Privacy Policy
Last Updated: 24 August 2026
This Privacy Policy explains how MFast ("MFast", "we", "us", or "our") collects, uses, stores,
shares, protects, and handles your personal information when you access or use our mobile applications
(including the MFast Customer App and the MFast Saathi / Rider App),
our website, and related on-demand parcel pickup, delivery, logistics, and digital platform services
(collectively, the "Services").
MFast operates in compliance with applicable Indian data protection laws, including the Digital Personal
Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and the
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or
Information) Rules, 2011.
By downloading, accessing, registering with, or using MFast Services, you acknowledge that you have read,
understood, and consented to the collection, processing, storage, and sharing of your information in accordance
with this Privacy Policy. If you do not agree with any part of this Privacy Policy, please do not use our Services.
1. Information We Collect
We collect only the information necessary to provide, maintain, optimize, secure, and enhance our on-demand
delivery and logistics platform. The categories of data collected depend on whether you use our Services as a
Customer (Sender/Receiver) or as a Delivery Partner / Rider.
1.1 Information Provided by Customers & General Users
- Account & Contact Information: Full Name, Mobile Phone Number, and optional Email Address collected during registration and verified via One-Time Password (OTP).
- Business & Company Details (where applicable): Company Name, Registered Business Address, Goods and Services Tax Identification Number (GSTIN), and Company Permanent Account Number (PAN) for corporate or business accounts.
- Pickup & Delivery Information: Complete pickup and drop-off addresses, landmark details, postal pincodes, recipient full name, and recipient contact phone number.
- Package Information: Category/type of goods, approximate weight, package dimensions, estimated declared value, special handling instructions, and optional photographs of parcels taken within the app.
- Profile Data: Optional profile picture and communication preferences.
1.2 Information Provided by Delivery Partners / Riders (Rider Onboarding & Verification)
To ensure platform safety, trust, regulatory compliance, and verified delivery fulfillment, riders must provide identity, vehicle, address, and financial verification documents:
- Live Profile Photograph: A real-time live selfie captured through the app camera to authenticate the rider's identity and display on customer order screens.
- Driving Licence: Copy and details of a valid Indian Driving Licence (DL) issued by the competent regional transport authority.
- Vehicle Registration Certificate (RC Book): Copy of the vehicle registration document for the vehicle used for delivery (e.g., bike, scooter, auto, or other supported vehicle modes).
- Identity & Address Verification: Front and back copies of Aadhaar Card and verifiable Address Proof (such as a recent Electricity Bill or Utility Bill).
- Emergency Contact Details: Name, phone number, and relationship of an emergency contact individual.
- Payout & Bank Account Information: Bank Account Holder Name, Bank Account Number, and IFSC Code to disburse rider delivery earnings, incentives, and payout settlements.
1.3 Location & Geolocation Information
- Customer Location: Precise (GPS) and approximate location data collected when the customer uses the app to set pickup/delivery coordinates, search addresses, or track active deliveries.
- Rider Location (Foreground & Background): High-precision GPS coordinates collected continuously from delivery riders while the Rider App is in use, running in the foreground, or running in the background during active shifts and while fulfilling assigned delivery orders. Background location tracking is essential to calculate travel distance, match nearby delivery requests, optimize navigation routes, provide live tracking to senders and recipients, ensure rider safety, and calculate accurate earnings.
1.4 Transaction, Wallet & Financial Data
- Payment Details: Transaction identifiers, payment methods (UPI, Net Banking, Credit/Debit Card, In-App Wallet, Cash on Delivery, Cash on Pickup), payment status, and billing summaries. All online card, net banking, and UPI transactions are securely processed by authorized third-party payment gateways (such as Razorpay / Cashfree / Stripe). MFast does not store sensitive card credentials, CVVs, net banking passwords, or UPI PINs.
- In-App Wallet: Wallet ledger balances, recharge records, transaction logs, promotional credits, and refund credits.
- Cash Collections & Settlements: Cash on Delivery (COD) and Cash on Pickup (COP) collection records, digital QR code payment settlements, and reconciliation logs.
1.5 Device, Technical & Diagnostic Information
- Device Identifiers: Device model, manufacturer, operating system version, unique device identifiers, hardware specifications, and network carrier information.
- Log & Performance Diagnostics: IP address, browser type, app crash reports, performance metrics, session timestamps, and system activity collected through tools such as Firebase Crashlytics.
- Push Notification Tokens: Firebase Cloud Messaging (FCM) tokens utilized exclusively to deliver real-time order alerts, status updates, OTPs, and operational notifications.
2. App Permissions & How They Are Used
The MFast mobile applications request specific device permissions strictly to enable essential features:
- Location Permission (Fine & Coarse): Required for pinpointing pickup/delivery locations, calculating delivery fares, calculating route distances, and providing real-time live shipment tracking.
- Background Location Permission (Rider App): Required for delivery partners to receive incoming order dispatches based on proximity, maintain accurate live order tracking for customers while the rider navigates using map apps, and verify delivery completion.
- Camera Permission: Used to capture real-time live selfies during rider onboarding, photograph identity documents (DL, RC, Aadhaar, Utility Bills), capture parcel photos, and scan delivery QR codes.
- Storage / Media Access: Used to select and upload document proofs and save receipts or invoices.
- Notifications Permission: Required to deliver order status updates, incoming delivery alerts for riders, driver arrival notices, security OTPs, and platform announcements.
- Foreground Service & Wake Lock (Rider App): Enables uninterrupted delivery status monitoring, GPS route recording, and prompt delivery dispatching during active duty.
3. How We Use Your Information
MFast processes collected information for the following lawful and operational purposes:
- Service Fulfillment: Facilitating parcel bookings, assigning nearest available riders, generating optimized routes, and successfully completing pickups and deliveries.
- Identity Verification & Safety: Authenticating user accounts via OTP, verifying rider identity documents, running KYC checks, validating driving permits, and maintaining safety across the platform.
- Real-Time Tracking & Communication: Providing live location tracking of active orders to senders and recipients, transmitting delivery ETA, sending delivery verification OTPs, and enabling communication between customer, rider, and support teams.
- Payment Processing & Financial Settlement: Processing order payments, crediting wallet balances, managing COD/COP reconciliations, and executing periodic payout disbursements to riders' bank accounts.
- Customer Support & Dispute Resolution: Responding to user inquiries, resolving delivery complaints, investigating lost or damaged parcels, and facilitating insurance or refund claims where applicable.
- Fraud Detection & Risk Prevention: Detecting fake orders, unauthorized account access, identity impersonation, fraudulent payment activities, location spoofing, and platform abuse.
- Legal & Regulatory Compliance: Complying with applicable Indian laws, tax regulations (GST filing and invoicing), statutory audit requirements, and valid law enforcement requests.
4. How We Share & Disclose Information
We do not sell, rent, trade, or monetize your personal data to any third party. We share information only in the limited circumstances described below:
- Between Customers and Delivery Partners: When an order is active, the sender and recipient receive the assigned rider's name, profile photo, vehicle details, contact number, and real-time GPS location. The rider receives the pickup/drop addresses, customer/recipient names, phone numbers, and delivery instructions needed to execute the delivery.
- Authorized Service Providers: We share data with trusted third-party service providers who assist us in operating our platform, subject to strict confidentiality and data protection obligations:
- Cloud Infrastructure & Database Hosting: Secure cloud servers and database storage providers.
- Mapping & Routing Services: Google Maps Platform APIs for geocoding, distance estimation, and route visualization.
- Payment Gateways: RBI-authorized payment aggregators (e.g., Razorpay, Cashfree, Stripe) for secure payment processing.
- Authentication & Notifications: SMS gateway providers for OTP delivery and Firebase (Google) for cloud messaging and crash reporting.
- Identity & Document Verification: Third-party verification services for document authenticity checks.
- Legal, Regulatory & Law Enforcement Requirements: We may disclose information if required to do so by applicable Indian law, court order, or governmental authority, or to protect the safety, rights, property, or integrity of MFast, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, restructuring, financing, or sale of company assets, user data may be transferred as part of the business assets under equivalent confidentiality protections.
5. Data Security & Encryption
MFast implements comprehensive technical, administrative, and organizational security measures to protect your personal data against unauthorized access, loss, misuse, alteration, or destruction:
- Encryption in Transit: All data transmitted between the mobile applications, website, and our servers is encrypted using Secure Sockets Layer / Transport Layer Security (SSL/TLS) protocols.
- Access Controls: Access to sensitive user documents and financial details is restricted on a strict need-to-know basis to authorized personnel and protected by multi-factor authentication.
- Secure Document Storage: Verification documents (DL, Aadhaar, RC, Utility Bills) are stored in secure cloud storage with restricted access permissions.
- Financial Security: Payment transactions adhere to PCI-DSS compliant standards through certified payment aggregators.
While we strive to employ best-in-class security measures, no electronic transmission over the internet or storage system is 100% immune to potential vulnerabilities. Users are responsible for keeping their login devices and OTP credentials confidential.
6. Data Retention & Minimization
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, provide ongoing delivery services, and satisfy legal, accounting, tax, or regulatory obligations:
- Account Information: Retained for the active lifespan of your user or rider account.
- Order & Transaction Records: Retained for a minimum period mandated under Indian tax (GST), financial reporting, and e-commerce compliance laws.
- Rider Verification Documents: Maintained for the duration of the rider's partnership with MFast and archived in accordance with statutory retention requirements.
7. Account Deletion & User Rights
Under the Digital Personal Data Protection Act, 2023 and applicable Indian regulations, you have specific rights regarding your personal information:
- Right to Access & Review: You have the right to review the personal data you have provided to us through your profile settings.
- Right to Correction & Update: You may correct, update, or rectify inaccurate or incomplete personal details directly within the app or by contacting our support team.
- Right to Account Deletion & Erasure: You have the right to request the permanent deletion of your MFast account and associated personal data. You can initiate an account deletion request through the mobile application settings or by emailing our Privacy & Grievance team. Upon receiving your verified request, we will delete or anonymize your personal data, except where retention is required by law (e.g., completed financial transaction records and tax logs).
- Right to Withdraw Consent: You may withdraw your consent for future data processing at any time. However, withdrawing essential consent (such as location access or contact details) will prevent us from delivering our on-demand logistics services to you.
- Right to Grievance Redressal: You have the right to register complaints regarding the handling of your data with our designated Grievance Officer.
8. Children's Privacy
MFast Services are strictly intended for individuals who are 18 years of age or older. We do not knowingly collect, solicit, or process personal information from children or minors under the age of 18. If we discover that a minor has provided us with personal data without verifiable parental or guardian consent, we will promptly delete such information and deactivate the associated account.
9. Third-Party Links & External SDKs
Our mobile applications and website may integrate third-party software development kits (SDKs), APIs, and links to external services (such as payment gateways and map navigation providers). These third-party entities operate under their own independent privacy policies. We encourage you to review the privacy policies of any third-party services you interact with.
10. Changes to This Privacy Policy
MFast reserves the right to revise, update, or modify this Privacy Policy at any time to reflect operational enhancements, new app features, technological advancements, or changes in legal regulations.
When updates occur, the "Last Updated" date at the top of this document will be updated. Material changes will be notified through in-app notifications, SMS alerts, or prominent notices on our platform. Continued use of MFast Services following the publication of an updated Privacy Policy constitutes your acceptance of the updated terms.
11. Grievance Officer & Contact Us
In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, the name and contact details of our Grievance Officer are provided below:
Grievance Officer: MFast Privacy & Grievance Cell
Entity: MFast
Email: mfastenterprise125@gmail.com
Phone / Helpline: +91 9137582829
Jurisdiction / Location: Mumbai, Maharashtra, India
If you have any questions, concerns, feedback, or requests regarding this Privacy Policy or your personal information, please feel free to reach out to us using the contact details above. We are committed to acknowledging and resolving grievances within the timelines prescribed by law.