)

Account, auth, KYC, payment, ride history — processed under your consent at signup. Real-time location during a ride or shift — under "certain legitimate uses" (Section 7) for fulfilling the ride contract. Background checks for drivers — consent at onboarding plus regulatory requirement. Telemetry and crash logs — under legitimate use for safety and reliability.

6. Sharing and cross-border transfers

Sub-processors used: Google Cloud Run (asia-south1, Mumbai) — application server hosting; India data residency. MongoDB Atlas — system of record for accounts, rides, payments. Cloudflare — CDN and TLS termination. Google Maps Platform — geocoding, routing, and live navigation. Stripe Inc. (US) — international card payments. Razorpay (India) — UPI / NACH / domestic cards. Twilio (US, routed through Indian DLT carriers) — OTP SMS and ride notifications. Cross-border transfer disclosure under DPDPA Section 16: Stripe, Twilio, Cloudflare, and Google Maps process data in jurisdictions outside India for the specific purposes named above. We do not transfer data to any country listed by the Central Government as restricted.

7. Driver location and rider safety

Real-time driver location is shared with the rider during an active ride (so the rider can track ETA and the route). Once the ride ends, the live feed stops. We retain trip-level GPS tracks (start, key waypoints, end) for 90 days for safety investigations; older tracks are aggregated to a low-resolution polyline for fraud detection and then dropped after 12 months.

8. Data principal rights (DPDPA Section 11)

You have the right to: Access — request a copy of all data we hold about you. Email dpo@tanvrit.com from your registered email. Correction — request correction of inaccurate or outdated data. Most fields can be edited in-app; for the rest email the DPO. Erasure — request deletion of your account and personal data. Use the public form at https://swyft.tanvrit.com/account/delete or email the DPO. Grievance redressal — escalate to the Data Protection Board of India under DPDPA Section 28 if a request is not resolved within 30 days. Nominate — appoint another person to exercise your rights in case of death or incapacity (Section 14).

9. Children's data

Swyft is not intended for users under 18. We do not knowingly accept driver registrations from minors and we discourage rider accounts from being created by minors. If you believe a minor has signed up, email dpo@tanvrit.com and we will delete the account within 72 hours.

10. Security

JWT authentication with mutex-protected token refresh; AES-256-GCM field-level encryption on Aadhaar, PAN, bank account, and licence numbers; TLS 1.3 in transit via Cloudflare; role-based access controls; OTP rate limiting; audit trails on all data-mutating operations. Best-effort availability today on Google Cloud asia-south1; a public uptime SLA will ship after our launch monitoring stack is live.

11. Breach notification

In the event of a personal data breach, we will notify the Data Protection Board of India within 72 hours of detection per DPDPA Section 8(6), and notify each affected data principal of the nature of the breach, the categories of data involved, and the steps we have taken in response.

12. Retention

Account data — retained while your account is active; purged within 90 days of an erasure request. Live GPS — discarded immediately after the ride ends. Ride trajectories — 90 days at full resolution; aggregated polyline up to 12 months. KYC documents — retained for the period required by RBI / Motor Vehicles Act (typically 5 years post-last-active). Financial records (payouts, invoices) — 7 years per Indian Income Tax Act § 44AA / GST § 35(1). Auth logs — 365 days for fraud and abuse investigation.

13. Cookies and local storage

Essential: authentication tokens, anti-CSRF tokens. Optional: theme and language preferences. We do not run advertising or third-party tracking cookies.

14. Updates to this policy

We will email registered users at least 30 days before any material change to this policy.

15. Contact and grievance redressal

Data Protection Officer — dpo@tanvrit.com. Postal — Tanvrit Pvt. Ltd., 168 Plot No 945, Gayatri Mandir se Purab, New Ariya, Sasaram, Bihar 821115, India. Escalation to the Data Protection Board of India per DPDPA Section 28 if a request is not resolved within 30 days.