Vtag

Privacy Policy

Last updated: 11 July 2026

Vtag Connect Private Limited("Vtag", "we", "us") is the Data Fiduciary, under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), for the personal data described in this policy. This policy applies to anyone who uses getvtag.com, holds a Vtag account, or scans a Vtag QR code as a Public Scanner — even if you never create an account.

This policy is incorporated into, and should be read together with, our Terms of Service, our Public Scanner & Emergency Alert Terms, our Cookie Policy, and our Data Deletion page. Those pages contain the precise detail for Scanners, cookies, and deletion mechanics; this page is the overall map.

On this page

1. Who we are & what this policy covers2. Definitions3. Personal data we collect4. Why we process it, and our legal basis5. Marketing communications6. Cookies & device identifiers7. Analytics8. Who we share data with9. Cross-border data transfer10. How long we keep your data11. Security12. Your rights as a Data Principal13. Children’s data14. Automated processing & fraud scoring15. Data breach notification16. Grievance redressal & the Data Protection Board17. Future GDPR readiness18. Changes to this policy19. Contact us

1. Who we are & what this policy covers

Vtag Connect Private Limited
CIN: U63991TS2025PTC200462
Registered office: Hyderabad, Telangana, India

This policy covers three groups of people, whose data we collect for different reasons and to different extents:

  • Account Holders / Owners — people who register a Vtag account and activate a QR sticker on their vehicle.
  • Public Scanners — anyone who scans a Vtag QR code to send an Alert, whether or not they hold an account.
  • Website visitors — anyone browsing getvtag.com without logging in or scanning a code.

2. Definitions

  • "Personal Data" — any data about an individual who is identifiable by or in relation to that data, as defined in the DPDP Act.
  • "Data Principal" — the individual to whom the personal data relates (you).
  • "Data Fiduciary" — the entity that determines the purpose and means of processing personal data (Vtag).
  • "Processing" — any operation performed on personal data, including collection, storage, use, sharing, and deletion.
  • "Consent Manager" — a DPDP Act mechanism through which a Data Principal can manage consent across fiduciaries. We do not currently route consent through a registered Consent Manager; consent is collected directly by us as described in Section 4.

3. Personal data we collect

Account Holders / Owners

CategoryExamples
Identity & contactName, mobile number, email address
Vehicle informationRegistration plate, make, model, year, colour — entered by you, not fetched from any government database (see our Disclaimer for how we describe this elsewhere)
Account securityA bcrypt hash of your PIN — we never store or can retrieve your actual PIN
ShippingDelivery address, for physical QR sticker orders
PaymentTransaction and subscription status — your card, UPI, or bank details are handled directly by Razorpay and are never stored on our servers
Alert historyAlerts received on your vehicle(s), and your response actions in the dashboard
Emergency contactsName and mobile number of any emergency contact you choose to register

Public Scanners

Full detail is in our Public Scanner & Emergency Alert Terms. In summary: name, OTP-verified mobile number, a hashed device fingerprint, a hashed IP address, and — for Emergency Alerts only — a live selfie, optional incident photos, and location (GPS or a typed landmark).

Website visitors

Basic, privacy-friendly analytics (page views, referrer, device type) with no cookie-based cross-site tracking. See Section 7.


4. Why we process it, and our legal basis

Under the DPDP Act, we process your personal data on the basis of your consent, given for a specific purpose at the point of collection (for example, when you register an account, activate a Tag, or verify your mobile number as a Scanner). Where processing is necessary for us to comply with a legal obligation — such as retaining certain financial records under tax law, or responding to a lawful government or police request — we rely on that legal obligation rather than consent, as permitted under the DPDP Act's provisions for certain legitimate uses.

  • To create and operate your account, and activate and manage your Vtag Tag(s).
  • To verify a Scanner's identity before relaying an Alert, and to prevent spam, fraud, and abuse.
  • To deliver Alerts to you via WhatsApp, SMS, and voice (never email, for Scanner-generated Alerts — see our Terms of Service Section 13).
  • To process payments and manage your Subscription, through Razorpay.
  • To ship physical products to you.
  • To investigate abuse, enforce our Policies, and cooperate with law enforcement where legally required (see Section 8).
  • To provide customer support and respond to your requests.
  • Where you have separately opted in, to send you marketing communications (see Section 5).

You may withdraw consent at any time, with effect for future processing, through your dashboard settings or by contacting us at grievance@getvtag.com. Withdrawing consent for processing necessary to operate your account (for example, mobile number verification) may mean we can no longer provide that part of the Service.


5. Marketing communications

We only send you marketing communications — product updates, offers, or promotional content — if you separately opt in. Marketing consent is never bundled with, or required for, the consent needed to operate your account, verify a Scanner, or deliver an Alert.

  • Promotional SMS and voice calls are sent in accordance with TRAI's Telecom Commercial Communications Customer Preference Regulations, 2018. We do not send promotional SMS or calls to a number registered on the National Customer Preference Register for the relevant category unless you have separately opted in through the applicable registered exemption.
  • Marketing messages on WhatsApp follow Meta's WhatsApp Business Platform messaging policies, which require your own opt-in before we can message you outside an active conversation you started.
  • Marketing emails include an unsubscribe link in every message.

You can withdraw marketing consent at any time — from your dashboard notification settings, by replying "STOP" to an SMS/WhatsApp message, by using the unsubscribe link in an email, or by emailing support@getvtag.com. We action opt-outs promptly and always before your next scheduled marketing communication. Opting out of marketing does not opt you out of transactional, account, security, or Alert-related communications, which are necessary for the Service and are not marketing.


6. Cookies & device identifiers

Full detail is in our Cookie Policy. In summary: we use session cookies to keep you logged in, and — only within the Public Scanner Portal — a hashed device fingerprint used solely for fraud prevention and to remember a completed OTP verification for a limited window. We do not use advertising cookies, tracking pixels, or cross-site fingerprinting.


7. Analytics

We use Plausible Analytics, a privacy-first analytics tool that does not use cookies and does not collect data that identifies you individually. It gives us aggregate counts — page views, referrers, device and browser type, and approximate location at a city level derived from IP address, which is not stored — so we can see which pages and features are used, and where the signup and checkout flows lose people.

  • Analytics data is used only for product improvement, reliability monitoring, and capacity planning.
  • It is never shared with or sold to advertisers or data brokers, never combined with your account identity to build an individual profile, and never used for cross-site or cross-device tracking.
  • Because Plausible does not use cookies for this purpose, no cookie-consent banner is shown for analytics — the consent requirement under the DPDP Act and applicable cookie rules applies to the identifiers described in Section 6, not to this aggregate analytics data.

8. Who we share data with

What we never do

  • We do not sell or rent your personal data to anyone, for any reason.
  • We do not show a Scanner's name, mobile number, or device information to the vehicle Owner, through any channel.
  • We do not show an Owner's mobile number or contact details to a Scanner.

We share limited personal data with:

  • Payment processing — Razorpay, to process payments and manage Subscriptions.
  • Communications — our SMS/voice and WhatsApp Business Platform providers, solely to deliver OTPs and Alerts.
  • Email — our transactional email provider, for account, billing, and security notices, and for marketing email you have opted into (never for Scanner-generated Alerts).
  • Cloud infrastructure — hosting, database, and content-delivery providers who store and process data on our behalf under contractual confidentiality and security obligations (see Section 9 on where this infrastructure is located).
  • Courier partners — your shipping address, solely to deliver physical orders.
  • Emergency contacts you register — an Emergency Alert selfie, location, and incident details, only after the Scanner's explicit consent and only for that specific Alert.
  • Law enforcement & regulators — only in response to valid legal process, or where necessary to protect someone's safety in a genuine emergency. See our Terms of Service Section 29.
  • A successor entity — in the event of a merger, acquisition, or sale of assets, subject to that entity assuming the obligations of this policy.

9. Cross-border data transfer

Your data is stored and processed on cloud infrastructure located in Singapore, using providers that maintain SOC 2 / ISO 27001-aligned security controls. This is a cross-border transfer of personal data from India, which is permitted under the DPDP Act, as Singapore is not, as of the date of this policy, a jurisdiction restricted by the Central Government under that Act. If the Central Government notifies restrictions affecting our infrastructure providers, we will update this policy and take any steps required to remain compliant. Data is encrypted at rest (AES-256) and in transit (TLS 1.3) regardless of where it is processed.


10. How long we keep your data

Account Holders

We keep your account data for as long as your account is active. If you delete your account, it is purged per our Data Deletion page — instantly for the self-serve flow, within 24 hours for an email request — except for the narrow financial-record retention described there.

Public Scanners

Governed by our Public Scanner & Emergency Alert Terms Section 7. In summary: Normal/Urgent Alert records (including your name and mobile number) are deleted 180 days after the Alert; Emergency Alert records have Scanner name and mobile removed after 180 days, with the full record (including the selfie) deleted after 365 days; records under active administrative or legal review are kept only as long as that review requires. OTPs are never stored in readable form and are deleted within 5 minutes of verification or expiry.


11. Security

We encrypt data at rest (AES-256) and in transit (TLS 1.3), apply role-based access controls so only authorised personnel can view Scanner identity or Emergency Alert evidence, log administrative access to sensitive records, and store PINs as bcrypt hashes rather than plaintext. No system is completely secure; see our Terms of Service Section 21 for the full security commitment, including how to report a vulnerability.


12. Your rights as a Data Principal

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and how we process it.
  • Correct inaccurate or incomplete personal data.
  • Erase personal data that is no longer necessary for the purpose it was collected for, subject to our legal retention obligations described in Section 10.
  • Withdraw consent at any time, as described in Section 4.
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, under Section 14 of the DPDP Act.
  • Grieve — raise a complaint with us first (Section 16 below), and escalate to the Data Protection Board of India if unresolved.

Account Holders can exercise most of these rights directly from the dashboard. Everyone — including Public Scanners, who do not hold an account — can exercise them by emailing grievance@getvtag.com with enough detail for us to locate your data (for a Scanner, this is typically the mobile number used and an approximate date).


13. Children's data

The Platform is not directed at, and we do not knowingly collect personal data from, individuals under 18. Our Terms of Service require every Account Holder and every Scanner to confirm they are 18 or older. We do not have a mechanism for verifiable parental consent under Section 9 of the DPDP Act, and if we become aware that we have collected data from someone under 18 without such consent, we will delete it. If you believe a child has used the Platform, contact grievance@getvtag.com.


14. Automated processing & fraud scoring

We use automated checks — duplicate-Alert detection, location-consistency checks, and OTP-failure monitoring — to flag or block potentially fraudulent activity, described in our Public Scanner & Emergency Alert Terms Section 9. These checks can restrict or block access (for example, requiring an extra verification step, or a temporary block), but a permanent ban or a report to law enforcement always involves human administrative review before it is actioned — automated signals flag for review, they do not by themselves impose the most serious consequences.


15. Data breach notification

If a personal data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required under Section 8(6) of the DPDP Act, describing the nature of the breach and the steps we are taking in response.


16. Grievance redressal & the Data Protection Board

Our designated contact for privacy grievances is the same Grievance Officer appointed under the Information Technology Rules, 2021 — see our Grievance Officer page for current contact details and response timelines. If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India, established under the DPDP Act.


17. Future GDPR readiness

Vtag does not currently offer the Platform to individuals located in the European Union or the United Kingdom, and is not currently subject to the EU General Data Protection Regulation ("GDPR") or the UK GDPR. This section is a statement of direction, not a claim of current GDPR compliance.

As international expansion is part of our roadmap, we are building our data practices ahead of time to align with GDPR principles, so that entering a GDPR-covered market does not require a ground-up rebuild of how we handle data. This includes:

  • Maintaining a documented lawful basis for each processing activity, not only a general consent statement.
  • Running a data protection impact assessment (DPIA) before launching any higher-risk processing activity in a GDPR-covered market — Emergency Alert selfie capture is the clearest current candidate.
  • Designing new features data-minimally and for a specific stated purpose, rather than collecting broadly and deciding on use later.
  • Supporting data portability in a structured, commonly used, machine-readable format on request.
  • Honouring erasure requests to the fuller standard GDPR's "right to be forgotten" requires, beyond the DPDP Act baseline in Section 12.
  • Appointing an EU/UK representative and, where the volume or risk of our processing requires it, a Data Protection Officer, before — not after — we offer the Service to individuals in those regions.

On the selfie point specifically: an Emergency Alert selfie is captured for human verification by the vehicle Owner and their emergency contacts, and is not processed through facial recognition or biometric templating. As currently processed, we do not treat it as "special category" biometric data under GDPR Article 9. If we ever introduce automated facial-recognition matching, we will update this policy first and implement the additional consent and safeguard requirements special category data demands before doing so.


18. Changes to this policy

We may update this policy as our products, providers, or legal obligations change. We will post the updated policy with a new "Last updated" date and, for material changes — including any change to what we collect, who we share it with, or how long we retain it — notify active Account Holders by email or in-app notice.


19. Contact us

Vtag Connect Private Limited
CIN: U63991TS2025PTC200462
Registered office: Hyderabad, Telangana, India
Correspondence address: Indiranagar, Bengaluru - 560038, Karnataka, India