Vahanse Privacy Policy
Status: DRAFT — FOR LEGAL REVIEW — NOT FOR EXECUTION
Version: 0.9 - Counsel Review Draft
Draft date: 31 August 2026
Operator: Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512)
Brand: Vahanse
Head office: Vahanfin Solutions Pvt Ltd, Nabibux House, 3rd Floor, Vakola Bridge Road, Santacruz (E), Mumbai 400 055, Maharashtra, India
This document is a Vahanse-specific working draft prepared for Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512), which operates the Vahanse brand. It is not legal advice and must be reviewed, approved and adapted by qualified Indian counsel before publication, signature or reliance. Commercial values, support contacts, regulatory representations, security commitments, service levels and any customer-specific terms must be validated against actual operations and contracts.
Purpose: Public privacy notice for Vahanse platform, website, enterprise and partner interactions.
Audience: Website visitors, users, customer personnel and vehicle-related data subjects
1. Scope and Operator
This Privacy Policy explains how Vahanfin Solutions Private Limited, operating the Vahanse brand, handles digital personal data and related information when individuals use Vahanse websites, dashboards, APIs, white-label interfaces, enterprise services, support channels or service workflows.
This policy is drafted to support current Indian legal requirements and Vahanse’s transition to the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 as their provisions commence. The DPDP framework has staged commencement, and this policy should be revalidated before each material commencement date.
2. Roles in Different Contexts
For direct Vahanse accounts and direct customer interactions, Vahanse may determine the purpose and means of processing and may act as the applicable data fiduciary/controller role under law.
For enterprise, white-label or API customers, the business customer may determine the purpose of processing and Vahanse may process personal data on its documented instructions under a Data Processing Agreement. The precise role depends on the service and contract.
3. Categories of Information
- Account information: name, business email, mobile number, designation, company, authentication identifiers and support history.
- Business information: company details, GST/KYB data, user roles, branches, commercial configuration and billing information.
- Vehicle information: registration number, RC-related information, chassis/engine information where lawfully processed, vehicle class, compliance status and service history.
- Compliance information: challan, insurance, fitness, permit, PUC, road-tax, blacklist/flag or other compliance-related records from authorized sources.
- Documents: RC, insurance, permits, invoices, receipts, authorizations and other documents uploaded or generated in a workflow.
- Transaction information: service orders, quotations, payments, refunds, invoices, settlement records and reconciliation metadata.
- Technical information: IP address, device/browser information, timestamps, logs, API keys/identifiers, webhook events, security events and cookie/analytics identifiers.
- Communications: calls, emails, chat, support tickets, feedback and account-management communications.
4. Sources of Information
Information may be collected directly from the individual, from the individual’s employer/business, from a white-label or API partner, from uploaded files, from authorized public/government/third-party data sources, from service providers, and from technical use of Vahanse.
5. Purposes of Processing
- Create and secure accounts and manage access.
- Provide vehicle/compliance monitoring and service workflows.
- Process service requests, payments, documents, fulfilment, refunds and reconciliation.
- Integrate with customer systems, APIs, webhooks and white-label deployments.
- Send operational alerts, expiry reminders, security notices and service updates.
- Prevent fraud, abuse and unauthorized data access.
- Provide customer support and resolve disputes.
- Maintain audit trails, accounting and statutory records.
- Improve platform reliability, user experience and permitted analytics.
- Comply with law, lawful authority requests and contractual obligations.
6. Consent and Other Permitted Processing
Where consent is required, Vahanse will seek consent that is specific, informed and capable of withdrawal as required by applicable law. In business contexts, Vahanse may also process data where necessary to perform contracts, comply with law, address security/fraud, respond to lawful requests, or on another lawful basis available at the relevant time.
Business customers are responsible for ensuring that they have authority and provide required notices/consents for personal data they submit to Vahanse.
7. Vehicle Numbers and Vehicle-Linked Information
A vehicle registration number can relate to an identifiable person in some contexts. Vahanse therefore applies access controls and purpose limitations to vehicle-linked information and requires customers to use it only for authorized business, compliance or service purposes.
8. Children
Vahanse is primarily intended for adults and business users. Vahanse does not knowingly offer accounts directly to children. If processing relating to a child becomes relevant, Vahanse and the applicable business customer must implement age/guardian controls required by then-applicable law before such processing.
9. Sharing
Vahanse may share information with contracted processors/subprocessors, cloud/infrastructure vendors, payment providers, communications providers, analytics/security providers, data sources, insurers, execution vendors, professional advisers and Authorities when reasonably necessary for an authorized purpose.
Vahanse does not sell personal data to advertisers. Customer data is not provided to unrelated advertisers for their independent advertising use merely because the customer uses Vahanse.
10. White-Label and Enterprise Customers
A white-label or enterprise customer may have access to data relating to its authorized customers, fleet, employees or vehicles. That customer is responsible for its own privacy notices, lawful instructions, user access and downstream use. Vahanse will apply contractual controls and role-based access where supported.
11. Subprocessors
Vahanse maintains an enterprise subprocessor list identifying material categories/providers used to process customer personal data. Enterprise customers may receive notice of material changes where contractually agreed.
12. International Processing
Where data is processed or accessed outside India, Vahanse will apply applicable contractual, security and legal controls and comply with restrictions or notifications issued under applicable Indian law. Actual hosting and subprocessor locations must be maintained in the current Subprocessor List.
13. Security
Vahanse uses administrative, technical and organizational controls appropriate to the nature of its services. Security controls are described at a high level in the Vahanse Security Overview. No system is risk-free; users should promptly report suspected credential compromise or security incidents.
14. Retention
Vahanse retains information for the period reasonably necessary to provide the service, comply with tax/accounting/legal obligations, resolve disputes, enforce agreements, maintain security/audit history and meet customer instructions. Retention schedules may differ by data category and enterprise contract.
15. Data Principal / Individual Rights
To the extent rights are in force and applicable, individuals may request access to prescribed information, correction, completion, updating, erasure, grievance redressal and withdrawal of consent as applicable. Requests may be subject to identity verification, legal retention and the role of the relevant enterprise customer.
16. Grievances
Privacy or personal-data grievances may be submitted to contact@vahanse.com. The final published policy should identify the designated grievance contact/officer and response process required by law at the relevant time.
17. Security Incidents
Vahanse maintains an incident-response process. Notifications to customers, individuals or authorities will be made where required by then-applicable law and contract, based on the nature and impact of the incident.
18. Cookies and Analytics
Vahanse uses only the cookies and analytics technologies described in the current Cookie Policy. Non-essential cookie controls should reflect the technologies actually deployed and applicable consent requirements.
19. Government and Legal Requests
Vahanse may disclose information where required by valid legal process or law. Where lawful and appropriate, Vahanse will seek to ensure that requests are properly directed, proportionate and documented.
20. Changes and Contact
This policy may be updated as the platform, law or processing changes. Material changes will be communicated as required. Operator: Vahanfin Solutions Private Limited, CIN U52290JH2023PTC021512, head office Nabibux House, 3rd Floor, Vakola Bridge Road, Santacruz (E), Mumbai 400 055, Maharashtra, India. Privacy contact: contact@vahanse.com.
Counsel Review Notes
- Counsel should confirm the DPDP commencement dates applicable at publication and align consent notices, breach reporting, retention and grievance mechanics accordingly.