This Privacy Policy explains how Zendly Express Private Limited ("Zendly", "we", "our", or "us") collects, uses, stores, shares, and protects personal data when you use the Zendly mobile application, website, customer support, and related sender, receiver, carrier, payment, and delivery services (collectively, the "Services").
This policy is intended to be read with our Terms and any in-app notices or consent screens. It is prepared with reference to applicable Indian law, including the Information Technology Act, 2000, its rules, and the Digital Personal Data Protection Act, 2023 and rules brought into force from time to time. Where a specific consent notice conflicts with this general policy, the more specific notice applies.
1. Scope and Who This Policy Covers
This policy applies to senders, receivers, carriers, partners, applicants, account holders, visitors, and other individuals who interact with Zendly. Different features collect different information. You may not be able to use a feature if information necessary for that feature is not provided.
2. Personal Data We Collect
2.1 Account and profile data
- Name, mobile number, email address, address, profile photo, preferred language, account role, and account status.
- Authentication information such as one-time passwords, access/session tokens, and role-selection information. We do not ask you to disclose your account password to other users.
2.2 Identity, eligibility, and verification data
- For Carriers, Aadhaar verification is mandatory as part of the identity verification process. Zendly may process Aadhaar-related information required to complete the verification, including the Aadhaar number, OTP, name and date-of-birth details, through the applicable identity-verification service.
- Zendly may retain the verification result, verification status, reference number, masked identifier and relevant audit information as permitted or required by applicable law. Zendly does not intend to retain Aadhaar OTPs after the verification process is completed.
- Additional identity or eligibility documents and related verification information may be requested where applicable, depending on the selected transport mode, service requirements or applicable law.
2.3 Location and route data
- Precise or approximate device location, pickup and delivery coordinates and addresses, selected routes, travel-plan locations, distance, proximity, geofence results, and timestamps.
- For carriers who choose to go online or perform an active delivery task, Zendly may collect and transmit location in the background, including when the app is not visible, so that nearby jobs can be matched and active deliveries can be tracked. A persistent system notification or background-location indicator may be shown where required by the operating system.
- For senders and other users, foreground location may be used for map selection, nearby-service checks, meeting-point verification, and delivery tracking.
2.4 Booking, parcel, and delivery data
- Booking identifiers; sender, receiver, and carrier details; pickup method; parcel type, category, description, weight, dimensions, declared value, fare, requested transport mode, delivery plan, schedule, and status history.
- Parcel photographs, booking attachments, pickup and drop-off proof photographs, OTP verification events, cancellation or report reasons, report comments and images, ratings, reviews, and delivery timestamps.
2.5 Payment, bank, wallet, and payout data
- Selected payment method, fare and amount, payment/order identifiers, payment status, transaction references, refunds, wallet balance, earnings, commissions, withdrawal requests, and settlement records.
- For carrier payouts: account-holder name, bank account number, bank name, IFSC code, verification status, and related payout details.
- Payment card, UPI, or similar payment credentials may be collected directly by the payment gateway within its checkout interface. Zendly does not intend to store full card numbers, CVV, UPI PINs, or payment-gateway secrets in the mobile app.
2.6 Device, notification, and technical data
- Device and app identifiers, Firebase Cloud Messaging token, notification preferences and delivery data, operating-system and app version, device model, IP address and server logs, language/locale, crash or diagnostic information, and security/session events.
- Locally stored app state may include login/session tokens, active booking identifiers, route selections, drafts, notification payloads, and cached booking or profile information.
2.7 Communications and support data
- Messages and information you submit through in-app chat, support, issue reporting, email, or other communications, including attachments and call records where lawfully maintained by the relevant support channel.
3. Device Permissions and User Controls
Depending on your device, role, and feature use, Zendly may request access to precise/approximate location, background location, camera, photos or media, notifications, and related device capabilities. Camera and media access supports profile photos, identity documents, parcel images, pickup/drop proof, and issue reports. Notification access supports booking, delivery, payment, safety, and job alerts. You can manage permissions in device settings, but denying a necessary permission may prevent the related feature from working.
4. Why We Use Personal Data
- Create, authenticate, secure, and manage accounts and roles.
- Provide fare estimates, bookings, matching, pickup, tracking, delivery, OTP verification, notifications, and customer support.
- Verify identity and eligibility, manage carrier onboarding, and reduce impersonation and fraud.
- Process payments, refunds, wallets, earnings, bank verification, withdrawals, settlements, and transaction reconciliation.
- Maintain service safety, enforce proximity and route requirements, investigate incidents, resolve disputes, and prevent misuse.
- Operate, troubleshoot, secure, analyse, and improve the Services and comply with legal, tax, accounting, audit, and regulatory obligations.
5. Location Data - Important Notice
Carrier background location is used only after the carrier grants the relevant device permission and activates a feature that requires ongoing availability or tracking, such as going online or handling an active task. Zendly uses this data for nearby job matching, availability, live delivery tracking, ETA, proximity and safety checks, operational support, and fraud prevention. Carrier background tracking should stop when the carrier goes offline, signs out, loses a valid session, or the applicable task ends, subject to device behaviour and processing needed to close the session.
Users can withdraw location permission in device settings. Carriers should also use the in-app offline control where available. Disabling location may prevent job matching, tracking, proximity confirmation, or delivery features from working.
6. How We Share Personal Data
Zendly does not sell personal data. We may disclose or make data available only as reasonably necessary to:
- Senders, receivers, and carriers involved in the same booking, limited to information required for matching, contact, pickup, tracking, delivery, safety, payment status, and dispute resolution.
- Service providers and processors supporting hosting, storage, communications, maps and geocoding, Firebase push notifications, identity verification, payment processing (including Razorpay), banking and payouts, customer support, security, and diagnostics.
- Other optional service partners where Zendly introduces an additional service in the future and the user selects or consents to that service.
- Professional advisers, auditors, prospective business transferees, and government, regulatory, court, law-enforcement, or other authorities where required or permitted by law.
7. Third-Party Services
The Services currently use or may interact with third parties such as Google Maps/Places, Google Firebase Cloud Messaging, Razorpay checkout/payment services, banks or payout providers, and identity-verification providers. Those providers may process information under their own terms and privacy notices. Relevant notices include Google, Firebase, and Razorpay.
8. Legal Grounds and Consent
Zendly processes personal data with consent where required, to provide services requested by you, for permitted legitimate uses under applicable law, and to meet legal obligations. You may withdraw consent through available app controls, device settings, or by contacting us. Withdrawal does not affect processing already lawfully completed and may prevent us from continuing a feature that depends on the data.
9. Data Retention
We retain personal data only for as long as reasonably necessary for the stated purposes, including active account and booking operations, safety, disputes, fraud prevention, legal claims, tax/accounting obligations, audits, and regulatory requirements. Retention periods vary by data type and legal requirement. Data may be deleted, de-identified, or securely archived when no longer required. Payment, transaction, KYC/verification, and dispute records may need to be retained for longer statutory periods.
10. Security
Zendly uses reasonable administrative, technical, and organisational safeguards appropriate to the nature of the data, including access controls, authentication, role-based permissions, monitoring, and service-provider controls. No application, network, or storage method is completely secure. Users should protect their device, OTPs, and account access and should promptly report suspected misuse.
11. International Processing
Some service providers may process or store data outside your state or outside India. Where cross-border processing occurs, Zendly will take steps required by applicable Indian law and contractual or organisational safeguards, subject to any government restrictions.
12. Your Rights and Choices
Subject to applicable law and verification of your request, you may ask to access a summary of your personal data and processing, correct or update inaccurate data, erase data that is no longer required, withdraw consent, deactivate your account, obtain grievance redressal, and nominate another individual where the law provides. You may update some information and notification or location choices directly in the app or device settings.
Requests may be sent to support@zendly.org. We may retain information that must be kept for legal obligations, safety, fraud prevention, disputes, or establishment and defence of legal claims.
13. Children's Privacy
Zendly is not intended for individuals under 18 years of age, and users must not create an account or use carrier, booking, identity-verification, or payment services if they are under 18. If we learn that a child's personal data was collected contrary to this requirement, we will take appropriate steps consistent with applicable law.
14. Cookies and Similar Technologies
Zendly's website and embedded web content, including payment checkout pages, may use cookies, local storage, SDKs, or similar technologies for authentication, functionality, security, preferences, and service performance. Browser or device controls may allow you to manage some of these technologies.
15. Account Deactivation and Deletion Requests
Where available, users may request account deactivation through the app. Requests for deletion or further assistance may be sent to support@zendly.org. Before acting, Zendly may verify identity and account ownership. Deactivation does not necessarily delete records that must be retained for ongoing bookings, payments, safety, legal compliance, fraud prevention, or disputes.
16. Changes to This Policy
We may update this Privacy Policy when our Services, technologies, providers, or legal obligations change. We will update the "Last Updated" date and provide additional notice through the app, website, email, or other appropriate channel when required. Where fresh consent is legally required, we will request it.
17. Contact and Grievance Redressal
Zendly Express Private Limited
Registered Office: 10/901, J, Main Road, Pavoorchatram, Tenkasi, Tamil Nadu – 627808, India
Privacy and Data-Rights Requests: support@zendly.org
General Support: support@zendly.org
Grievance Officer: M. Saravanakumar, Founder
Grievance Contact: support@zendly.org / +91 9789090990
Please include sufficient information to identify your account and describe the request. Do not email OTPs, passwords, full payment credentials, or unnecessary identity-document copies.
