infoAt a Glance: Our Data Commitments
- check_circleZero Data Brokerage: We never sell, rent, or trade your personal or travel data to third parties.
- check_circleAutomated 30-Day GPS Purge: High-frequency live vehicle tracking points are permanently expunged every 30 days.
- check_circleData Sovereignty: Passenger and vehicle records are hosted securely with strict Row-Level Security (RLS) protections.
1Data Fiduciary & Identity
Under the provisions of the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000, the Data Fiduciary responsible for processing personal data on this transit platform is:
Entity: Pather Saathi Transit Technologies
Headquarters: Sribhumi, Barak Valley, Assam - 788710, India
Operational Corridors: Sribhumi • Silchar • Hailakandi • Cachar District Transit
Email Contact: support@pathersaathi.in
Emergency Telephone: +91 6002089037
2Categories of Personal Data Collected
Pather Saathi collects only the minimal personal data necessary to facilitate safe, reliable, and verified transit bookings in Barak Valley:
3Real-Time Vehicle GPS Telemetry & Automated 30-Day Purge
To power real-time bus tracking and arrival time predictions for passengers across the Barak Valley highways, driver devices stream high-frequency GPS coordinates (latitude, longitude, speed, heading, and timestamp) while an active trip run is in progress.
auto_deleteAutomated 30-Day Data Minimization Purge
In strict accordance with DPDPA 2023 data minimization mandates, fine-grained GPS coordinate breadcrumbs recorded in our database table (public.trip_locations) are automatically and permanently deleted after thirty (30) days via a scheduled database maintenance job (purge_stale_trip_locations).
Historical aggregate trip summaries (origin, destination, departure time, and passenger count) are preserved for statutory tax and audit compliance, but high-resolution geographic paths are irreversibly purged.
4Purposes of Data Processing
- Facilitating bus seat reservations and whole-vehicle charters between Sribhumi, Silchar, and Hailakandi.
- Dispatching digital ticket confirmations, PNR vouchers, and trip updates via transactional SMS and WhatsApp.
- Broadcasting active bus locations on public map visualizers for passenger safety and schedule certainty.
- Authenticating passengers and operators using secure email Magic Links, OTPs, and encrypted credentials.
- Broadcasting real-time disruption or schedule cancellation alerts when road conditions or weather impact transit.
5Infrastructure Partners & Strict Non-Sale Clause
We contract only with ISO-certified infrastructure processors that comply with Indian data residency and privacy requirements:
- Supabase: Managed PostgreSQL cloud database, authentication service, and WebSockets realtime GPS channel.
- Vercel Inc.: Application compute, edge network hosting, and Core Web Vitals telemetry.
- Transactional SMS Gateways (Fast2SMS / Twilio): TRAI DLT-registered telecommunication gateways delivering OTP and ticket notifications.
6Your Rights Under DPDPA 2023
As a Data Principal under Indian law, you possess enforceable legal rights regarding your personal information:
Right to Access
You may inspect the summary of personal data and processing activities associated with your account.
Right to Correction
You can correct out-of-date phone numbers, names, or email credentials at any time in your Profile.
Right to Erasure
You may request permanent account deletion and removal of your personal travel history, subject to statutory tax laws.
Right to Grievance Redressal
You are entitled to rapid resolution of data inquiries by our designated officer within 30 statutory days.
7Technical Security Safeguards
We implement comprehensive technical and organizational safeguards:
- Row-Level Security (RLS): Granular PostgreSQL security policies ensuring passengers and fleet operators can only read or write records they legitimately own.
- Transport Layer Encryption: All data in transit is encrypted using 256-bit TLS/SSL certificates with strict HTTPS enforcement.
- PKCE & Cookie Protection: Authentication codes utilize RFC 7636 Proof Key for Code Exchange (PKCE) and HTTP-only, secure, same-site session cookies.
- Cryptographic Password Hashing: Passwords are hashed using modern salted bcrypt algorithms and are never stored in plaintext.
8Protection of Children & Minors
In compliance with DPDPA 2023 Section 9, Pather Saathi does not intentionally track, profile, or solicit personal data from children under the age of 18 without verifiable consent from a parent or legal guardian. Bookings for minors must be arranged and supervised by an adult ticket holder.
9Revisions & Updates to This Policy
We may periodically update this policy to incorporate new transit features, revised statutory guidelines, or regional transit regulations. Whenever changes occur, the "Last Updated" date at the top of this document will be amended, and prominent notices will be displayed on the platform homepage for material modifications.
10Grievance Redressal Officer
Under Section 10 of the Digital Personal Data Protection Act, 2023, if you have any questions, concerns, complaints, or exercise of data rights, you may address our designated Grievance Officer:
Designation: Data Protection & Grievance Redressal Officer
Organization: Pather Saathi Transit Technologies
Office Address: Pather Saathi Transit Center, Station Road, Sribhumi, Barak Valley, Assam - 788710
Email Address: support@pathersaathi.in / grievance@pathersaathi.in
Phone: +91 6002089037 (Monday – Saturday, 9:00 AM – 6:00 PM IST)
Statutory Resolution Timeline: All valid grievances will be acknowledged within 48 hours and definitively resolved within 30 business days.