Data Fiduciary (Company)
Active Rental System
This Privacy Policy explains how Active Rental System ("we", "us", "our") collects, uses, discloses, and protects personal data in connection with our products:
- Active Rental — the web-based rental management platform (orders, customers, billing, stock/warehouse operations).
- Active Rental Ops — the companion Android/iOS app for staff and customers (Outward/Inward orders, Customers, Stock).
- TransitIQ — our transport and fleet management platform and its mobile apps (trip, order, and delivery tracking and alerts).
Together, the "Services". This Policy is written to align with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). By using the Services, you agree to the collection and use of information as described here.
Who this applies to
Our Services are business-to-business (B2B) tools. Users are employees, contractors, or authorized personnel of Active Rental System and of the client businesses (e.g. rental companies, transport operators) that use our Services — not members of the general public signing up directly. Client businesses may enter personal data about their own customers (e.g. name, phone number) into the Services; for that data, the client business is the data controller and we process it on their behalf as described in Section 5.
1. Personal Data We Collect
1.1 Account & identity data
- Name, username, email address, and/or phone number used to sign in.
- Role/permissions within your organization (e.g. staff, warehouse, admin, driver, dispatcher).
- Authentication data used to verify your identity and secure your account.
1.2 Business data you or your organization enter
- Order records (Outward/Inward orders), stock and inventory data, billing/invoice records.
- Customer records entered by your organization (name, phone number, address) for the purpose of managing rentals or deliveries.
- Trip, vehicle, and delivery records (TransitIQ) — including trip status and, where applicable, assigned driver/vehicle information.
1.3 Device & technical data
- Push notification tokens (Firebase Cloud Messaging) — used solely to deliver trip/order/delivery alerts to your device. We do not use these tokens for advertising.
- Standard technical logs: IP address, device/browser type, app version, and timestamps of requests, used for security, diagnostics, and abuse prevention.
We do not access your device camera, photo library, or precise location. If a future feature requires this, this Policy will be updated and, where required, your consent will be requested before that feature is enabled.
1.4 Cookies & local storage
The Active Rental web platform uses strictly necessary cookies/local storage to keep you signed in and remember basic preferences. We do not use third-party advertising or cross-site tracking cookies.
2. How We Use Personal Data
| Purpose | Data used |
|---|---|
| Provide and operate the Services (orders, stock, billing, trip tracking) | Account data, business data |
| Authenticate you and secure your account | Account data, technical logs |
| Send trip/order/delivery notifications | Push notification tokens |
| Customer support and troubleshooting | Account data, technical logs |
| Detect, prevent, and investigate fraud, abuse, or security incidents | Technical logs, account data |
| Comply with legal, tax, and regulatory obligations | Account data, business/billing data |
2.1 Sensitive Personal Data
Our Services are designed for operational business data and do not require collection of sensitive personal data (as defined under the DPDP Act: financial data, health, biometric, etc.). However, if your organization enters sensitive data (e.g., driver bank details for reimbursement), we process it with the same security and confidentiality as all personal data. Your organization must ensure lawful basis for collecting and sharing such data with us.
2.2 Automated Processing & Profiling
We do not use your personal data for automated decision-making or profiling that produces a legal or similarly significant effect without your explicit consent. Analytics on operational data (e.g., "which items are most rented") are performed on anonymized, aggregated data and do not identify you personally.
2.3 Service Providers & Subprocessors
We engage the following service providers to operate the Services (each bound by confidentiality agreements):
- Cloud Hosting & Infrastructure: AWS / Google Cloud / Linode (data stored in India regions)
- Push Notifications: Firebase Cloud Messaging (Google)
- Authentication & Security: Third-party identity providers (where applicable)
- Logging & Monitoring: Third-party monitoring services for uptime and security
Your organization may request an updated list of subprocessors or details of data processing agreements (DPAs) at any time. We will provide subprocessor change notifications in accordance with the DPDP Act.
2.4 Data Processing Agreements (DPA)
For B2B customers, we provide a Data Processing Agreement (DPA) that outlines how we process your organization's personal data as a processor on your behalf. If you require a DPA or wish to review/sign one, contact us at privacy@activerental.in.
3. Legal Basis
We process personal data on the basis of: (a) your consent (e.g. at account creation/login), (b) performance of the service agreement between us and your organization, and (c) compliance with legal obligations. You may withdraw consent at any time by contacting us at privacy@activerental.in, subject to any data we are required to retain by law or that is necessary to complete an already-initiated transaction.
4. Data Sharing & Disclosure
We do not sell personal data. We may share personal data only with:
- Service providers who process data on our behalf to operate the Services (e.g. hosting/infrastructure providers, push-notification delivery via Firebase Cloud Messaging), under contractual confidentiality obligations.
- Your own organization — data you enter is visible to authorized users within your organization as configured by your organization's administrators.
- Legal & regulatory authorities — where required by applicable law, court order, or governmental request.
- Successors — in connection with a merger, acquisition, or sale of assets, subject to this Policy continuing to apply to your data.
5. Data of Your Organization's Customers
Where your organization uses our Services to store its own customers' personal data (e.g. names and phone numbers for rental or delivery purposes), your organization is responsible for having a lawful basis to collect and share that data with us, and for responding to that customer's own rights requests. We act as a data processor for this category of data and will assist your organization in fulfilling such requests on reasonable request.
6. Data Storage & Security
- Data is hosted on infrastructure operated in India.
- All data in transit is encrypted (HTTPS/TLS). Authentication tokens on mobile devices are stored using platform-provided secure storage.
- Access to production data is limited to authorized personnel on a need-to-know basis.
- No method of transmission or storage is 100% secure; we work to protect your data but cannot guarantee absolute security.
7. Data Retention
We retain personal data for as long as your account or your organization's subscription is active, and for a reasonable period afterward to comply with legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. You may request earlier deletion under Section 8, subject to those obligations.
Data Retention Schedule
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & Authentication Data | Duration of subscription + 12 months | Legal & tax compliance, dispute resolution |
| Business Data (Orders, Inventory, Trips) | Duration of subscription + 7 years | Financial/accounting records, tax law (India) |
| Customer Data (entered by your org) | Duration of subscription + 90 days | Service delivery completion; your org controls longer retention |
| Technical Logs & IP Addresses | 90 days | Security, abuse prevention, diagnostics |
| Push Notification Tokens | Active session only; deleted upon logout | Service delivery; no long-term storage |
| Grievance Records | 2 years | Dispute resolution, legal compliance (DPDP Act) |
After the retention period, data is securely deleted or anonymized. You can request earlier deletion at any time (see Section 8).
8. Your Rights (Data Principal Rights under the DPDP Act, 2023)
Under the DPDP Act, you have specific rights as a "Data Principal" — but these apply only to your personal data, not to your organization's business data. Here's what that means:
8.1 What You Can Control: Your Personal Data
You have Data Principal rights over personal data that identifies you as an individual:
- Your account details (name, email, phone, username)
- Your role/permissions within your organization
- Your login activity and session history
- Your authentication data
For this data, you have the right to:
- Right to Access: Request a copy of your personal account data and how we use it.
- Right to Correction: Request we fix inaccurate or outdated information in your account (e.g., your email address or phone number).
- Right to Erasure: Request deletion of your personal account data after you leave your organization (subject to legal retention requirements like accounting records). We will complete erasure within 30 days of your request.
- Right to Restrict Processing: Request that we limit how we process your personal data (e.g., "don't send me notifications").
- Right to Data Portability: Request your personal account data in a machine-readable format (e.g., CSV) so you can move it elsewhere.
- Right to Withdraw Consent: Withdraw your consent to use the Services at any time. Your account will be deactivated, but your organization's business data remains intact.
- Right Related to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing that significantly affects you, unless we have obtained your explicit consent or the processing is necessary for a legal obligation.
- Right to Grievance Redressal: Raise a complaint if we mishandle your personal data.
- Right to Nominate: Nominate another person to exercise these rights on your behalf in case of death or incapacity.
8.2 What You Cannot Control: Your Organization's Business Data
You do NOT have the right to access, delete, or port your organization's business data — even if you work there. Here's why:
Business data (orders, inventory, customer records, trips, billing, trip reports) belongs to your organization (the Data Controller), not to you as an individual. Examples:
- You cannot unilaterally delete orders or inventory records
- You cannot export customer lists or billing data without authorization from your company's management
- You cannot restrict processing of delivery/trip data without your company's approval
Why? Under the DPDP Act, your organization is the Data Controller of this data — it decides why and how it's processed. As an employee, you're just a user accessing it for your job. The Data Principal rights belong to your organization, not to you individually.
In Plain English: Your personal data is yours. Your company's business data is your company's. Don't confuse the two.
8.3 Your Organization's Rights Over Business Data
As a Data Controller, your organization can:
- Request access to all business data we hold
- Request we correct or delete business data (subject to legal retention requirements)
- Request portability of business data in a structured format
- Audit how we process and protect its data
- Require a Data Processing Agreement (DPA) outlining our responsibilities as a processor
Your organization's administrators can contact us at privacy@activerental.in to exercise these rights.
How to Exercise Your Personal Data Rights
To exercise any of the personal data rights above, email privacy@activerental.in with the following information:
- Your full name and registered email address/phone number
- The specific right you are exercising (e.g., "Right to Access", "Right to Erasure")
- Description of the personal data in question (e.g., "my account data")
- Your signature or authenticated digital signature (for formal requests)
Response Timeline: We will acknowledge your request within 5 business days and provide a substantive response within 30 days. If your request is complex, we may extend this by an additional 30 days, with notification of the reason for extension. All responses are provided at no cost to you.
9. Data Breach Notification
In the event of a personal data breach (unauthorized access, loss, or disclosure), we will:
- Notify affected data principals (users) without undue delay, typically within 72 hours of discovering the breach, unless the breach poses no material risk.
- Notify your organization (if you are our customer and the data controller) immediately.
- Provide details of the breach, affected data categories, likely consequences, and mitigation measures.
- File a report with the Data Protection Board of India (if required under the DPDP Act).
You will be notified via email, SMS, or in-app notification to the contact details registered with us. In case of mass breaches affecting over 500 individuals, we will also issue a public notice via our website.
10. Consent & Withdrawal of Consent
How You Give Consent: By creating an account and using the Services, you consent to the collection and processing of personal data as described in this Policy. You may provide explicit consent for specific processing activities (e.g., promotional communications) at account setup or later via your account settings.
How to Withdraw Consent: You may withdraw consent at any time by:
- Adjusting your account privacy settings
- Emailing privacy@activerental.in with a request to withdraw consent for specific processing
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, nor does it affect other lawful bases for processing (e.g., contractual obligation to deliver the Service, legal compliance).
10.1 Glossary of Terms (DPDP Act Definitions)
To help you understand this Policy, here are key terms as defined or understood under the Digital Personal Data Protection Act, 2023:
- Personal Data: Any information about an identified individual or an individual who can be identified (directly or indirectly) using that information.
- Sensitive Personal Data: Personal data that reveals financial, health, biometric, sex life, or cast/religion information.
- Processing: Any operation on personal data (collection, use, storage, sharing, deletion, etc.).
- Data Fiduciary: Active Rental System — the entity that decides why and how personal data is processed.
- Data Principal: You — the person whose personal data is processed.
- Data Processor: An entity that processes personal data on behalf of a Data Fiduciary (under a contract/DPA).
- Consent: Your voluntary, informed, and explicit agreement to the processing of your personal data for a specified purpose.
- Data Breach: Unauthorized access, loss, or disclosure of personal data.
- Grievance Officer: A designated officer responsible for addressing your complaints about personal data processing.
11. Children's Privacy
Our Services are intended for business use by adult personnel and are not directed at children. We do not knowingly collect personal data from individuals under 18 years of age. If we discover that a child has provided personal data, we will delete it promptly. Parents or guardians who believe their child has provided personal data to us should contact us immediately at privacy@activerental.in.
12. Grievance Officer & Complaint Redressal
Grievance Contact
Grievance Redressal Process
In accordance with the DPDP Act, 2023, any complaints or grievances regarding the processing of your personal data may be addressed to our Grievance Officer.
How to File a Grievance:
- Email privacy@activerental.in with subject line: "Grievance: [Your name]"
- Include a detailed description of the issue, relevant dates, and what remedy you seek
Grievance Resolution Timeline
| Step | Timeline |
|---|---|
| Acknowledge receipt of grievance | 5 business days |
| Initial investigation & response | 30 days from filing |
| Extended investigation (if complex) | Additional 30 days (with notice) |
| Final redressal or escalation notice | 60 days maximum |
Escalation to Data Protection Board of India
If you are not satisfied with our grievance redressal, you have the right to lodge a complaint with the Data Protection Board of India as per Section 18 of the DPDP Act. For more information and to lodge a complaint:
Data Protection Board of India
https://www.dpdpa.com/
You may lodge a complaint with the Board if:
- You believe we have violated your rights under the DPDP Act
- We have failed to provide a satisfactory response to your grievance within 60 days
- You wish to appeal our grievance decision
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be reflected by updating the "Effective date" above. Continued use of the Services after changes take effect constitutes acceptance of the revised Policy.
14. Contact Us
Questions about this Privacy Policy or our data practices can be sent to privacy@activerental.in.
© 2026 Active Rental System.