Privacy Policy
Effective Date: August 2, 2026 | Last Updated: August 2, 2026
iLogitix – Logistics, Compliance & Workforce Platform
Operated by iFleetify Technologies LLP
1. Introduction
iFleetify Technologies LLP ("we", "us", "our", or "Company"), a Limited Liability Partnership registered in Ahmedabad, Gujarat, India (LLPIN / CIN: ACD-6633), respects your privacy and complies with:
- Information Technology Act, 2000
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Digital Personal Data Protection Act, 2023 (DPDP)
This policy applies to all users of iLogitix (the "Service") — including logistics / TMS, GST e-invoice & e-way bill modules, HRMS, and related features — and to tenants, administrators, employees using the platform, and other end users.
By using the Service, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, you must not use the Service.
2. Data We Collect
2.1 Personal Data
- Name, email address, phone number
- Login credentials (username, password)
- Role & permissions within the platform
- Profile information and preferences
2.2 Logistics & Business Data
Where you use logistics / TMS features, we process:
- Booking & LR Data: LR (Lorry Receipt) numbers, booking details, consignor/consignee information
- Transaction Data: Invoice amounts, payment records, GST details, billing accounts
- Logistics Data: Origin/destination addresses, pincodes, vehicle numbers, driver information
- Delivery Data: Delivery status, POD (Proof of Delivery), OTP verification records, delivery location
- Customer Data: Customer billing accounts, credit limits, customer contact information
2.3 E-Way Bill & GST Compliance Data (where enabled)
- GSTIN, transporter / vehicle details, consignment and invoice particulars used for e-way bills
- E-way bill numbers, status, distance, validity / expiry, extension history, consolidated e-way bill records
- GSP / portal credentials and authentication tokens you configure (stored securely; used only to provide the feature)
- Operational reports and notifications related to missing / expiring e-way bills
2.4 HRMS / Workforce Data (where enabled)
Where you use HRMS modules, we process employee and workforce data that you (Tenant) enter or that employees submit through self-service, which may include:
- Identity & contact: name, employee code, photo, date of birth, gender, marital status, addresses, personal/work email, phone, emergency contacts
- Employment: department, designation, branch/work location, joining/exit dates, reporting manager, employment category, shifts, week-offs
- Identifiers & statutory (where provided): PAN, Aadhaar, UAN, PF / ESI numbers, passport details, tax regime
- Bank & compensation: bank account number, IFSC, bank name, account holder name, wage type, salary / daily wage
- Attendance & leave: check-in/out times, attendance status, geo-location / geo-fence coordinates (where self-attendance is enabled), regularization requests, leave balances and leave requests
- Payroll: payroll period data, payslips, deductions/earnings as configured by you
- Documents & profile extras: uploaded employee documents (e.g. ID proofs), education, experience, skills
Sensitive / high-risk identifiers: PAN, Aadhaar, bank account numbers, and similar identifiers are processed only because you choose to store them for employment / payroll purposes. You must collect and use them lawfully (including Aadhaar usage restrictions under Indian law). We process them as your Data Processor and do not use them for our own marketing.
2.5 Technical Data
- IP address and location data
- Browser & device information
- Logs & API activity
- Usage patterns & analytics
- Cookies and tracking technologies
2.6 Payment & Billing Data (platform subscription)
- Subscription / service invoice details (invoice number, amounts, due dates, status)
- Online payment metadata from Razorpay (order id, payment id, status, charged amount, gateway fee markup, timestamps)
- Offline / manual payment records (amount, method, reference, date/time)
We do not store raw card numbers, CVV, full track data, or UPI PINs. Sensitive payment credentials are handled by Razorpay on Hosted Checkout. We store only limited metadata needed for reconciliation, support, accounting, and dispute resolution.
3. Purpose of Processing
We process your data for the following purposes:
3.1 Logistics / TMS Service Delivery
- Managing booking and LR lifecycle
- Tracking deliveries and generating POD
- OTP verification for secure deliveries
- Route / dispatch related workflows
- Invoice generation with GST-aware calculations
- Payment tracking and reconciliation within your logistics operations
3.2 E-Way Bill & GST Compliance Features
- Generating, syncing, extending, consolidating, and reporting e-way bills via GSP / portal integrations you enable
- Authenticating to government-connected systems using credentials you provide
- Sending operational alerts (e.g. missing / expiring e-way bills) as configured
3.3 HRMS / Workforce Administration
- Maintaining employee masters and employment records you enter
- Recording attendance, leave, and regularization workflows
- Supporting geo-fenced self-attendance where you enable it
- Running payroll periods and generating payslips for your workforce
- Sending HRMS-related notifications (e.g. leave / action emails) as configured
3.4 Account Management
- User authentication and authorization
- Role-based access control (including HRMS self-service linkage to users)
- Account administration and support
- Communication regarding service updates
3.5 Financial Operations (platform subscription)
- Raising and sending service invoices for subscription / platform charges
- Processing online payments via Razorpay and recording manual / offline payments
- Payment reconciliation, duplicate-credit prevention, failed-payment and refund handling where applicable
- Maintaining records for accounting, audits, tax (when applicable), and dispute resolution
- Tenant billing account / credit features within the logistics product (separate from platform subscription)
3.6 Compliance & Security
- Supporting GST / e-invoice / e-way bill workflows you configure (you remain responsible for filings)
- Audit trails for logistics, e-way, and HRMS transactions
- Security monitoring and fraud prevention
- Regulatory reporting (if required of us as processor / platform operator)
- Legal compliance with applicable laws
3.7 Service Improvement
- Analytics and usage patterns
- Platform optimization and enhancements
- Customer support and troubleshooting
4. Data Fiduciary & Processor Roles
Under the DPDP Act, 2023:
- You (Tenant/Organization): Act as the Data Fiduciary for personal data of your customers, consignors/consignees, drivers, employees, and other individuals you process in logistics, e-way bill, and HRMS modules
- We (iFleetify Technologies LLP): Act as the Data Processor for such Tenant data
You confirm that you have a lawful basis (including consent, employment relationship, contract, or legal obligation as applicable) for all data principals (your customers, employees, vendors, drivers) whose data is processed through the Service, in accordance with applicable data protection laws including the DPDP Act, 2023.
As Data Processor, we process data solely for the purposes specified in this Privacy Policy and as instructed by you (Data Fiduciary).
5. Customer & Third-Party Data (Data Fiduciary Responsibilities)
As Tenant, you collect and process data about your customers (consignors, consignees, drivers, etc.) and — where HRMS is enabled — your employees and related contacts. Important responsibilities:
5.1 Your Responsibilities as Data Fiduciary
- Establish a lawful basis before collecting/processing personal data (customers, employees, drivers, etc.)
- Inform data principals about processing purposes (including attendance geo-location and payroll identifiers where used)
- Handle data principal requests (access, correction, deletion, etc.)
- Comply with DPDP Act and employment / labour notice requirements for workforce data
- Respond to privacy complaints from customers and employees
- Ensure data accuracy and completeness (including e-way bill and payroll inputs)
- Implement appropriate security measures and limit internal access to sensitive HR / bank / ID data
- Use Aadhaar and other regulated identifiers only as permitted under Indian law
5.2 Our Role as Data Processor
- Process data only as instructed by you (Data Fiduciary)
- Assist with data subject requests (subject to fees for complex requests)
- Maintain reasonable security measures
- Notify you of data breaches affecting your data
- Comply with data processing agreements
⚠️ IMPORTANT
You warrant that all customer and employee data processed through the Service is collected and used lawfully (including for logistics, e-way bill, and HRMS purposes). You are solely responsible for compliance with data protection and employment laws as Data Fiduciary. We are not liable for your failure to obtain a proper lawful basis or comply with data protection obligations.
6. Data Security & Breach Response
We implement reasonable technical and organizational safeguards to protect your data, including:
- Encryption in transit (HTTPS/TLS) and at rest
- Access controls & multi-factor authentication
- Regular security audits and assessments
- Secure data centers with physical security
- Backup & disaster recovery procedures
- Network security and firewall protection
- Employee training on data security
6.1 Breach Notification Timeline
- Affected tenants notified within 72 hours of discovery
- Regulatory authorities notified per legal requirements (DPDP Act)
- Data principals (your customers) notified by you (as Data Fiduciary)
- We will provide breach details to assist your notifications
⚠️ IMPORTANT - No Liability For:
- Breaches caused by tenant credential compromise
- Breaches in third-party services outside our control
- Social engineering attacks on tenant employees
- Unauthorized access via compromised API keys
- Data exposure due to misconfigured tenant settings
- Breaches due to user negligence or weak passwords
No system is 100% secure. We cannot guarantee absolute security. Breaches may occur despite reasonable safeguards.
7. Data Sharing
We do NOT sell your data to third parties.
Data may be shared with the following categories of service providers:
7.1 Communication Services
- SMS Providers: Twilio, MSG91, TextLocal, AWS SNS
- WhatsApp Services: Twilio WhatsApp, WhatsApp Business API, Gupshup
- Email delivery providers: For transactional emails (invoices, OTPs, HRMS / e-way notices)
- Purpose: Delivery notifications, OTP delivery, customer communications, and HRMS / e-way operational notices as configured by you
- Data Shared: Recipient phone numbers / emails, message content
7.2 Financial & Compliance Services
- Payment Gateway – Razorpay: To create payment orders, process Hosted Checkout, confirm payment status via APIs/webhooks, and process refunds where applicable
- Data Shared with Razorpay: Transaction amounts, currency, invoice/order references, and business contact details needed for checkout — not raw card/UPI secrets on our side
- E-Invoice / E-Way Bill / GSP & government systems: Where enabled by you, invoice / consignment / vehicle / GSTIN data and credentials you configure are transmitted to GSP and/or GST portal systems to perform e-invoice / e-way bill operations. Those systems process data under their rules; we do not control government portals.
7.3 Cloud Infrastructure
- Primary hosting: Amazon Web Services (AWS ap-south-1, Mumbai, India) for application, database, and backups
- Purpose: Secure hosting, storage, backup, and infrastructure
- Data Shared: Platform data necessary to operate the Service (subject to cloud provider terms and safeguards)
7.4 Legal & Regulatory
- Legal Authorities: When required by law, court orders, or government requests
- Regulatory Bodies: For compliance with applicable regulations
7.5 Business Transfers
- In case of merger, acquisition, or sale of assets
- Data transfer subject to successor entity's privacy policy (with opt-out rights where applicable)
All third parties are contractually bound to maintain confidentiality and use data only for specified purposes. We require third parties to implement appropriate security measures.
8. Data Retention & Deletion
8.1 Active Accounts
- All transaction data retained while account is active
- Historical LR/booking data: Indefinitely (or as per your subscription plan)
- E-way bill operational records: while active (or as required for your GST / audit needs)
- HRMS employee, attendance, leave, and payroll / payslip data: while active (you should export before offboarding employees or terminating the Tenant)
- Subscription invoices and payment records (including Razorpay metadata): retained while active and thereafter as needed for accounting, disputes, and applicable Indian record-keeping rules (commonly up to 8 years for books of account where relevant)
- User accounts: Retained while active
8.2 Terminated Accounts
- Booking/LR data: 90 days post-termination
- E-way bill records: 90 days post-termination (subject to longer retention if needed for legal hold)
- HRMS workforce data (employees, attendance, leave, payslips, documents): typically 30–90 days post-termination for operational deletion, after which data is permanently deleted from active systems (subject to backups and legal hold)
- Invoice / payment / financial records: retained as required for accounting, disputes, and Indian tax / commercial record-keeping (even where GST is not currently charged on platform subscription invoices)
- User accounts: 30 days
- Audit logs: 90-365 days depending on log type
- Backups: Deleted after 90 days (subject to backup rotation)
8.3 Compliance Retention
- Financial and invoice records: As per applicable Indian laws and our accounting practice
- Where GST applies to any charges in future: retention as required under GST / tax laws
- You (Tenant) remain responsible for retaining payroll, wage, PF/ESI, and GST / e-way records for periods required by Indian labour and tax law — export from the Service as needed
- Audit trails: 90-365 days depending on log type
- Security logs: 90-180 days
You are responsible for exporting your data before account termination. We are not obligated to retain data beyond the retention periods stated herein. After retention period expires, data will be permanently deleted and cannot be recovered.
9. Your Rights (DPDP Act, 2023)
As a data principal, you have the following rights:
9.1 Right to Access
Request a copy of your personal data that we process. We will provide data in a structured, commonly used format.
9.2 Right to Correction
Request correction of inaccurate or incomplete personal data. You can update most data through the Service interface.
9.3 Right to Deletion
Request deletion of personal data, subject to legal and legitimate retention requirements (for example invoice and payment records retained for accounting, disputes, and applicable Indian laws). Deletion may affect service availability.
9.4 Right to Withdrawal of Consent
Withdraw consent for data processing. Withdrawal may affect service availability as certain data processing is necessary for service delivery.
9.5 Right to Grievance Redressal
File complaints with our Grievance Officer (Ravi Patel, Designated Partner) using the contact details in Section 16, or with the Data Protection Board (DPB) if you believe your data rights have been violated.
9.6 Exercising Your Rights
To exercise these rights, contact us at info@ilogitix.com or info@ifleetify.com. We will respond within 30 days as required by the DPDP Act, 2023.
Note: For data that you (Tenant) collect about your customers or employees, you (as Data Fiduciary) are responsible for handling their data subject requests. We will assist you as Data Processor.
10. Third-Party Integrations
The Service may integrate with third-party services for enhanced functionality:
- Razorpay – online subscription invoice payments (Hosted Checkout)
- SMS/WhatsApp providers for notifications
- E-Invoice / E-Way Bill / GSP services and GST government portals where enabled
- Mapping / Places services for logistics location features and HRMS geo-fence attendance (where enabled)
- Email delivery providers for transactional emails (invoices, payment confirmations, OTPs, HRMS / e-way notices)
We are not responsible for third-party privacy practices. Your use of integrated third-party services is subject to their privacy policies. Please review third-party privacy policies before using integrated services.
Third-party services may collect and process data independently. We recommend reviewing their privacy policies.
11. Cookies & Tracking Technologies
We use cookies and similar technologies to:
- Maintain session state & authentication
- Remember preferences & settings
- Analyze usage patterns and improve service
- Ensure security and prevent fraud
You can control cookies through your browser settings, but disabling cookies may affect service functionality (e.g., you may need to log in more frequently).
We do not use cookies for advertising or tracking across other websites.
12. Data Location & Transfers
Primary hosting for the Service application, databases, and backups is on Amazon Web Services in India (AWS region ap-south-1, Mumbai).
- Payment card / UPI credential processing occurs with Razorpay under Razorpay's systems and compliance obligations (we do not store raw card/UPI credentials).
- Certain optional subprocessors (for example SMS/WhatsApp providers, email delivery providers, e-invoice / e-way bill GSPs, maps/places providers) may process limited data to deliver those features. Some of those providers may process data outside India as needed for that feature.
- Where cross-border processing occurs for such subprocessors, we rely on contractual and reasonable security safeguards and applicable law.
By using features that depend on third-party communications or government-connected tax services, you acknowledge that limited related data may be processed by those providers as described in this Policy and their own policies.
13. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
14. Data Processing by Module
Depending on which modules you enable, the Service processes data for logistics, GST compliance, and workforce operations:
14.1 Shipping & Delivery Data
- Consignor and consignee information (names, addresses, contact details)
- Origin and destination locations
- Shipment contents and values
- Delivery status and tracking information
- POD (Proof of Delivery) and delivery confirmations
14.2 Vehicle & Driver Data
- Vehicle registration numbers
- Driver names and contact information
- Vehicle tracking data (if GPS enabled)
14.3 E-Way Bill & GST Compliance Data
- GSTIN, invoice / consignment particulars, transporter and vehicle details used for e-way bills
- E-way bill numbers, validity, extensions, consolidated e-way bills, and sync status from GSP / portals
- Credentials you store for GSP / portal authentication
Government / GSP systems may retain copies of filings under their own rules. Accuracy and lawful use of e-way bill data remain your responsibility.
14.4 HRMS / Workforce Data
- Employee identity, employment, statutory, and bank details you maintain
- Attendance punches and optional geo-location used for geo-fence validation
- Leave and regularization workflows
- Payroll period outputs and payslips
- Employee documents and profile attachments
We are not the employer. You must inform employees about monitoring (e.g. geo-fenced attendance) and process workforce data only for legitimate employment / payroll purposes.
14.5 Financial & Billing Data
- Tenant logistics invoice amounts and customer payment records within your operations
- Platform subscription service invoices and payment history (online via Razorpay or manual)
- GST details and tax calculations where applicable to your logistics documents / features
- Credit limits and billing accounts within the logistics product
You (Tenant) are responsible for establishing a lawful basis with consignors, consignees, drivers, employees, and other parties whose data is processed through the Service.
15. Updates to Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or service features. Material changes will be notified via:
- Email to registered email address
- In-service notifications
- Updated policy posted on website with updated "Last Updated" date
Continued use of the Service after changes constitutes acceptance of the updated policy. If you disagree with changes, you must stop using the Service and terminate your account.
We encourage you to review this Privacy Policy periodically to stay informed about how we process your data.
16. Contact Information & Grievance Officer
For privacy-related inquiries, complaints, billing/payment data questions, or to exercise your rights, contact:
iFleetify Technologies LLP
Registered Office: 49/1 Parsottam Nagar, Near Ramapir Temple
Besides Gokulnagar, Sarkhej
Ahmedabad – 382210, Gujarat, India
LLPIN / CIN: ACD-6633
Email: info@ilogitix.com | info@ifleetify.com
Phone: +91 8511 8611 04
Grievance Officer
Name: Ravi Patel
Designation: Designated Partner
Email: info@ilogitix.com | info@ifleetify.com
Phone: +91 8511 8611 04
Address: Same as registered office above
SLA: We will acknowledge grievances within 48 hours and endeavour to resolve them within 30 days of receiving a complete complaint. You may also escalate privacy concerns to the Data Protection Board of India where applicable under the DPDP Act.
📋 Additional Information
For details on subscription terms, SLA, API usage, and data protection addendum, please refer to the Terms of Service and applicable Annexures.
Note: This Privacy Policy should be read in conjunction with the Terms of Service. In case of conflict between this Privacy Policy and signed agreements, the signed agreements shall prevail.