Summary. Anchor is a workforce management app for employees and drivers assigned company vehicles. We process personal data and precise location so you can view your assignment, access company documents, and allow your employer to verify that you — the assigned worker — are using the vehicle. Vehicles are tracked by on-board GPS chips; the App additionally collects phone location (including in the background, with consent) to compare against the vehicle tracker.
1. Who we are
This Privacy Policy (“Policy”) describes how Aurex Digital (“we”, “us”, or “our”) collects, uses, stores, discloses, and protects personal data when you use:
- the Anchor mobile application for Android (“App”);
- our customer portal API at
https://api.aurexdigital.in(“API”); and - this website where this Policy is published (“Website”).
MSME registration number: [To be updated]
General contact: info@aurexdigital.in
2. Scope and applicability
This Policy applies to assigned users and authorised persons who access the App using credentials linked to a vehicle assignment agreement with a company using the Aurex platform.
We aim to comply with applicable Indian laws, including:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”); and
- other applicable regulations relating to workforce management, consumer protection, and telecommunications.
Where your employer's assignment agreement or privacy notice imposes additional obligations, those documents also apply to the extent they govern your relationship with that employer.
3. Definitions
- Personal data means any data about an identifiable individual.
- Sensitive personal data may include precise geolocation, as classified under applicable law.
- Company means the employer or fleet operator that assigned you the vehicle and uses the Aurex platform.
- Agreement means your vehicle assignment agreement with the company.
- Data principal means you, the individual to whom the personal data relates.
- Data fiduciary means the entity that determines the purpose and means of processing. Depending on context, your company and/or Aurex Digital may act as a data fiduciary.
- Data processor means an entity that processes personal data on behalf of a data fiduciary. Aurex Digital may act as a processor for companies in respect of assigned-user data stored and transmitted through our platform.
4. Roles: data fiduciary and processor
Anchor connects assigned vehicle users with the companies that provide their vehicles. In many cases:
- your company is the primary party responsible for the vehicle assignment and may be the data fiduciary for assignment and user records; and
- Aurex Digital provides the App, API, hosting, and related infrastructure, and may process data as a data fiduciary for App operations or as a data processor acting on instructions of companies.
For questions about how your company uses your data, contact them directly. For App-specific privacy questions, contact us using the details in Section 20.
5. Information we collect
Depending on how you use the App and the permissions you grant, we may collect the following categories of information.
5.1 Identity and access credentials
- Vehicle registration number
- Assignment / reference number
- Session authentication token issued after successful login
5.2 Personal and profile information
- Assigned user name
- Agreement identifier
- Company name
- Vehicle description / label
5.3 Assignment and program information
- Assignment terms, program tenure, and status
- Program schedule (due dates, amounts, completed entries, overdue status)
- Program records (amounts, dates, reference numbers, record types)
- Summary figures shown on your dashboard
- Assignment documents made available to you through the App (file names, types, download metadata)
- Transfer initiation details when you use company-configured methods (amount, method selected, schedule entry)
5.4 Location information (phone and vehicle)
- Phone location — precise GPS coordinates from your device (latitude, longitude, accuracy, timestamps)
- Vehicle location — collected separately by on-board GPS trackers installed in assigned vehicles and transmitted to our platform; not read directly from this App
Phone location is collected only after you grant permission and consent in the App. Your company may compare phone and vehicle locations to verify authorised use. See Section 8.
5.5 Device, app, and technical information
- Device operating system version and device manufacturer/model (where available through system APIs)
- App version
- Network connectivity status
- IP address and request metadata in server logs
- Crash, diagnostic, and performance data if we enable analytics or error reporting in future releases (we will update this Policy if we do)
- Locally stored preferences such as terms acceptance, location consent status, active assignment session, and notification reminder state
5.6 Communications and notifications
- Schedule reminder notification content generated on-device based on program due dates
- Foreground service notification shown while background location verification is active
5.7 Information we do not intentionally collect
We do not require access to your contacts, photos, microphone, calendar, SMS content, or call logs for core App functionality. We do not sell your personal data.
6. How we collect information
- Directly from you when you sign in, accept terms, grant permissions, initiate transfers through company-configured methods, or interact with the App.
- From your company via the API when your credentials are validated and dashboard data is retrieved.
- Automatically when the App transmits location updates, syncs in the background, sends heartbeat signals, or communicates with our servers.
- From your device through Android permissions you approve (location, notifications, and device location/GPS state).
7. Legal bases and consent
We process personal data based on one or more of the following grounds, as applicable under Indian law:
- Consent — e.g. when you accept this Policy and Terms, and when you explicitly allow location access and background location.
- Performance of contract — to provide App features linked to your vehicle assignment agreement.
- Legal obligation — to comply with applicable laws, court orders, or regulatory requests.
- Legitimate uses — as permitted under the DPDP Act, such as preventing fraud, ensuring network security, and maintaining service integrity, where applicable.
You may withdraw consent for optional processing (such as background location) through device settings and in-app controls. Withdrawal may limit or disable features. Some processing may continue where required by law or your assignment agreement.
8. Location data (important)
Dual verification. Assigned vehicles have on-board GPS trackers. This App additionally collects your phone’s precise location (including in the background, with consent) so your company can compare both signals and confirm you — the assigned user — are using the vehicle, not an unauthorised person.
8.1 What this App collects vs the vehicle tracker
- Vehicle GPS chip — reports vehicle location to our platform independently of this App
- This App (phone) — reports your phone location when you grant Android permissions
- Your company — may view both and check that they match
8.2 When phone location is collected
- After you sign in and accept the Terms and this Policy
- After you explicitly grant location permissions through Android and in-app prompts
- While a foreground location service is running
- Periodically via scheduled background sync and heartbeat mechanisms
- When significant movement is detected (e.g. beyond a configured distance threshold)
8.3 Frequency
Location collection is periodic, not continuous streaming. Depending on device state, movement, battery optimisations, and network availability, updates may occur at intervals ranging from approximately hourly to every few hours, and when material movement is detected. If device GPS/location is turned off, collection may pause until location is re-enabled.
8.4 Purpose of phone location collection
- To verify that the assigned user’s phone is at or near the vehicle reported by the on-board GPS tracker
- To help companies prevent unauthorised use of assigned vehicles
- To display verification and tracking information to authorised company personnel on the company dashboard
- To detect prolonged gaps in phone location reporting and trigger follow-up under company policies
8.5 Who receives location data
Phone location data is transmitted to our API and made available to the company associated with your assignment and authorised Aurex Digital personnel who require access for support, security, and system administration on a need-to-know basis. Vehicle tracker data follows the same access rules.
8.6 Your controls
- You may decline location permission; some features may be restricted.
- You can change permissions in Android Settings at any time.
- Revoking background location may cause the App to limit functionality or display setup prompts.
- Uninstalling the App stops future collection from that device.
8.7 Prominent disclosure
Before background location permission is requested, the App presents an in-app explanation of phone vs vehicle tracking, why both are used, and that data is shared with your company. This Policy supplements that disclosure.
9. How we use information
We use personal data to:
- authenticate you and maintain your session across one or more assigned vehicles on a device;
- display assignment summaries, program schedules, records, and documents;
- initiate and record transfer requests through company-configured methods and display receipts;
- collect and transmit phone location data for verification as described in Section 8;
- send program schedule reminders and service notifications;
- maintain background services, including restart after reboot where permitted;
- monitor API security, troubleshoot errors, and prevent abuse;
- comply with legal obligations and enforce our Terms;
- improve the App and develop new features in accordance with applicable law.
10. How we share information
We may share personal data with:
10.1 Your company
The company that assigned your vehicle receives assignment-related data, phone location data, and vehicle tracker data necessary for monitoring and verification under your agreement.
10.2 Service providers and infrastructure partners
We use third parties to host, secure, and operate the platform, which may include cloud hosting providers, database services, networking/CDN providers, and email or SMS gateways if enabled. These providers process data only to perform services for us under contractual confidentiality and security obligations.
10.3 Transfer service providers
If you initiate a transfer through a third-party interface configured by your company (e.g. UPI intent or checkout link), transaction data is handled by the relevant service provider in accordance with its terms. We do not store full card details on our servers unless explicitly stated otherwise in the transfer flow.
10.4 Legal and safety disclosures
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of users, employers, Aurex Digital, or the public.
10.5 Business transfers
If we undergo a merger, acquisition, restructuring, or sale of assets, personal data may be transferred subject to this Policy or a successor policy with notice as required by law.
10.6 What we do not do
- We do not sell or rent your personal data to third-party advertisers.
- We do not share location data with unrelated third parties for their independent marketing.
11. Third-party transfers
When you initiate a transfer through company-configured methods in the App, we transmit instructions to our API and, where applicable, redirect you to third-party interfaces. Service providers may collect identifiers, transaction amounts, and device/network metadata necessary to process the transaction. Review the provider’s privacy notice before completing a transfer.
12. Data retention
We retain personal data only as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law or your assignment agreement.
- Session tokens — for the duration of your authenticated session and as configured on our servers.
- Location history — for the period required by your company’s policies and applicable law; companies may retain location records on the platform according to their retention schedules.
- Assignment and program records — typically for the life of the agreement and statutory limitation / regulatory periods thereafter.
- Server logs — for a limited period for security and debugging, unless extended for incident investigation.
- On-device data — until you clear app data or uninstall the App.
When data is no longer required, we take reasonable steps to delete, anonymise, or aggregate it.
13. Security
We implement reasonable administrative, technical, and organisational safeguards designed to protect personal data, including:
- HTTPS/TLS encryption for data in transit between the App and API;
- access controls and authentication for API endpoints;
- restricted access to production systems on a need-to-know basis;
- secure development and deployment practices.
No method of transmission or storage is completely secure. You are responsible for keeping your device secure and not sharing your agreement credentials with unauthorised persons.
If we become aware of a personal data breach likely to affect your rights, we will notify affected parties and authorities as required by applicable law.
14. Your rights
Subject to applicable law (including the DPDP Act), you may have the right to:
- Access personal data we hold about you;
- Correction of inaccurate or incomplete data;
- Erasure of data where retention is no longer necessary and no legal exception applies;
- Withdraw consent for processing based on consent;
- Nominate another individual to exercise your rights in the event of death or incapacity, as permitted by law;
- Grievance redressal through our Grievance Officer (Section 20).
To exercise rights relating to assignment records, we may direct you to your employer where they are the data fiduciary. We will assist as required by law.
We may need to verify your identity before responding. We aim to respond within timelines prescribed by applicable law.
15. Children
The App is intended for adults who are assigned company vehicles as part of their work. We do not knowingly collect personal data from children under 18. If you believe a child has provided data through the App, contact us and we will take appropriate steps.
16. International transfers
Our primary systems are intended to be hosted in India. If data is processed or stored outside India, we will do so in compliance with applicable cross-border transfer requirements under Indian law and with appropriate safeguards.
17. Third-party links and services
The App may open external links (e.g. third-party transfer pages, document downloads, device settings). This Policy does not apply to third-party websites or services. Review their privacy policies separately.
The App uses Google Play services libraries for location on Android. Google’s processing is governed by Google’s policies.
18. Automated decision-making
We do not make solely automated decisions that produce significant legal effects about you without human involvement, except where permitted by law. Employers may apply their own workforce policies outside the App.
19. Changes to this policy
We may update this Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be notified through the App, Website, or other reasonable means where required. Continued use after the effective date constitutes acceptance of the updated Policy where permitted by law.
20. Grievance redressal and contact
In accordance with applicable Indian law, you may contact our Grievance Officer for privacy-related complaints or questions:
- Grievance Officer: Aurex Digital
- Email: info@aurexdigital.in
We will endeavour to resolve grievances within 30 days or within the period prescribed under applicable law, whichever is shorter.
If you are not satisfied with our response, you may have the right to approach the Data Protection Board of India or other competent authority once operational under the DPDP Act, or other remedies available under law.
General support: info@aurexdigital.in