Privacy Policy

Active Rental System · Effective date: 19 September 2026

Data Fiduciary (Company)

Active Rental System

This Privacy Policy explains how Active Rental System ("we", "us", "our") collects, uses, discloses, and protects personal data in connection with our products:

  • Active Rental — the web-based rental management platform (orders, customers, billing, stock/warehouse operations).
  • Active Rental Ops — the companion Android/iOS app for staff and customers (Outward/Inward orders, Customers, Stock).
  • TransitIQ — our transport and fleet management platform and its mobile apps (trip, order, and delivery tracking and alerts).

Together, the "Services". This Policy is written to align with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). By using the Services, you agree to the collection and use of information as described here.

Who this applies to

Our Services are business-to-business (B2B) tools. Users are employees, contractors, or authorized personnel of Active Rental System and of the client businesses (e.g. rental companies, transport operators) that use our Services — not members of the general public signing up directly. Client businesses may enter personal data about their own customers (e.g. name, phone number) into the Services; for that data, the client business is the data controller and we process it on their behalf as described in Section 5.

1. Personal Data We Collect

1.1 Account & identity data

  • Name, username, email address, and/or phone number used to sign in.
  • Role/permissions within your organization (e.g. staff, warehouse, admin, driver, dispatcher).
  • Authentication data used to verify your identity and secure your account.

1.2 Business data you or your organization enter

  • Order records (Outward/Inward orders), stock and inventory data, billing/invoice records.
  • Customer records entered by your organization (name, phone number, address) for the purpose of managing rentals or deliveries.
  • Trip, vehicle, and delivery records (TransitIQ) — including trip status and, where applicable, assigned driver/vehicle information.

1.3 Device & technical data

  • Push notification tokens (Firebase Cloud Messaging) — used solely to deliver trip/order/delivery alerts to your device. We do not use these tokens for advertising.
  • Standard technical logs: IP address, device/browser type, app version, and timestamps of requests, used for security, diagnostics, and abuse prevention.

We do not access your device camera, photo library, or precise location. If a future feature requires this, this Policy will be updated and, where required, your consent will be requested before that feature is enabled.

1.4 Cookies & local storage

The Active Rental web platform uses strictly necessary cookies/local storage to keep you signed in and remember basic preferences. We do not use third-party advertising or cross-site tracking cookies.

2. How We Use Personal Data

PurposeData used
Provide and operate the Services (orders, stock, billing, trip tracking)Account data, business data
Authenticate you and secure your accountAccount data, technical logs
Send trip/order/delivery notificationsPush notification tokens
Customer support and troubleshootingAccount data, technical logs
Detect, prevent, and investigate fraud, abuse, or security incidentsTechnical logs, account data
Comply with legal, tax, and regulatory obligationsAccount data, business/billing data

2.1 Sensitive Personal Data

Our Services are designed for operational business data and do not require collection of sensitive personal data (as defined under the DPDP Act: financial data, health, biometric, etc.). However, if your organization enters sensitive data (e.g., driver bank details for reimbursement), we process it with the same security and confidentiality as all personal data. Your organization must ensure lawful basis for collecting and sharing such data with us.

2.2 Automated Processing & Profiling

We do not use your personal data for automated decision-making or profiling that produces a legal or similarly significant effect without your explicit consent. Analytics on operational data (e.g., "which items are most rented") are performed on anonymized, aggregated data and do not identify you personally.

2.3 Service Providers & Subprocessors

We engage the following service providers to operate the Services (each bound by confidentiality agreements):

  • Cloud Hosting & Infrastructure: AWS / Google Cloud / Linode (data stored in India regions)
  • Push Notifications: Firebase Cloud Messaging (Google)
  • Authentication & Security: Third-party identity providers (where applicable)
  • Logging & Monitoring: Third-party monitoring services for uptime and security

Your organization may request an updated list of subprocessors or details of data processing agreements (DPAs) at any time. We will provide subprocessor change notifications in accordance with the DPDP Act.

2.4 Data Processing Agreements (DPA)

For B2B customers, we provide a Data Processing Agreement (DPA) that outlines how we process your organization's personal data as a processor on your behalf. If you require a DPA or wish to review/sign one, contact us at privacy@activerental.in.

3. Legal Basis

We process personal data on the basis of: (a) your consent (e.g. at account creation/login), (b) performance of the service agreement between us and your organization, and (c) compliance with legal obligations. You may withdraw consent at any time by contacting us at privacy@activerental.in, subject to any data we are required to retain by law or that is necessary to complete an already-initiated transaction.

4. Data Sharing & Disclosure

We do not sell personal data. We may share personal data only with:

  • Service providers who process data on our behalf to operate the Services (e.g. hosting/infrastructure providers, push-notification delivery via Firebase Cloud Messaging), under contractual confidentiality obligations.
  • Your own organization — data you enter is visible to authorized users within your organization as configured by your organization's administrators.
  • Legal & regulatory authorities — where required by applicable law, court order, or governmental request.
  • Successors — in connection with a merger, acquisition, or sale of assets, subject to this Policy continuing to apply to your data.

5. Data of Your Organization's Customers

Where your organization uses our Services to store its own customers' personal data (e.g. names and phone numbers for rental or delivery purposes), your organization is responsible for having a lawful basis to collect and share that data with us, and for responding to that customer's own rights requests. We act as a data processor for this category of data and will assist your organization in fulfilling such requests on reasonable request.

6. Data Storage & Security

  • Data is hosted on infrastructure operated in India.
  • All data in transit is encrypted (HTTPS/TLS). Authentication tokens on mobile devices are stored using platform-provided secure storage.
  • Access to production data is limited to authorized personnel on a need-to-know basis.
  • No method of transmission or storage is 100% secure; we work to protect your data but cannot guarantee absolute security.

7. Data Retention

We retain personal data for as long as your account or your organization's subscription is active, and for a reasonable period afterward to comply with legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. You may request earlier deletion under Section 8, subject to those obligations.

Data Retention Schedule

Data CategoryRetention PeriodReason
Account & Authentication DataDuration of subscription + 12 monthsLegal & tax compliance, dispute resolution
Business Data (Orders, Inventory, Trips)Duration of subscription + 7 yearsFinancial/accounting records, tax law (India)
Customer Data (entered by your org)Duration of subscription + 90 daysService delivery completion; your org controls longer retention
Technical Logs & IP Addresses90 daysSecurity, abuse prevention, diagnostics
Push Notification TokensActive session only; deleted upon logoutService delivery; no long-term storage
Grievance Records2 yearsDispute resolution, legal compliance (DPDP Act)

After the retention period, data is securely deleted or anonymized. You can request earlier deletion at any time (see Section 8).

8. Your Rights (Data Principal Rights under the DPDP Act, 2023)

Under the DPDP Act, you have specific rights as a "Data Principal" — but these apply only to your personal data, not to your organization's business data. Here's what that means:

8.1 What You Can Control: Your Personal Data

You have Data Principal rights over personal data that identifies you as an individual:

  • Your account details (name, email, phone, username)
  • Your role/permissions within your organization
  • Your login activity and session history
  • Your authentication data

For this data, you have the right to:

  • Right to Access: Request a copy of your personal account data and how we use it.
  • Right to Correction: Request we fix inaccurate or outdated information in your account (e.g., your email address or phone number).
  • Right to Erasure: Request deletion of your personal account data after you leave your organization (subject to legal retention requirements like accounting records). We will complete erasure within 30 days of your request.
  • Right to Restrict Processing: Request that we limit how we process your personal data (e.g., "don't send me notifications").
  • Right to Data Portability: Request your personal account data in a machine-readable format (e.g., CSV) so you can move it elsewhere.
  • Right to Withdraw Consent: Withdraw your consent to use the Services at any time. Your account will be deactivated, but your organization's business data remains intact.
  • Right Related to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing that significantly affects you, unless we have obtained your explicit consent or the processing is necessary for a legal obligation.
  • Right to Grievance Redressal: Raise a complaint if we mishandle your personal data.
  • Right to Nominate: Nominate another person to exercise these rights on your behalf in case of death or incapacity.

8.2 What You Cannot Control: Your Organization's Business Data

You do NOT have the right to access, delete, or port your organization's business data — even if you work there. Here's why:

Business data (orders, inventory, customer records, trips, billing, trip reports) belongs to your organization (the Data Controller), not to you as an individual. Examples:

  • You cannot unilaterally delete orders or inventory records
  • You cannot export customer lists or billing data without authorization from your company's management
  • You cannot restrict processing of delivery/trip data without your company's approval

Why? Under the DPDP Act, your organization is the Data Controller of this data — it decides why and how it's processed. As an employee, you're just a user accessing it for your job. The Data Principal rights belong to your organization, not to you individually.

In Plain English: Your personal data is yours. Your company's business data is your company's. Don't confuse the two.

8.3 Your Organization's Rights Over Business Data

As a Data Controller, your organization can:

  • Request access to all business data we hold
  • Request we correct or delete business data (subject to legal retention requirements)
  • Request portability of business data in a structured format
  • Audit how we process and protect its data
  • Require a Data Processing Agreement (DPA) outlining our responsibilities as a processor

Your organization's administrators can contact us at privacy@activerental.in to exercise these rights.

How to Exercise Your Personal Data Rights

To exercise any of the personal data rights above, email privacy@activerental.in with the following information:

  • Your full name and registered email address/phone number
  • The specific right you are exercising (e.g., "Right to Access", "Right to Erasure")
  • Description of the personal data in question (e.g., "my account data")
  • Your signature or authenticated digital signature (for formal requests)

Response Timeline: We will acknowledge your request within 5 business days and provide a substantive response within 30 days. If your request is complex, we may extend this by an additional 30 days, with notification of the reason for extension. All responses are provided at no cost to you.

9. Data Breach Notification

In the event of a personal data breach (unauthorized access, loss, or disclosure), we will:

  • Notify affected data principals (users) without undue delay, typically within 72 hours of discovering the breach, unless the breach poses no material risk.
  • Notify your organization (if you are our customer and the data controller) immediately.
  • Provide details of the breach, affected data categories, likely consequences, and mitigation measures.
  • File a report with the Data Protection Board of India (if required under the DPDP Act).

You will be notified via email, SMS, or in-app notification to the contact details registered with us. In case of mass breaches affecting over 500 individuals, we will also issue a public notice via our website.

10. Consent & Withdrawal of Consent

How You Give Consent: By creating an account and using the Services, you consent to the collection and processing of personal data as described in this Policy. You may provide explicit consent for specific processing activities (e.g., promotional communications) at account setup or later via your account settings.

How to Withdraw Consent: You may withdraw consent at any time by:

  • Adjusting your account privacy settings
  • Emailing privacy@activerental.in with a request to withdraw consent for specific processing

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, nor does it affect other lawful bases for processing (e.g., contractual obligation to deliver the Service, legal compliance).

10.1 Glossary of Terms (DPDP Act Definitions)

To help you understand this Policy, here are key terms as defined or understood under the Digital Personal Data Protection Act, 2023:

  • Personal Data: Any information about an identified individual or an individual who can be identified (directly or indirectly) using that information.
  • Sensitive Personal Data: Personal data that reveals financial, health, biometric, sex life, or cast/religion information.
  • Processing: Any operation on personal data (collection, use, storage, sharing, deletion, etc.).
  • Data Fiduciary: Active Rental System — the entity that decides why and how personal data is processed.
  • Data Principal: You — the person whose personal data is processed.
  • Data Processor: An entity that processes personal data on behalf of a Data Fiduciary (under a contract/DPA).
  • Consent: Your voluntary, informed, and explicit agreement to the processing of your personal data for a specified purpose.
  • Data Breach: Unauthorized access, loss, or disclosure of personal data.
  • Grievance Officer: A designated officer responsible for addressing your complaints about personal data processing.

11. Children's Privacy

Our Services are intended for business use by adult personnel and are not directed at children. We do not knowingly collect personal data from individuals under 18 years of age. If we discover that a child has provided personal data, we will delete it promptly. Parents or guardians who believe their child has provided personal data to us should contact us immediately at privacy@activerental.in.

12. Grievance Officer & Complaint Redressal

Grievance Contact

privacy@activerental.in

Grievance Redressal Process

In accordance with the DPDP Act, 2023, any complaints or grievances regarding the processing of your personal data may be addressed to our Grievance Officer.

How to File a Grievance:

  • Email privacy@activerental.in with subject line: "Grievance: [Your name]"
  • Include a detailed description of the issue, relevant dates, and what remedy you seek

Grievance Resolution Timeline

StepTimeline
Acknowledge receipt of grievance5 business days
Initial investigation & response30 days from filing
Extended investigation (if complex)Additional 30 days (with notice)
Final redressal or escalation notice60 days maximum

Escalation to Data Protection Board of India

If you are not satisfied with our grievance redressal, you have the right to lodge a complaint with the Data Protection Board of India as per Section 18 of the DPDP Act. For more information and to lodge a complaint:

Data Protection Board of India
https://www.dpdpa.com/

You may lodge a complaint with the Board if:

  • You believe we have violated your rights under the DPDP Act
  • We have failed to provide a satisfactory response to your grievance within 60 days
  • You wish to appeal our grievance decision

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be reflected by updating the "Effective date" above. Continued use of the Services after changes take effect constitutes acceptance of the revised Policy.

14. Contact Us

Questions about this Privacy Policy or our data practices can be sent to privacy@activerental.in.

© 2026 Active Rental System.