Kawst LogoKawst
Legal

Privacy Policy

Version 2026-09-25 · Effective 25 September 2026

How Kawst collects, uses, shares, stores and protects personal data — for fleet owners, owner-cum-drivers, drivers, supervisors, vendors and the customers whose trips are managed through Kawst.

1. Who we are and what this policy covers

Kawst is a fleet-operations and B2B logistics platform for the Indian commercial transport market. It is a product of One Kom Labs Technologies LLP ("we", "Kawst", "us"), having its registered office at A-414, SLV Central Park, Bidare Agrahara, Bandapura Road, Bengaluru, Karnataka 560067, India. It is offered through the Kawst Android app, the Kawst web app at app.kawst.in, the Kawst Admin app used by our staff, and public web pages at kawst.in (payment links, trip-share pages, quotations, invoices and receipts).

This policy applies to every person whose personal data we process: fleet owners, owner-cum-drivers, salaried drivers, supervisors and staff added by an owner, vendors and partner operators, B2B clients, and the end customers of a fleet owner whose trip, quotation, invoice or payment is handled through Kawst. It is a standalone notice under Section 5 of the DPDP Act and is separate from our Terms and Conditions and from the Consent Notice you accept in the app.

Our roles. Kawst is the Data Fiduciary for the personal data of every account holder on the platform. Where a fleet owner uses Kawst to manage their own drivers, staff and customers, the fleet owner is the Data Fiduciary for that data and Kawst acts as their Data Processor under our Terms and Conditions; we process it only on the owner's instructions and as described here.

2. What personal data we collect

We collect only what each feature needs. The table below itemises the data and the purpose it serves, as the DPDP Rules require.

Account & identity

  • What we collect: Mobile number (verified by OTP), name, role (owner / owner-cum-driver / driver / supervisor / vendor / personal), profile photo, preferred language; email and name if you sign in with Google.
  • Why we collect it: Create and secure your account; show you the right features for your role; contact you about your account.

Business identity (owners)

  • What we collect: Business name, GSTIN, PAN where you enter it, business address, bank/UPI details you add for invoices and settlements, branch details.
  • Why we collect it: Issue GST-compliant invoices, receipts and credit notes; settle payments; enforce plan limits.

Driver documents (KYC)

  • What we collect: Driving licence number and image, one government photo ID (Aadhaar, Voter ID or Passport) as image or via DigiLocker, address, date of birth, photograph, experience and ratings.
  • Why we collect it: Verify that a driver holds a valid licence before they can seek work or be assigned a vehicle; meet an owner's duty of care; build the driver's portable work record.

Vehicle data

  • What we collect: Registration number, RC details fetched from VAHAN via our verification partner, chassis/engine identifiers, insurance, fitness, permit and PUC details and expiry dates, vehicle photos, FASTag ID.
  • Why we collect it: Populate the vehicle record from the RC; send compliance reminders; match trips and expenses to the right vehicle.

Location

  • What we collect: Precise GPS position of the driver's phone during a duty or trip, including in the background while a trip is running (a persistent notification is shown); position of hardware GPS trackers fitted to a vehicle.
  • Why we collect it: Live fleet map, trip distance and timeline, geofence alerts, journey-plan billing, idling and detention detection, theft and tamper alerts.

Motion sensors

  • What we collect: Accelerometer and gyroscope readings from the driver's phone during a trip, processed into driving-behaviour scores (harsh braking, acceleration, cornering).
  • Why we collect it: Driving-behaviour feedback and owner safety reporting. Optional: collected only if you allow it (we ask once), and you can change it any time in Profile → Privacy.

Photos you upload

  • What we collect: Odometer readings, fuel bills, damage photos, expense receipts, vehicle and document images.
  • Why we collect it: Verify expenses and fuel entries (partly with AI, see Section 5), record vehicle condition at custody hand-over, keep a maintenance history.

Financial & employment records

  • What we collect: Trips, fares, expenses, advances and loans, salary structure, attendance, leaves, payroll runs, payslips, statutory deductions, settlement ledgers, invoices, receipts, payment-link and FASTag recharge orders.
  • Why we collect it: Run the owner's operations, payroll and money ledger; give drivers their own earnings and attendance record; generate statutory documents.

Customer & CRM data entered by owners

  • What we collect: Names, phone numbers, pickup/drop addresses and trip details of the owner's customers, B2B clients and leads; quotation and booking details.
  • Why we collect it: Quotations, bookings, trip-share links, invoices and payment collection on the owner's behalf. The owner is the Data Fiduciary for this data.

Device & diagnostics

  • What we collect: Device model, OS version, app version, push-notification token, crash reports, performance metrics, anonymised usage events, App Check attestation.
  • Why we collect it: Keep the app reliable and secure; deliver notifications; fix crashes; understand which features are used.

Communications

  • What we collect: Support requests, in-app feedback, ratings, suggestions, and messages sent through Kawst to customers or drivers.
  • Why we collect it: Support you; improve the product; resolve disputes.

Sensitive data. Government identity documents, precise location and financial records are sensitive. We collect them only for the purposes above, restrict who can see them (Section 7), and never use them for advertising or profiling unrelated to fleet operations.

Data about other people. If you enter a customer's, driver's or employee's details into Kawst, you confirm that you are entitled to share them with us and that you have given those persons the notice required of you. Kawst provides public-facing notices on every customer-visible page (trip share, payment, invoice).

3. Where the data comes from

  1. Directly from you, when you register, fill a form, upload a document, or enter a trip, expense or customer.
  2. Automatically from your device, when you grant a permission: location (foreground and background), notifications, photo picker, and overlay display for the in-trip status chip.
  3. From a fleet owner or supervisor who adds you as a driver, staff member, vendor or partner operator.
  4. From our verification partner, when we look up a driving licence, an identity document, an RC or a FASTag on your instruction.
  5. From hardware GPS trackers fitted to a vehicle by its owner.
  6. From a customer who opens a trip-share, quotation, invoice or payment link and interacts with it.

We process personal data on the basis of your consent under Section 6 of the DPDP Act, given in the app through the Consent Notice, and for certain legitimate uses under Section 7 — in particular, where you voluntarily provide data for a stated purpose, to comply with law or a court order, to respond to a medical emergency, and where an owner processes an employee's data for employment purposes. Each purpose is listed against its data in Section 2. We do not use your data for a purpose that is incompatible with the one you were told about without asking you again.

5. Automated processing and AI

Kawst uses machine-learning models for a small number of well-defined tasks: reading an odometer or fuel-bill photo to extract the figures, checking an expense entry for inconsistencies, splitting a maker and model name from an RC record, generating catalogue images of vehicle models, and scoring driving behaviour from motion-sensor data. These outputs are decision support for the fleet owner, who remains responsible for any decision about a driver's pay, employment or conduct. No decision with a legal or similarly significant effect on you is taken by automated means alone. Photos and vehicle records sent to the AI service are processed by Google's generative-AI API, which may process the data outside India (see Section 8). We strip names and phone numbers from these requests wherever the task does not need them.

6. Who we share data with

We do not sell, rent or trade personal data. We share it only with the parties below, each of whom is bound by contract to process it only for us and to keep it secure.

Google Firebase / Google Cloud (Mumbai region, asia-south1)

  • What they receive: All platform data: authentication, database, file storage, push notifications, crash reports, analytics, remote configuration, App Check.
  • Purpose: Hosting and core infrastructure.

Google Maps Platform

  • What they receive: Coordinates and addresses to display.
  • Purpose: Maps, routing and geocoding.

Google generative-AI API (Gemini)

  • What they receive: Odometer, fuel-bill and damage photos; RC and vehicle text; catalogue data.
  • Purpose: AI verification and extraction described in Section 5.

Amazon Web Services (Mumbai region, ap-south-1)

  • What they receive: Hardware tracker telemetry; requests to our AI service.
  • Purpose: Telemetry ingestion and the AI verification service.

SurePass (identity and vehicle verification)

  • What they receive: Driving licence number, identity document details, vehicle registration number, FASTag ID; DigiLocker consent flows.
  • Purpose: DL, Aadhaar/ID, RC and FASTag verification against government registries.

Payment gateways — Razorpay, Cashfree, PhonePe, HDFC SmartGateway, Stripe

  • What they receive: Payer name, phone, email, amount, order reference.
  • Purpose: Collecting customer payments through payment links and paid invoices; subscription billing. Card and bank details are entered on the gateway's page, never on Kawst.

A1 Topup (FASTag recharge)

  • What they receive: FASTag ID, vehicle number, recharge amount.
  • Purpose: FASTag balance and recharge.

SMS / WhatsApp / email providers

  • What they receive: Phone number or email and the message content.
  • Purpose: OTPs, trip updates, quotations, invoices, payment reminders.

Google AdMob

  • What they receive: Advertising identifier and coarse device data, on the free plan only.
  • Purpose: Displaying advertisements that fund the free plan. Opt out through your device's ad settings.

Fleet owners, supervisors and partner operators you work with

  • What they receive: Driver profile, documents, location during duty, attendance, earnings, ratings — as the feature requires.
  • Purpose: Running the fleet you belong to. A driver's personal data is visible only to the owner who employs them and the staff that owner authorises.

Customers of a fleet owner

  • What they receive: Vehicle number, driver first name and masked phone number, live position during their trip.
  • Purpose: Trip-share pages. Full phone numbers are never shown on a public page.

Law enforcement, courts and regulators

  • What they receive: What the law requires.
  • Purpose: Compliance with a legal obligation or a lawful order.

If Kawst is acquired or merges with another business, personal data may transfer to the successor, who will be bound by this policy. We will notify you before that happens.

7. Security

  1. Data in transit is encrypted with TLS. Data at rest is encrypted by our cloud providers.
  2. Every server endpoint authenticates the caller before doing anything else; every database rule scopes owner data to the owning account. Admin tools require a separate secret and an admin role.
  3. Access by Kawst staff is limited to what support and operations require, uses the separate Kawst Admin app, and is logged in an append-only audit trail.
  4. Public links (trip share, payment, invoice, quotation) are unguessable capability tokens that expire — 48 hours to 90 days depending on the page — and cannot be listed or enumerated.
  5. Secrets and API keys live in managed secret stores, never in the app.
  6. Security logs are retained for at least one year. We test our rules and endpoints with automated suites on every change.

No system is perfectly secure. If we learn of a personal-data breach that affects you, we will tell you without delay, in plain language, what happened, what data was involved, what we are doing, and what you can do — and we will notify the Data Protection Board of India as the DPDP Rules require.

8. Where your data is stored

Our primary infrastructure runs in Google Cloud's Mumbai region and Amazon Web Services' Mumbai region, so your data is stored and processed in India by default. Two exceptions: the generative-AI API used for photo and text extraction (Section 5) may process requests outside India, and payment gateways and notification providers may route data through their own global infrastructure under their own safeguards. We will move AI processing to an India-resident endpoint before 13 May 2027 and will update this policy when we do.

9. How long we keep data

Account and profile

  • Retained for: While your account is active, then deleted within 30 days of a deletion request or 24 months of inactivity, whichever is earlier.

Raw GPS breadcrumbs and motion-sensor data

  • Retained for: 12 months, after which only trip-level summaries (start, end, distance, duration) are kept.

Driver documents (DL, ID images)

  • Retained for: While the driver's account is active; deleted with the account. An owner's copy of a former driver's record is limited to name, DL number, employment dates and rating.

Trips, expenses, payroll, ledger entries

  • Retained for: While the owner's account is active, then per the statutory periods below.

GST invoices, receipts, credit notes, payroll and statutory records

  • Retained for: 72 months from the end of the relevant financial year, as required by Section 36 of the CGST Act, 2017 and applicable labour and tax law, even if the account is deleted.

Payment and FASTag transaction records

  • Retained for: As required by RBI and the gateway's rules — typically 5 to 8 years.

Security and audit logs

  • Retained for: At least 12 months.

Public link pages

  • Retained for: The token expires 48 hours to 90 days after creation; the underlying record follows the rules above.

Crash and analytics data

  • Retained for: 90 days in identifiable form, aggregated thereafter.

Trial-abuse fingerprint and consent record

  • Retained for: From the start of your free trial, and for up to 3 years after the account is deleted (see "Free trials and account deletion" below).

Free trials and account deletion. To prevent misuse of free trials and promotions, when your free trial starts we store a one-way cryptographic fingerprint of your verified phone number and email address together with your trial start date. When you delete your account we delete your data and your login, but keep this fingerprint and a record of which versions of our Terms, Privacy Policy and Consent Notice you accepted, for up to 3 years. The fingerprint cannot be used to recover your phone number or email and is used for no other purpose.

Where retention rests on your consent and you withdraw it, we will erase the data or make it anonymous and, where the Rules require, give you 48 hours' notice before doing so.

10. Your rights

Under the DPDP Act you have the right to:

  1. Access: a summary of the personal data we hold about you, the processing we do, and the parties we have shared it with.
  2. Correction and completion: fix inaccurate, misleading or incomplete data. Most profile fields can be edited in the app.
  3. Erasure: delete your account and personal data. Use Profile → Account & role → Delete my account, or write to us. We erase everything except what Section 9 requires us to keep, delete your login, and send you an erasure confirmation.
  4. Withdraw consent: as easily as you gave it — the switches in Profile → Privacy turn motion sensors and marketing on or off; job-seeker visibility and home-location sharing are switched in your job profile, and background location in your phone's app permissions for Kawst. Withdrawal does not affect processing already done, and some features will stop working (for example a driver cannot run a tracked trip without location).
  5. Grievance redressal: raise a complaint with our Grievance Officer (Section 12). We acknowledge within 48 hours and resolve within 30 days, or sooner where the law requires.
  6. Nominate: name a person to exercise these rights for you if you die or become incapacitated.
  7. Complain to the regulator: if you are not satisfied with our response, you may complain to the Data Protection Board of India (dpb.gov.in).

To exercise a right, use the in-app control where one exists or write to the Grievance Officer with your registered mobile number. We will verify your identity before acting. There is no fee. This policy and the Consent Notice are available in English, Hindi, Kannada, Tamil, Malayalam and Punjabi in the app, and in any other Eighth Schedule language on request.

11. Children

Kawst is for adults. Commercial driving in India requires a person to be at least 18 (20 for transport vehicles), and every role on the platform requires you to be 18 or older. We do not knowingly collect a child's data. If you believe a child has registered, tell us and we will delete the account.

12. Grievance Officer and Data Protection contact

As required by the DPDP Rules, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Consumer Protection (E-Commerce) Rules, 2020:

Grievance Officer: Mandhir Singh

Phone: +91 91879 51284

Email: privacy@kawst.in — or support@kawst.in

Postal address: A-414, SLV Central Park, Bidare Agrahara, Bandapura Road, Bengaluru, Karnataka 560067, India

Hours: Monday to Saturday, 10:00 to 18:00 IST. Acknowledgement within 48 hours; resolution within 30 days.

13. Cookies and web pages

kawst.in and app.kawst.in use only strictly necessary cookies and local storage: your session, your language, and an installable-app preference. We do not use tracking cookies or third-party advertising cookies on the web. Public pages record only the standard server log (IP address, user agent, time) for security, kept 12 months.

14. Changes to this policy

We will give at least 15 days' notice in the app and by SMS or email before a material change takes effect, and will ask for fresh consent where the change adds a new purpose. The version number and effective date at the top identify the notice you consented to; earlier versions are available on request.


© 2026 One Kom Labs Technologies LLP. Kawst is a product of One Kom Labs Technologies LLP. Kawst and the Kawst logo are trademarks of One Kom Labs Technologies LLP.

Want to delete your account?

You can permanently delete your account and associated data from Profile → Privacy in the app, or by signing in here. This action cannot be undone.

Go to My Account