Skip to content
GayaRentals

Legal

Privacy policy

Last updated October 2026

We collect what a cab booking actually needs and nothing else. This page says precisely what that is.

01What we collect

To take a booking we need your name, mobile number and trip details. Email is optional and only used to send your confirmation and receipt.

We store the pickup and drop locations you enter, the vehicle and date you choose, and the fare we quoted. If you pay online, our payment provider handles your card or UPI details — those never reach our servers.

If you enter your name and number at checkout but do not finish the booking, we keep them, together with the trip you priced, so that we can get in touch about that trip. The same applies to anything you send us through the contact form.

If you sign in with Google, Google tells us your name and email address. We use them only to show you your trips — including any booking made with that email address.

02Why we collect it

To dispatch a driver to the right place at the right time, to contact you about the trip — including one you priced but did not book — and to keep a record for accounting and dispute resolution. That is the whole list.

03Mobile number verification

When you sign in with your mobile number, and at checkout when online payment is not available, we send a one-time code by SMS to confirm the number is yours. This protects you from someone booking a cab in your name, and protects us from fake bookings. The code is stored only as a hash and expires within minutes. When you pay the advance online instead, no code is sent — the payment confirms the booking.

04Who we share it with

Only where the booking cannot happen otherwise:

  • Your driver — name, number and pickup point, so they can find you.
  • Razorpay — for online payments and refunds.
  • Brevo — to deliver confirmation email.
  • 2Factor — to deliver the SMS verification code.
  • Google — only if you choose to sign in with Google.
  • Our hosting provider — the server our website and database run on.

We do not sell your data, and we do not share it for advertising.

05Cookies

One cookie, and only if you sign in: a session identifier that keeps you signed in. It contains no personal data — just a random value that maps to your session on our server. Signing in with Google also sets a second cookie for the few minutes the sign-in takes, holding random values that tie Google’s reply to your browser; it is deleted as soon as you are signed in. We use no advertising or cross-site tracking cookies.

06How long we keep it

Booking records are retained for seven years, which is what Indian tax rules require of business records. Details left at an unfinished checkout, and contact-form enquiries, are deleted automatically twelve months after we last heard from you. Verification codes and sessions expire within minutes and days respectively. You can ask us to delete anything not covered by the seven-year requirement.

07Your rights

Under India’s Digital Personal Data Protection Act you may ask what we hold about you, ask us to correct it, or ask us to delete it. Write to nnilmani000@gmail.com and we will respond within 30 days.

08Security

The site is served over HTTPS. Passwords are stored using scrypt and are never recoverable, only verifiable. Access to the booking database is limited to the owner and authorised staff.

09Children

Our service is not directed at children under 18, and we do not knowingly collect their data. Minors travelling with us are booked by an adult.

10Changes and contact

If this policy changes materially we will update the date at the top and, where it affects you, tell you directly. Questions go to nnilmani000@gmail.com or +91 91531 36744.