Legal
Privacy Policy
Effective: 29 July 2026 · Last updated: 29 July 2026
Quick summary
- We collect only what we need to book, deliver and bill your rides safely.
- We do not sell your personal data. Ever.
- Location data in our mobile apps is used only while you have an active or upcoming ride, and only while the app is in use unless you explicitly enable background location for driver-partner apps.
- You can request access, correction, or deletion of your data at any time by writing to sales@commutec.in.
1. Who this policy covers
This Privacy Policy explains how Aurafox Solutions Pvt Ltd ("Commutec", "we", "us", "our") collects, uses, discloses and protects personal data when you:
- Visit www.commutec.in or any Commutec sub-domain;
- Use our mobile applications, including rider, corporate admin and driver-partner apps distributed via the Google Play Store and Apple App Store;
- Book, receive, or supply corporate mobility services through Commutec (employee transport, corporate car rental, events, hotel transfers, and related services);
- Contact us for sales, support, careers, or investor enquiries.
2. Data controller & contact
Aurafox Solutions Pvt Ltd
BSEL Tech Park, Vashi, Navi Mumbai 400703, Maharashtra, India
Email: sales@commutec.in
Phone: +91 88050 22389
3. Data we collect
We collect only the categories of data listed below. This list mirrors the disclosures we make on the Google Play Data Safety form and the Apple App Store Privacy Nutrition Labels.
3.1 Identity & contact data
- Name, work email, personal email, phone number, employee ID (when provided by your employer), and profile photo (optional).
3.2 Account & authentication data
- Login credentials, OTP verification tokens, session tokens, and password reset tokens.
3.3 Trip & booking data
- Pickup and drop addresses, waypoints, trip time, vehicle preference, ride status, ratings, SOS events, and trip receipts.
3.4 Location data
- Rider apps: precise device location, collected only while the app is in the foreground and only while you have an active or upcoming ride, used for pickup, en-route ETA, safety and SOS.
- Driver-partner apps: precise device location, collected in the foreground and — only if you explicitly grant it — in the background during an active duty shift, used for dispatch, navigation and passenger safety.
3.5 Payment & billing data
- Corporate billing accounts, GSTIN, invoice history. Card / UPI credentials are handled by PCI-DSS certified payment processors — we do not store card numbers or CVVs on our servers.
3.6 Device & technical data
- Device model, OS version, app version, IP address, mobile network carrier, crash logs, diagnostic logs and unique app install identifiers used for analytics and fraud prevention.
3.7 Communications
- In-app chat with driver, support tickets, call recordings for safety and quality (with disclosed IVR notice), and marketing preferences.
3.8 Data we do not collect
- We do not collect contacts, calendar, SMS, microphone, photos, health, biometric, or financial account data from your device.
- We do not use device identifiers for cross-app tracking or advertising.
4. How we use your data
- Deliver the service: book, dispatch, complete and invoice rides; provide customer support.
- Safety: real-time trip monitoring, SOS, driver verification, incident investigation.
- Communications: transactional messages (booking confirmations, trip alerts, receipts) and, with consent, service updates.
- Product improvement: aggregated analytics, crash diagnostics, quality audits.
- Compliance: tax invoicing, audit trails, and responding to lawful requests.
We do not sell your personal data and we do not use it for targeted advertising or profiling beyond the service.
5. Legal bases (GDPR / India DPDP Act, 2023)
- Contract: to provide the mobility services you or your employer contracted for.
- Consent: for marketing emails, optional analytics, and background location for driver-partners.
- Legitimate interests / legitimate use: fraud prevention, security, product improvement.
- Legal obligation: tax, accounting, transport regulator and lawful government requests.
6. Location data — mobile apps
Location is central to a mobility product. We are transparent about exactly when and why it is used, in line with Apple App Store §5.1.1 and Google Play Location Permissions policy.
- Foreground only, by default. Rider apps request "While Using the App" location permission and use it only during active or scheduled trips.
- Background location is requested only in the driver-partner app, only after a clear in-app explanation, and only for the strict purpose of dispatch and on-trip navigation while on duty. You may revoke it at any time from OS settings.
- We never use location for advertising, and we never sell location data.
- Coarse location may be used briefly at app start to show nearby cities / operators.
7. Mobile app permissions
- Location — pickup, ETA, safety (rider); dispatch, navigation (driver).
- Notifications — booking updates, trip alerts, SOS confirmations.
- Camera — optional profile photo, KYC document capture for driver-partners.
- Phone — one-tap call to your assigned driver or to Commutec support.
Every permission is optional and can be revoked from your device settings; some features will not work without them.
8. How we share your data
- Your employer (for corporate bookings): trip metadata, cost, compliance and audit data as agreed in the master service agreement between Commutec and the employer.
- Ground operators & driver-partners: the minimum information needed to complete your ride (name, pickup/drop, phone via masked calling where available).
- Service providers (see §9) under written contracts that restrict use to Commutec's instructions.
- Regulators & law enforcement: when required by valid legal process.
- Business transfers: in the event of a merger or acquisition, with continued protection of your data.
9. Third-party SDKs & processors
Categories of processors we currently use:
- Cloud hosting & database: AWS (India regions) and equivalent managed database providers.
- Maps & geocoding: Google Maps Platform, Mapbox.
- Payments: PCI-DSS certified Indian payment gateways (e.g., Razorpay, RBI-licensed acquirers).
- Communications: transactional email (e.g., Amazon SES / Postmark), SMS/OTP (DLT-registered aggregators), masked calling providers.
- Analytics & crash reporting: Google Analytics 4 (web), Firebase Crashlytics (apps). IP anonymisation is enabled where offered.
- Customer support: ticketing and CRM tools.
Each processor is bound by a data processing agreement and processes data only on our documented instructions.
10. Cookies & analytics
Our website uses:
- Essential cookies for session, security and preferences.
- Analytics cookies (Google Analytics 4) to understand aggregate usage. You can opt out through your browser or via the Google Analytics opt-out add-on.
We do not use advertising cookies or cross-site tracking pixels.
11. Data retention
- Account data: retained while your account is active, and up to 90 days after deletion request for backups.
- Trip & invoice data: retained for 8 years to comply with Indian tax, GST and companies-law audit requirements.
- Support tickets: 3 years.
- Crash logs / diagnostics: up to 90 days.
12. Security
- TLS 1.2+ in transit and AES-256 at rest for databases and backups.
- Role-based access control, least-privilege service accounts and audit logging.
- Vendor risk reviews and periodic penetration testing.
- No security system is perfect. We will notify affected users and the relevant regulator without undue delay in the event of a personal data breach that is likely to result in risk.
13. International transfers
Personal data is primarily processed in India. Where sub-processors operate outside India (e.g., certain analytics or crash-reporting services), transfers rely on Standard Contractual Clauses or the vendor's approved transfer mechanism, and only the minimum data is shared.
14. Your rights
Depending on where you live (India DPDP Act, EU/UK GDPR, or other applicable law) you may:
- Access, correct or update your data;
- Request erasure of your data ("right to be forgotten");
- Restrict or object to certain processing;
- Withdraw consent at any time (without affecting prior processing);
- Port your data to another service;
- Nominate another person to exercise your rights on your behalf (DPDP §14);
- Lodge a complaint with a supervisory authority (e.g., India's Data Protection Board, or your local EU DPA).
To exercise any right, email sales@commutec.in. We respond within 30 days.
15. Account & data deletion
Both Google Play and Apple App Store require an easy way to request account and data deletion. You can do this in any of the ways below:
- In-app: Profile → Settings → Delete my account.
- Web: commutec.in/contact — choose "Delete my data".
- Email: sales@commutec.in with subject "Delete my account".
On receiving a verified deletion request we will delete or irreversibly anonymise your personal data within 30 days, except records we are legally required to retain (e.g., tax invoices for 8 years, which are kept in restricted archival storage).
16. Children
Commutec is a B2B corporate mobility service and is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has provided us data, please contact us and we will delete it.
17. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or in-app notice at least 15 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.
18. Grievance officer (India)
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023:
Grievance Officer: Randeep Singh Lobana
Aurafox Solutions Pvt Ltd, BSEL Tech Park, Vashi, Navi Mumbai 400703
Email: sales@commutec.in
Response time: within 15 days of receipt of a complaint.
This policy is provided in English. In case of any conflict between translated versions, the English version prevails.
