Drafting note — remove before publishing. Replace every bracketed placeholder. Every statement here must match (a) what the Rider app's code and third-party SDKs actually do, (b) your Apple App Privacy “Nutrition Label,” and (c) your Google Play Data Safety form — the store forms for the Rider app are separate from the customer app's. This is a workforce app: because use is a condition of employment, consent is generally NOT the lawful basis for core processing (see Section 4). Have an employment/data-protection lawyer review the final version. This template is not legal advice.
This Privacy Notice explains how PINIT LLP (“Pinit,” “we,” “us,” “our”) and, where you are employed by an authorized Pinit franchise or Pinit directly, that franchise entity (together, your “Employer”), collect, use, share, and protect information when you use the Pinit Rider application (the “Rider App”) as part of your work as a Pinit rider.
The Rider App is a work tool for authorized Pinit riders only. It is not a consumer app. Because operating it is a condition of your role, most processing described here is necessary to perform your employment contract and to run our logistics operation — not something you “opt in” to. Where the law does require your consent for a specific feature, we ask for it separately and you can decline that feature without losing your job.
1. Who is responsible for your data (Data Fiduciary / Controller)
The entity responsible for your personal data depends on which Pinit entity or franchise employs you:
- Employing entity: your Employer as named in your employment/engagement letter.
- Platform operator: PINIT LLP, which provides the Rider App and central systems.
- Registered address: 4th Floor, 8-2-309/3/B/1 & 8-2-309/3/B/2, Road no.14 Banjara Hills, Hyderabad, Telangana 500034
- Contact: admin@pinitsarees.com • HR: +91 8688361661
- Where Pinit and a franchise jointly determine how your data is used, we act as joint data fiduciaries and each remain accountable for the parts we control. Your HR/employment records are separately governed by your Employer's HR privacy notice.
2. Summary of key points
- What we collect: your rider identity and employment identifiers, precise location while you are on an active shift or task, trip and delivery records, cash-collection and reconciliation records, proof-of-delivery and damage photos, in-app/masked call records, device and diagnostic data, and performance metrics.
- Why: to assign and route tasks, verify deliveries and cash handling, keep you and the goods safe, calculate pay and incentives, and meet legal and tax obligations.
- Location: collected only while you are clocked in to an active shift or task — not off-shift, and not in the background when you are off duty.
- Automated decisions: performance scores can feed pay, incentive, and disciplinary processes. You have a right to human review (Section 12).
- Who we share with: your Employer/franchise, our payment gateway Razorpay, service providers and SDK vendors, and authorities where legally required. We do not sell your data.
- Your control: you can access and correct your data and raise a grievance. Some employment and financial records must be retained by law even after you leave (Section 8).
3. Information we collect
3.1 Information you or your Employer provide
| Category | Examples | Required? |
|---|---|---|
| Rider identity & employment data | Name, rider/employee ID, photo, phone, assigned zone/franchise, vehicle details, shift roster | Required for the role |
| Onboarding & compliance data | Driving licence, ID/KYC references, background-check status, bank/UPI details for salary and cash settlement | Required by law/role |
| Attendance & shift data | Clock-in/clock-out, shift check-in photo (if enabled), break records | Required for the role |
| Support data | Messages, tickets, and attachments you send to rider support | Optional |
3.2 Information collected while you use the Rider App
| Category | Examples |
|---|---|
| Precise location (on-shift only) | GPS coordinates while clocked in to an active shift or task, used for routing, live tracking, and proof of visit |
| Derived movement metrics | Idle/wait time and ETA / arrival-performance scoring computed from your on-shift location and timestamps |
| Trip & task records | Assigned suitcases/orders, pickup and drop timestamps, route taken, distance, status updates |
| Cash & settlement records | Cash collected, amounts reconciled, shortfalls/overages, settlement status |
| Proof-of-delivery & damage media | Photos you capture at handover or for a damage/return claim |
| Communication records | Masked/in-app calls to customers (metadata such as time and duration; content only if recorded and disclosed) |
| Motion / activity | Device motion/activity signals used for trip detection and safety features |
| Device & diagnostics | Device model, OS version, app version, unique device/installation ID, crash logs, network/IP, battery for reliability |
3.3 Device permissions we request
We ask for these only for the feature described, and only after your device prompts you. Declining a permission may prevent you from performing tasks that require it, which can affect your ability to work a shift.
| Permission | Why we use it | If declined |
|---|---|---|
| Camera | Proof-of-delivery photos and damage/return evidence; shift check-in (if enabled) | You cannot complete tasks that require photo capture |
| Phone / calls | Contact customers via masked or in-app calling for pickups and deliveries | You cannot reach customers through the app |
| Bluetooth | Connect to receipt printer / handheld scanner / POS | Connected-device features unavailable |
| Motion & activity | Detect trips/movement for routing accuracy and safety alerts | Reduced trip-detection accuracy |
| Notifications | Task assignments, slot reminders, safety and operational alerts | You may miss assignments and alerts |
| Precise location | Live routing and proof-of-visit while on an active shift/task (foreground; and while-in-use only during a shift) | You cannot be assigned or tracked for tasks |
4. Lawful basis and why consent is usually not the basis
Because using the Rider App is a condition of your engagement, we do not rely on your “consent” for core processing; consent that you cannot freely refuse is not valid. Instead we rely on:
- Performance of your employment/engagement contract — assigning tasks, routing, delivery verification, pay and settlement.
- Legitimate interests / legitimate business operation — security of high-value goods and cash, fraud prevention, safety, and service quality.
- Legal obligation — tax, payroll, labour, and record-keeping requirements.
- Consent — only for optional, non-essential features (e.g., [optional wellness features]); you may withdraw it without affecting your employment.
Under India's Digital Personal Data Protection Act, 2023, we process your data for these lawful purposes and for the legitimate uses the Act permits in an employment context. Where GDPR/UK GDPR applies to any rider, the equivalent bases are contract, legitimate interests, and legal obligation.
5. How we use your information
- Assign, route, and track shifts, suitcase bookings, and deliveries.
- Verify proof of delivery and reconcile cash/deposit/COD collection.
- Calculate pay, incentives, penalties, and adjustments.
- Keep riders and goods safe, detect fraud/theft, and investigate incidents.
- Measure and improve operational performance and app reliability.
- Communicate assignments, reminders, and safety and compliance notices.
- Comply with legal, tax, and regulatory obligations.
6. Location data — specifics
- When: only while you are clocked/Scan in, in to an active shift or task. Location collection stops when you clock out or scan out.
- Precision: precise GPS, needed for routing and proof-of-visit.
- Derived data: we compute idle/wait time and ETA / arrival-performance scores from your location and timestamps.
- Not collected: we do not track your location off-shift or continuously in the background when you are off duty.
- Retention of location trails: 90 days for raw trails
8. Third-party services and SDKs
The Rider App includes third-party tools that may process data. Keep this list accurate — it must match the Rider app's store disclosures.
| Provider | Purpose | Data involved |
|---|---|---|
| [Firebase / Google Analytics] | Analytics, crash reporting | Device IDs, usage, diagnostics |
| [Crashlytics / Sentry] | Crash diagnostics | Device, crash logs |
| Razorpay | Payout & cash-settlement processing | Transaction details, contact/bank info |
| [Maps / routing provider] | Navigation and routing | Location, device data |
| [Push provider] | Task and safety notifications | Push tokens, device IDs |
| [Cloud provider, e.g., AWS/GCP] | Hosting | All stored data |
| [Call-masking provider] | Customer calls | Phone numbers, call metadata |
Drafting note — remove before publishing. List EVERY SDK in the Rider build. The Rider app should not contain any advertising SDK; if one is present, remove it or disclose it. Undisclosed SDK collection is the leading cause of store rejection. This list is expected to be similar to the customer app but is NOT identical — verify against the Rider build.
9. Data retention
| Data | Retention |
|---|---|
| Rider profile & app account | For the duration of engagement; deactivated on offboarding, then deleted/anonymized within [30–90] days except records below |
| Location trails | [LOCATION_RETENTION_PERIOD] |
| Trip / delivery records | [e.g., 24 months] for operations and dispute resolution |
| Cash & settlement records | 7 years for tax, accounting, and legal compliance |
| Payroll / statutory HR records | As required by labour and tax law |
| Proof-of-delivery / damage media | [e.g., 12–24 months] or until the related claim is resolved |
| Support tickets | [24] months |
| Logs & diagnostics | [90] days |
10. Data security
We use administrative, technical, and physical safeguards — encryption in transit (TLS) and at rest, access controls, least-privilege, and logging. On company-managed devices we may enforce security via mobile device management (MDM). No system is perfectly secure; if a breach affecting your data occurs, we will notify you and regulators as required by law.
11. Company and personal (BYOD) devices
Riders use a mix of company-issued and personal (BYOD) devices. On any device, the Rider App only accesses work-related data — tasks, on-shift location, and the permissions in Section 3.3. We do not access your personal photos, messages, contacts, or browsing.
- Company devices: may be managed by MDM; we can enforce security policies and remotely wipe the work profile/app.
- Personal devices: we manage only the Rider App and its work data; on offboarding we deactivate the account and remove work data, and you should uninstall the app.
12. Automated decision-making and monitoring
We use performance metrics — including on-time / ETA scores, idle time, completion and reconciliation rates that can feed pay, incentive, and disciplinary decisions. Where a decision produces a significant effect on you:
- A human reviews it before any final disciplinary or pay-reduction outcome.
- You have the right to request human review, an explanation of the main factors, and to contest the outcome through the grievance process (Section 15).
- Monitoring is proportionate and limited to on-shift activity for the purposes in Section 5.
13. Your rights
Subject to the limits that apply in an employment context, you may:
- Access the personal data we hold about you and get a copy.
- Correct inaccurate or incomplete data.
- Request deletion of data we are not required to keep by law.
- Object to or restrict certain processing, and withdraw consent for optional features.
- Nominate another person to exercise your rights (India, DPDP Act).
- Raise a grievance and, where applicable, complain to a data-protection authority.
How: use in-app support or contact admin@pinitsarees.com. We verify your identity and respond within the time the law requires (generally 30–45 days). Note that some employment, tax, and cash-handling records cannot be deleted on request because we must retain them by law.
14. Account and data deletion
Because this is a workforce app, you cannot self-delete your entire account while engaged, as that would prevent you from working and remove records we must keep. However:
- During engagement: you can request correction of your data and deletion of any non-mandatory data through rider support.
- On offboarding: your account is deactivated and access removed; personal data is deleted or anonymized within 30–90 days, except records we must retain by law (Section 9).
- Request a deletion review: deletion url email admin@pinitsarees.com with the subject “Delete my rider data.” If you used “Sign in with Apple,” we revoke the associated tokens.
15. Contact and grievance redressal
- Rider support: admin@pinitsarees.com / +91 9177708629
- HR / employment queries: +91 8688361661
- Registered office: 4th Floor, 8-2-309/3/B/1 & 8-2-309/3/B/2, Road no.14 Banjara Hills, Hyderabad, Telangana 500034
16. Changes to this Notice
We may update this Notice and will post the new version with a revised “Last updated” date; for material changes we will give additional notice through the app or your Employer. Continued use of the Rider App after changes means you are aware of the updated Notice.
