Privacy Policy
Last Updated: August 28, 20261. Introduction
Poyaloo ("we", "our", or "us"), operated by Poyaloo Technologies Pvt. Ltd. (incorporation pending, currently represented by Dinexora UG), operates the Poyaloo cashless, scan-and-go public transit ticketing platform in Kerala, India. We are committed to protecting the privacy of our commuters, operators, and partners.
This Privacy Policy is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) of India, Section 43A of the Information Technology Act, 2000, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It outlines how we collect, process, store, and secure your personal data (referred to as "personal data" or "information") as a Data Fiduciary.
2. Data Fiduciary & Grievance Redressal Officer
Under the DPDP Act, 2023, Poyaloo acts as the Data Fiduciary. Our headquarters and contact details are:
Poyaloo Technologies Pvt. Ltd.
opposite Infosys Campus, Thampuranmukku, Thiruvananthapuram, Kerala 695583, Kerala, India
Email: contact@dinexora.de
In compliance with Section 4 of the DPDP Act and the IT Act, we have appointed a Grievance Redressal Officer to handle any user complaints, queries, or requests regarding personal data processing:
Grievance Redressal Officer: Sreelesh Kunnath
Poyaloo Technologies Pvt. Ltd., opposite Infosys Campus, Thampuranmukku, Thiruvananthapuram, Kerala 695583, Kerala, India
Email: grievance@poyaloo.com / contact@dinexora.de
3. Consent and Notice (DPDP Act Sec. 5 & 6)
We process your personal data only after providing a clear notice and obtaining your free, specific, informed, unconditional, and unambiguous consent. By registering on the Poyaloo app, you consent to the processing of your data for ticketing, transit verification, and wallet management. You have the right to withdraw your consent at any time, which will limit our ability to provide transit services to you.
4. Personal Data We Collect
We collect only the minimum necessary data to facilitate cashless ticketing in Kerala's bus networks (Data Minimisation):
- Identity & Account Data (Data Principal): Name, mobile number (verified via OTP), role (Passenger or Conductor), and digital wallet balances.
- Transit & Ticket Logs: Bus boarding and alighting stops (stops within Kerala districts), ticket purchase details, fares paid (in Indian Rupees - INR), validation timestamps, and scan logs.
- Location & GPS Data: Real-time location data of conductors while active on routes (in compliance with Kerala Motor Vehicles Department standards) to verify schedule adherence. Passenger location is accessed only during ticket scans to prevent out-of-boundary validation.
- Financial Transaction Logs: Top-up records, payment gateway identifiers (e.g., UPI, debit/credit cards, net banking transaction IDs). Note: We do not store raw card numbers or UPI PINs; all payments are handled securely by RBI-licensed payment aggregators.
5. Purposes of Processing
Your personal data is processed solely for specific, lawful purposes related to Kerala's transit services:
- To validate bus tickets via QR codes scanned on private stage carriages and KSRTC bus services in Kerala.
- To maintain passenger digital wallets in compliance with RBI guidelines on semi-closed wallets.
- To verify conductor route logs and GPS coordinates in alignment with Kerala Motor Vehicles Department (MVD) guidelines.
- To prevent fraud, ticket cloning, and unauthorized conductor logins.
6. Data Storage & Localization
In accordance with Indian regulations and data localization requirements, all personal data, transaction logs, and ticketing records of Poyaloo users are stored on secure cloud databases located within the geographic boundaries of India.
7. Rights of the Data Principal (DPDP Act Sec. 11, 12, 13 & 14)
Under the DPDP Act, 2023, you (as the Data Principal) possess the following statutory rights:
- Right to Summary & Access (Sec. 11): Request a summary of your personal data being processed, the identities of Data Fiduciaries we share it with, and download a digital copy.
- Right to Correction & Erasure (Sec. 12): Rectify inaccurate details, update obsolete information, or request the erasure of your personal data when it is no longer required for the purpose of ticketing.
- Right to Grievance Redressal (Sec. 13): File a complaint with our Grievance Officer regarding any privacy concern. If unresolved, you hold the right to escalate to the Data Protection Board of India.
- Right to Nominate (Sec. 14): Nominate another individual to exercise your data rights in the event of death or incapacity.
8. Data Security & Breach Notification
We employ reasonable security practices and procedures (complying with IS/ISO/IEC 27001 standards) to protect personal data from unauthorized access, modification, or disclosure. In the event of a personal data breach, we will notify the Data Protection Board of India (DPBI) and the affected users in the manner prescribed by the DPDP Act rules.