This Privacy Policy describes how TEZride(the “Platform”) collects, uses, shares, and protects your personal information. We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.
1. Information we collect
From users (patients / callers):
- Phone number and optional name (required to place a booking).
- Pickup and drop location (coordinates + address).
- Patient condition category and selected equipment add-ons (not medical records).
- Free-text notes you choose to include with the booking.
- Emergency contact phone numbers and names (only if you save them).
From Providers (fleet owners and drivers):
- Name, phone, email, password (hashed with bcrypt — we cannot see it).
- Business details, PAN, Aadhaar, driver licence, vehicle registration, insurance, and fitness certificate.
- Driver live location while on an active shift (for dispatch and tracking).
- Pricing, equipment, and availability information you list.
Automatically:
- Device and browser type, IP address (for rate-limiting and security).
- Session cookie (signed, httpOnly) — used only for keeping you logged in.
2. How we use your data
- To match you with the nearest available ambulance with the right equipment.
- To dispatch your booking to the Provider and share pickup/drop with the driver.
- To alert your saved emergency contacts with a live tracking link (SOS bookings only).
- To verify Provider identity and keep the marketplace trustworthy.
- To operate, secure, and improve the Platform.
- To contact you for account recovery or service updates.
3. Who sees your data
- Provider and assigned driver — only for the specific booking you place (your phone, name, pickup/drop, patient condition, notes).
- Your emergency contacts — if you add them and place an SOS booking, they receive a location tracking link.
- TEZride admin — for Provider document verification, complaint handling, and platform security.
- Service providers we use: Neon (database hosting), Netlify (web hosting), Resend (password-reset emails), OpenStreetMap and Photon (map tiles and geocoding). Each handles only what it needs for its function.
- We do not sell your personal data to advertisers or data brokers.
4. Data retention
- Booking records: retained for 7 years (tax + dispute resolution).
- Provider verification documents: retained for the life of the Provider account plus 7 years after deletion.
- Driver location data: retained for 30 days, then aggregated/anonymised.
- Session cookies: expire automatically.
- Password reset tokens: expire in 30 minutes.
5. Your rights (under DPDP Act, 2023)
- Access: request a summary of the personal data we hold about you.
- Correct: fix inaccurate data.
- Delete: request deletion (we may retain data required by law).
- Withdraw consent: stop processing your data (which may mean closing your account).
- Grievance: escalate complaints unaddressed within 30 days to the Data Protection Board of India.
To exercise any of these, email support@swedana.in.
6. Security
Passwords are hashed with bcrypt. Sessions are HMAC-signed. Data in transit uses HTTPS. Database and backups are encrypted at rest by our hosting provider. Despite these controls, no online service is 100 % secure; we will notify you of any breach affecting your data within 72 hours, as required by the DPDP Act.
7. Children
Users under 18 may be patients (e.g. neonatal and pediatric transport) but must not create bookings themselves. An adult guardian must place the booking.
8. Cookies
We use essential cookies only — a signed session cookie to keep you logged in, and an admin session cookie for platform administrators. We do not use third-party advertising or analytics cookies.
9. Changes
We may update this Privacy Policy. Material changes will be announced on the Platform. Your continued use after an update constitutes acceptance of the revised Policy.
10. Contact
Grievance Officer: support@swedana.in