Privacy Policy

Last updated: June 2026

TOVA is a service operated by Marshbarks Services, Hyderabad, Telangana, India. This policy explains how we collect, use, store, and protect your personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian laws.

1. Who We Are (Data Fiduciary)

Marshbarks Services is the Data Fiduciary responsible for processing your personal data through the TOVA platform (website: gotova.in, WhatsApp bot: +91 78429 57070).

Registered address: Hyderabad, Telangana, India.

Grievance Officer: Kshitij Umesh · marshbarks.services@gmail.com · +91 93905 37737

2. Personal Data We Collect

We collect only the data necessary to operate the service:

  • WhatsApp phone number — your primary identity on TOVA, used for login, booking confirmation, and ride updates.
  • Name — provided voluntarily during registration, displayed to your co-passengers for safety.
  • Government employee details — role, department, and Employee ID number (PF number, HRMS ID, or Employee Code) or a photo of your Employee ID card / Service Book. We do not collect Aadhaar numbers. Collected only for the verified-network pilot and kept confidential.
  • Ride data — pickup location, destination, date, time, and fare for each booking.
  • Payment data — order IDs and payment status, processed by Razorpay. We never see or store your card number, UPI PIN, or bank credentials.
  • Location — used only when you tap "Use my location" to auto-fill pickup. Not stored on our servers. Host location is shared with riders during an active trip only if the live-tracking feature is enabled.
  • Device/usage data — browser type, IP address, page visits — collected automatically for security and debugging purposes.

3. Purpose and Legal Basis for Processing

We process your data for the following purposes, each with a clear lawful basis under the DPDP Act:

  • Providing the service — booking confirmation, matching riders with hosts, processing payments. (Contractual necessity)
  • Safety and verification — verifying government employee identity during the pilot phase to maintain a trusted community. (Legitimate interest / consent)
  • Communication — sending ride confirmations, cancellation notices, and host notifications via WhatsApp. (Contractual necessity)
  • Refunds and dispute resolution — maintaining booking and payment records as required for financial compliance. (Legal obligation)
  • Service improvement — understanding usage patterns to improve the platform. (Legitimate interest)

4. How We Share Your Data

We do not sell, rent, or trade your personal data. We share it only in these limited circumstances:

  • Razorpay India Pvt. Ltd. — for payment processing. Subject to Razorpay's privacy policy.
  • Meta Platforms (WhatsApp) — to deliver booking messages via the WhatsApp Business API.
  • Between riders and hosts — your first name and phone number are shared with the host of your booked trip (and vice versa) solely to facilitate the ride and for safety. No other riders on the trip see your number.
  • Cloudinary (Cloudinary Ltd.) — for secure storage of government ID photos uploaded for identity verification. Photos are stored in a private folder and accessible only to TOVA administrators.
  • Railway (Railway Corp.) — our backend database infrastructure, hosted in their cloud environment.
  • Law enforcement — when required by a court order or applicable Indian law.

No data is transferred outside India except as required by Razorpay's, Meta's, Cloudinary's, or Railway's own infrastructure. All maintain industry-standard data protection practices.

5. Data Retention

  • Booking and payment records — retained for 3 years from the date of the ride, as required for GST and financial compliance.
  • Government ID details — retained for the duration of your account. Deleted within 30 days of account deletion.
  • Account data (name, phone) — retained until you delete your account. Upon deletion, personal identifiers are anonymised within 30 days; booking records are retained in anonymised form for 3 years.
  • Location data — not stored. Used transiently to auto-fill pickup location and cleared immediately after.

6. Your Rights as a Data Principal (DPDP Act 2023)

Under the Digital Personal Data Protection Act, 2023, you have the following rights:

  • Right to access — download all personal data we hold about you. Self-service: log in and call GET /rider/my-data via the app, or contact us and we will provide a full export within 48 hours.
  • Right to correction — request correction of inaccurate or incomplete data.
  • Right to erasure — request deletion of your personal data (subject to our legal retention obligations). Use the "Delete my account" option in the app or contact us.
  • Right to grievance redressal — raise a complaint with our Grievance Officer within 30 days of an issue. We will respond within 48 hours and resolve within 30 days.
  • Right to nominate — nominate an individual to exercise your rights on your behalf in the event of your death or incapacity.

To exercise any right, contact our Grievance Officer: marshbarks.services@gmail.com or WhatsApp +91 93905 37737.

If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India once constituted under the DPDP Act.

7. Security

We implement reasonable technical and organisational measures to protect your data:

  • All data is transmitted over HTTPS with TLS encryption.
  • Payment credentials are handled entirely by Razorpay (PCI-DSS compliant) and never pass through our servers.
  • Access to our database is restricted to authorised personnel only.
  • OTP-based authentication is used for all logins — no passwords stored.

In the event of a data breach that is likely to affect your rights, we will notify you within 72 hours as required by law.

8. Cookies and Tracking

TOVA does not use advertising trackers or third-party analytics cookies. We use a single session cookie (Google Translate preference) if you use the language switcher. This cookie stores only your language preference and expires when you clear your browser data.

9. Children's Privacy

TOVA is intended for use by adults aged 18 and above. We do not knowingly collect personal data from children under 18. If you believe a minor has registered, contact us immediately for deletion.

10. Changes to This Policy

We may update this policy when our practices change or when required by law. Material changes will be notified via WhatsApp to registered users. The latest version is always available at gotova.in/privacy. Continued use of TOVA after changes constitutes acceptance.

11. Contact and Grievance Officer

Grievance Officer: Kshitij Umesh

Email: marshbarks.services@gmail.com

WhatsApp: +91 93905 37737

Address: Hyderabad, Telangana, India

Response time: within 48 hours. Resolution time: within 30 days.

© 2026 Marshbarks Services · TOVA · Terms · Refund Policy · Data Deletion