Privacy Policy
How we collect, use, and protect your personal data.
Effective Date: [Insert Date] · Last Updated: [Insert Date] · Jurisdiction: India
1. Introduction
At Aapi Jau ("Platform", "we", "us", "our"), we are committed to protecting your privacy and handling personal data with transparency, security, and care.
Aapi Jau is operated by [Legal Entity Name], having its registered office at [Registered Business Address, City, State, PIN, India]. This entity is responsible for the personal data described in this Policy to the extent applicable.
This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use the Aapi Jau mobile application, website, or associated services as a Customer, Vendor, Delivery Partner, or visitor.
By accessing or using the Platform, you acknowledge that you have read this Privacy Policy. Where applicable law requires consent for a particular processing activity, Aapi Jau will seek consent through a clear notice and an affirmative action. Use of the Platform alone is not intended to replace any consent that law requires to be separately obtained.
This Policy is intended to operate in accordance with applicable Indian privacy, data-protection, information-technology, consumer, and sectoral laws, including applicable provisions of the Information Technology Act, 2000, the SPDI Rules, 2011, the Digital Personal Data Protection Act, 2023, and rules made thereunder as and when applicable.
2. Information We Collect
We collect information depending on your role and the features you use. We aim to collect only information reasonably necessary for the stated purposes.
2.1 Information You Provide Directly
| User Type | Data Collected |
|---|---|
| All Users | Full name, mobile number, email address where used, profile photo if uploaded, and authentication information. If the Platform uses OTP-only login, no password is collected. |
| Customers | Delivery addresses, order preferences, support communications, and payment-related references. Full card or UPI credentials are generally processed by the payment gateway and are not stored by Aapi Jau. |
| Vendors | Business name/address/type, FSSAI/GST/PAN/business-registration information where applicable, bank account details, KYB/KYC documents, product catalogue, settlement and compliance information. Aadhaar is collected only where legally permitted and necessary. |
| Delivery Partners | Identity and contact information, PAN, driving licence, vehicle registration/insurance where applicable, bank details, KYC documents, delivery activity, and Aadhaar only where legally permitted and necessary. |
2.2 Information Collected Automatically
- Location Data: Customer location during address selection/order placement or active tracking when permission is granted; Delivery Partner location while the Partner is online, available for assignments, or actively completing a delivery, as needed for dispatch, navigation, safety, and proof of delivery. Location collection should stop or be materially reduced when the Partner goes offline, subject to technical and legal requirements.
- Device Information: Device type, operating system, app version, device identifiers or advertising identifiers where lawfully used, and crash/performance data.
- Usage Data: Screens/features used, interaction logs, search activity, session information, and performance data.
- Log Data: IP address, access timestamps, security events, error logs, and similar technical records.
2.3 Information from Third Parties
- Payment gateway provider: transaction status, payment reference IDs, refunds/chargeback status, and other payment metadata. We do not ordinarily receive full card or UPI credentials.
- Maps/navigation provider: coordinates and location-related data used for address search, routing, ETA, and real-time tracking.
- OTP/SMS/email/push providers: mobile number, email address, device token, delivery status, and message metadata as necessary to send service communications.
- Vendors or Delivery Partners: order-status, preparation, pickup, delivery, incident, KYC, settlement, and support information relevant to your transaction.
3. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Account creation and authentication | Name, mobile number, email where used, authentication data |
| Order processing and fulfilment | Customer address, order details, Vendor catalogue/status, Delivery Partner location/status |
| Real-time delivery tracking | Delivery Partner GPS location and order status during the relevant delivery |
| Payment processing and invoicing | Transaction data, order value, payment method type/reference, refund or chargeback status |
| Vendor KYC/KYB and compliance | Business documents and government IDs only as necessary and legally permitted |
| Delivery Partner KYC and compliance | Identity, driving/vehicle documents and government IDs only as necessary and legally permitted |
| Vendor settlements / Delivery Partner payouts | Bank details, earnings, deductions and settlement records |
| Customer support and ticket resolution | Order data, contact details, communications, evidence and support logs |
| Failed delivery and Outstanding Due management | Order data, proportionate delivery proof, GPS/timestamps, contact-attempt records, account due status |
| Service notifications | Device token, mobile number or email for OTPs, order updates, safety alerts and account notices |
| Optional marketing communications | Contact details and communication preferences, subject to applicable consent/opt-out requirements |
| Safety, fraud prevention and security | Usage patterns, device/security logs, transaction history and account activity |
| Analytics and improvement | Aggregated, de-identified, or limited usage/performance data as appropriate |
| Legal compliance and dispute resolution | Relevant data to meet legal, tax, regulatory, contractual, or dispute-resolution obligations |
4. How We Share Your Information
We do not sell personal data. We share personal data only where reasonably necessary for the purposes described in this Policy, with appropriate safeguards and subject to applicable law.
4.1 Within the Platform Ecosystem
- Customers → Vendors: Customer name or order identifier, delivery-related details where necessary, and order details for preparation and fulfilment.
- Customers → Delivery Partners: Customer name/order identifier, delivery address, contact method, and delivery instructions reasonably necessary to complete the delivery.
- Vendors → Aapi Jau: Business/KYB, catalogue, order, settlement, compliance, and support information.
- Delivery Partners → Aapi Jau: KYC, availability, location while online/working, delivery activity, proof, earnings, safety, and support information.
4.2 With Third-Party Service Providers
| Provider Category | Purpose | Typical Data Shared |
|---|---|---|
| Payment gateway (e.g., the provider enabled in production) | Payment processing/refunds | Order amount, transaction reference, customer/payment identifiers as required by the provider |
| Maps/navigation provider | Address search, routing, ETA, tracking | Pickup/drop coordinates and route/location data |
| Cloud hosting/storage provider | Infrastructure, databases, backups | Platform data necessary to host and secure the service |
| Push/analytics/crash provider | Notifications, app performance, diagnostics | Device token, app/device data, events, crash diagnostics |
| OTP/SMS/email provider | Authentication and communications | Mobile number/email, template/message metadata, delivery status |
| Professional/legal/regulatory service providers | Compliance, audit, dispute handling | Only data reasonably necessary for the relevant purpose |
We require service providers, through applicable contracts, platform terms, security controls, or other lawful arrangements, to handle personal data only for authorized purposes and with protections appropriate to the nature of the data and service.
4.3 Legal & Regulatory Disclosure
We may disclose personal data to courts, law-enforcement agencies, regulators, tax authorities, or other competent authorities when required or permitted by applicable law, or where reasonably necessary to establish, exercise, or defend legal rights.
4.4 Business Transfers
If all or part of the business is reorganized, merged, financed, acquired, or sold, relevant personal data may be transferred subject to applicable law, due diligence safeguards, and continuity of appropriate privacy protections.
5. Location Data
| User Type | When Collected | Purpose |
|---|---|---|
| Customer | When permission is granted during address selection, order placement, or active order tracking | Set/confirm delivery location, show route/ETA, enable relevant order features |
| Delivery Partner | While online/available for assignment or actively completing a delivery | Assign nearby orders, navigation, real-time tracking for the relevant customer, safety, delivery proof and dispute resolution |
Customer Control: Customers may deny or disable device location permission, but they may then need to enter an address manually and some tracking or nearby-service features may be limited. Delivery Partners generally need location enabled while online or on a delivery for dispatch and navigation. Location collection should stop or be materially reduced when the Delivery Partner goes offline, except where a limited residual processing need is clearly disclosed and lawful.
Precise location is retained only for as long as reasonably necessary for operational, safety, fraud-prevention, proof-of-delivery, or dispute purposes, subject to the retention schedule and applicable law.
6. Sensitive / High-Risk Personal Data
Some information — such as government-issued identity documents, bank details, precise location history, and other information requiring enhanced protection under applicable law or company policy — may present higher privacy or security risk. We collect such information only where reasonably necessary and legally permitted, apply additional access/security controls, and limit sharing to authorized recipients. Biometric data will not be collected unless a specific feature requires it, a lawful basis/consent exists, and this Policy is updated before collection.
7. Data Retention
| Data Category | Target Retention Period / Rule |
|---|---|
| Account information | For the account lifecycle and then only as long as reasonably required for legal, fraud, support, or dispute purposes. |
| Outstanding Due records | Until resolved, then for the period reasonably required for audit, fraud, accounting, or dispute purposes. |
| Order and transaction records | For the period required by applicable tax, accounting, consumer, payment, and legal obligations. |
| KYC / KYB documents | For the account lifecycle and any additional period required or permitted by applicable KYC, tax, fraud-prevention, or legal obligations. |
| Location logs | For the shortest period reasonably necessary for operational, safety, proof-of-delivery, fraud, and dispute purposes; the current technical target should be confirmed by the developer before publication. |
| Support and ticket records | For as long as reasonably required to resolve the matter and maintain an appropriate audit trail. |
| Notification/security logs | For short operational/security periods appropriate to the purpose. |
| Aggregated/anonymized analytics | May be retained longer where it no longer identifies an individual. |
Specific retention periods should be implemented in backend systems and periodically reviewed. On account deletion or a valid erasure request, data will be deleted or anonymized within the period required by applicable law, except data that must or may lawfully be retained for legal, accounting, fraud, security, contractual, or dispute purposes.
8. Data Security
We maintain technical and organizational safeguards appropriate to the nature of the data and the risks involved. Measures may include encrypted transport, encryption or other protections for stored data where appropriate, role-based access controls, secure cloud configurations, credential hashing where passwords are used, logging/monitoring, backups, and periodic security reviews.
Specific technical claims (for example, a particular encryption algorithm, cloud region, audit cadence, or certification) should be published only after the production architecture has been verified by the developer/security team. No method of transmission or storage is completely secure, and Users should protect their account credentials and promptly report suspected unauthorized access.
9. Your Rights and Choices
- Access / information: request information about personal data handled by Aapi Jau as available under applicable law.
- Correction and updating: request correction of inaccurate or incomplete personal data.
- Erasure: request deletion of personal data, subject to lawful retention exceptions.
- Withdrawal of consent: where processing is based on consent, withdraw that consent through a method that is reasonably easy to use; withdrawal does not affect processing already lawfully carried out.
- Grievance: raise a privacy grievance through the contact details below.
- Nomination: exercise any nomination right available under applicable Indian data-protection law when that provision applies.
- Account deletion: request account deletion through the in-app account/settings flow if available, or by contacting [grievance@aapijau.com].
We will acknowledge and respond to valid privacy requests within the timeframe required by applicable law and, as an operational target, ordinarily within 30 days unless the request is complex or another statutory timeframe applies.
10. Children's Privacy
The Platform is intended for individuals aged 18 years and above. We do not knowingly permit minors to create accounts. If we learn that personal data was collected from a minor contrary to our policy or applicable law, we will take reasonable steps to restrict the account and delete the data unless retention is legally required. Contact [support@aapijau.com] to report a suspected minor account.
11. Cookies, Analytics, Notifications & Marketing
The mobile application may use SDKs and similar technologies for app functionality, analytics, crash diagnostics, security, and push notifications. Traditional browser cookies may also be used on any website version of the Platform if such a website is deployed.
Transactional/service communications such as OTPs, order confirmations, rider updates, payment/security alerts, and account notices are different from promotional marketing. Where required, promotional messages will be sent based on applicable consent or preference rules, and Users will be provided an opt-out/unsubscribe mechanism. Disabling marketing will not stop essential service communications.
11A. Outstanding Due Balance Data
Where a Customer refuses or is unavailable to accept an order after pickup, an Outstanding Due may be recorded in accordance with the Terms and Conditions. Related data may include the Order ID, amount breakdown, Delivery Partner incident report, proportionate delivery proof, GPS/timestamps, contact-attempt records, account status, dispute records, and payment records after settlement.
Delivery proof should be limited to what is reasonably necessary. Delivery Partners should avoid unnecessarily capturing unrelated persons, interiors, neighbouring homes, identification documents, or other sensitive information in photographs or recordings.
12. Third-Party Links and Services
The Platform may contain links to or integrations with third-party services. Those providers may process personal data under their own privacy terms. We encourage Users to review relevant third-party privacy information where appropriate.
13. Cross-Border Processing and Storage
Personal data may be processed or stored in India and, depending on the configuration and location of authorized service providers, in other jurisdictions. Aapi Jau will use service providers and transfer mechanisms consistent with applicable Indian law and any government restrictions in force at the relevant time. The production hosting region and provider locations should be verified before publication rather than assumed.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in law, technology, providers, or Platform features. The revised version will display a new "Last Updated" date. We will provide a reasonable notice of material changes through the Platform, email, or another suitable method, and will seek fresh consent where applicable law requires it.
15. Grievance Officer / Privacy Contact
Aapi Jau will maintain the grievance and privacy contact details required by applicable law. Before publication, the following details must be completed and the responsible person must be operationally able to receive and process requests:
| Grievance / Privacy Contact | Registered Address |
|---|---|
| Name / Designation: [Officer Name] | [Legal Entity Name] |
| Email: [grievance@aapijau.com] | [Registered Business Address] |
| Response: within applicable legal timelines | [City, State, PIN Code]India |
16. Contact Us
| General Support | Data Privacy Queries |
|---|---|
| Email: [support@aapijau.com]Phone: [Support Number]Hours: Mon-Sat, 9 AM - 6 PM | Email: [grievance@aapijau.com]Subject: Privacy Request - [Your Name] |
By using the Platform, you acknowledge that you have read and understood this Privacy Policy. Where consent is required for a specific processing activity, consent will be obtained separately or through the relevant in-app notice and affirmative action.
Questions?
Reach our team through the contact section on the main site, or read the other legal document.