Data Deletion & User Rights Policy
Last updated: 11 July 2026
Our Privacy Policy establishes what rights you have over your data. This policy is the operational detail behind those rights — exactly how to delete your account or a vehicle, request or correct your data, and precisely how long we keep every category of information, including the exceptions.
On this page
1. Purpose & who this applies to2. Definitions3. Your rights at a glance4. Account deletion — self-serve5. Account deletion — by request6. What account deletion actually removes7. Vehicle deletion8. Data access requests9. Correction requests10. Public Scanner information11. Emergency evidence & selfies12. Audit logs13. Retention schedule — the full table14. Legal holds15. Backup data16. Deletion timelines17. Applicable legal obligations18. What we cannot delete, and why19. Changes to this policy20. Contact & how to request1. Purpose & who this applies to
This policy applies to Account Holders (who have data tied to a registered account) and Public Scanners (who have data tied to specific Alerts even without an account). It is incorporated into, and supplements, our Privacy Policy and our Public Scanner & Emergency Alert Terms.
2. Definitions
- "Legal Hold" — a suspension of normal deletion for a specific record because it is connected to an active police investigation, court proceeding, or valid legal request, described in Section 14.
- "Backup Retention Window" — the rolling period during which deleted data may still exist in an encrypted disaster-recovery backup, described in Section 15.
- "Data Principal", "Personal Data", and other DPDP Act terms have the meaning given to them in our Privacy Policy Section 2.
3. Your rights at a glance
| Right | What it means | How to exercise it |
|---|---|---|
| Access | Get a copy of the data we hold about you | Section 8 |
| Correction | Fix inaccurate or incomplete data | Section 9 |
| Erasure | Delete your account, a vehicle, or specific data | Sections 4–7 |
| Withdraw consent | Stop future processing based on consent | Privacy Policy Section 4 |
| Nominate | Name someone to exercise these rights if you die or are incapacitated | Email us (Section 20) |
| Grieve | Escalate an unresolved request | Grievance Officer page |
4. Account deletion — self-serve
- Log in to your dashboard at getvtag.com/login.
- Go to Profile → Account → Delete account.
- Confirm via OTP. Deletion of your account record begins immediately.
5. Account deletion — by request
Can't access your account, or prefer email? Write to delete@getvtag.com from your registered email, including your registered mobile number so we can locate the right account. We verify the request is genuinely from you before acting on it, then confirm and complete deletion within 24 hours.
6. What account deletion actually removes
- Your mobile number, email, name, and PIN hash.
- All vehicle records associated with your account (plate, make, model, year, colour).
- Your Alert inbox and message history as an Owner.
- Login sessions and analytics logs older than 7 days; more recent ones clear on their normal schedule shortly after.
What isn't removed on account deletion — and why — is explained fully in Section 18.
7. Vehicle deletion
You don't have to delete your whole account to remove one vehicle — for example, after selling it. From your dashboard, go to the vehicle's page and choose Remove vehicle. This deactivates the associated Vtag Tag (per our Terms of ServiceSection 8) and deletes that vehicle's record and its Alert history from your account, while leaving the rest of your account and other vehicles untouched.
8. Data access requests
To get a copy of the personal data we hold about you, email grievance@getvtag.com from your registered email (Account Holders) or with your Alert's mobile number and approximate date (Public Scanners). We verify the request is genuinely from you, then provide the data in a commonly used, readable format within the timeline in Section 16.
9. Correction requests
Most account details (name, email, vehicle information) can be corrected directly in your dashboard. For anything you can't edit yourself — or if you're a Public Scanner asking us to correct a name or number tied to a past Alert — email grievance@getvtag.com with what's wrong and what it should say instead.
10. Public Scanner information
A Scanner never holds an account, so there's nothing to "delete" in the account sense — but the identity and Alert data collected during scanning still has a defined lifespan, set out in full in our Public Scanner & Emergency Alert Terms Section 7, and summarised in the master table at Section 13 below. A Scanner can request early deletion or a copy of their own data the same way as anyone else (Sections 8–9), by identifying themselves via the mobile number they used.
11. Emergency evidence & selfies
Emergency Alert selfies and incident photos follow the same 365-day full-record retention as the rest of the Emergency Alert (Section 13), with one addition: where a specific piece of evidence is connected to an active police investigation, a court proceeding, or a legal complaint, we retain it under a Legal Hold (Section 14) for as long as that matter requires, even past the normal 365-day mark. We do not extend retention on our own initiative "just in case" — only where a specific, identified legal matter is actually open.
12. Audit logs
We keep an internal audit trail of sensitive administrative actions — who reviewed or blocked what, and when — for 365 days, for accountability and security purposes. Audit log entries are not linked to your Owner or Scanner profile in a way that's shown to you or anyone outside authorised Vtag administrators, and are deleted on the same 365-day schedule as the records they relate to, subject to the same Legal Hold exception.
13. Retention schedule — the full table
| Data | Retention | Legal Hold applies? |
|---|---|---|
| OTP (login or Scanner verification) | Never stored readable; hash deleted within 5 minutes of verification or expiry | No |
| Account Holder data | While account is active; deleted per Sections 4–6 on request | Yes, if legally compelled |
| Normal/Urgent Alert (incl. Scanner name/mobile) | 180 days from the Alert | Yes |
| Emergency Alert — Scanner name/mobile | Removed at 180 days; rest of record continues | Yes |
| Emergency Alert — full record incl. selfie/evidence | 365 days from the Alert | Yes (Section 11) |
| Audit log entries | 365 days | Yes |
| Login sessions / analytics logs | 7 days | No |
| Financial & GST-relevant records | 72 months (6 years) from the due date of the relevant annual return — Section 17 | N/A — statutory |
| Statutory books of account | 8 years — Section 17 | N/A — statutory |
| Encrypted disaster-recovery backups | Rolling window per our hosting provider's backup plan — Section 15 | No — passive residue only |
This table reflects what our systems actually enforce, including an automated daily process that purges Alert and audit log data on the schedule above — it is not a manual, best-effort promise.
14. Legal holds
Where a specific record is connected to an active police investigation, court proceeding, or a valid legal request we've received, we place it under a Legal Hold: our normal deletion schedule for that record is paused until the matter concludes or the hold is lifted. In practice, this already applies automatically to any Alert an administrator has flagged, marked fake, or marked abusive under our Acceptable Use & Community Policy— those records are excluded from routine deletion precisely because they're the ones most likely to matter later. A Legal Hold applies only to the specific record it concerns, never to your entire account, and does not stop you from deleting other, unrelated data.
15. Backup data
We take automated, encrypted backups of our database for disaster-recovery purposes. When you delete data, it is removed from our live, production database immediately (or within the timeline in Section 16) — but it may persist in an existing backup snapshot until that backup is rotated out on our hosting provider's standard schedule. Backups exist solely to restore service after a failure; they are not queried, searched, or used for any other purpose, and access to them is restricted to the same authorised personnel who can access production data. Where we create a non-production copy of data for testing (for example, a staging environment), that copy is stripped of identifying personal data before use — real names, phone numbers, and similar fields are masked, not copied as-is.
16. Deletion timelines
| Request | Timeline |
|---|---|
| Self-serve account deletion (Section 4) | Immediate |
| Email account deletion request (Section 5) | Within 24 hours of verification |
| Vehicle deletion (Section 7) | Immediate |
| Data access request (Section 8) | Acknowledged within 24 hours, fulfilled within 15 days |
| Correction request (Section 9) | Acknowledged within 24 hours, fulfilled within 15 days |
These acknowledgement and resolution windows match those on our Grievance Officerpage. If we can't meet a stated timeline for a specific request — for example, because we need to verify your identity further — we'll tell you why and give a revised estimate rather than let the deadline pass silently.
17. Applicable legal obligations
Our retention schedule (Section 13) is shaped by the following, in addition to our own operational judgment about what's genuinely useful to keep:
- Digital Personal Data Protection Act, 2023 — the overarching framework for how long we may hold personal data relative to the purpose it was collected for, detailed in our Privacy Policy.
- Central Goods and Services Tax Act, 2017, Section 36 — requires accounts and records relevant to GST to be retained for 72 months (6 years) from the due date of furnishing the annual return for the relevant financial year. This is the correct basis for retaining anonymised financial records — an earlier version of this page cited "Section 36 of the IT Act", which does not exist and was an error; it has been corrected here.
- Companies Act, 2013, Section 128 — requires a company to retain its statutory books of account for 8 years.
- Income Tax Act, 1961 — requires retention of books of account and supporting documents for a period generally aligned with the GST retention window above.
- Information Technology Act, 2000 and IT Rules, 2021 — inform our security, breach-notification, and grievance-redressal obligations, detailed in our Grievance Officer page.
18. What we cannot delete, and why
Deletion isn't always instant everywhere, and that's deliberate
Deleting your account removes everything in Section 6, but a small, specific set of data continues to exist afterward, for reasons we think are worth being upfront about rather than burying in a footnote:
- Anonymised financial records connected to a transaction you completed, retained for the statutory window in Section 17. These contain no personally identifiable information once anonymised — they exist to prove a transaction occurred for tax purposes, not to identify you.
- Any record under an active Legal Hold (Section 14), for as long as the underlying matter requires.
- Backup residue within the rolling window described in Section 15, which is not accessible for any purpose other than disaster recovery and ages out on its own schedule.
Everything else — your name, mobile number, email, PIN hash, vehicle records, and message history — is genuinely gone, not just hidden from your view.
19. Changes to this policy
If we change a retention period, add a new data category, or change how deletion requests are processed, we'll update this policy and post a new "Last updated" date. A shortened retention period applies going forward; it doesn't retroactively delete data earlier than a request already in progress would.
20. Contact & how to request
- Account deletion: delete@getvtag.com
- Access, correction & other data rights: grievance@getvtag.com
- Formal escalation: see our Grievance Officer page
- General support: support@getvtag.com