Privacy Policy
Last updated: May 2026
1. Introduction
Ridivo ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what information we collect, why we collect it, how we use it, and your rights under applicable law, including India's Digital Personal Data Protection Act, 2023 (DPDPA).
2. Information We Collect
2a. Information you provide directly
| Data | Purpose |
|---|---|
| Phone number | Account creation and OTP authentication |
| Full name, username, profile photo | Public profile |
| Date of birth | Age verification |
| Vehicle details (make, model, type) | Ride coordination |
| Emergency contacts (name, phone) | SOS notifications |
| Skills (e.g., first aid, bike repair) | SOS skill routing |
| Payment information | Processed by Razorpay — we do not store raw card data |
2b. Information collected automatically
| Data | Purpose |
|---|---|
| Live GPS location | Ride tracking, SOS trigger, location sharing |
| Home location (optional) | Personalisation |
| Device identifiers (FCM token, device name) | Push notifications |
| IP address | Security (admin IP binding, rate limiting) |
| Session tokens | Authentication |
| App usage and crash logs | Debugging and service improvement |
2c. Information from third parties
- Razorpay: payment status (not raw card data)
- Firebase: FCM delivery receipts
3. How We Use Your Information
- Ride coordination: create and manage rides, share live location with co-participants, trigger and respond to SOS alerts.
- Authentication: OTP verification, session management, token refresh.
- Push & SMS notifications: ride invites, SOS alerts, expense splits, badge awards, subscription reminders.
- Safety: Safety Score calculation, false alarm detection, IP-based admin session security.
- Payments: subscription billing, wallet credits, gift purchases via Razorpay.
- Analytics & improvement: aggregate, anonymised usage statistics.
- Legal compliance: fraud prevention, responding to lawful requests from authorities.
We do not sell your personal data to third parties for advertising.
4. Live Location Data
Your GPS location is collected only while you are an active participant in a running ride (approximately every 3–60 seconds depending on your subscription tier). Location data is:
- Shared in real time with other accepted participants of the same ride.
- Shared with anyone who has a valid tracking link you or the captain created.
- Used to populate SOS responder views during an active SOS alert.
You can stop location sharing by ending your participation in the ride.
5. Emergency Contacts & SOS
Emergency contacts you add are notified via SMS only when you trigger an SOS alert. Their phone numbers are stored securely and are not shared with other ride participants or third parties.
6. Data Sharing
We share your data only in the following circumstances:
| Recipient | What is shared | Reason |
|---|---|---|
| Other ride participants | Name, avatar, live location (during active ride), vehicle | Ride coordination |
| Public tracking link viewers | Name, latest GPS location | Voluntary share by you or captain |
7. Data Retention
| Data type | Retention period |
|---|---|
| Account profile | Until account deletion + 30 days |
| Live location pings | Deleted after ride history retention period |
| OTP records | 30 days after verification |
| Session tokens | Until logout or expiry (30 days) |
| Payment records | 7 years (as required by Indian tax law) |
| Deleted account data | Hard-deleted within 30 days, except payment records |
8. Data Security
We use the following measures to protect your data:
- HTTPS/TLS for all data in transit.
- Bcrypt hashing for OTPs; SHA-256 for refresh tokens.
- JWT-based authentication with short-lived access tokens (15 minutes).
No system is completely secure. If you suspect your account has been compromised, contact us immediately.
9. Your Rights (DPDPA 2023 & General)
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data via your profile settings or by contacting us.
- Withdraw consent for non-essential data processing (e.g., location) at any time by leaving active rides.
- Nominate a person to exercise your rights in the event of your death or incapacity (DPDPA requirement).
- File a complaint with the Data Protection Board of India if you believe your rights have been violated.
To exercise any of these rights, email us at privacy@ridivo.com. We will respond within 30 days.
10. Children's Privacy
Ridivo is not intended for users under 18. We do not knowingly collect personal data from minors. If we learn we have inadvertently collected such data, we will delete it promptly.
11. Cookies & Local Storage
Our web platform may use cookies for session management and analytics. You can disable cookies in your browser settings, but this may affect functionality.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via in-app notification or email at least 7 days before the change takes effect. Continued use after that date constitutes acceptance.
13. Contact — Data Controller
- Email: privacy@ridivo.com
- Grievance Officer: officer@ridivo.com (as required under Indian IT Act Rules)