← Yantram

Privacy Policy

Last updated 5 September 2026

01Who we are

Yantram is operated by [REGISTERED COMPANY NAME], a company incorporated in India with its registered office at [REGISTERED ADDRESS] (“Yantram”, “we”, “us”). We run a marketplace connecting construction firms with vendors of building materials and equipment.

For the purposes of India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”), we are the Data Fiduciary for the personal data described below. This policy explains what we collect, why we collect it, how long we keep it, and what you can require us to do with it.

02What we collect, and why

Every item below is collected for a stated purpose and kept only for as long as that purpose or the law requires. We do not collect anything for a purpose not listed here.

Mobile number

It is how you sign in — we send a one-time code rather than asking you to keep a password. It is also how a vendor and a driver reach each other about a live delivery.

While your account is open

Name, role and company

So your colleagues can see who booked an order or approved a payment, and so we know who has authority to act for your firm.

While your account is open

GST number and registered address

Required to raise a valid tax invoice. Verified against the GST registry where you ask us to.

8 years (statutory)

Site addresses and their coordinates

To match your request to vendors who can actually reach it, quote a realistic delivery window, and give a driver a destination.

While the site is on your account

Site engineer name and phone

So a driver arriving at a site has someone to call. Shared with the assigned vendor for that delivery only.

While the site is on your account

Device location during an active delivery

To show a builder where their delivery is. Captured only while an order is in motion, only from a device whose user has granted permission, and never in the background once the delivery ends.

30 days

Delivery photographs

Proof of delivery. It is what settles a dispute about whether, when and in what condition goods arrived.

8 years (statutory)

Vendor documents (GST certificate, RC book, premises photographs)

To verify that a vendor is a real, registered business and that listed equipment exists and is roadworthy.

While the vendor account is open, then 8 years

Orders, invoices, payments and credit records

To run the transaction, raise invoices, settle vendors, and manage the credit we extend.

8 years (statutory)

Technical logs and crash reports

To find and fix failures. These contain the page you were on, the request identifier, and — where you were signed in — your user identifier.

30 days

In-app behaviour (screens opened, a booking started, support contacted)

To understand how Yantram is actually used, and to notice early when a company's usage pattern looks like it is heading toward churn — so we can reach out before they leave, rather than after. Unlike everything else on this page, this purpose is not necessary to fulfil an order; see clause 3 for how to turn it off.

12 months

The eight-year retentions are not our choice. Section 36 of the Companies Act, 2013 and the GST rules require books of account and tax records to be preserved for that period, and a delivery photograph is part of the record supporting an invoice.

03Behavioural analytics for retention marketing

Separately from the data we collect to run your account, we log a small set of in-app actions — a screen opened, a booking flow started, a quote viewed, support contacted — against your account. This is the one purpose on this page that is not necessary to fulfil an order: we use it to understand usage patterns across our customers and to identify, early, when a company’s engagement looks like it is heading toward churn, so our team can reach out before a relationship lapses rather than after.

Every one of these events is something you did in the product, not a page you were merely shown, and none of it is shared with any third party or used for advertising. Server-recorded facts about your own orders — a delivery completing, a claim being raised — are logged alongside the same way; a browser is never allowed to assert one of those happened, only a completed transaction is.

Because this is a distinct purpose from operating your account, it is also the one thing on this page you can switch off independently: turn off “Usage analytics” in Settings and no further behavioural events are recorded against your account. Doing so does not affect order history, invoices, or anything needed to run your account — it only stops the usage signal described above.

04Location, specifically

Location is the most sensitive thing we handle, so it is worth being precise. A browser will not give us a device’s position unless the person using it grants permission, on that device, for this site. There is no way for us to override that from our side, and we do not attempt to.

We ask for it in exactly two situations: when a builder chooses to drop a pin for a new site, and while a vendor’s delivery is actually in motion. In the second case tracking starts when the order is dispatched and stops when it is marked delivered — not between jobs, not overnight, not when the app is closed. Each stored position is tied to the specific order it was captured for, so the question “why do you hold this?” always has an answer, and rows are deleted automatically after 30 days.

You can withdraw the permission at any time in your browser’s site settings. Doing so stops collection immediately. It also stops live tracking working, which is the only thing it is used for.

05Who else sees it

We do not sell personal data, and we do not share it for anyone else’s advertising. We share it only:

  • Between the parties to a transaction. A vendor you have accepted sees the delivery address, the site contact and the order. A builder sees the assigned vendor and driver. Neither sees anything about your other orders.
  • With service providers who act on our instructions. Our hosting and database provider (Google Cloud, in their Mumbai region), our SMS and WhatsApp messaging providers for delivering one-time codes and order updates, and our payment and settlement partners. Each is bound to use the data only to provide that service.
  • Where the law requires it — a court order, a tax authority, or a lawful request from a government agency.

Your data is stored in India. If that ever changes we will say so here before it happens, and only to a country not restricted by the Central Government under the DPDP Act.

06Your rights

Under the DPDP Act you can, at any time:

  • Ask what we hold — a summary of your personal data and who we have shared it with.
  • Have it corrected or completed if it is wrong or out of date. Most of it you can edit yourself in the app.
  • Have it erased, unless we are required to keep it — which, for invoices, payments and the delivery records supporting them, we are, for eight years.
  • Withdraw consent as easily as you gave it. Location permission is revoked in your browser; notification consent in the app’s settings.
  • Nominate someone to exercise these rights on your behalf in the event of your death or incapacity.
  • Complain — to our Grievance Officer first, and to the Data Protection Board of India if we do not resolve it.

Write to [PRIVACY EMAIL] and we will respond within 30 days. We may need to confirm your identity first, which for most requests means a one-time code to your registered number.

07How we protect it

Traffic is encrypted in transit and data is encrypted at rest. Access within Yantram is scoped by role, so an operations executive who handles deliveries cannot see credit limits or record payments. Every change to an order, an invoice or a credit line is written to an audit trail with the person who made it.

If a breach affects your data we will notify you and the Data Protection Board as the DPDP Act requires, without waiting to complete our own investigation first.

08Children

Yantram is a tool for businesses and is not directed at anyone under 18. We do not knowingly create accounts for children. If you believe a child’s data has reached us, tell us and we will delete it.

09Changes, and how to reach us

If we change this policy in a way that affects what we collect or why, we will tell you in the app before it takes effect, not only by editing this page.

Grievance Officer: [NAME], [PRIVACY EMAIL], [REGISTERED ADDRESS]. As required by section 13 of the DPDP Act, this is the person responsible for answering questions about how we handle your data.