Privacy Policy
Effective: 2026-07-01
A R Courier and Cargo Services, operating under the brand name "Deliver Hub" ("we", "us"), respects your privacy. This policy explains what personal data we collect, why, and your rights under the Digital Personal Data Protection Act, 2023.
1. Data We Collect
- Account data: name, email, phone, password (hashed), business details.
- KYC data: PAN, GSTIN, bank account, business address, uploaded documents. Sensitive KYC data is encrypted at rest.
- Shipment data: pickup and delivery addresses, item descriptions, weight, dimensions, COD amounts.
- Recipient data: buyer name, address, and phone — collected on your behalf as the shipper and passed to courier partners for delivery.
- Payment data: wallet transactions, invoice records. Card details are handled by our PCI-compliant payment processor and never stored on our servers.
- Usage data: log files, IP addresses, device info, and browser fingerprint for security and analytics.
2. How We Use Data
- To provide, maintain, and improve the service.
- To share shipment data with courier partners so they can deliver.
- To verify your identity (KYC) and comply with legal obligations (GST, AML).
- To detect fraud, abuse, and prohibited shipments.
- To communicate service updates, security alerts, and (with consent) marketing emails.
3. Data Sharing
We share data with: (a) courier partners (only what they need to deliver), (b) payment processors, (c) KYC verification providers (Digilocker, penny-drop banks), (d) cloud infrastructure providers (AWS), and (e) law enforcement when legally required.
4. Data Retention
Account and shipment data is retained for the duration of your account plus 7 years thereafter (as required for GST and business records). KYC data is retained per RBI/FIU-IND requirements. You may request deletion of unretained data at any time.
5. Your Rights
Under the DPDP Act you have the right to: access your data, correct inaccuracies, request deletion (subject to retention obligations), withdraw consent, and file grievances. Contact privacy@deliverhub.in to exercise these rights.
6. Security
We use AES-256 encryption for secrets at rest, TLS 1.3 for all data in transit, role-based access controls, and immutable audit logs. No system is 100% secure — we recommend using a strong unique password and enabling MFA.
7. Data Transfers
Our infrastructure is hosted in AWS ap-south-1 (Mumbai). We may transfer data to other AWS regions for backup and disaster recovery, subject to safeguards required by Indian law.
8. Grievance Officer
For grievances under the DPDP Act, contact our Grievance Officer at grievance@deliverhub.in. We respond within 30 days.
9. Changes
We may update this policy. Material changes will be notified by email at least 15 days before they take effect.