1. Introduction & Definitions
Effective Date: 22 July, 2026 | Version: 3.2.1
This Privacy Policy (hereinafter referred to as the "Policy") constitutes a legally binding agreement between Somnath Taxi (hereinafter referred to as "Company", "We", "Us", or "Our") and the user (hereinafter referred to as "You", "Your", or "User") of the Somnath Taxi mobile application, website, and associated booking services. This Policy is designed to be compliant with the Information Technology Act, 2000 (India), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the General Data Protection Regulation (GDPR) principles where applicable to our international clientele.
For the purposes of this Policy, the following terms shall have the meanings ascribed to them:
"Personal Data" means any information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available with a body corporate, is capable of identifying such person.
"Sensitive Personal Data" includes but is not limited to passwords, financial information such as bank account or credit card/debit card details, physical and mental health condition, sexual orientation, medical records, and biometric information.
"Processing" means any operation or set of operations performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation, retrieval, consultation, disclosure, alignment, combination, blocking, erasure, or destruction.
"Service" refers to the taxi booking and transportation services provided by the Company through any medium.
2. Detailed Categories of Information Collected
To facilitate a seamless, safe, and personalized transportation experience, we collect the following exhaustive categories of data. We collect this data at the time of registration, booking, during the ride, and through your interactions with our customer support team.
2.1. Identity and Demographic Data
- Full Legal Name (as per government-issued ID such as Aadhaar, Passport, or Driving License).
- Gender and Date of Birth (to ensure the correct driver allocation and for safety compliance).
- Preferred language and communication preferences.
2.2. Contact and Communication Data
- Primary mobile phone number (mandatory for booking confirmation and driver communication).
- Secondary contact number or emergency contact details.
- Email address (for sending invoices, receipts, promotional offers, and policy updates).
- Correspondence history (including chat logs, call recordings for quality and training purposes, and emails exchanged with support).
2.3. Location and Travel Data
- Real-time GPS location data (collected continuously while the app is in the foreground during a ride to ensure accurate tracking and driver assignment).
- Historical trip data (pickup and drop-off addresses, route taken, distance traveled, duration of trip, toll plazas crossed).
- Frequent travel patterns and saved addresses (Home, Office, Airport) for quick booking.
2.4. Financial and Transaction Data
- Payment method details (Cash, UPI ID, masked credit/debit card numbers). We do not store complete card details on our servers; all payment processing is handled by PCI-DSS compliant third-party gateways.
- Transaction history (ride fares, cancellation charges, waiting fees, discounts applied, refund transactions).
- GSTIN or billing address for corporate invoices.
2.5. Technical and Device Data
- IP address, device ID, MAC address, operating system version, browser type and version.
- App version, crash logs, and performance data to troubleshoot technical issues.
- Cookies and similar tracking technologies used on our website for session management and analytics.
3. Detailed Purposes of Data Processing
Every piece of information we collect is processed for a specific, legitimate, and lawful purpose. These purposes include, but are not limited to:
- Ride Execution and Dispatch: To find the nearest available driver, provide real-time ETA, share trip progress with your emergency contacts, and enable SMS/email notifications regarding your ride status.
- Customer Support and Query Resolution: To verify your identity when you call, investigate complaints (e.g., driver behavior, fare disputes), process refunds, and coordinate lost & found items.
- Analytics and Business Intelligence: To analyze demand patterns across different city zones, optimize our fleet distribution, reduce passenger wait times, and predict peak-hour requirements. This is done using anonymized aggregate data.
- Marketing and Promotional Communication: To inform you about exclusive discounts, festival offers, referral bonuses, and loyalty program points. You have the right to withdraw consent for marketing at any point by clicking the "Unsubscribe" link in our emails or contacting support.
- Safety and Security: To implement safety features such as trip sharing, emergency SOS alerts, and driver background verification. We use location data to detect route deviations and potential safety incidents.
- Compliance with Legal and Regulatory Obligations: To comply with the Motor Vehicles Act, Income Tax Act, state transport department regulations, and respond to lawful requests from government authorities, courts, or law enforcement agencies.
4. Data Sharing and Third-Party Disclosures
We hold your data in strict confidence. We do not sell, rent, or trade your personal data for advertising or any commercial purposes. However, to deliver our service effectively, limited data sharing is essential with the following categories of recipients:
- Driver Partners: We share your name, mobile number, pickup address, and any special instructions (e.g., wheelchair accessibility) with the assigned driver solely to facilitate the ride.
- Third-Party Service Providers: We engage trusted vendors for specific functions:
- Payment Gateways: (Razorpay, PayU, etc.) to process transactions.
- Mapping Services: (Google Maps) to provide routing and navigation.
- Communication Platforms: (Twilio, MSG91) to send SMS and WhatsApp notifications.
- Cloud Hosting: (AWS, Azure) to store data securely.
- Government and Regulatory Bodies: When mandated by law, court order, or for the prevention of fraud and public safety, we may disclose information to law enforcement or transport authorities.
- Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred to the new entity, which will be bound by the same privacy obligations.
All third-party providers are bound by strict data protection agreements and are prohibited from using your data for their own purposes.
5. Robust Security Measures
We employ a multi-layered security architecture to protect your data from unauthorized access, alteration, disclosure, or destruction. Our security framework includes:
- Encryption: All data transmitted between your device and our servers is protected using 256-bit SSL (Secure Sockets Layer) encryption. Our databases are also encrypted at rest.
- Network Security: We deploy advanced firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS) to monitor and block malicious traffic.
- Access Control: Access to personal data is strictly restricted to authorized personnel on a "need-to-know" basis. All employees undergo mandatory annual training on data privacy and sign strict confidentiality agreements.
- Regular Audits: We conduct periodic internal and external security audits (including vulnerability scans and penetration testing) to identify and remediate potential threats.
- Secure Storage: Sensitive data like financial information is tokenized and stored in isolated, highly secure environments compliant with PCI DSS Level 1 standards.
6. Data Retention and Deletion Policy
We retain your personal data only for as long as is necessary to fulfill the purposes outlined in this Policy, or as required by applicable Indian laws. The specific retention periods are:
- Ride and Transaction Records: Retained for a period of 7 (seven) years from the date of the ride to comply with income tax and commercial record-keeping regulations.
- Active Account Data: Retained as long as you maintain an account with us. If you request account deletion, your data will be anonymized or deleted within 30 days, except for records we are legally obligated to retain.
- Analytics Data: Anonymized and aggregated data may be retained indefinitely for business intelligence and trend analysis, provided it does not identify any individual.
- Marketing Data: Retained until you withdraw consent. Once you unsubscribe, your contact details are immediately removed from marketing lists.
7. Your Comprehensive Rights
As a data subject under Indian law and in accordance with global best practices, you possess the following rights regarding your personal data. We are committed to facilitating the exercise of these rights without undue delay.
- Right to Access: You have the right to request a complete copy of all personal data we hold about you, along with information on how it is processed.
- Right to Rectification: If any of your information is inaccurate or incomplete, you have the right to request correction or updates.
- Right to Erasure (Right to be Forgotten): You can request the deletion of your personal data, subject to legal retention obligations. We will anonymize or delete your data within 30 days of such a request.
- Right to Object / Withdraw Consent: You have the right to object to the processing of your data for marketing purposes and to withdraw your consent for specific data processing activities at any time.
- Right to Data Portability: You have the right to receive your data in a structured, commonly used, and machine-readable format (e.g., JSON/CSV) and have the right to transmit that data to another controller.
- Right to Grievance Redressal: You have the right to lodge a complaint with our appointed Grievance Officer or with the appropriate Data Protection Authority.
To Exercise Your Rights: Please send a written request to kanjipithiya5259@gmail.com or call our Data Protection Officer at +91 7984588357. We will respond within 24/7.
8. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance user experience, analyze site traffic, and personalize content. We use the following types of cookies:
- Strictly Necessary Cookies: These are essential for the basic functioning of our website (e.g., session management, login persistence).
- Performance/Analytics Cookies: We use Google Analytics to track page views and user behavior. This data is anonymized and used solely for improving our platform.
- Marketing Cookies: Used to display relevant promotional banners to you on third-party websites (e.g., retargeting). You can opt out of these via your browser settings.
You can manage or delete cookies in your browser settings. However, please note that disabling certain cookies may affect the performance and functionality of our website.
9. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately. We will take steps to remove that information from our systems. Any user under 18 must have the explicit consent of their parent or legal guardian to use our services.
10. Data Breach Notification Protocol
Despite our robust security measures, in the unlikely event of a data breach that compromises your personal information, we have a comprehensive incident response plan. We will:
- Immediately contain the breach and conduct a forensic investigation.
- Notify the relevant authorities (such as the Indian Computer Emergency Response Team - CERT-In) within the statutory time frame.
- Inform affected users via email or SMS within 72 hours of detection of the breach, detailing the nature of the breach, the data potentially affected, and the mitigation steps we are taking.
11. Updates and Changes to This Policy
We continuously review and update this Privacy Policy to reflect changes in our data practices, technology, and legal requirements. When we make significant changes, we will:
- Notify you via the email address associated with your account.
- Post a prominent notice on our website and mobile application for at least 15 days prior to the effective date of the changes.
- Update the "Effective Date" at the top of this Policy.
We encourage you to review this Policy periodically. Your continued use of our services after the effective date constitutes your acceptance of the revised terms.
12. Grievance Redressal Mechanism
In compliance with the Information Technology Act, 2000, and the rules thereunder, we have appointed a Grievance Officer to address your concerns regarding data privacy and processing. The details are as follows:
- Name: Mr. Kanji Pithiya
- Email: kanjipithiya5259@gmail.com
- Phone: +91 7984588357 (Ext. 101)
- Working Hours: 24/7
If you are not satisfied with the resolution provided by our Grievance Officer, you have the right to escalate the matter to the relevant data protection authority.
13. Frequently Asked Questions (FAQs) on Privacy
No. We do not sell, rent, or trade your personal data with any third-party advertisers. Your data is used exclusively for providing our taxi services and for internal analytics.
We retain your GPS location data associated with completed rides for a period of 7 years to comply with tax and legal requirements. However, live location data is not stored after the ride is completed.
Yes. You can request account deletion by emailing kanjipithiya5259@gmail.com. We will process your request within 30 days, except for data we are legally required to retain for taxation or fraud prevention purposes.
Absolutely. We do not store your full card details on our servers. All payment transactions are processed through globally certified, PCI-DSS compliant payment gateways.
We only share data with law enforcement or government authorities when it is legally mandated by a court order or a statutory requirement under Indian law.
In the event of a merger or acquisition, your data will be transferred to the new entity, which will be contractually obligated to uphold the same privacy standards and policies.
We recommend using mobile data. However, our app uses end-to-end SSL encryption, meaning even over public Wi-Fi, your data remains encrypted.
Yes. Simply click on the 'Unsubscribe' link in any promotional email or SMS, or update your notification preferences in the app settings.
We use algorithms for dynamic pricing and driver matching, but these do not produce legal or similarly significant effects on you. These are standard business optimization tools.
You can submit a Data Subject Access Request (DSAR) via email. We will compile and provide your data in a readable format within 24/7.
The app only accesses your GPS location when it is in the foreground (actively being used) or when you have a ride in progress. We do not collect background location data.
We process your data based on contractual necessity (to provide the ride), legal obligation (tax compliance), and legitimate interests (to improve our services).
Mr. Ramesh Patel is the Grievance Officer. You can reach him at kanjipithiya5259@gmail.com.
We review this Policy at least once a year or whenever there is a significant change in our data processing practices. You will be notified of major updates.
Immediately contact our support team at +91 7984588357 or email kanjipithiya5259@gmail.com. We will initiate our incident response protocol right away.