Privacy Policy

Last Updated: January 2026

1. Introduction

1.1 Commitment to Privacy

Sankat Mochan Sajilo Yatra Pvt. Ltd. (Registration No. 368115/81/82), operating the SubhYatra platform ("SubhYatra," "we," "us," or "our"), is committed to protecting your privacy and ensuring the security of your personal information. The SubhYatra application is developed by Nexalaris Tech Pvt. Ltd. (Technology Partner). This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our mobile application and services.

1.2 Legal Framework

This Privacy Policy is designed to comply with:

  • Individual Privacy Act, 2075 (2018) - Nepal's primary privacy legislation
  • Individual Privacy Regulation, 2077 (2020) - Implementation rules
  • Digital Privacy and Data Protection Act, 2082 (2025) - New comprehensive data protection law
  • Electronic Transaction Act, 2063 (2008) - Digital transaction regulations
  • Consumer Protection Act, 2075 (2018) - Consumer rights protection

1.3 Data Controller

Sankat Mochan Sajilo Yatra Pvt. Ltd. is the data controller responsible for your personal data.

Sankat Mochan Sajilo Yatra Pvt. Ltd.

Registration: 368115/81/82

Address: Chandrapur, Rauthad, Madhesh Province, Nepal

Email: privacy@subhyatranepal.com | sankatmochan1992@gmail.com

Phone: +977 9808877530

Website: https://subhyatranepal.com

Technology Partner (IP Owner):

Nexalaris Tech Pvt. Ltd.

Registration: 354796/81/82

Email: contact@nexalaris.com

2. Information We Collect

2.1 Information You Provide Directly

Account Registration Information

  • Full name
  • Email address
  • Phone number
  • Profile photograph (optional)
  • Password (encrypted)

Identity Verification Information

  • Government-issued ID (for drivers)
  • Driving license details (for drivers)
  • Vehicle registration documents (for drivers)

Transaction Information

  • Ride history
  • Payment records
  • Fare details

Communication Information

  • Customer support inquiries
  • Feedback and reviews
  • In-app messages

2.2 Information Collected Automatically

Location Data

  • Real-time GPS location during active rides (passengers and drivers)
  • Background location for drivers when online/available
  • Pickup and drop-off locations
  • Route information

Device Information

  • Device type and model
  • Operating system version
  • Unique device identifiers
  • Mobile network information
  • IP address

Usage Information

  • App usage patterns
  • Feature interactions
  • Session duration
  • Crash reports and diagnostics

2.3 Information from Third Parties

Maps and Navigation Services

  • Route calculations from Google Maps
  • Traffic information
  • Estimated travel times

Payment Processors (Future)

  • Transaction confirmations
  • Payment verification status

3. Purpose of Data Collection

3.1 Primary Purposes

As required under Section 4 of the Individual Privacy Act, 2075, we collect your data for the following specified purposes:

PurposeData UsedLegal Basis
Account creation and managementName, email, phoneContract performance
Providing ride servicesLocation, ride detailsContract performance
Fare calculation and billingLocation, distance, timeContract performance
Safety and securityLocation, ride history, IDLegitimate interest
Customer supportCommunications, account dataContract performance
Service improvementUsage data, feedbackLegitimate interest
Legal complianceAll relevant dataLegal obligation

3.2 Secondary Purposes

With your consent, we may use data for:

  • Personalized recommendations
  • Marketing communications
  • Analytics and research (anonymized)

3.3 No Unauthorized Use

We will NOT use your personal data for any purpose not disclosed in this Policy without obtaining your explicit consent, as required by Nepal's privacy laws.

5. Data Storage and Security

5.1 Data Localization

In compliance with the Digital Privacy and Data Protection Act, 2082:

  • User data is primarily stored on servers in the Asia-Pacific region
  • Sensitive personal data may be stored on servers within Nepal or in compliant jurisdictions
  • We ensure adequate data protection for any cross-border transfers

5.2 Security Measures

We implement robust security measures including:

Technical Measures:

  • End-to-end encryption for sensitive data
  • Secure HTTPS connections
  • Database encryption at rest
  • Regular security audits and penetration testing
  • Access controls and authentication
  • Secure API communications

Organizational Measures:

  • Employee data protection training
  • Access limited to authorized personnel only
  • Confidentiality agreements
  • Incident response procedures

5.3 Data Breach Notification

In compliance with the Digital Privacy and Data Protection Act, 2082:

  • We will notify the Data Protection Authority within 72 hours of discovering a breach
  • Affected individuals will be notified promptly if the breach poses high risk
  • We maintain records of all data breaches and responses

6. Data Retention

6.1 Retention Periods

Data TypeRetention PeriodReason
Account informationDuration of account + 2 yearsService provision and legal requirements
Ride history5 yearsLegal compliance, dispute resolution
Location traces30 daysSafety and dispute resolution
Transaction records5 yearsFinancial and tax regulations
Support communications3 yearsQuality assurance, dispute resolution
Audit logs5 yearsSecurity and compliance

6.2 Retention Principles

  • Data is retained only as long as necessary for stated purposes
  • Anonymized data may be retained longer for analytics
  • Legal requirements may mandate longer retention

6.3 Data Deletion

Upon account deletion or retention period expiry:

  • Personal data is securely deleted or anonymized
  • Backup data is purged within 90 days
  • Legal hold data is retained as required

7. Data Sharing and Disclosure

7.1 Sharing with Service Providers

We share data with trusted service providers who assist us:

Provider TypeData SharedPurpose
Cloud hosting (Supabase)All service dataData storage and processing
Maps provider (Google)Location dataNavigation and routing
Push notifications (Firebase)Device tokensNotifications delivery
AnalyticsAnonymized usage dataService improvement

All service providers are contractually bound to protect your data.

7.2 Sharing Between Users

  • Passengers see: Driver name, photo, vehicle details, rating, live location during ride
  • Drivers see: Passenger name, pickup/drop location, contact option

7.3 Sharing for Safety

We may share data with:

  • Emergency services when safety is at risk
  • Law enforcement pursuant to valid legal process
  • Emergency contacts (when SOS feature is activated)

7.4 Legal Disclosure

We may disclose data when required by:

  • Court orders
  • Government authority requests
  • Legal proceedings
  • Protection of rights and safety

7.5 No Sale of Data

We do NOT sell your personal data to third parties for marketing purposes.

8. Your Rights

8.1 Rights Under Nepal Law

Under the Individual Privacy Act, 2075 and Digital Privacy and Data Protection Act, 2082, you have the right to:

Right to Access

Request a copy of your personal data we hold and understand how your data is being used

Right to Correction

Request correction of inaccurate data and update incomplete information

Right to Deletion

Request deletion of your personal data, subject to legal retention requirements

Right to Object

Object to processing for certain purposes and opt-out of marketing communications

Right to Data Portability

Receive your data in a structured, commonly used format and transfer your data to another service

Right to Withdraw Consent

Withdraw previously given consent, without affecting lawfulness of prior processing

8.2 Exercising Your Rights

To exercise your rights:

  • Email us at privacy@subhyatranepal.com
  • Use in-app privacy settings
  • Contact customer support

We will respond to requests within 30 days as required by law.

8.3 Right to Complain

If you believe your privacy rights have been violated, you may:

  • Contact us first for resolution
  • File a complaint with the Data Protection Authority of Nepal
  • Seek compensation through the District Court (Section 31, Individual Privacy Act)

9. Location Data

9.1 Why We Collect Location Data

Location data is essential for:

  • Connecting you with nearby drivers
  • Providing accurate fare estimates
  • Enabling real-time ride tracking
  • Ensuring safety during rides
  • Improving service coverage

9.2 Location Collection Practices

User TypeWhen CollectedPurpose
PassengersDuring ride booking and active ridesService provision
Drivers (foreground)When online and during ridesService provision
Drivers (background)When availability is ONDriver matching

9.3 Location Permissions

  • You control location permissions through your device settings
  • Denying location permission will prevent core app functionality
  • Background location for drivers is required for matching

9.4 Location Data Retention

  • Real-time location: Not stored after ride completion
  • Ride route data: Stored for 30 days
  • Pickup/drop locations: Stored with ride history (5 years)

10. Cookies and Tracking

10.1 Mobile App Tracking

Our mobile app may use:

  • Firebase Analytics for usage statistics
  • Crash reporting tools
  • Performance monitoring

10.2 Website Cookies

Our website (subhyatranepal.com) uses:

  • Essential cookies for functionality
  • Analytics cookies (with consent)

10.3 Managing Preferences

You can manage tracking through:

  • App settings
  • Device advertising settings
  • Browser cookie settings

11. Children's Privacy

11.1 Age Restriction

  • Our Services are not intended for individuals under 18 years
  • We do not knowingly collect data from minors
  • Minors may only use Services under adult supervision

11.2 Parental Rights

If you believe we have collected data from a minor:

  • Contact us immediately at privacy@subhyatranepal.com
  • We will promptly delete such data

12. International Data Transfers

12.1 Transfer Mechanisms

When data is transferred outside Nepal:

  • We ensure adequate protection measures
  • Transfers comply with Nepal's data protection requirements
  • Service providers are bound by data protection agreements

12.2 Server Locations

  • Primary servers: Asia-Pacific region
  • Backup servers: Secure cloud infrastructure
  • CDN: Global distribution for performance

13. Changes to This Policy

13.1 Policy Updates

We may update this Privacy Policy to reflect:

  • Changes in our practices
  • New features or services
  • Legal or regulatory requirements

13.2 Notification of Changes

  • Material changes will be notified via email or in-app notification
  • Updated Policy will be posted on our website and app
  • Continued use constitutes acceptance of changes

13.3 Review History

  • Version 1.0: January 2026 (Initial release)

14. Data Protection Officer

14.1 DPO Appointment

In compliance with the Digital Privacy and Data Protection Act, 2082, we have appointed a Data Protection Officer.

14.2 DPO Contact

Email: dpo@subhyatranepal.com

For privacy-related inquiries and complaints

15. Contact Us

15.1 Privacy Inquiries

For questions about this Privacy Policy or your personal data:

Data Controller (Service Operator):

Sankat Mochan Sajilo Yatra Pvt. Ltd.

Registration: 368115/81/82

Privacy: privacy@subhyatranepal.com

DPO: dpo@subhyatranepal.com

Support: support@subhyatranepal.com

Phone: +977 9808877530

Address: Chandrapur, Rauthad, Madhesh Province, Nepal

Technology Partner:

Nexalaris Tech Pvt. Ltd.

Email: contact@nexalaris.com

Phone: +977 9814846711

15.2 Response Time

We aim to respond to all privacy-related inquiries within 30 days.

15.3 Regulatory Authority

Data Protection Authority of Nepal (Contact details to be updated when Authority is established)

16. Acknowledgment

By using SubhYatra's services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.

This Privacy Policy complies with Nepal's Individual Privacy Act 2075, Individual Privacy Regulation 2077, Digital Privacy and Data Protection Act 2082, Electronic Transaction Act 2063, and Consumer Protection Act 2075.