Legal

Privacy Policy

Last updated: May 31, 2025

This Privacy Policy describes how RideAlong ("RideAlong", "we", "our") collects, uses, and protects your personal data in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 and applicable Indian laws.

1. Data We Collect

We collect the following categories of personal data when you use RideAlong:

  • Account data: Name, email address, mobile number, profile photo, and password (hashed).
  • Ride data: Rides created, rides joined, itineraries, check-in locations, and ride history.
  • Device & usage data: Device type, operating system, app version, IP address, crash logs, and feature usage events.
  • Location data: Your device location, with your permission, used to show rides near you. We do not continuously track or share your live location.
  • Communications: Messages sent through in-app chat (WhatsApp groups are operated by Meta and subject to their privacy policy).

2. Purpose of Processing

We process your personal data for the following purposes:

  • Creating and managing your RideAlong account.
  • Facilitating ride discovery, creation, and group coordination.
  • Sending transactional notifications (ride confirmations and itinerary updates).
  • Improving the app through analytics and crash reporting.
  • Complying with applicable laws including the DPDP Act, 2023 and the Information Technology Act, 2000.
  • Preventing fraud, abuse, and ensuring platform safety.

We do not sell your personal data to third parties. We do not use your data for targeted advertising.

3. Data Sharing

We share your data only in the following limited circumstances:

  • Other riders: Your name, profile photo, and ride activity are visible to members of rides you join or organise.
  • Ride organiser (phone number): When a ride organiser approves your request to join their ride, your phone number is shared with that organiser so they can coordinate the ride (e.g. add you to a WhatsApp group). By requesting to join a ride you consent to this sharing.
  • Infrastructure providers: Cloudflare (CDN & storage), AWS / Hetzner (hosting), and similar services that process data on our behalf under Data Processing Agreements.
  • Legal obligations: When required by Indian law, court order, or government authority.

4. Data Retention

We retain your data for the following periods:

  • Account data: As long as your account is active, plus 30 days after deletion for backup purposes.
  • Payment records: 7 years as required by Indian tax laws.
  • Usage / analytics data: 12 months in identifiable form, then aggregated anonymously.
  • Crash & error logs: 90 days.

After the applicable retention period, data is securely deleted or anonymised.

5. Your Rights

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), you have the following rights:

  • Right of access: Request a copy of all personal data we hold about you.
  • Right to correction: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your account and associated personal data.
  • Right to data portability: Receive your data in a machine-readable format (JSON).
  • Right to withdraw consent: Withdraw consent to location tracking or marketing communications at any time.
  • Right to grievance redressal: Lodge a complaint with our Grievance Officer (details below).

To exercise these rights, visit your Account page or email our Grievance Officer.

6. Security

We implement the following security measures:

  • TLS/HTTPS encryption for all data in transit.
  • Passwords hashed with argon2id (never stored in plain text).
  • One-time passcodes and refresh tokens stored only in hashed form.
  • Authentication tokens stored in the device's secure storage (iOS Keychain / Android Keystore).
  • Encryption at rest provided by our database and storage hosts at the infrastructure level.
  • Role-based access controls and audit logging for administrative actions.

Despite these measures, no system is 100% secure. Please notify us immediately if you suspect unauthorised access to your account.

7. Cookies & Tracking

Our website uses minimal, privacy-respecting cookies: a session cookie for authentication, and basic analytics to understand page traffic (no cross-site tracking). The mobile app does not use cookies. You can disable cookies in your browser settings, though this may affect website functionality.

8. Children's Privacy

RideAlong is not intended for persons under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that a minor has registered, we will promptly delete their account and associated data.

9. Changes to This Policy

We may update this policy periodically. When we make material changes, we will notify you via in-app notification and email at least 30 days before the changes take effect. Continued use of RideAlong after the effective date constitutes acceptance of the updated policy.

10. Grievance Officer

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, the details of the Grievance Officer are:

Name: Nuthan T Y

Designation: Grievance Officer, RideAlong

Email: ridealongcareservice@gmail.com

Response time: Within 72 hours of receipt

RideAlong

Operated from India

Questions? ridealongcareservice@gmail.com