Saarun
VisionAboutProgramNewStoriesDownloadContact
Saarun · User app · v5

Terms & Conditions

Last updated October 6, 2026

SAARUN PRIVACY POLICY
Effective Date: 5 October 2026

Version: 3

Last Updated: 5 October 2026

Platform: Saarun (User app, Partner app, Shop portal, Admin tools, website, and related APIs)

Operator / Company: Siffrum Analytics Private Limited (“Siffrum”, “Saarun”, “we”, “us”, “our”)

Registered / operating office:
Siffrum Analytics Private Limited

Vericity House 116, Rajbagh

Srinagar, Jammu & Kashmir – 190010, India

Privacy / grievance email: privacy@siffrum.com
Support email: support@siffrum.com

This Privacy Policy is an electronic record under the Information Technology Act, 2000 and applicable rules. It explains how we access, collect, use, share, store, secure, and delete personal and sensitive user data when you use Saarun.

By creating an account, using Saarun apps or portals, submitting KYC, going Online as a Partner, or continuing to use the Services, you acknowledge this Privacy Policy. If you do not agree, do not use Saarun.

On this page

  1. 1. WHO WE ARE
  2. 2. SCOPE
  3. 3. WHAT WE COLLECT
  4. 4. HOW WE USE INFORMATION
  5. 5. SHARING
  6. 6. SECURE DATA HANDLING PRACTICES (PERSONAL AND SENSITIVE USER DATA)
  7. 7. RETENTION
  8. 8. YOUR CHOICES AND RIGHTS
  9. 9. CHILDREN
  10. 10. COOKIES / SIMILAR TECH
  11. 11. LINKS
  12. 12. GRIEVANCE OFFICER
  13. 13. GOVERNING LAW
  14. 14. CHANGES
  15. 15. ACCEPTANCE

1. WHO WE ARE

Saarun is a technology marketplace that connects Users and Shops who need local goods transport with independent Partners (drivers) who fulfil trips after KYC. Saarun does not sell personal data.

2. SCOPE

This Policy covers personal data processed in connection with:
• Saarun User app

• Saarun Partner app

• Shop web portal

• Admin console

• Backend APIs, realtime (SignalR), push notifications (FCM), SMS OTP

• Partner KYC / verification vendors where configured

It does not cover third-party sites or apps we do not control (payment gateways’ own pages, map tile providers, SMS gateways, verification vendors’ own portals), which have their own policies.

3. WHAT WE COLLECT

3.1 Account and contact
• Name (where provided)

• Mobile number

• Email (Admin / Shop / profile where used)

• OTP for login (processed via SMS provider; retained only as needed for verification)

• Role (user / partner / shop / admin)

• Device push tokens (FCM)

3.2 Bookings, bargains and trips
• Pickup / drop coordinates and addresses

• Goods / load details, vehicle preference, notes, photos of goods where you upload them

• Receiver phone (if provided)

• Bargain amounts and final fare / platform-fee snapshots

• Trip status, OTP events, cancellation reasons, payment markers, ratings

3.3 Partner KYC
• Plate number, DL number, DOB (as entered)

• Vehicle type

• Verification results from KYC vendors and stored response JSON for audit

• Vehicle photos

• Masked identity / bank / UPI identifiers as returned by verification vendors

• KYC status, Admin notes, approve / reject reasons

3.4 LOCATION DATA (IMPORTANT — ACCESS AND COLLECTION)
Saarun accesses and collects LOCATION data as follows:

  • A. Saarun Partner app
  • We access precise device LOCATION (GPS / network-assisted location) when you allow location permission.
  • We collect and transmit your LOCATION to Saarun servers when you browse nearby jobs, Go Online, or are on an active trip.
  • While you are Online and waiting for jobs, LOCATION is collected periodically for nearby-job matching (not continuous live tracking).
  • Continuous live LOCATION (frequent GPS updates, including in the background when the app is not visible) runs only while you are on an active trip, so we can:
  • show live Partner position to the booker;
  • run geofence / OTP pickup and drop checks;
  • keep trip safety features working during the delivery.
  • We may store recent LOCATION points and related trip route context needed for matching, tracking, support, disputes, and safety.
  • B. Saarun User / Shop flows
  • We may access LOCATION (or use map-picked / typed addresses and coordinates you provide) to set pickup and drop points, estimate distance, and show Partner approach during a trip.
  • User LOCATION is accessed only as needed for booking and trip features when you allow it or enter addresses / pins yourself.
  • C. What we do NOT do with LOCATION
  • We do not sell LOCATION data.
  • We do not use LOCATION for unrelated advertising networks.
  • We do not run continuous live Partner LOCATION tracking while you are only Online and waiting for jobs.
  • We do not collect Partner background LOCATION when you are Offline and not on an active trip (beyond brief permission / device checks needed to show status).

3.5 Payments
• Payment mode markers (cash / online gateway)

• Gateway order / payment references (full card data is handled by the payment gateway where applicable, not stored as raw card numbers on Saarun servers)

3.6 Support
• Tickets, messages, call-back requests, CSAT scores / comments

3.7 Device and logs
• App / device version, IP address, access and error logs, Admin audit actions

4. HOW WE USE INFORMATION

We use information to:
• Provide and operate Saarun (login, requests, bargain, trips, support)

• Match Users / Shops with nearby Partners using LOCATION and job details

• Verify Partners before Go Online where KYC is required

• Process platform fees and payment records

• Send OTP, trip, bargain, and support notifications

• Prevent fraud, abuse, and unsafe behaviour

• Comply with law and respond to lawful requests

• Improve the product using aggregated / anonymised insights where feasible

We do not sell personal data.
We do not use KYC vendor documents for advertising.

5. SHARING

We may share data with:
• Other trip parties — limited trip context needed to complete the job (status, approach, OTP flows as designed). Partner name / phone / vehicle identifiers and live LOCATION during an active trip may be shown to the User / Shop as needed.

• Cloud / infrastructure providers — hosting, database, object storage, Redis, maps, SMS, FCM under contract

• KYC / verification vendors — Partner document / UPI verification

• Payment gateways — online payments

• Advisors / auditors — under confidentiality

• Authorities — when required by law or to protect safety / rights / fraud investigations

6. SECURE DATA HANDLING PRACTICES (PERSONAL AND SENSITIVE USER DATA)

Saarun uses technical and organisational measures intended to protect personal and sensitive user data, including LOCATION, KYC, and account data:
• Transport security: API and app traffic use HTTPS / TLS where configured in production.

• Access control: role-based Admin access; Partners and Users only see data needed for their role and active trips.

• Least privilege: secrets, gateway keys, and vendor credentials are kept server-side; they are not embedded in public client builds for production use.

• Storage controls: production databases and object storage are access-restricted; KYC photos and verification payloads are retained for review and audit with minimisation of long-term raw files where feasible.

• Device permissions: LOCATION and other sensitive permissions are requested only for disclosed features; Partners can revoke location permission in device Settings (doing so may prevent Go Online / nearby jobs / live tracking).

• Monitoring and logs: access and error logs support security and fraud investigation; Admin actions may be audited.

• Incident response: we investigate suspected unauthorised access and take reasonable containment and notification steps required by applicable law.

• No system is 100% secure. You should also protect your device, OTP, and account access.

7. RETENTION

We keep data only as long as needed for the service, disputes, safety, fraud prevention, and law. Typical aims:
• Account — while active + limited period after closure

• Trip / bargain / payment records — business retention (for example up to 3 years, or longer if required)

• LOCATION points tied to trips / Online sessions — as needed for matching, tracking, support, safety, and disputes, then minimised

• KYC photos / vendor payloads — review + audit; minimise long-term raw files

• Support — resolved + archive period

• Security logs — rolling window unless investigation requires longer

8. YOUR CHOICES AND RIGHTS

Subject to applicable law (including DPDP principles where applicable), you may request access, correction, withdrawal of consent (where processing is consent-based), or deletion / restriction in certain cases via privacy@siffrum.com, or delete your account in the Saarun apps as described in Section 8A.

Withdrawal of KYC or LOCATION consent may mean a Partner cannot Go Online, see nearby jobs, or complete tracked trips.
Account deletion requests may be refused or delayed where we must retain records for law, safety, or disputes. After deletion we may stop providing services that depended on that data.

You may choose not to provide optional data; required data is needed for core features.
On Android / iOS you can change LOCATION and notification permissions in system Settings at any time.

8A. DATA DELETION
You can request deletion of your Saarun account and associated personal data in either of the following ways:

A) In-app deletion (User app and Partner app)
1. Open the Saarun app and sign in.

2. Go to Profile / Settings.

3. Tap “Delete account”.

4. Confirm by typing your registered name (or DELETE if no name is set).

5. On confirmation, we deactivate your account, end your session, and stop providing services that depend on that account.

B) Request by email
Email privacy@siffrum.com from your registered contact with subject “Data deletion request”, and include your registered mobile number and whether you use the User or Partner app. We aim to acknowledge requests within a reasonable period and complete deletion subject to the limits below.

What deletion means
• We soft-delete / deactivate your account so it is no longer usable for login or new bookings/trips.

• We stop active processing for profile, presence, and marketing where applicable.

• Signing in again with the same phone may reactivate a soft-deleted account; if you want permanent closure without reactivation, say so clearly in your email request.

What we may retain
We may keep limited records after deletion where required or permitted by law, including trip/payment history, KYC/fraud/safety records, tax/accounting records, and dispute evidence, for the periods described in Section 7 (Retention). Those records are restricted and not used to provide active app services.

Device data
You can also remove local app data by uninstalling the app and clearing app storage in your device settings. Uninstalling alone does not delete your Saarun server account — use Delete account or email us as above.

9. CHILDREN

Saarun is for adults capable of entering transport arrangements. We do not knowingly onboard minors as Users or Partners.

10. COOKIES / SIMILAR TECH

Our websites may use cookies or similar technologies for session, security, and analytics. You can control cookies in your browser; some features may not work if disabled.

11. LINKS

Third-party links are not controlled by us. Their privacy practices are their own.

12. GRIEVANCE OFFICER

Under applicable IT / consumer e-commerce rules, you may contact:

Grievance Officer
Siffrum Analytics Private Limited

Vericity House 116, Rajbagh, Srinagar, J&K – 190010, India

Email: privacy@siffrum.com

Hours: Monday–Friday, 10:00–17:00 IST (excluding public holidays)

13. GOVERNING LAW

This Policy is governed by the laws of India. Subject to mandatory law, courts at Srinagar, Jammu & Kashmir shall have jurisdiction over disputes arising from this Policy.

14. CHANGES

We may update this Policy by revising the published version (website Privacy page and/or in-app Legal documents). Continued use after an update means you accept the revised Policy. Please check this page from time to time.

15. ACCEPTANCE

By creating an account, using Saarun apps or portals, submitting KYC, granting LOCATION permission, or continuing to use the Services, you acknowledge this Privacy Policy.

Read Privacy PolicyBack to home