CarTechTravel

Privacy Notice

Last Updated: July 15, 2026

CarTechTravel ("we," "our," or "us") handles personal data as described in this notice and follows applicable Indian data-protection requirements, including provisions of the Digital Personal Data Protection Act, 2023 (DPDPA) as they come into force. This notice explains what we collect, why we process it, how long we retain it, and how to contact us about your data.

1. Data Collection & Notice

We collect and process personal data only where you have granted free, specific, informed, unconditional, and unambiguous consent. The categories of information processed include:

  • Account Identity: Name, email address, Google authentication profile details, and login session keys.
  • Vehicle Ledger Details: Make, model, sub-variant, odometer readings, and registration numbers that you enter to manage your garage.
  • Uploaded Documents: PDFs or photographs of service bills and repair quotes you upload for estimate audits.
  • Technical logs: IP address hashes, browser type, cookies, and website interactions collected for rate limiting and diagnostic security.
  • Fuel-checker suggestions: Selected manufacturer, model, configuration, selected and manufacturing dates where supplied, result status, suggestion category, optional note, and optional official source page. The form does not request an account, email, registration number, VIN, phone number, image, or attachment.
  • Fuel-feedback abuse prevention: A keyed HMAC-SHA-256 pseudonymous network identifier is stored in the rate-limit log. The raw network address is not stored by this workflow.
  • Fuel-checker usage metrics: We may collect low-cardinality pageview and interaction counts for the E20 checker. Authenticated account identity and the site’s legacy analytics session reference are not attached to checker pageviews or checker interaction events, and checker query parameters are not stored in these metrics. This route-specific rule does not describe analytics on other signed-in parts of the site.

2. Purposes of Processing

Your personal data is processed solely for specified, lawful purposes related to vehicle maintenance analysis:

  • Authenticating your account and dashboard access.
  • Analyzing and parsing invoice line items to identify dealer upselling and inflated charges.
  • Compiling local workshop honesty ratings and directory features.
  • Processing Sandboxed PhonePe transaction metadata.
  • Investigating system bugs and ensuring platform security.
  • Manually reviewing fuel-documentation suggestions. A suggestion does not automatically publish, alter, or upgrade a compatibility result.

3. AI Processing & Redaction

DPDPA 2023 Compliance & Data Minimization Shield

Before your uploaded service bills are sent to AI models (Google Gemini) for character extraction, our ingestion pipeline applies a mandatory privacy shield. This shield detects and redacts private personal identifiers—such as names, phone numbers, home addresses, and chassis/VIN numbers. Only dealership details and specific line item costs are processed by the AI models.

4. Third-Party Processors

We do not sell, rent, or trade your personal data. We only engage trusted Data Processors operating under strict confidentiality contracts to support service delivery:

  • Cloud hosting and database infrastructure (Supabase, Vercel).
  • AI and machine learning inference API platforms.
  • Secured Payment Gateways (PhonePe).
  • Upstash Redis for security rate limiting.

5. Payment Information

Payment processing is handled directly by PhonePe. CarTechTravel does not store your credit card numbers, CVVs, UPI PINs, or raw bank details on our servers. We only save transaction references and status flags to audit your credits.

6. Technical Safeguards

We implement reasonable technical, operational, and administrative safeguards designed to protect personal data against accidental loss, unauthorized access, or leakage. In accordance with Section 8 of the DPDPA 2023, in the event of a personal data breach, we will notify both the Data Protection Board of India (DPBI) and the affected users in the prescribed format.

7. Retention & Storage Limitation

Under the data minimization principle, we retain your data only for as long as necessary to fulfill the specified audit purpose.

Storage Limitation Policy

Raw uploaded PDF or image service invoices are stored temporarily in our secure cloud storage for processing. All raw invoice files are permanently deleted from our storage bucket 7 days after the audit is generated. Only the structured, anonymized parsed line items (which do not contain PII) are retained in your active history.

Fuel suggestion retention

Fuel-checker suggestion content is deleted after 90 days. Rate-limit event rows, which contain the keyed pseudonymous network identifier and request-window data, are deleted after 48 hours. A daily database cleanup job enforces both periods; failed runs are monitored through the scheduled-job history and can be rerun manually by an authorized operator. We do not retain a longer-lived aggregate from a suggestion in this implementation.

Anonymous checker usage metrics are separate from feedback submissions. Suggestions remain manual-review-only and continue to follow the retention periods above.

8. Rights of Data Principals (DPDPA 2023)

As a Data Principal in India, you hold the following statutory rights, which you can exercise directly from your dashboard or by submitting a request:

  • Right to Access: Access a summary of your personal data being processed and download it in a portable JSON format.
  • Right to Correction & Completion: Request the correction of inaccurate details or completion of incomplete information in your profile and vehicles.
  • Right to Erasure: Request the deletion of your account and all associated personal data from active systems.
  • Right to Withdraw Consent: Withdraw your consent at any time. Withdrawal of consent will immediately trigger account suspension and initiate the data purge sequence.
  • Right of Nomination: Nominate an individual to exercise your data rights in the event of death or incapacity.

Fuel suggestions can be submitted without an account and are therefore not included automatically in an authenticated account export or account-erasure operation. If you contact privacy@cartechtravel.com, provide the approximate submission time, selected vehicle details, category, and a non-sensitive description so we can attempt to locate the row. Identification or deletion may be technically impossible if those details are insufficient, and we do not collect an email or other identifier solely to make guest submissions linkable. The 90-day automatic deletion period limits this exposure.

The 48-hour rate-limit identifier is purpose-specific and is not intended to identify a person or connect a suggestion to an account export. Rotating the HMAC key prevents future identifiers from matching earlier rate-limit buckets; it does not recover the raw network address.

9. Children & Persons with Disabilities

CarTechTravel does not knowingly collect or process the personal data of children under the age of 18 or persons with disabilities without verifiable parental or guardian consent. We do not engage in behavioral tracking or targeted advertising of children. If we discover that we have inadvertently collected data from a child without guardian consent, we will permanently purge it within 48 hours.

10. Grievance Redressal & Consent Managers

If you have any questions, concerns, or grievances regarding the processing of your personal data, you may contact our designated Grievance Officer:

Attn: Data Privacy Grievance Officer
Email: privacy@cartechtravel.com
Address: CarTechTravel Compliance Dept, Bengaluru, Karnataka, India

You also have the right to manage, give, or withdraw your consent through a registered Consent Manager as and when the Consent Manager framework is operationalized by the Data Protection Board of India (DPBI).