1. Who we are
UpDown is a community carpooling and shared-ride service. It helps people travelling in the same direction find or offer rides, request seats, communicate about journeys, and manage their ride activity.
This Privacy Policy explains how [INSERT FULL LEGAL ENTITY NAME], operating under the brand name “UpDown” (“UpDown”, “we”, “us”, or “our”), collects, uses, stores, discloses, and otherwise processes personal data when you:
- use the UpDown mobile application (the “App”);
- visit or interact with the UpDown website at [INSERT PRODUCTION WEBSITE URL] (the “Website”);
- contact our support, privacy, grievance, safety, or other teams; or
- otherwise interact with services that link to this Privacy Policy.
For applicable Indian data-protection law, [INSERT FULL LEGAL ENTITY NAME] is the entity that determines why and how your personal data is processed and is expected to act as the “Data Fiduciary.”
Our registered office is:
[INSERT FULL REGISTERED ADDRESS, INCLUDING COUNTRY AND POSTAL CODE]
Privacy contact: [INSERT PRIVACY EMAIL ADDRESS] Grievance contact: [INSERT GRIEVANCE OFFICER EMAIL ADDRESS] Support contact: [INSERT SUPPORT EMAIL ADDRESS]
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through the App, the Website, customer support, verification processes, ride-related communications, notifications, and related UpDown operations.
It does not apply to:
- a third-party website, application, or service that has its own privacy policy;
- information processed independently by a rider, driver, vehicle owner, or other community member outside UpDown's systems;
- an employer, educational institution, or other organisation that independently processes information about you; or
- data that has been irreversibly anonymised so that it can no longer reasonably identify an individual.
UpDown helps community members coordinate shared rides. Unless expressly stated otherwise in the applicable terms, UpDown does not operate the vehicles used for rides and is not the driver, rider, employer, or agent of community members. This distinction does not limit UpDown's responsibility for personal data that UpDown itself controls.
3. A short privacy overview
This summary is provided for convenience. The remainder of this Privacy Policy contains the complete explanation.
| Topic | Summary |
|---|---|
| Account access | We use your phone number and one-time password information to create or access an account and help prevent unauthorised use. |
| Profile | We process details such as your name, date of birth, gender, city, occupation, bio, profile photo, ratings, and verification status. |
| Location and rides | We process pickup and destination addresses, geographic coordinates, dates, times, routes, seats, fare information, and ride status to provide shared-ride features. |
| Verification | If you choose an available verification flow, we may process a work email or permitted identity/document information and the resulting verification status. |
| Communications | We process messages, notifications, ride requests, support communications, and related metadata. |
| Device and analytics | The App uses Firebase services and may process device, app-instance, screen-view, and app-use information. Some current analytics events may include journey details, as explained below. |
| Website | The current Website is designed as a static public site and does not intentionally use advertising trackers. Hosting systems may still process standard request and security logs. |
| Sharing | We share limited information with other users when needed to arrange a ride and with vendors that help operate the service. We do not publish identity documents or verification tokens to other users. |
| Sale of data | We do not sell personal data for money. We do not use personal data for third-party targeted advertising unless this Policy and any required consent flow are updated first. |
| Your choices | Depending on applicable law, you may ask for access, correction, completion, updating, erasure, consent withdrawal, or grievance redressal. |
| Children | This draft assumes UpDown will be restricted to people aged 18 or older. UpDown must technically enforce that rule before relying on this statement. |
4. Personal data we collect
The data we collect depends on how you use UpDown, the permissions you grant, the features available in your location, and the choices you make.
4.1 Account and authentication data
We may collect and process:
- your country code and mobile phone number;
- one-time password (“OTP”) request and verification information;
- an internal user identifier;
- authentication and session tokens;
- the time and status of login, signup, resend, and verification attempts;
- fraud, abuse-prevention, and rate-limiting information; and
- push-notification tokens associated with the device used to access your account.
Authentication tokens and an internal user identifier may be stored locally on your device to keep you signed in. You are responsible for maintaining control over your device and promptly notifying us if you believe your account or device has been compromised.
4.2 Profile and account data
When you create or update a profile, we may process:
- full name;
- date of birth;
- gender;
- city;
- occupation;
- profile biography or introduction;
- profile photograph;
- language preference, including Hindi or English;
- saved preferences and onboarding state;
- account creation and update timestamps;
- phone-verification and work-email-verification status;
- trust or verification badges;
- ratings and number of completed rides; and
- other information you choose to add to your profile.
Do not place information in your profile biography or photograph that you do not want made visible to people with whom the service permits your profile to be shared.
4.3 Location, route, and ride data
UpDown's core functions require journey and location information. Depending on the feature you use, we may process:
- a pickup or origin address;
- a destination or drop-off address;
- latitude and longitude for pickup, destination, and selected locations;
- a device's current location when you choose to use a “current location” or nearby-ride feature and grant location permission;
- searched locations and place-search text;
- route distance, estimated duration, and route geometry;
- departure and estimated arrival date and time;
- selected travel date and time;
- recurring-ride frequency, selected days, and end date;
- ride status, including open, full, in progress, completed, or cancelled;
- available, total, and requested seats;
- split-fare or price-per-seat information;
- potential fare estimates;
- electric-vehicle preference;
- ride-request status and response time;
- cancellation time and reason code; and
- ride history and the identifiers linking riders, drivers, vehicles, requests, and conversations.
Location data may reveal where you live, work, study, travel, or regularly spend time. Choose pickup and drop-off points carefully. Avoid using a precise private address where a nearby public meeting point is sufficient.
The current App requests location access only while the App is in use. This Policy does not authorise continuous background location tracking. If UpDown later introduces live-trip tracking or background location, we will provide a separate, prominent notice and obtain any consent required before enabling it.
4.4 Vehicle data
If you offer rides, we may process:
- a vehicle name or description;
- vehicle registration number;
- the vehicle selected for a particular journey; and
- vehicle information copied into ride records so riders can recognise the relevant ride.
Do not add a vehicle unless you are authorised to use it for the relevant journey.
4.5 Ride requests, ratings, and community activity
We may process:
- ride requests and their status;
- requested seats and estimated fare;
- rider and driver names, ratings, completed-ride totals, and profile details used in ride cards;
- acceptance, rejection, cancellation, and completion activity;
- post-ride ratings and feedback, where available;
- reports, complaints, safety concerns, moderation decisions, and related evidence; and
- records needed to investigate misuse, fraud, harassment, or violations of our terms or community rules.
4.6 Messages, notifications, and support data
When you communicate through or about UpDown, we may process:
- in-app message content;
- conversation participants;
- the ride associated with a conversation;
- sender, sent-time, delivery, and read-status information;
- notification title, body, type, read status, and related ride or conversation identifiers;
- support requests and correspondence;
- attachments or evidence you voluntarily provide; and
- records of how we respond to a request or grievance.
Other participants in a conversation can copy, save, or share messages outside UpDown. Do not send financial credentials, OTPs, identity-document images, or other information that is unnecessary for the journey.
4.7 Verification data
Verification features are optional unless we clearly state that a particular check is required for a particular feature. Depending on the verification method offered, we may process:
- a work email address;
- work-email verification status, token, token hash, and expiry information;
- the type and status of a verification request;
- a driving licence or other government-issued identity document number;
- document photographs or image locations;
- submission, review, approval, rejection, and update timestamps; and
- internal notes needed to review the verification.
A badge means only that the specific check described by UpDown was completed under the process in use at that time. It does not mean that UpDown guarantees a person's identity, background, driving ability, conduct, vehicle condition, or suitability for a ride.
Aadhaar notice: Do not submit Aadhaar data unless UpDown has expressly enabled a legally compliant Aadhaar flow, clearly explains the permitted purpose, and is authorised to conduct that verification. This draft does not represent that UpDown is authorised to perform Aadhaar authentication or offline verification.
4.8 Camera, photo-library, and uploaded-image data
If you grant permission and choose the relevant feature, the App may access:
- the camera to take a profile or verification image;
- selected images from your photo library; and
- image metadata that remains embedded in a selected file.
The App should access only the image you choose or create for the stated purpose. You can manage camera and photo permissions through your device settings. Removing permission does not automatically delete an image already uploaded to UpDown; use the relevant deletion control or contact us.
4.9 Device, app, network, and log data
We and our service providers may process technical information such as:
- device platform and operating system;
- device model or device name, where available;
- App version;
- device and app-instance identifiers;
- Firebase Cloud Messaging registration token;
- browser type and user agent;
- Internet Protocol (“IP”) address;
- language, time zone, and approximate region derived from technical data;
- API requests, timestamps, response codes, diagnostic events, and security logs;
- crash, error, and performance information if those tools are enabled; and
- information used to detect abuse, maintain availability, and protect accounts.
4.10 App analytics and usage data
The current App integrates Google Analytics for Firebase. Depending on configuration and consent controls, analytics may include:
- app-instance identifier;
- pseudonymous device or advertising identifiers made available by the operating system or SDK;
- device and operating-system information;
- approximate location derived from network information;
- session, engagement, and screen-view information;
- login and signup method;
- an internal UpDown user identifier;
- ride searches, including origin, destination, and date;
- published-ride events, including origin, destination, fare, and seats;
- seat-request events, including ride identifier and seats; and
- ride-cancellation events, including ride identifier and reason.
Journey locations can be sensitive in context. Before launch, UpDown must minimise analytics payloads so that precise addresses, exact journey details, phone numbers, names, message content, document data, or other directly identifying data are not sent to analytics services. Where required, analytics collection will be based on your consent and accompanied by an in-App control to change your choice.
4.11 Website data
When you visit the Website, the hosting and security systems may automatically process standard request information such as your IP address, browser, device type, requested page, referring page, date and time, and response status. We use this information to deliver, secure, diagnose, and understand the Website.
The current version of the Website does not intentionally set advertising cookies or include third-party advertising trackers. If we add analytics, a waitlist, contact forms, chat, embedded media, or similar technologies, we will update this Policy and provide any legally required notice or consent control before they are activated.
If you submit a form on the Website, we will process the information identified in that form for the purpose stated next to it. A waitlist or marketing form must include separate, clear consent language where required.
4.12 Information from other people and organisations
We may receive information about you from:
- another rider or driver who requests, offers, completes, rates, reports, or communicates about a ride involving you;
- a vehicle owner or account holder authorised to manage relevant details;
- verification and fraud-prevention providers;
- messaging, email, hosting, mapping, routing, and analytics providers;
- law-enforcement or government authorities acting through lawful process; and
- publicly available sources where collection and use are lawful and necessary for a stated purpose.
If you provide personal data about another person, you must be authorised to do so and must not provide more than is necessary.
4.13 Data we do not currently need for the described service
Unless we give you a specific notice for a new feature, UpDown does not require access to your contact list, microphone, continuous background location, bank-account password, card PIN, UPI PIN, or mobile OTP sent by another service. Never disclose these credentials in an UpDown profile, message, support request, or ride conversation.
The current product implementation reviewed for this draft does not include an active UpDown wallet or payment-processing flow. If payments are introduced, we will provide additional privacy information identifying the payment data and payment providers involved.
5. How we use personal data
We may use personal data for the following purposes.
5.1 Provide and operate UpDown
- create, authenticate, and maintain accounts;
- remember language and App preferences;
- build and display profiles;
- enable users to add and manage vehicles;
- search for, publish, request, accept, decline, cancel, and manage rides;
- calculate routes, distance, duration, seat availability, and fare estimates;
- support recurring rides;
- enable conversations and notifications;
- maintain upcoming, completed, and cancelled ride history; and
- provide ratings and other features you request.
5.2 Facilitate community interactions
- show relevant profile and ride details to potential or confirmed co-travellers;
- notify drivers about requests and riders about decisions or ride updates;
- make it easier to identify the relevant person, vehicle, route, and meeting point; and
- support post-ride ratings and community accountability.
5.3 Verification and trust
- verify a phone number or work email;
- receive and review optional document-verification submissions where lawfully offered;
- display accurate verification status;
- prevent misuse of verification badges; and
- investigate conflicting, false, or fraudulent information.
5.4 Safety, security, integrity, and legal compliance
- secure accounts, systems, and personal data;
- detect and prevent spam, fraud, abuse, harassment, unsafe activity, or unauthorised access;
- enforce our Terms of Use and Community Guidelines;
- investigate reports, complaints, disputes, and incidents;
- preserve evidence where reasonably necessary;
- comply with applicable law, valid legal process, or lawful government requests; and
- establish, exercise, or defend legal claims.
5.5 Communicate with you
- send OTPs and account communications;
- provide ride-request, message, verification, service, and safety notifications;
- respond to support, privacy, and grievance requests;
- send material policy or service notices; and
- send promotional messages only where legally permitted and subject to available opt-out controls.
5.6 Improve and administer the service
- understand App and Website performance and feature use;
- diagnose technical problems;
- conduct testing and quality assurance;
- improve accessibility, reliability, safety, and usability;
- develop new features using aggregated, de-identified, or appropriately protected data where feasible; and
- prepare business, security, and operational reporting.
We do not use the content of private ride conversations for unrelated advertising.
6. Grounds on which we process personal data
We process personal data only for lawful purposes. Depending on the applicable law and context, processing may be based on:
- your consent, including consent for optional permissions, optional verification, analytics where required, or marketing;
- your voluntary provision of data for a specified service, such as when you ask us to search for a ride, publish a ride, send a message, respond to a request, or resolve a support issue;
- performance of the service you request and steps needed to administer your account and journeys;
- compliance with law, legal process, or an enforceable request from a competent authority;
- protection from threats, including measures reasonably necessary to respond to a medical emergency, disaster, breakdown of public order, cyber incident, fraud, or safety concern where recognised by law; and
- another lawful ground expressly permitted under applicable legislation.
Where consent is the basis of processing, you may withdraw it as described in Section 15. Withdrawal does not invalidate processing that was lawful before withdrawal. If the information is necessary to provide a feature, withdrawing consent may mean that you cannot continue to use that feature.
7. Device permissions and your controls
The App may request the following device permissions:
| Permission | Why it may be requested | What happens if you decline |
|---|---|---|
| Location while using the App | Use current location, show nearby map context, or help select pickup and destination points | You may need to enter or select locations manually. Features that require device location may not work. |
| Camera | Take a profile photo or capture a permitted verification document | You may choose an existing image where supported or skip an optional verification. |
| Photos/media | Select a profile or permitted verification image | You may use the camera where supported or skip the optional upload. |
| Notifications | Receive ride requests, request decisions, messages, verification updates, and service notices | You can still open the App to check updates, but may miss time-sensitive notifications. |
You can change permissions in your device settings. The exact controls and labels vary by operating system.
8. When information is visible to other users
Community carpooling requires limited information sharing between users. Depending on the ride stage and feature, another user may see:
- your name and profile photo;
- city, occupation, bio, rating, completed-ride count, and displayed verification status;
- whether you are offering or requesting a ride;
- relevant pickup, destination, date, time, seat, fare, and vehicle information;
- request and ride status; and
- messages you send in a conversation with that user.
We aim to limit information to what is reasonably needed for discovery, decision-making, and coordination. We do not intend to display your full phone number, full work email, authentication token, verification token, identity-document number, or identity-document image to other users.
The exact visibility rules for search results, pending requests, accepted rides, completed rides, and blocked or reported accounts must be reflected in the App's user interface and access controls.
9. How we disclose personal data
We may disclose personal data in the circumstances below.
9.1 Other UpDown users
We disclose the limited profile, ride, vehicle, request, rating, and communication information described in Section 8 when necessary to provide the shared-ride service.
9.2 Vendors and data processors
We may use vendors to provide infrastructure, databases, hosting, storage, content delivery, maps, places, routes, analytics, push notifications, email, OTP delivery, customer support, security, moderation, and similar functions. They may process personal data only for the services they provide to us and subject to appropriate contractual and security obligations.
The current product code indicates use or contemplated use of the following services:
| Provider/service | Function and data that may be involved |
|---|---|
| Google Firebase Analytics | App analytics, app-instance identifiers, device/app details, approximate location, screen views, and configured UpDown events. |
| Firebase Cloud Messaging | Push-notification token, platform information, and notification delivery data. Notification content may pass through the service. |
| Firebase Remote Config | App configuration, App identifiers, IP address, and technical service data needed to deliver configuration. |
| Google Maps Platform and Places | Map rendering, place searches, selected coordinates, IP address, API request information, and device/server technical data. |
| UpDown's configured OSRM routing service | Origin and destination coordinates used to calculate a route, distance, duration, and geometry. |
| Resend, if enabled | Work email address and verification email content needed to deliver work-email verification. |
| [INSERT PRODUCTION CLOUD/HOSTING PROVIDER] | Hosting, databases, storage, backups, security, and operational logs. |
| [INSERT PRODUCTION OTP/SMS PROVIDER] | Phone number, country code, OTP delivery, status, and anti-abuse information. |
| [INSERT CUSTOMER SUPPORT/MODERATION PROVIDERS, IF ANY] | Support communications, reports, and case-management data. |
Provider availability and configuration may change. Before publication, this table must be reconciled against signed contracts, production architecture, and the App Store/Google Play privacy disclosures.
9.3 Professional advisers
We may disclose data to auditors, insurers, lawyers, accountants, security specialists, and other professional advisers where reasonably necessary and subject to confidentiality obligations.
9.4 Legal and safety disclosures
We may disclose data when we reasonably believe disclosure is necessary to:
- comply with applicable law, regulation, court order, or lawful request;
- respond to an emergency involving risk of death or serious physical harm;
- protect the rights, safety, property, and integrity of users, UpDown, or the public;
- investigate fraud, cyber incidents, abuse, or violations of our terms; or
- establish, exercise, or defend legal claims.
We will assess requests for data and disclose only what we reasonably believe is required, unless prohibited from doing so.
9.5 Business changes
If UpDown is involved in a merger, acquisition, financing, restructuring, insolvency, sale of assets, or similar transaction, personal data may be reviewed or transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections. We will provide notice if a transaction materially changes the entity responsible for your data or the purposes for which it is processed.
9.6 With your direction or consent
We may disclose information when you instruct us to do so or provide specific consent.
10. No sale of personal data and no third-party targeted advertising
UpDown does not sell personal data for monetary consideration.
The current product is not designed to show third-party targeted advertisements based on your ride history, precise location, messages, identity documents, or verification data. If our model changes, we will update this Policy and introduce any notice, choice, and consent controls required by law before using personal data for that purpose.
11. Automated processing and recommendations
UpDown uses automated systems to provide search results, geographic proximity results, route calculations, fare estimates, recurring schedules, notification routing, rate limiting, and similar operational features.
These systems may affect which rides are displayed or how results are ordered, but the current service is not intended to make a solely automated decision that produces legal or similarly significant effects about you. Drivers decide whether to accept or decline a ride request, and riders choose whether to request a journey.
If UpDown later introduces automated fraud, safety, eligibility, pricing, or suspension decisions that significantly affect users, we will review the legal requirements, provide an appropriate explanation, and introduce human-review or appeal measures where required.
12. Retention and deletion
We keep personal data only for as long as it is reasonably necessary for the purposes described in this Policy, including to provide the service, maintain safety and security, resolve disputes, enforce agreements, comply with law, and establish or defend legal claims.
The retention period depends on the nature of the data and why it is processed:
- Account and profile data: generally retained while your account remains active and for a limited period after deletion where necessary for legal, fraud-prevention, safety, or dispute purposes.
- Authentication and verification records: retained only as long as needed to authenticate the account, maintain the relevant verified status, prevent misuse, or comply with law. Raw document images should not be retained longer than is necessary for the stated verification purpose.
- Ride, request, vehicle, rating, and cancellation records: retained while needed to provide ride history, handle complaints, maintain platform integrity, meet recordkeeping obligations, or resolve claims.
- Messages and notifications: retained while needed to provide conversation history, investigate safety or support issues, and meet applicable legal or security requirements.
- Device tokens: retained while associated with an active account or device and removed or disabled when they become invalid, the account is deleted, or they are no longer needed.
- Analytics data: retained according to UpDown's configured analytics-retention settings and then deleted or aggregated. UpDown must document the selected production setting before launch.
- Support, grievance, safety, and legal records: retained for the period reasonably required to investigate, respond, demonstrate compliance, and manage potential or actual claims.
- Security and processing logs: retained for the minimum period required by applicable law and then erased or de-identified unless continued retention is legally required or reasonably necessary for an ongoing investigation.
- Backups: deleted or overwritten according to the applicable backup cycle. Data may remain in a protected backup for a limited period after deletion from live systems and will not be restored except for disaster recovery, security, or legal requirements.
When the purpose has ended and retention is no longer required, we will delete, anonymise, or securely isolate the data as appropriate. Anonymised or aggregated information that cannot reasonably identify you may be retained and used for legitimate business and research purposes.
Before publication, UpDown must approve and implement a written retention schedule covering every production database, log store, analytics property, storage bucket, support tool, vendor, and backup system.
13. Security
We use, and require relevant providers to use, reasonable administrative, technical, organisational, and physical safeguards appropriate to the nature of the data and risks involved. Depending on the system, these safeguards may include access controls, authentication, network protections, transport encryption, masking, logging, monitoring, backups, incident response, vendor controls, and employee confidentiality requirements.
No internet transmission, mobile device, database, or storage system is completely secure. You should use a secured device, keep your operating system and App updated, protect access to your phone number and messages, and never share an OTP or account token. If you believe your account or data may have been compromised, contact [INSERT SECURITY OR SUPPORT EMAIL] immediately.
14. International processing and transfers
UpDown is focused on users in India, but some service providers may operate infrastructure or support teams in other countries. As a result, personal data may be processed outside your state or outside India.
Where personal data is transferred internationally, we will take steps required by applicable law, such as assessing the provider, using contractual data-protection terms, limiting the data transferred, implementing security measures, and complying with any restriction or government order governing transfers from India.
The locations and transfer mechanisms used by production vendors must be verified before launch and reviewed when vendors or infrastructure change.
15. Your rights and how to exercise them
Subject to applicable law, verification of your request, and lawful exceptions, you may have the right to:
15.1 Obtain information about processing
You may request a summary of personal data being processed, the processing activities undertaken, and information about the other entities with which the data has been shared where applicable.
15.2 Access your information
You may request access to personal data associated with your account. Some information is already available through your profile, vehicles, rides, messages, and settings.
15.3 Correct, complete, or update information
You may correct inaccurate information, complete incomplete information, and update information that has changed. Certain verified fields may require a new verification process.
15.4 Request erasure
You may request deletion of personal data that is no longer necessary for the specified purpose. We may retain limited information when retention is necessary for a continuing specified purpose, security, fraud prevention, dispute resolution, compliance with law, or legal claims. We will explain the basis of a refusal where required.
15.5 Withdraw consent
Where processing is based on consent, you may withdraw that consent with reasonable ease. You can revoke device permissions through device settings and use any in-App privacy controls that are made available. For other consent withdrawals, contact us using the details below.
Withdrawal applies going forward and does not invalidate prior lawful processing. A feature may stop working if the withdrawn data is necessary for that feature.
15.6 Manage communications
You may disable push notifications through device settings. Essential account, security, policy, and ride-service messages may still be shown in the App or sent through another registered channel where necessary. Marketing messages, if introduced, will include the legally required opt-out method.
15.7 Grievance redressal
You may raise a concern about our handling of personal data or exercise of your rights. We will acknowledge, investigate, and respond within the period required by applicable law and our published grievance process.
15.8 Nominate another individual
Where the Digital Personal Data Protection Act, 2023 (“DPDP Act”) applies, you may have the right to nominate another individual to exercise your data-protection rights in the event of your death or incapacity, in the manner prescribed by law.
15.9 Complain to the competent authority
Please first give us an opportunity to resolve your grievance through the process below. Where applicable, you may then have the right to approach the Data Protection Board of India or another competent authority in accordance with the procedure and commencement timeline under applicable law.
15.10 Your responsibilities when exercising rights
When exercising privacy rights, you must provide authentic information, comply with applicable law, avoid impersonating another person, and avoid filing a grievance or complaint that is knowingly false or frivolous. These responsibilities do not prevent you from raising a good-faith concern or disputing information you reasonably believe is inaccurate.
15.11 Submit a request
To exercise a privacy right, contact:
Email: [INSERT PRIVACY RIGHTS EMAIL] In-App path: [INSERT PRIVACY-CENTRE OR ACCOUNT SETTINGS PATH] Web form: [INSERT FIRST-PARTY PRIVACY REQUEST URL, IF ANY] Postal address: [INSERT POSTAL ADDRESS]
Please write “Privacy Request” in the subject line and describe the account and request clearly. We may ask for information reasonably necessary to verify that the request relates to you and to protect your account from unauthorised requests. Do not send a password, OTP, full identity-document copy, or unnecessary information by ordinary email.
We will not discriminate against you for making a good-faith privacy request. If we cannot fulfil all or part of a request, we will provide the reason where required by law. We aim to resolve privacy grievances within one month after receipt, or within any shorter period required by applicable law; UpDown must confirm that this service level is operationally supported before publication.
16. Account deletion
You may request deletion through [INSERT IN-APP ACCOUNT-DELETION PATH] or by contacting [INSERT ACCOUNT-DELETION EMAIL OR URL].
Deleting the App from your device does not delete your UpDown account or server-side information. Logging out removes the local session from the device but does not by itself erase your account history.
When an account-deletion request is verified, we will begin deletion or de-identification of personal data that is no longer required. We may retain limited records for the reasons described in Section 12. Data already shared with another user, such as messages received by that person, may remain visible to that person where necessary to preserve conversation integrity, safety records, or the other person's legitimate records, subject to applicable law.
This section must not be published until UpDown has implemented and tested the stated account-deletion mechanism across the App, API, databases, Firebase/analytics, vendors, support systems, and backups.
17. Children and age eligibility
This draft assumes UpDown is intended only for individuals aged 18 years or older. A person under 18 must not create an account, publish or request a ride, or submit personal data through UpDown.
If we learn that we have processed a child's personal data contrary to this rule, we will take reasonable steps to restrict the account and delete the data unless retention is required by law or necessary to protect the child or another person.
If UpDown decides to permit people under 18, it must first implement verifiable parental consent, age-assurance, child-safety, no-tracking/no-targeted-advertising, and other measures required under Indian law. A date-of-birth field alone is not sufficient to establish verifiable parental consent.
Parents or guardians who believe a child has used UpDown should contact [INSERT CHILD-SAFETY OR PRIVACY EMAIL].
18. Personal data breaches
We maintain an incident-response process intended to identify, contain, investigate, remediate, and document personal-data incidents. If a breach affects your personal data, we will notify affected individuals and the competent authority as required by applicable law. A notice may describe the nature and likely consequences of the breach, mitigation measures, steps you can take, and a contact for questions.
19. Third-party services and links
The App or Website may link to or use third-party services. Their handling of data is governed by their own terms and privacy policies where they act independently. Relevant policies include:
- Google Privacy Policy: https://policies.google.com/privacy
- Firebase privacy and security information: https://firebase.google.com/support/privacy
- Google Maps Platform privacy and security information: https://developers.google.com/maps/security/compliance/security-compliance
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
We are not responsible for a third party's independent practices. Review the relevant policy before providing information to that service.
20. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in law, technology, vendors, security practices, or the service. We will post the updated version with a new “Last updated” date.
If a change materially affects how we process personal data, we will provide a prominent notice through the App, Website, registered contact channel, or another appropriate method before the change takes effect where required. If new consent is required, we will request it rather than treating continued use as consent.
Previous versions will be archived for an appropriate period at [INSERT POLICY ARCHIVE URL, IF AVAILABLE].
21. Language and accessibility
This Policy should be made available in clear English and, when launched, a complete and professionally reviewed Hindi version. If another language version conflicts with the English version, the version designated by applicable terms and law will control, subject to mandatory rights.
If you need this Policy in an accessible format, contact [INSERT ACCESSIBILITY OR SUPPORT EMAIL].
22. Contact us and grievance officer
For questions about this Privacy Policy or our processing of personal data, contact:
Privacy contact
Name or role: [INSERT DATA PROTECTION/PRIVACY CONTACT] Email: [INSERT PRIVACY EMAIL] Postal address: [INSERT POSTAL ADDRESS] Telephone, if provided: [INSERT NUMBER]
Grievance Officer
Name: [INSERT GRIEVANCE OFFICER NAME] Designation: Grievance Officer Email: [INSERT GRIEVANCE OFFICER EMAIL] Postal address: [INSERT POSTAL ADDRESS] Published response period: Within one month after receipt, or within any shorter period required by applicable law.
Please do not send identity documents, OTPs, passwords, payment credentials, or unnecessary sensitive information in an initial email.