Privacy Policy

Effective Date: September 7, 2026

Caxi ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy details our data collection, processing, storage, and protection practices in strict compliance with the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

1. Scope & Data Fiduciary Role

Under the DPDP Act, 2023, Caxi acts as the Data Fiduciaryregarding personal data collected from passengers ("Riders"), independent driver partners ("Partners"), corporate clients, and visitors using our mobile applications, web portal (caxi.in), and connected services.

2. Personal Data We Collect

We collect only personal data necessary to provide safe, reliable, and legally compliant transportation and delivery aggregator services:

  • Identity & Profile Data: Full name, verified mobile number, email address, profile photograph, and corporate account affiliations.
  • Driver Partner KYC & Verification Data: Commercial driving license details, vehicle registration certificate (RC), commercial vehicle insurance, vehicle fitness and pollution (PUC) certificates, PAN, and bank account details for earnings disbursements. Driver profiles and credentials are synchronized across our verified partner registry.
  • Precise Geolocation & Telemetry Data:Real-time GPS coordinates, route waypoints, direction heading, and speed during active trips. For drivers, location data is transmitted while in the "Online" status to facilitate nearby ride matching.
  • Financial & Billing Data:Razorpay payment order identifiers, transaction ledgers, digital wallet balances, corporate billing credits, fare breakdowns, and statutory Goods & Services Tax (GST) invoice records. We do not store raw debit/credit card numbers or net banking passwords.
  • Communications & Emergency SOS Data: In-app chat messages between riders and drivers during active trips, emergency contact details, SOS distress alerts, and customer support ticket records.
  • Device & Technical Metadata: IP address, device model, operating system, and Firebase Cloud Messaging (FCM) device push notification tokens.

3. Lawful Grounds & Purpose of Processing

Under Sections 4, 6, and 7 of the DPDP Act, 2023, we process your personal data under the following lawful grounds:

  • Performance of Contract: Facilitating ride requests, real-time routing, upfront fare computation, cash collection verification, electronic receipt generation, and driver earnings settlements.
  • Safety & Emergency Telemetry: Providing live trip tracking for riders, automated driver reachability monitoring, emergency SOS dispatch to local emergency services, and courier package verification.
  • Statutory & Regulatory Obligations: Compliance with the Motor Vehicles Aggregator Guidelines, 2020, tax invoicing under the Central Goods and Services Tax (CGST) Act, 2017, and lawful court or police orders.
  • Explicit Consent: Sending non-essential promotional discounts, referral reward notifications, or optional feedback collection, which you can opt out of at any time.

4. Public Live Tracking & Privacy Shield

When you share a live trip tracking link (/track/[rideId]) with family, friends, or trusted contacts:

  • Cryptographic Capability Tokens: Access is protected by server-generated, cryptographically salted SHA-256 capability tokens.
  • PII Redaction: The public tracking interface displays vehicle category, live GPS coordinate markers, and estimated arrival time. It never displays rider phone numbers, payment details, wallet balances, or rider full names to public viewers.
  • Automatic Expiration: Public tracking tokens automatically expire and become invalid immediately upon trip completion or after a 24-hour safety window.

5. Data Minimization & Real-Time Overwriting

In accordance with the DPDP principle of data minimization:

  • Driver partner idle location updates in our real-time database are continuously overwritten in place. We do not retain historical breadcrumb trails of idle drivers when not on an active trip.
  • When a user or driver logs out, device push notification tokens are immediately severed and removed across all database registries to eliminate ghost notifications.

6. Data Sharing & Third-Party Disclosures

We do not sell, rent, or trade your personal data. Disclosures are strictly limited to:

  • Between Riders and Drivers:Drivers receive the rider's first name, pickup location, and destination. Riders receive the driver's verified name, photo, vehicle model, license plate number, and customer rating.
  • Authorized Service Processors: Cloud infrastructure (Google Firebase / Google Cloud hosted in India regions asia-south1 and asia-southeast1), SMS OTP providers, and RBI-regulated payment gateways (Razorpay).
  • Law Enforcement & Emergency Authorities: Verifiable legal requests, criminal investigations, or emergency SOS alerts under applicable Indian laws.

7. Your Rights under the DPDP Act, 2023

As a Data Principal, you are entitled to the following statutory rights:

  • Right to Access Information (Section 11): You may view your complete profile, ride history, transaction receipts, and stored payment methods directly in the app.
  • Right to Correction & Erasure (Section 12): You may correct inaccurate profile data at any time. You have the statutory right to request complete account deletion through the app or by writing to our Grievance Officer.
  • Right of Grievance Redressal (Section 13): You may file a complaint regarding personal data processing with our designated Grievance Officer, with an assured turnaround within 30 days.
  • Right to Nominate (Section 14): You have the right to nominate an individual who, in the event of death or incapacity, shall exercise your privacy rights.

8. Account Deletion & Statutory Retention Policy

When you submit an account deletion request through the Caxi App or Web Portal:

  • Active Trip Guard: Account deletion cannot be processed while you have an ongoing active or unfulfilled trip.
  • Complete PII & Storage Purge: Your authentication identity, personal profile, device tokens, KYC identity documents, driver licenses, and private uploads across all database collections and Cloud Storage buckets are permanently and irreversibly deleted.
  • Statutory Tax Ledger Exception (CGST Act, 2017 & DPDP Act Sec 8(8)): In accordance with Section 36 of the Central Goods and Services Tax Act, 2017, completed financial transaction ledgers and B2B/B2C GST tax invoices are retained for the mandatory statutory period of six (6) years. During this retention period, all personal identifiers (names, photos, phone numbers) are permanently stripped and redacted, retaining only anonymized fiscal records for tax audit compliance.

9. Children's Privacy (Section 9 Compliance)

The Caxi platform is strictly intended for individuals aged eighteen (18) and above. We do not knowingly collect, process, or track personal data belonging to minors. If we discover that personal data of an individual under 18 has been collected without verifiable parental consent, we will promptly delete such data.

10. Information Security & Encryption

We employ multi-layer security measures including AES-256 encryption for data at rest, TLS 1.3 encryption for data in transit, token-bucket IP/UID rate-limiting to defend against unauthorized automated extraction, and strict role-based access controls limiting database administration solely to vetted security personnel.

11. Grievance Officer & Regulatory Escalation

In accordance with the Information Technology Act, 2000 and Section 13 of the DPDP Act, 2023, the details of our designated Data Protection Grievance Officer are:

Name: Asif Iqbal
Designation: Grievance Redressal & Data Protection Officer
Email: support@caxi.in
Registered Address: Caxi Technologies, Sector 12F, Bokaro Steel City, Jharkhand, India - 827012
Hours:Monday – Friday, 9:00 AM – 6:00 PM IST

If your grievance is not resolved satisfactorily within thirty (30) days, you have the statutory right under Section 13(3) of the DPDP Act to file a complaint before the Data Protection Board of India.