Who can use the app
Access is limited to driver accounts provisioned by operations. The app has no public sign-up flow. It uses Firebase Authentication for work-email and password sign-in, with a pre-enrolled SMS or authenticator factor when multi-factor authentication applies. The service verifies that the signed-in account has the driver role.
Information handled
- Driver identity, work email, account identifier and authentication security records.
- Driving licence, identity proof, address proof, document issuer, last four identifier characters and expiry date used for KYC review.
- Assigned routes, delivery addresses, site-access instructions, package scans, stop status, failed-attempt reasons and shift checklist state.
- Delivery handoff photos, recipient signatures and fresh delivery codes used to complete proof of delivery.
- Incident category, severity and description, plus COD collection, paper receipt, sealed-bag and finance-handover records.
- Notification registration token, Firebase installation information and app-integrity attestation used for dispatch updates and abuse prevention.
Foreground location
Location sharing is off by default and must be started by the driver for an active delivery. The app requests foreground access only, stops sharing when the app is no longer active or the selected stop changes, and sends at most one current snapshot every 30 seconds. The latest snapshot replaces the earlier snapshot for that dispatch and expires from customer tracking after four hours. The app does not request background location.
Evidence and device storage
KYC and delivery evidence upload through short-lived secure upload instructions to private storage and pass an integrity and malware-scan gate. Temporary plaintext captures are removed after upload, encryption or when the app leaves the foreground. Route cache, queued commands and staged offline proof use account-bound encrypted device storage. Fresh delivery codes, COD collection details and location snapshots are not placed in the offline command queue.
Processors and deliberate transfers
Firebase processes authentication, app-integrity and push-notification data. HardwareAtHome infrastructure processes routes, KYC, evidence, incidents and COD records. Private object storage and security scanning process evidence files. When a driver explicitly opens navigation, the delivery address is passed to Google Maps. A masked call opens the device dialler with a short-lived proxy number instead of exposing the customer's number in the app.
Controls, retention and requests
Camera, notification and foreground-location permissions can be denied in Android settings, although KYC and delivery-proof work cannot be completed without required evidence. Signing out revokes the registered notification endpoint and clears account-bound route, queue and temporary evidence data from the device. Server-side KYC, delivery, incident, COD and audit records may remain subject to the applicable operational, dispute, fraud, safety and legal-retention requirements.
Driver accounts are created and managed by operations rather than in the app. Use the assigned operations support channel for access or correction requests. Privacy concerns can also follow the published grievance process. The operator and grievance details below must be configured before launch; a pending label is not a registered business identity.
Business identity
Operator and contact details
- Legal entity
- Pending launch approval — legal entity name
- Registration
- Pending launch approval — CIN or business registration number
- Registered office
- Pending launch approval — registered office address
- Grievance officer
- Pending launch approval — grievance officer name
- Pending launch approval — grievance email
- Phone
- Pending launch approval — grievance phone