1. Introduction
1.1 Commitment to Privacy
Sankat Mochan Sajilo Yatra Pvt. Ltd. (Registration No. 368115/81/82), operating the SubhYatra platform ("SubhYatra," "we," "us," or "our"), is committed to protecting your privacy and ensuring the security of your personal information. The SubhYatra application is developed by Nexalaris Tech Pvt. Ltd. (Technology Partner). This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our mobile application and services.
1.2 Legal Framework
This Privacy Policy is designed to comply with:
- Individual Privacy Act, 2075 (2018) - Nepal's primary privacy legislation
- Individual Privacy Regulation, 2077 (2020) - Implementation rules
- Digital Privacy and Data Protection Act, 2082 (2025) - New comprehensive data protection law
- Electronic Transaction Act, 2063 (2008) - Digital transaction regulations
- Consumer Protection Act, 2075 (2018) - Consumer rights protection
1.3 Data Controller
Sankat Mochan Sajilo Yatra Pvt. Ltd. is the data controller responsible for your personal data.
Sankat Mochan Sajilo Yatra Pvt. Ltd.
Registration: 368115/81/82
Address: Chandrapur, Rauthad, Madhesh Province, Nepal
Email: privacy@subhyatranepal.com | sankatmochan1992@gmail.com
Phone: +977 9808877530
Website: https://subhyatranepal.com
Technology Partner (IP Owner):
Nexalaris Tech Pvt. Ltd.
Registration: 354796/81/82
Email: contact@nexalaris.com
2. Information We Collect
2.1 Information You Provide Directly
Account Registration Information
- Full name
- Email address
- Phone number
- Profile photograph (optional)
- Password (encrypted)
Identity Verification Information
- Government-issued ID (for drivers)
- Driving license details (for drivers)
- Vehicle registration documents (for drivers)
Transaction Information
- Ride history
- Payment records
- Fare details
Communication Information
- Customer support inquiries
- Feedback and reviews
- In-app messages
2.2 Information Collected Automatically
Location Data
- Real-time GPS location during active rides (passengers and drivers)
- Background location for drivers when online/available
- Pickup and drop-off locations
- Route information
Device Information
- Device type and model
- Operating system version
- Unique device identifiers
- Mobile network information
- IP address
Usage Information
- App usage patterns
- Feature interactions
- Session duration
- Crash reports and diagnostics
2.3 Information from Third Parties
Maps and Navigation Services
- Route calculations from Google Maps
- Traffic information
- Estimated travel times
Payment Processors (Future)
- Transaction confirmations
- Payment verification status
3. Purpose of Data Collection
3.1 Primary Purposes
As required under Section 4 of the Individual Privacy Act, 2075, we collect your data for the following specified purposes:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account creation and management | Name, email, phone | Contract performance |
| Providing ride services | Location, ride details | Contract performance |
| Fare calculation and billing | Location, distance, time | Contract performance |
| Safety and security | Location, ride history, ID | Legitimate interest |
| Customer support | Communications, account data | Contract performance |
| Service improvement | Usage data, feedback | Legitimate interest |
| Legal compliance | All relevant data | Legal obligation |
3.2 Secondary Purposes
With your consent, we may use data for:
- Personalized recommendations
- Marketing communications
- Analytics and research (anonymized)
3.3 No Unauthorized Use
We will NOT use your personal data for any purpose not disclosed in this Policy without obtaining your explicit consent, as required by Nepal's privacy laws.
4. Consent
4.1 Obtaining Consent
In compliance with the Individual Privacy Act, 2075:
- We obtain your consent before collecting personal information
- Consent is obtained through clear affirmative action (accepting this Policy)
- You are informed of the purpose of collection at the time of consent
4.2 Types of Consent
- Express Consent: Required for sensitive data and location tracking
- Implied Consent: For data necessary to provide requested services
4.3 Withdrawing Consent
You may withdraw consent at any time by:
- Adjusting app permissions
- Contacting us at privacy@subhyatranepal.com
- Deleting your account
Note: Withdrawing consent may limit your ability to use certain features.
5. Data Storage and Security
5.1 Data Localization
In compliance with the Digital Privacy and Data Protection Act, 2082:
- User data is primarily stored on servers in the Asia-Pacific region
- Sensitive personal data may be stored on servers within Nepal or in compliant jurisdictions
- We ensure adequate data protection for any cross-border transfers
5.2 Security Measures
We implement robust security measures including:
Technical Measures:
- End-to-end encryption for sensitive data
- Secure HTTPS connections
- Database encryption at rest
- Regular security audits and penetration testing
- Access controls and authentication
- Secure API communications
Organizational Measures:
- Employee data protection training
- Access limited to authorized personnel only
- Confidentiality agreements
- Incident response procedures
5.3 Data Breach Notification
In compliance with the Digital Privacy and Data Protection Act, 2082:
- We will notify the Data Protection Authority within 72 hours of discovering a breach
- Affected individuals will be notified promptly if the breach poses high risk
- We maintain records of all data breaches and responses
6. Data Retention
6.1 Retention Periods
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | Duration of account + 2 years | Service provision and legal requirements |
| Ride history | 5 years | Legal compliance, dispute resolution |
| Location traces | 30 days | Safety and dispute resolution |
| Transaction records | 5 years | Financial and tax regulations |
| Support communications | 3 years | Quality assurance, dispute resolution |
| Audit logs | 5 years | Security and compliance |
6.2 Retention Principles
- Data is retained only as long as necessary for stated purposes
- Anonymized data may be retained longer for analytics
- Legal requirements may mandate longer retention
6.3 Data Deletion
Upon account deletion or retention period expiry:
- Personal data is securely deleted or anonymized
- Backup data is purged within 90 days
- Legal hold data is retained as required
7. Data Sharing and Disclosure
7.1 Sharing with Service Providers
We share data with trusted service providers who assist us:
| Provider Type | Data Shared | Purpose |
|---|---|---|
| Cloud hosting (Supabase) | All service data | Data storage and processing |
| Maps provider (Google) | Location data | Navigation and routing |
| Push notifications (Firebase) | Device tokens | Notifications delivery |
| Analytics | Anonymized usage data | Service improvement |
All service providers are contractually bound to protect your data.
7.2 Sharing Between Users
- Passengers see: Driver name, photo, vehicle details, rating, live location during ride
- Drivers see: Passenger name, pickup/drop location, contact option
7.3 Sharing for Safety
We may share data with:
- Emergency services when safety is at risk
- Law enforcement pursuant to valid legal process
- Emergency contacts (when SOS feature is activated)
7.4 Legal Disclosure
We may disclose data when required by:
- Court orders
- Government authority requests
- Legal proceedings
- Protection of rights and safety
7.5 No Sale of Data
We do NOT sell your personal data to third parties for marketing purposes.
8. Your Rights
8.1 Rights Under Nepal Law
Under the Individual Privacy Act, 2075 and Digital Privacy and Data Protection Act, 2082, you have the right to:
Right to Access
Request a copy of your personal data we hold and understand how your data is being used
Right to Correction
Request correction of inaccurate data and update incomplete information
Right to Deletion
Request deletion of your personal data, subject to legal retention requirements
Right to Object
Object to processing for certain purposes and opt-out of marketing communications
Right to Data Portability
Receive your data in a structured, commonly used format and transfer your data to another service
Right to Withdraw Consent
Withdraw previously given consent, without affecting lawfulness of prior processing
8.2 Exercising Your Rights
To exercise your rights:
- Email us at privacy@subhyatranepal.com
- Use in-app privacy settings
- Contact customer support
We will respond to requests within 30 days as required by law.
8.3 Right to Complain
If you believe your privacy rights have been violated, you may:
- Contact us first for resolution
- File a complaint with the Data Protection Authority of Nepal
- Seek compensation through the District Court (Section 31, Individual Privacy Act)
9. Location Data
9.1 Why We Collect Location Data
Location data is essential for:
- Connecting you with nearby drivers
- Providing accurate fare estimates
- Enabling real-time ride tracking
- Ensuring safety during rides
- Improving service coverage
9.2 Location Collection Practices
| User Type | When Collected | Purpose |
|---|---|---|
| Passengers | During ride booking and active rides | Service provision |
| Drivers (foreground) | When online and during rides | Service provision |
| Drivers (background) | When availability is ON | Driver matching |
9.3 Location Permissions
- You control location permissions through your device settings
- Denying location permission will prevent core app functionality
- Background location for drivers is required for matching
9.4 Location Data Retention
- Real-time location: Not stored after ride completion
- Ride route data: Stored for 30 days
- Pickup/drop locations: Stored with ride history (5 years)
11. Children's Privacy
11.1 Age Restriction
- Our Services are not intended for individuals under 18 years
- We do not knowingly collect data from minors
- Minors may only use Services under adult supervision
11.2 Parental Rights
If you believe we have collected data from a minor:
- Contact us immediately at privacy@subhyatranepal.com
- We will promptly delete such data
12. International Data Transfers
12.1 Transfer Mechanisms
When data is transferred outside Nepal:
- We ensure adequate protection measures
- Transfers comply with Nepal's data protection requirements
- Service providers are bound by data protection agreements
12.2 Server Locations
- Primary servers: Asia-Pacific region
- Backup servers: Secure cloud infrastructure
- CDN: Global distribution for performance
13. Changes to This Policy
13.1 Policy Updates
We may update this Privacy Policy to reflect:
- Changes in our practices
- New features or services
- Legal or regulatory requirements
13.2 Notification of Changes
- Material changes will be notified via email or in-app notification
- Updated Policy will be posted on our website and app
- Continued use constitutes acceptance of changes
13.3 Review History
- Version 1.0: January 2026 (Initial release)
14. Data Protection Officer
14.1 DPO Appointment
In compliance with the Digital Privacy and Data Protection Act, 2082, we have appointed a Data Protection Officer.
14.2 DPO Contact
Email: dpo@subhyatranepal.com
For privacy-related inquiries and complaints
15. Contact Us
15.1 Privacy Inquiries
For questions about this Privacy Policy or your personal data:
Data Controller (Service Operator):
Sankat Mochan Sajilo Yatra Pvt. Ltd.
Registration: 368115/81/82
Privacy: privacy@subhyatranepal.com
Support: support@subhyatranepal.com
Phone: +977 9808877530
Address: Chandrapur, Rauthad, Madhesh Province, Nepal
15.2 Response Time
We aim to respond to all privacy-related inquiries within 30 days.
15.3 Regulatory Authority
Data Protection Authority of Nepal (Contact details to be updated when Authority is established)
16. Acknowledgment
By using SubhYatra's services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.
This Privacy Policy complies with Nepal's Individual Privacy Act 2075, Individual Privacy Regulation 2077, Digital Privacy and Data Protection Act 2082, Electronic Transaction Act 2063, and Consumer Protection Act 2075.