AUTO-KART PRIVATE LIMITED

CIN: U45200TS2026PTC209701

 

PRIVACY POLICY

Effective Date:

 

 

Auto-Kart Private Limited ("Auto-Kart", "we", "us", or "our") operates a technology-enabled marketplace connecting vehicle owners with mechanics and roadside assistance providers across India (the "Platform"). This Privacy Policy ("Policy") governs how we collect, use, store, share, and protect your personal data when you access or use our Platform.

This Policy applies to: (a) Customers who book services through the Platform; (b) Mechanics/Garages who register and subscribe to the Platform; (c) website visitors; and (d) applicants seeking to join the Platform as Mechanics (together, "Data Principals" or "you").

 

Important Notice:  By registering with or using the Platform, you agree to be bound by this Policy. If you do not agree with any part of this Policy, please do not access or use the Platform.

 

This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Auto-Kart acts as a Data Fiduciary within the meaning of the DPDPA.

 

Clause 1. Definitions

 

 

In this Policy, the following terms have the meanings given below. Capitalised terms not defined here shall bear the meaning assigned to them under the DPDPA or the IT Act, as applicable.

 

"Consent" means a free, specific, informed, unconditional, and unambiguous indication of your agreement to the processing of your Personal Data for a specified purpose, given by a clear affirmative action, as defined under section 2(6) of the DPDPA.

"Data Fiduciary" means a person who alone or in conjunction with other persons determines the purpose and means of processing Personal Data — in this context, Auto-Kart Private Limited.

"Data Principal" means the individual to whom Personal Data relates — in this context, you, the user of the Platform.

"Data Processor" means any person who processes Personal Data on behalf of, and under the instructions of, a Data Fiduciary, including third-party service providers engaged by Auto-Kart.

"Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under section 2(t) of the DPDPA.

"Processing" means an automated operation or set of operations performed on Digital Personal Data, including collection, recording, storage, retrieval, use, sharing, disclosure, or erasure.

"Sensitive Personal Data" means personal data revealing passwords, financial data, health data, official identifiers, sex life, sexual orientation, biometric data, genetic data, caste or tribe, religious or political belief, or any other category notified as sensitive by the Central Government under the SPDI Rules.

"Platform" means the Auto-Kart application, website, and related technology services operated by Auto-Kart Private Limited.

"Significant Data Fiduciary (SDF)" means a Data Fiduciary notified by the Central Government under section 10 of the DPDPA on the basis of volume, sensitivity of data, risk to rights of Data Principals, or other criteria. Auto-Kart will comply with additional SDF obligations if and when so notified.

"Purpose Limitation" means the principle that Personal Data shall be collected only for a specified, explicit, and legitimate purpose and shall not be processed in a manner incompatible with that purpose.

 

Clause 2. Information We Collect

 

 

We collect Personal Data in accordance with the principle of data minimisation - only such data as is adequate, relevant, and necessary for the purpose for which it is collected. The information we collect depends on your role on the Platform.

 

2A. Information Collected from Customers

When you book a service through Auto-Kart, we collect the following categories of Personal Data:

 

2.1   Identity and Contact Information: your name, mobile number, and email address.

2.2   Location Data: your GPS coordinates or the service address you provide at the time of booking, used solely to identify the nearest available Mechanic. See Clause 4 for further detail.

2.3   Vehicle Details: registration number, make, model, year, fuel type, and nature of the reported issue.

2.4   Transaction Information: job value, payment instrument type, payment reference number, and GST details.

2.5   Service History: past bookings, job status, job photographs uploaded by either party during the job, and warranty sign-off records.

2.6   Feedback and Ratings: ratings, written reviews, and complaint submissions you make regarding a Mechanic.

2.7   Device and Usage Data: device type, operating system version, app version, IP address, session timestamps, and clickstream data, collected automatically when you use our app or website. This data is used for security, debugging, and analytics.

2.8   Inferred Data: preferences and behavioural patterns derived from your usage of the Platform (e.g., preferred service types, frequently used locations). This inferred data is used only to personalise your experience and is not shared with third parties for independent profiling.

 

2B. Information Collected from Mechanics

When you register and subscribe to the Platform, we collect:

 

2.9   Identity and KYC Documents: full name, photograph, masked Aadhaar (last four digits only — full Aadhaar numbers are never stored), PAN, and government-issued ID for verification.

2.10   Business Details: garage or business name, trade licence number, GSTIN, and operating address.

2.11   Contact Information: mobile number, WhatsApp number, and email address.

2.12   Real-Time Location: GPS coordinates when the app is active and you are set to "On Duty", used to allocate nearby service leads. See Clause 4.

2.13   Financial Information: bank account number, IFSC code, and UPI ID for processing settlements. This constitutes Sensitive Personal Data under the SPDI Rules.

2.14   Performance and Profiling Data: customer ratings, written reviews, job completion rate, cancellation rate, response time metrics, and upheld complaint count. This data is used to produce a Performance Profile that influences lead allocation and subscription enforcement. See Clause 10.

2.15   Subscription and Billing Records: subscription plan tier, payment history, billing dates, invoice records, and penalty deductions.

2.16   Audit Logs: a timestamped log of all Platform actions taken by your account (job acceptance, cancellation, status changes) is maintained for security, fraud detection, and dispute resolution purposes under the IT Act, 2000.

 

2C. Information Collected from All Users

2.17   Communications Records: records of all support tickets, chat messages, emails, and complaint submissions you make to Auto-Kart, retained for grievance and legal compliance purposes.

2.18   Voluntary Submissions: any additional information you voluntarily provide to us, including through feedback forms, surveys, or applications to join the Platform.

 

2D. Information We Do Not Collect

We do not collect, and you must not submit, the following:

 

2.19   Full Aadhaar card numbers (only the last four digits of masked copies are stored).

2.20   Biometric data such as fingerprints, iris scans, or facial recognition data.

2.21   Health, medical, or genetic data.

2.22   Data revealing caste, religion, political opinion, or trade union membership.

2.23   Children's data: the Platform is not directed at persons under 18 years of age. We do not knowingly collect Personal Data from minors. Persons under 18 must not use the Platform without the supervision of a parent or guardian who accepts this Policy on their behalf.

 

Clause 3. Lawful Basis for Processing

 

 

Under the DPDPA, every instance of processing Personal Data must rest on a lawful basis. Auto-Kart processes your Personal Data on one or more of the following bases, depending on the specific processing activity:

 

3.1   Consent (DPDPA s.6): where you have given us free, specific, informed, unconditional, and unambiguous consent. Consent is obtained at the point of registration via affirmative click-through acceptance of this Policy and, where required, separately for specific activities (e.g., location tracking, marketing communications). You may withdraw consent at any time (see Clause 11.4).

3.2   Legitimate Use (DPDPA s.7): where processing is necessary for the performance of a function of the State, compliance with law, or for purposes reasonably expected by the Data Principal, including safety and security functions, employment-related processing, and research or archiving in the public interest.

3.3   Legal Obligation: where processing is required by applicable law, including retention of financial records under the CGST Act, 2017 (8 years), TCS compliance, and responding to valid orders of courts or regulatory authorities.

3.4   Contract Performance: where processing is necessary to perform our contractual obligations to you under the Terms of Use or the Mechanic Subscription Agreement.

 

The table below maps key processing activities to their lawful basis:

 

Processing Activity

Lawful Basis (DPDPA)

Data Category Involved

Account creation and management

Consent (s.6)

Identity, contact, KYC

Service lead allocation

Consent / Legitimate Use (s.7)

Location, performance data

Payment processing and GST invoicing

Legal Obligation (s.7(b))

Transaction, financial data

KYC and identity verification

Consent / Legal Obligation

KYC documents, PAN, Aadhaar

Operational communications (OTPs, alerts)

Consent / Contract Performance

Contact information

Marketing communications

Consent (s.6) — opt-in only

Contact information

Fraud and revenue leakage detection

Legitimate Use (s.7)

Location, transaction, usage

Grievance and dispute resolution

Legal Obligation / Legitimate Use

All relevant categories

Analytics and Platform improvement

Consent / Legitimate Use

Pseudonymised usage data

Compliance with court/statutory orders

Legal Obligation (s.7(b))

As directed by authority

 

Clause 4. Purpose Limitation and Data Minimisation

 

 

4.1   Purpose Limitation: Personal Data collected for a specified purpose shall not be processed for any purpose incompatible with the original purpose, without obtaining fresh consent or establishing a separate lawful basis. We will not use your vehicle data for insurance marketing, your location history for advertising, or your financial information for any purpose other than settlement processing, without your explicit consent.

4.2   Data Minimisation: We collect only such Personal Data as is adequate, relevant, and not excessive in relation to the purpose for which it is processed. Each data category described in Clause 2 is collected because it is necessary for a specific, identified function of the Platform.

4.3   Accuracy Obligation: Auto-Kart shall take reasonable steps to ensure that the Personal Data we hold is accurate, complete, and kept up to date, having regard to the purpose for which it is being processed (DPDPA s.8(3)). You are responsible for keeping your account information current. We provide in-app tools for you to correct your own information at any time.

4.4   Storage Limitation: Personal Data shall not be retained for longer than is necessary for the purpose for which it was collected, subject to applicable legal retention obligations. Specific retention periods are set out in Clause 6.

 

Clause 5. Location Data

 

 

5.1  Customers. We collect your location at the time of booking only to identify the nearest available Mechanic and to dispatch them to your vehicle. We do not persistently track or store your location data after the job is marked complete or cancelled.

 

5.2  Mechanics. We collect your real-time GPS coordinates when the app is active and your status is "On Duty". This data is used to: (a) allocate service leads based on proximity; (b) display your estimated arrival time to the Customer during an active job; and (c) verify job-completion location for audit and dispute purposes. Location tracking ceases automatically when you switch to "Off Duty" or close the application. Raw location data is retained for 30 days from the relevant job date and then permanently deleted; aggregated and anonymised location metrics may be retained for Platform analytics.

 

5.3  Consent and Revocation. Location access is sought via your device's operating system permission prompt and requires your affirmative grant. You may revoke location permission at any time through your device settings. Revocation will: (i) for Mechanics - prevent lead allocation while Off Duty status cannot be verified; (ii) for Customers - may prevent booking completion where a service address cannot be confirmed. Revocation does not affect Personal Data already collected prior to revocation.

 

5.4  No Background Tracking. We do not collect location data when the app is running in the background and you are not actively using the Platform or assigned to a live job.

 

Clause 6. Retention of Personal Data

 

 

6.1  General Principle. Personal Data shall be retained only for so long as is necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law. On expiry of the applicable retention period, data will be securely deleted or irreversibly anonymised.

 

6.2   Customer Account Data: duration of your active account plus 3 years after account closure or last activity, whichever is later.

6.3   Mechanic Account Data: duration of your active subscription plus 5 years after subscription termination.

6.4   Job and Service Records (including photographs and sign-offs): 5 years from the date of job completion.

6.5   Payment and GST Records: 8 years, as mandated by section 35 of the CGST Act, 2017 and section 44AA of the Income Tax Act, 1961.

6.6   KYC Documents (Mechanic): 5 years after subscription termination, in compliance with applicable anti-money laundering and KYC norms.

6.7   Location Data (raw GPS logs): 30 days from the relevant job date, then permanently deleted. Aggregated, anonymised analytics derived from location data: 36 months.

6.8   Customer Support and Complaint Records: 3 years from the date of resolution.

6.9   Audit Logs (IT Act compliance): 180 days (6 months), as required under Rule 3(1)(j) of the IT Intermediary Guidelines Rules, 2021; extended to 365 days where a grievance or investigation is pending.

6.10   Website Visitor and Cookie Data: 13 months from the date of collection.

6.11   Consent Records: retained for the duration of the relationship plus 3 years, as evidence of the lawful basis for processing.

 

6.12  Deletion on Request. We will process a valid deletion request within 90 days of receipt, subject to legal retention obligations. Data subject to a mandatory retention period will be flagged as 'deletion pending' and deleted promptly upon expiry of that period. We will confirm completion of deletion to you in writing.

6.13  Anonymisation. Where we anonymise Personal Data (rendering it no longer capable of identifying you), such anonymised data falls outside the scope of this Policy and may be retained and used indefinitely for analytics, research, and Platform improvement.

 

Clause 7. Sharing Your Personal Data

 

 

7.1  No Sale of Data. We do not sell, trade, rent, or otherwise transfer your Personal Data to any third party for their independent commercial use. Any sharing is strictly limited to what is described in this Clause 7.

 

7A. Between Customers and Mechanics

When a booking is confirmed, we share limited information between the parties solely to enable service delivery:

 

7.2   Customers may see: the Mechanic's name, photograph, rating score, garage name, approximate distance, and real-time GPS location during the active job only.

7.3   Mechanics may see: the Customer's name, masked mobile number (where technically possible), vehicle details, service address, and job description.

 

This sharing ceases automatically on job completion or cancellation. Neither party may use the other party's Personal Data for any purpose other than the immediate service engagement, and any such misuse constitutes a breach of this Policy and applicable law.

 

7B. With Data Processors (Third-Party Service Providers)

We engage Data Processors who process Personal Data on our behalf and under our written instructions. Auto-Kart remains responsible as Data Fiduciary for all processing by its Data Processors. All Data Processors are bound by written data processing agreements that require: (a) processing only on documented instructions from Auto-Kart; (b) equivalent security standards; (c) confidentiality obligations; and (d) assistance with Data Principal rights requests.

 

7.4   Cloud Hosting Providers: for secure storage and processing of Platform data within India.

7.5   Payment Aggregators (e.g., Razorpay, PhonePe): for processing Customer payments and Mechanic settlement disbursements. Financial data shared with these providers is governed by their own PCI-DSS compliant privacy frameworks.

7.6   KYC and Identity Verification Partners: for document verification, PAN validation, and GSTIN lookup during Mechanic onboarding.

7.7   Communication Service Providers: SMS gateways, WhatsApp Business API providers, and email delivery services, used for OTPs, booking confirmations, invoices, and renewal reminders.

7.8   Analytics Providers: for understanding navigation patterns on the Platform. Only pseudonymised data is shared with analytics providers; no directly identifying information is transmitted.

7.9   Legal and Audit Advisors: where necessary for litigation support, regulatory compliance, or statutory audits, subject to professional confidentiality obligations.

 

7C. When Required by Law

We may disclose Personal Data when: (a) required by a court order, statutory obligation, or direction of a competent authority; (b) necessary to protect the rights, property, or safety of Auto-Kart, our users, or the public; or (c) required to assist law enforcement under applicable law. Where legally permissible, we will notify you before making such disclosure so that you may seek a protective order.

 

7D. Business Restructuring

If Auto-Kart undergoes a merger, acquisition, sale of assets, or corporate restructuring, your Personal Data may be transferred to the successor entity. The successor will be contractually required to assume obligations equivalent to those in this Policy. We will notify you at least 30 days before any such transfer takes effect, where legally permissible.

 

7E. Cross-Border Transfers

7.10   As of the effective date of this Policy, all Personal Data is stored and processed on servers located within India.

7.11   If we propose to transfer Personal Data outside India in the future, we will do so only in compliance with section 16 of the DPDPA and any applicable cross-border transfer rules notified by the Central Government.

7.12   Permitted transfer mechanisms may include: (a) transfer to countries notified as adequate by the Central Government; (b) transfer subject to standard contractual clauses approved under the DPDPA; or (c) transfer with the explicit consent of the Data Principal. We will update this Policy at least 30 days before any cross-border transfer takes effect.

 

Clause 8. Cookies and Tracking Technologies

 

 

We use cookies and similar tracking technologies (collectively, "Cookies") on our website to operate the Platform, remember your preferences, and analyse usage patterns.

 

8.1   Strictly Necessary Cookies: essential for the Platform to function (login session management, CSRF security tokens, load balancing). These Cookies cannot be disabled as they are technically required for service delivery.

8.2   Functional Cookies: remember your preferences such as language selection, login state, and display settings. Active for up to 12 months.

8.3   Analytics Cookies: used to understand how visitors navigate the website, which pages are most visited, and how users arrive at the Platform. These Cookies are activated only upon your affirmative consent and are retained for 13 months.

8.4   Marketing and Targeting Cookies: used to display relevant advertisements on third-party platforms (e.g., Google, Meta). These Cookies require your explicit opt-in consent and are retained for 13 months. You may opt out at any time.

 

8.5  Consent Mechanism. On your first visit to our website, a Cookie consent banner is displayed. Your consent choices are recorded with a timestamp and can be reviewed or changed at any time via the Cookie Settings link in the website footer. Consent records are retained for 3 years (see Clause 6.11).

8.6  Managing Cookies. You may also manage Cookies through your browser settings. Note that disabling Strictly Necessary Cookies will prevent the Platform from functioning. Disabling Analytics or Marketing Cookies will not affect core Platform functionality.

8.7  Do Not Track. Our Platform currently does not respond to browser "Do Not Track" signals. We will update this Policy if our practice changes.

 

Clause 9. Security of Personal Data

 

 

9.1  Security Measures. We implement appropriate technical, organisational, and physical safeguards to protect Personal Data against unauthorised access, disclosure, alteration, or destruction, including:

 

9.2   Encryption of Personal Data in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent.

9.3   Role-based access controls (RBAC) ensuring that only authorised personnel can access Personal Data strictly on a need-to-know basis.

9.4   Multi-factor authentication (MFA) for all Platform administrative accounts.

9.5   Regular automated vulnerability scanning and periodic third-party penetration testing (at least annually).

9.6   Secure deletion and irreversible anonymisation protocols applied at the end of the applicable retention period.

9.7   Mandatory confidentiality and data protection obligations in all employment contracts, contractor agreements, and third-party service provider agreements.

9.8   A documented Information Security Policy, reviewed at least annually or on any material change to our processing activities.

 

🔔 Personal Data Breach Notification:  In the event of a Personal Data breach that is likely to result in a risk to your rights, we will notify you and report the breach to the Data Protection Board of India as soon as reasonably practicable, and in any event within the timeframe prescribed by the DPDPA and the Rules thereunder (Rules not yet in force as of the effective date of this Policy; we will update this notice when prescribed timelines are published). Notification will include the nature of the breach, categories of data affected, and remedial steps taken.

 

9.9  Your Responsibility. You are responsible for maintaining the confidentiality of your account credentials (username and password). You must not share your login credentials with any third party. You agree to notify us immediately at privacy@autokart.in if you become aware of any unauthorised use of your account. Auto-Kart is not liable for losses arising from your failure to safeguard your credentials.

9.10  Security Limitation. No method of internet transmission or electronic storage is completely secure. While we implement all commercially reasonable security measures, we cannot guarantee absolute security against factors beyond our reasonable control, including sophisticated cyberattacks or force majeure events.

 

Clause 10. Automated Decision-Making and Profiling

 

 

10.1  Profiling of Mechanics. Our Platform generates a Performance Profile for each Mechanic comprising: customer ratings, review sentiment, job completion rate, cancellation rate, response time, and upheld complaint count. This Performance Profile influences lead allocation priority, enforcement of the Mechanic Subscription Agreement, and — in cases of threshold breach — may trigger a review process.

10.2  Automated Systems. Our Platform uses automated systems for: (a) lead allocation — assigning jobs to Mechanics based on proximity, availability, and Performance Profile score; (b) performance threshold monitoring — automatically flagging accounts where defined thresholds are breached; and (c) fraud and revenue leakage detection — identifying unusual patterns such as off-platform job diversion or unusually high cancellation rates.

 

Human Review Guarantee:  No significant decision that adversely affects your subscription benefits — including suspension, demotion, or termination of subscription — is taken by automated means alone. Every adverse action involves a mandatory human review step by Auto-Kart personnel, and you will receive written notice with an opportunity to respond before any action is finalised, in accordance with the Mechanic Subscription Agreement.

 

10.3  Right to Contest Automated Decisions. If you believe that an automated decision affecting your account is incorrect or unfair, you may contact our support team at privacy@autokart.in. We will arrange a human review of the relevant decision within 15 working days and communicate the outcome to you in writing.

10.4  Customer Profiling. We derive limited inferences from Customer usage data (e.g., preferred service types, frequently visited areas) solely to personalise service recommendations. This inferred data is not shared with third parties and is not used to make decisions that adversely affect your access to the Platform.

 

Clause 11. Your Rights as a Data Principal

 

 

Under the DPDPA and other applicable law, you have the rights described in this Clause 11. To exercise any of these rights, contact us at privacy@autokart.in. We will acknowledge your request within 48 hours and respond substantively within 30 days (or such shorter period as may be prescribed). We will verify your identity before acting on any rights request.

 

11.1  Right to Access. You may request: (a) confirmation of whether we hold Personal Data about you; (b) a summary of the Personal Data we hold and the purposes for which it is being processed; and (c) a list of the entities or categories of entities with whom your Personal Data has been shared. We will provide this information in a clear, readable format.

11.2  Right to Correction and Completion. You may request correction of inaccurate Personal Data and completion of incomplete Personal Data. You may update most information directly in your account settings. Where a correction has legal implications (e.g., correcting KYC data), we may require supporting documentation before acting.

11.3  Right to Erasure. You may request deletion of your Personal Data where: (a) the purpose for which it was collected is no longer served; (b) you have withdrawn consent and there is no other lawful basis for retention; or (c) the data is being processed unlawfully. Erasure will be subject to any mandatory legal retention obligations (see Clause 6). We will delete data within 90 days of a valid erasure request and confirm completion to you.

11.4  Right to Withdraw Consent. Where processing is based on your consent, you may withdraw that consent at any time through your in-app settings or by emailing privacy@autokart.in. Withdrawal is prospective only — it does not affect the lawfulness of processing carried out before withdrawal. Withdrawal may affect your ability to access certain features of the Platform (e.g., revoking location consent will affect lead allocation for Mechanics).

11.5  Right to Data Portability. To the extent required by the DPDPA and Rules thereunder (when notified), you may request that we provide your Personal Data in a commonly used, machine-readable format to enable transfer to another service provider.

11.6  Right to Grievance Redressal. You have the right to a prompt and effective remedy for any privacy-related concern. Please refer to Clause 17 for the grievance redressal process. If your complaint is not resolved within 30 days, you may escalate to the Data Protection Board of India.

11.7  Right to Nominate. You may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity. To register a nominee, please contact privacy@autokart.in for the nomination form.

 

Identity Verification:  To protect against unauthorised access to your data, all rights requests must be accompanied by identity verification. We may request: (a) confirmation of your registered email or mobile number via OTP; (b) a scanned copy of a government-issued ID for requests of a sensitive nature; or (c) any other verification reasonably required. We will not process rights requests that cannot be verified.

 

Clause 12. Third-Party Links and Services

 

 

12.1  The Platform may contain hyperlinks to third-party websites, payment gateways, and social media platforms. Auto-Kart is not responsible for the privacy practices, security, or content of those third-party services.

12.2  Your financial information entered on third-party payment platforms (e.g., Razorpay, PhonePe) is processed under their own PCI-DSS compliant privacy frameworks. We encourage you to review their privacy policies before completing any payment.

12.3  Once you navigate away from the Auto-Kart Platform, our obligations under this Policy do not extend to any third-party service or website you visit.

12.4  Auto-Kart is not liable for any loss or damage arising from your interaction with third-party services linked from our Platform.

 

Clause 13. Public Content and Reviews

 

 

13.1  Ratings, reviews, and comments you post on the Platform may be visible to other users and, where indicated, to the general public. Your first name and last initial may be displayed alongside your review.

13.2  You must not include Sensitive Personal Data or the Personal Data of third parties in your public reviews or comments. Auto-Kart is not liable for Personal Data you choose to disclose publicly on the Platform.

13.3  To request removal of a review or public comment, contact us at privacy@autokart.in. We will process the request within 30 days, subject to our content moderation policies and any applicable legal requirements.

 

Clause 14. Alerts and Communications

 

 

We may contact you by SMS, WhatsApp, email, or in-app notification for the following purposes:

 

14.1   Transactional Communications (cannot be opted out of): booking confirmations, job updates, OTPs, receipts, GST invoices, subscription renewal reminders, payment receipts, account security alerts, and Policy change notifications.

14.2   Promotional Communications (consent required; opt-out available): offers, discounts, new feature announcements, and marketing campaigns. These are sent only where you have given prior consent and may be unsubscribed from at any time.

 

14.3  Opt-Out. You may withdraw consent for promotional communications at any time by: (a) using the unsubscribe link in any marketing email; (b) adjusting your notification preferences in-app; or (c) emailing privacy@autokart.in. Opt-out will take effect within 10 working days. Transactional messages will continue while your account is active, as they are necessary for service delivery.

14.4  DND Compliance. Where you have registered your mobile number on the TRAI Do Not Disturb (DND) registry, we will respect DND preferences for promotional SMS communications. Transactional SMS messages are exempt from DND restrictions under TRAI regulations.

 

Clause 15. Children

 

 

15.1  The Platform is not directed at persons under 18 years of age. We do not knowingly collect Personal Data from minors.

15.2  If you are under 18, you must not register on or use the Platform independently. If you use the Platform with the assistance of a parent or guardian, that parent or guardian accepts this Policy on your behalf and is responsible for all data submitted through the account.

15.3  If a parent or guardian believes that their child has independently submitted Personal Data to us, they should contact privacy@autokart.in immediately. We will delete such data without undue delay upon verification of the request.

15.4  Verifiable Parental Consent. Section 9 of the DPDPA requires Data Fiduciaries to obtain verifiable consent of a parent or lawful guardian before processing a child's Personal Data, once this provision is brought into force and the manner of verification is prescribed by the Central Government. Ahead of this provision taking effect, we are developing a verification mechanism (which may include OTP-based confirmation of the parent's or guardian's identity, or such other method as may be prescribed) to confirm that consent given on behalf of a child has genuinely been given by a parent or lawful guardian. We will implement this mechanism, and update this Policy accordingly, by the date on which Section 9 of the DPDPA comes into force.

 

Clause 16. Changes to This Policy

 

 

16.1  We may update this Policy from time to time to reflect changes in applicable law, our data processing practices, or the services we offer. All updated versions will be posted on our Platform with the revised effective date and version number.

16.2  For material changes - those that significantly affect how we process your Personal Data, expand the categories of data collected, add new sharing arrangements, or reduce your rights — we will provide at least 15 days' prior notice by email or in-app notification. Where required by the DPDPA, we will seek fresh consent before any material change takes effect.

16.3  For non-material changes (e.g., corrections, clarifications, or administrative updates), the revised Policy will take effect on the posted effective date without advance notice.

16.4  Your continued use of the Platform after the effective date of any revised Policy constitutes your acceptance of the updated terms to the extent permitted by applicable law. If you do not agree to a material change, you must stop using the Platform before the change takes effect and may request deletion of your data under Clause 11.3.

16.5  An archive of prior versions of this Policy will be maintained and made available upon request by contacting privacy@autokart.in.

 

Clause 17. Grievance Officer and Redressal

 

 

In the event of any discrepancy, concern, or grievance relating to your Personal Data or the manner in which it is handled, you may contact our Grievance Officer. The Grievance Officer is a senior individual appointed pursuant to Rule 3(2) of the IT Intermediary Guidelines Rules, 2021 and the DPDPA.

 

Grievance Officer

 

Designation

Grievance Officer / Data Protection Contact, Auto-Kart Private Limited

Email

privacy@autokart.in

Phone

+91-___________ (Monday to Friday, 10:00 AM – 6:00 PM IST)

Postal Address

Auto-Kart Private Limited, H.No 2-41, Near Hanuman Temple, Keesara, Nagaram, Hyderabad – 500083, Telangana

Acknowledgement Timeline

Within 48 hours of receipt of grievance

Resolution Timeline

Within 30 days of receipt, or such shorter period as may be prescribed

 

17.1  Grievance Process. On receipt of a grievance, the Grievance Officer will: (a) acknowledge receipt within 48 hours; (b) investigate the matter and provide a substantive response within 30 days of receipt; and (c) where the grievance is upheld, take appropriate remedial action and notify you of the steps taken.

17.2  Escalation to the Data Protection Board. If your grievance is not resolved to your satisfaction within 30 days, you may escalate the matter to the Data Protection Board of India (Board) established under section 18 of the DPDPA. Details of the Board's complaint mechanism will be updated on this page once the Board is constituted and its procedures are published.

17.3  Escalation to CERT-In. For matters involving a data security incident or breach, you may also report to the Indian Computer Emergency Response Team (CERT-In) under the IT Act, 2000.

 

Clause 18. Your Consent

 

 

18.1  By registering with and using the Platform, you expressly consent to our collection, processing, storage, and sharing of your Personal Data as described in this Policy. Your consent is specific, informed, and voluntarily given by your affirmative act of registration and use.

18.2  Where separate consent is required for specific processing activities (e.g., location tracking, marketing communications, Analytics Cookies), such consent is sought separately at the relevant point of interaction and is independent of your general consent to this Policy.

18.3  You may withdraw consent at any time as described in Clause 11.4. Withdrawal of consent does not affect any processing lawfully carried out prior to withdrawal.

 

Clause 19. Governing Law and Jurisdiction

 

 

19.1  This Policy is governed by the laws of the Republic of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and all regulations and rules made thereunder.

19.2  Subject to Clause 19.3, any dispute arising from or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of competent jurisdiction at Hyderabad, Telangana.

19.3  Nothing in this Clause 19 limits your right to bring a complaint before the Data Protection Board of India or any other regulatory authority having jurisdiction under applicable law.

 

Clause 20. General Provisions

 

 

20.1  Entire Agreement. This Policy, together with the Terms of Use and the Mechanic Subscription Agreement (where applicable), constitutes the entire agreement between Auto-Kart and you with respect to the collection, processing, and protection of your Personal Data.

20.2  Conflict. In the event of any conflict between this Policy and the Terms of Use or the Mechanic Subscription Agreement with respect to privacy and data protection matters, this Policy shall prevail.

20.3  Assignment. You may not assign your rights or obligations under this Policy to any third party without Auto-Kart's prior written consent. Auto-Kart may transfer its rights under this Policy to a successor entity in connection with a corporate restructuring, without requiring your separate consent, provided the successor assumes equivalent data protection obligations.

20.4  Severability. If any provision of this Policy is found by a court of competent jurisdiction to be unlawful, void, or unenforceable, that provision shall be severed from the remaining provisions, which shall continue in full force and effect.

20.5  Waiver. Any failure or delay by Auto-Kart to enforce any provision of this Policy shall not constitute a waiver of that provision or any other provision of this Policy.

20.6  Language. This Policy is drafted in English. If translated into any other language for convenience, the English version shall prevail in the event of any inconsistency.

20.7  Notices. All notices to Auto-Kart under this Policy should be addressed to privacy@autokart.in or to the registered address set out in Clause 17.

20.8  Force Majeure. Auto-Kart is not liable for any failure to comply with this Policy to the extent such failure is caused by a force majeure event, including acts of God, cyberattacks by state or non-state actors, natural disasters, government orders, or other circumstances beyond our reasonable control, provided we take all commercially reasonable steps to mitigate the impact.

 

 

This Policy has been prepared for Auto-Kart Private Limited  |  CIN: U45200TS2026PTC209701

Effective from the date first stated above  |  Version 2.1  |  Supersedes Version 2.0

© Auto-Kart Private Limited. All Rights Reserved.