Privacy Policy
Last updated: September 8, 2026
1. Overview
Murli V Tech Private Limited ("SafeRoute", "we", "us") operates the SafeRoute API and dashboard. This Privacy Policy explains what data we collect, how we use it, and your rights.
We comply with the Digital Personal Data Protection Act, 2023 (India) and align with GDPR principles for international customers.
2. Data We Collect
2.1 Account Data
- Company name, email address, password (bcrypt-hashed)
- API key (generated, not personal)
- Billing address and GSTIN (for invoices)
- Payment records (Razorpay payment IDs — we do NOT store card numbers)
2.2 Vehicle and Session Data
- Vehicle number, driver name, driver phone
- GPS location (latitude, longitude) during active sessions
- Motion sensor data (accelerometer readings)
- EPS scores and alert history
2.3 Usage Data
- API call counts (for billing and quota management)
- IP addresses (for security and rate limiting)
- Audit logs (actions taken by users and admins)
3. How We Use Your Data
- To provide the Service: Compute EPS scores, dispatch alerts, display dashboards
- For billing: Process payments, generate GST invoices, manage subscriptions
- For security: Rate limiting, abuse prevention, audit logging
- For improvement: Aggregate, anonymized analytics to improve detection accuracy
- For compliance: Maintain records as required by Indian law
4. Data Retention
Retention periods are based on your plan:
- Trial: 7 days of session/alert history
- Starter: 30 days
- Growth: 90 days
- Fleet/Enterprise: 365 days
Trial accounts are deleted 90 days after trial expiry. Paid accounts retain data during active subscription. After cancellation, data is deleted within 30 days unless legally required.
5. Data Sharing
We do NOT sell your data. We share data only with:
- Razorpay — Payment processing (payment IDs only)
- Twilio — WhatsApp alert delivery (phone numbers only)
- MSG91/Fast2SMS — SMS alert delivery (phone numbers only)
- Your SMTP provider — Email alert delivery
- Law enforcement — Only when legally compelled by valid court order
Each processor is bound by data processing agreements and only receives the minimum data needed.
6. Your Webhooks
When you register a webhook, we send alert data to your URL. You are responsible for securing your webhook endpoint. All outgoing webhooks are HMAC-signed so you can verify authenticity.
7. Data Security
- Passwords are bcrypt-hashed (cost factor 12)
- API keys are unique per organization
- JWT tokens expire after 24 hours
- Database is encrypted at rest (PostgreSQL)
- All communication is over HTTPS/TLS
- Webhook URLs must be HTTPS (SSRF protection)
- Rate limiting prevents brute-force attacks
- Audit logs track all security-relevant actions
8. Your Rights
You have the right to:
- Access your data via the dashboard or API
- Export your data (contact support)
- Delete your account and data (via the dashboard)
- Correct inaccurate data
- Object to processing (contact us)
- Withdraw consent for data sharing
9. International Transfers
Your data is stored on servers in India (Mumbai region). If you are outside India, your data is still stored in India. We comply with cross-border data transfer requirements under Indian law.
10. Children's Privacy
The Service is for businesses only. We do not knowingly collect data from individuals under 18. If you believe a minor's data was collected, contact us immediately.
11. Cookies
The dashboard uses localStorage for authentication tokens. We do not use third-party tracking cookies or advertising networks.
12. Changes to This Policy
We may update this Privacy Policy with 30 days' notice. Material changes will be announced via email to registered users.
13. Contact
For privacy questions, data requests, or complaints:
Murli V Tech Private Limited
Email: privacy@saferoute.in
Response time: 30 days