1. Introduction
This Privacy Policy explains how Finnid Infotech Private Limited ("Company", "we", "us"), operating the DeliveryDost platform at deliverydost.in, collects, uses, stores, and protects your personal data.
We are committed to safeguarding your privacy in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and other applicable Indian laws. By using the platform, you consent to the practices described in this policy.
2. Data We Collect
2.1 Information You Provide
- Account Information — Name, mobile number, email address, role selection (EC/BC/DP/DPCM/Promoter/Sub-Promoter).
- Identity Documents — Aadhaar, PAN, driving licence, vehicle RC (for Delivery Partners); GST certificate, trade licence (for Business Centers).
- Business Details — Business name, address, pickup locations, outlet information.
- Financial Information — Bank account details for payouts, UPI ID, wallet transaction records.
2.2 Information Collected Automatically
- Device & Browser Data — IP address, browser type, operating system, device identifiers.
- Usage Data — Pages visited, features used, delivery orders created/accepted, timestamps.
- Location Data — GPS coordinates during active deliveries (Delivery Partners only), pickup and drop-off locations.
- Communication Data — In-platform messages between BCs and DPs, complaint records.
3. How We Use Your Data
- Account Management — To create, verify, and maintain your account; authenticate via OTP.
- Service Delivery — To facilitate delivery order matching, bidding, tracking, and completion.
- Payments — To process wallet top-ups, delivery payments, promoter cascade earnings, and bank payouts via CashFree.
- Notifications — To send transactional alerts via SMS, email, WhatsApp, and push notifications.
- Platform Improvement — To analyse usage patterns, improve features, and fix bugs.
- Safety & Fraud Prevention — To detect fraudulent activity, verify identities, and maintain platform integrity.
- Legal Compliance — To fulfil regulatory obligations, respond to legal requests, and resolve disputes.
4. Cookies & Tracking
4.1 Essential Cookies
We use cookies that are strictly necessary for the platform to function:
- Session cookies — To maintain your login state.
- Authentication cookies — To verify your identity across requests.
- OTP verification cookies — Stored as Base64-encoded values in HTTP-only cookies, valid for 10-15 minutes, and auto-deleted after verification or expiry.
4.2 Analytics
5. Third-Party Integrations
We share limited data with the following service providers to operate the platform:
| Service |
Purpose |
Data Shared |
| CashFree |
Payment processing |
Transaction amounts, bank details |
| Fast2SMS |
SMS & OTP delivery |
Mobile numbers, OTP codes |
| Google Analytics |
Usage analytics |
Anonymised usage data |
| SignalR |
Real-time delivery tracking |
Location data (active deliveries) |
| Aggregator Partners |
Delhivery, Borzo, Shiprocket — fallback delivery routing |
Pickup/drop addresses, parcel details |
We do not sell your personal data to any third party.
6. Data Retention
| Data Category |
Retention Period |
| Account data |
3 years after account deletion |
| Financial & transaction records |
8 years (tax & compliance requirements) |
| Analytics data |
26 months |
| Communication & complaint logs |
1 year |
| Location/tracking data |
90 days after delivery completion |
| OTP cookies |
10-15 minutes (auto-deleted) |
7. Your Rights under the DPDP Act 2023
As a data principal, you have the following rights:
- Right to Access — Request a copy of the personal data we hold about you.
- Right to Correction — Request correction of inaccurate or incomplete personal data.
- Right to Erasure — Request deletion of your personal data (subject to legal retention requirements).
- Right to Withdraw Consent — Withdraw your consent for data processing at any time. This may affect your ability to use certain platform features.
- Right to Grievance Redressal — File a complaint with our Grievance Officer or escalate to India's Data Protection Board.
To exercise any of these rights, contact us at support@deliverydost.in. We will respond within 30 days.
8. Data Security
We implement the following measures to protect your data:
- HTTPS Encryption — All data transmitted between your device and our servers is encrypted using TLS.
- HTTP-Only Cookies — Authentication and OTP cookies are not accessible via client-side scripts.
- Role-Based Access Control — Internal access to user data is restricted based on employee roles.
- Regular Security Audits — We conduct periodic security assessments to identify and fix vulnerabilities.
- Secure Payment Processing — All payment data is processed through PCI-DSS compliant CashFree infrastructure.
9. Children's Privacy
The DeliveryDost platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data, we will take steps to delete such data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. We will notify registered users of material changes via email or in-app notification. Continued use of the platform after changes constitutes acceptance of the revised policy.
11. Grievance Officer
In accordance with the DPDP Act 2023 and the Information Technology Act 2000, our Grievance Officer can be contacted at:
- Email: support@deliverydost.in
- Phone: +91-8069578416
- Address: Finnid Infotech Pvt. Ltd., Lucknow, Uttar Pradesh, India
If you are not satisfied with our response, you may escalate your complaint to India's Data Protection Board as established under the DPDP Act 2023.
12. Contact Us
For any privacy-related questions or requests:
- Email: support@deliverydost.in
- Phone: +91-8069578416
- Parent Company: Finnid Infotech Private Limited, Lucknow, Uttar Pradesh, India
- Parent Website: finnid.in