Gudsle · Legal
Privacy Policy
How RIZQOM PRIVATE LIMITED ("Gudsle") collects, uses, shares, and protects your personal data.
Last updated: 24 July 2026
1. Data we collect
- Identity & account: name, mobile number, email, password (hashed), PAN and GSTIN (where provided), billing address, and referral information.
- Sensitive personal & KYC data: for Transporters and Drivers — Aadhaar number, PAN, GSTIN, driving licence, and uploaded copies of these documents; vehicle registration, insurance, fitness, and permit documents.
- Financial data: bank account number, IFSC, account-holder name, UPI ID, and payment-gateway payout-account identifiers.
- Location data: saved, pickup, and drop addresses with coordinates; a Driver’s live location during an active trip; and delivery-geofence data.
- Shipment & delivery evidence: lorry receipts, consignor/consignee name, phone, and GSTIN, goods value and weight, e-way bill numbers, POD photos, signatures, geotags and OTP logs, dispute evidence, expense receipts, and invoices.
- Transaction data: Razorpay order, payment, and refund identifiers and bank UTRs.
- Security & device data: OTPs, trusted-device tokens, user-agent strings, and IP addresses captured in login and admin audit logs.
- Behavioural data: ratings, reviews, reliability scores, notification preferences, and activity logs.
- Consignee data: a consignee’s name and phone number are provided to us by the Shipper solely to complete delivery.
We do not use advertising, analytics, or third-party tracking SDKs. We use only essential, first-party cookies (see “Cookies” below).
2. How we collect it & why (purpose and lawful basis)
We collect data directly from you, automatically as you use the Platform (for example a Driver’s location during a trip), and from Transporters about their consignees. We process it to:
- perform the transport-booking contract — matching, bookings, tracking, POD, and payouts;
- meet legal obligations — GST invoicing, TCS, TDS, and e-way bill records;
- verify identity and prevent fraud (with your consent for KYC and location); and
- operate, secure, and improve the Platform.
3. Sharing & sub-processors
We share personal data only as needed to run the service, with the following categories of recipients:
- other users to the extent needed to complete a booking (e.g. a Shipper’s consignment details with the accepting Transporter and Driver);
- the sub-processors listed below; and
- government, regulatory, or law-enforcement authorities where required by law.
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Razorpay (payment gateway) | Payments, subscriptions, refunds, and transporter payout onboarding (KYC) | Payment and order details; for payouts: business name, PAN, GST, email, phone, contact name, registered address, bank account, IFSC, and beneficiary name |
| Maps & location provider | Address autocomplete, geocoding, and routing | Typed address queries and location coordinates |
| SMS provider | OTP and transactional SMS | Mobile number and OTP code |
| Email provider | Transactional email | Email address, name, phone, and message content |
| Cloud hosting & storage (Mumbai region, India) | Private document/photo storage and application hosting | All uploaded KYC, vehicle, POD, expense, and dispute files, and the application database |
| Error-monitoring service | Diagnostics (only when enabled) | Exceptions, stack traces, and request path/method (no session replay) |
| Push-notification service (Android) | Push notifications | Push message payloads |
4. Aadhaar — data minimisation
We collect Aadhaar details solely to verify the identity of Transporters and Drivers for KYC. Once a KYC submission is approved, we delete the full Aadhaar number and the uploaded Aadhaar document, and retain only the last four digits and the verification status. We do not use Aadhaar for any other purpose.
5. Cookies
We use only essential, first-party cookies that are necessary to sign you in and to keep your session and account secure (authentication and security tokens). We do not use advertising, analytics, or tracking cookies.
6. How we protect your data
We apply reasonable security practices under the SPDI Rules, including HTTPS/TLS in transit, httpOnly authentication cookies, hashed passwords and device tokens, private object storage served only through authenticated, short-lived links with per-owner access checks, and encrypted local storage in the mobile app. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.
7. Your rights
Subject to the DPDP Act, you may request to access, correct, or erase your personal data, withdraw consent, or nominate another person to exercise your rights. To make a request:
- use our Data Request form, which reaches our team at support@gudsle.com; or
- email our Grievance Officer at support@gudsle.com.
We will verify and action valid requests. Note that we may need to retain certain data to meet legal obligations (for example, tax and invoicing records) or where an active booking is in progress.
8. Retention
We retain personal data for as long as necessary to provide the service and to meet legal, tax, and accounting obligations, after which it is deleted or anonymised. A detailed, category-wise retention schedule is being finalised and will be published here — coming soon.
9. Children
The Platform is not intended for anyone under 18, and we do not knowingly collect data from children.
10. Cross-border transfers
Your data is primarily hosted in India (Mumbai region). Some sub-processors — such as our email, error-monitoring, and maps providers — may process limited data on servers outside India. Any such transfer is made in accordance with Section 16 of the DPDP Act and applicable law.
11. Contact & grievances
Data Fiduciary: RIZQOM PRIVATE LIMITED, Zaffran Colony, Zawan, Srinagar, Jammu and Kashmir, 191101, India. For privacy questions or grievances, contact our Grievance Officer at support@gudsle.com — see the Contact & Grievance page. We may update this policy from time to time and will post material changes here.