KYC & Sensitive Personal Data Disclosure

Last updated: June 2025

This page goes deeper than our general Privacy Policy on one specific topic: how we handle sensitive personal data — especially the KYC documents agents upload, and the passenger details users provide. It explains how long we keep this data, who can see it, and what your rights are.

1. Definitions

We use "sensitive personal data" in this document in the broad sense used by the SPDI Rules under the IT Act and by the Digital Personal Data Protection Act, 2023, including but not limited to:

  • Government identifier numbers (Aadhaar, PAN);
  • Financial information (bank account numbers, UPI IDs);
  • Biometric-like data (live selfies used to match identity documents);
  • Phone numbers verified via OTP;
  • Passenger PII collected for the purpose of booking;
  • Other documents you upload that contain identity, address, or financial information.

We collect this data only as needed to operate the platform.

2. What we collect from agents (KYC)

Before an agent can accept bookings, they complete KYC. We collect the following.

2.1 Aadhaar

The Aadhaar number (12-digit) and a scan/photo of the Aadhaar card (or e-Aadhaar PDF). Used only to verify your identity by visual review by our admin team and to deduplicate against other agent accounts. We do not seed your Aadhaar into UIDAI authentication APIs and do not perform Aadhaar-based eKYC against UIDAI infrastructure — the verification is documentary, not biometric. Once verified, Aadhaar numbers are masked to the last 4 digits everywhere in the UI, including your own profile.

2.2 PAN

The PAN number (10-character) and a scan/photo of the PAN card. Used for identity verification, beneficiary creation at Razorpay, and TDS / Section 194-O tax compliance on the earnings we pay you. Masked to the last 4 digits in the UI after verification.

2.3 IRCTC agent certificate

Proof of your authorisation by IRCTC to book Tatkal tickets — typically the IRCTC agent ID card or certificate. Used to ensure that bookings on TatkalDone are made by IRCTC-authorised agents on the official IRCTC platform. This is a regulatory document, not a personal identifier, but it is treated with the same access controls.

2.4 Live selfie

A self-captured photograph taken inside the onboarding flow. Used by the admin team to match against the photo on your Aadhaar/PAN. Not used to train any face-recognition model. Not shared with any third party.

2.5 Bank and UPI details

Your bank account number and IFSC (or a UPI VPA), and the account holder name. Used solely to make payouts via Razorpay and to create the payout beneficiary record. The corresponding payout beneficiary reference is stored on your agent record. Razorpay may perform a small reverse-penny-drop verification to confirm the account; the result is stored as a verification status on your record. The penny amount, if any, is deducted from your first payout if it is not refunded automatically by your bank. Masked to the last 4 digits in the UI.

2.6 Phone number

Verified via WhatsApp OTP on the Meta WhatsApp Cloud API and normalised to E.164 (+91XXXXXXXXXX). A uniqueness record is created to prevent the same phone number from being used on multiple accounts.

2.7 Other agent profile data

Display name, experience years, class preferences, route preferences, and per-class self-service charges. These are not sensitive but are stored against your agent record.

3. What we collect from users (booking PII)

For each booking you create, we collect:

  • Lead passenger name, age, gender, and berth preference;
  • Co-passengers' names, ages, genders, and berth preferences;
  • Optional child indicators;
  • Source and destination station details;
  • Date of journey, train number, and class;
  • Your contact phone and email, already on file from your account;
  • The payment receipt from Razorpay.

For saved passengers — so you don't re-type the same details every time — the same data is stored against your account. You can delete saved passengers at any time from your profile.

4. How and where it is stored

4.1 Documents — Cloudinary

All uploaded documents (KYC files, ticket images, profile selfies) are stored on Cloudinary, a global media-asset provider, under signed and access-controlled URLs.

  • Documents are uploaded directly from your browser to Cloudinary using short-lived signed upload signatures issued by our server — the file does not transit our application servers.
  • Each document URL is non-guessable and bound to your account.
  • Access is gated by short-lived signed download URLs generated by our server, only when an authorised principal (you, your accepted agent for ticket proof, or admin reviewers for KYC) requests it.
  • Every admin access to a KYC document is recorded in an audit log.

4.2 Identifiers and structured data — Firestore

Numeric identifiers (Aadhaar, PAN, bank, UPI), bank verification status, names, and other structured fields are stored in Firebase Firestore, with read access enforced by our Firestore security rules. Server-side access uses the Firebase Admin SDK with role checks.

4.3 Payment cards and UPI PINs — never on our infrastructure

Card numbers, CVVs, full UPI PINs, and netbanking passwords are entered only on Razorpay's hosted payment page. We never see, store, or log them. We receive only Razorpay's tokenised reference and the success/failure result.

4.4 OTPs — auto-expiring storage

OTPs are stored with a 5-minute TTL and an attempt cap. After verification or expiry they are deleted automatically.

5. Who can see your data

We apply the principle of least privilege.

5.1 Your own data

You can always see the data we hold about you in your profile.

5.2 KYC — admin reviewers only

Only admin/superadmin accounts with the verification role can fetch KYC documents, and only via short-lived signed URLs. Every access is logged.

5.3 Bank/UPI — admin reviewers and the payouts pipeline

Visible to admin reviewers during onboarding verification and to the server-side payouts pipeline that talks to Razorpay. Other agents and users cannot see your bank details.

5.4 Passenger PII — controlled visibility

We mask passenger details so that not every agent invited to a booking can see every passenger's full identity. The access rule is enforced uniformly in code and cannot be overridden by individual agents:

  • You (the booking owner) — always see full details.
  • Admin — always sees full details.
  • The accepted agent, once the booking has reached the deposit-paid stage or later (i.e. they have skin in the game and need to enter passenger details on IRCTC) — sees full details.
  • Other invited agents during pre-deposit broadcast — see only age, gender, and berth preference; names and contact details are masked.
  • All other parties — see nothing.

5.5 Other agents — no access

No agent can see another agent's KYC, bank details, identity, or contact information. The platform discloses only the minimum needed for the booking — the agent's display name to the user, and the user's identity to the accepted agent.

5.6 Third-party providers — strictly scoped

  • Razorpay — sees what is needed for payment processing and, for agents, the beneficiary KYC needed for Payouts.
  • Cloudinary — sees the uploaded files but does not see your TatkalDone identity tied to them beyond the public ID.
  • Firebase (Google) — stores the structured data and authenticates you.
  • Meta WhatsApp Cloud API — sees the phone number and the templated message content we send (OTP, booking notifications).
  • IRCTC — sees passenger details only as part of the actual booking on the IRCTC platform, entered by the agent.
  • Tax authorities — receive what is required for TDS / Section 194-O compliance on agent earnings.

Each provider operates under its own privacy commitments. We do not authorise any provider to use your data for advertising or for purposes other than running our service.

5.7 Law enforcement and regulators

We disclose data only in response to a valid legal request — a written notice from a competent authority, a court order, or a regulatory directive. We log every such disclosure and, where the law permits, notify the affected user.

6. We do not sell your data

We do not sell your personal information to anyone, ever. We do not share it for third-party advertising. We do not let third parties profile you across other websites or apps based on your TatkalDone activity. We do not run an ad network. There is no data-monetisation line of business at TatkalDone.

7. Retention

  • Active users — retained while your account is active, so you can continue to use the service.
  • Bookings and financial records — retained for 8 years, to comply with the Income Tax Act, 1961, the Companies Act, 2013, and GST recordkeeping requirements, irrespective of account closure.
  • Agent KYC — active agents — retained for the lifetime of the agent account, and for a further period as below after closure.
  • Agent KYC — rejected or withdrawn applications — retained for 90 days, to allow re-application and to investigate fraud rings, then deleted unless we have a specific fraud-prevention reason to retain it longer.
  • Agent KYC — suspended or terminated agents — retained for 7 years, for tax, regulatory, anti-fraud, and statute-of-limitations purposes.
  • OTPs — auto-deleted 5 minutes after creation.
  • Grievance records — retained for at least 180 days after closure (see our Grievance Redressal Policy).
  • Refresh tokens — hashed and stored until revocation or expiry (30 days from issue); revoked tokens are retained as hashes only, to detect replay attacks, then purged.
  • Logs — server-side request and audit logs are retained for 180 days, unless a longer retention is required for a security investigation.
  • Cache — Redis caches auto-expire within their TTLs and are not authoritative records.

8. Cross-border transfer

Our service providers (Firebase, Cloudinary, Meta WhatsApp Cloud API) operate globally and may process your data on servers outside India. We use providers that comply with industry-standard data protection commitments and have published policies on cross-border processing. Our database (Firestore) and our payment partner (Razorpay) operate primarily on infrastructure serving India. No data transfer is made for sale or onward marketing.

9. Your rights

You have the following rights, exercisable by emailing support@tatkaldone.in from your registered email, or via the Grievance channel. We will verify your identity before acting on a rights request.

9.1 Right to access

You can ask for a copy of the personal data we hold about you. We will respond within 30 days with a structured export.

9.2 Right to correction

You can ask us to correct inaccurate or outdated data. Most fields (name, email, phone via re-verification, payment preferences, passenger lists) can be corrected by you directly in the app.

9.3 Right to deletion / erasure

You can ask us to delete your account and the personal data associated with it. We will:

  • Delete or anonymise data we are not required to keep;
  • Retain data we are required to keep for tax, fraud, and regulatory reasons (see section 7) and tell you what is being retained and for how long;
  • Confirm completion of the deletion within 30 days.

9.4 Right to withdraw consent

Where our processing is based on your consent (for example, WhatsApp notifications), you can withdraw consent at any time. Some processing is based on contractual necessity or legal obligation and cannot be unilaterally withdrawn while you continue to use the service.

9.5 Right to nominate

Under the Digital Personal Data Protection Act, 2023, you may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Contact support@tatkaldone.in to register a nomination.

9.6 Right to grievance redressal

If your rights request is not handled to your satisfaction, you can use the Grievance Redressal Policy, including escalation to the Data Protection Board of India once operational.

10. Security measures

We use reasonable security practices and procedures, including:

  • Encryption in transit — all traffic between you and our servers is TLS-encrypted.
  • Encryption at rest — provided by our cloud storage and database providers.
  • Authentication — short-lived JWT access tokens (15-minute lifetime), hashed refresh tokens, OTP verification for phone changes, and replay-resistant refresh-token rotation.
  • Authorisation — role-based access control (user, agent, admin, superadmin) enforced both at the application layer and in Firestore security rules.
  • Rate limiting — per-IP and per-phone rate limits on OTP, login, refresh, and other sensitive endpoints.
  • Bot protection — proxy-layer bot detection on API routes.
  • Audit logging — every admin action on a booking or KYC document is logged.
  • Least privilege — admins are scoped to their role; superadmin is reserved for break-glass operations.
  • Signed URLs — every KYC/document fetch goes through a short-lived signed URL.
  • No card data on our servers — payment data lives only at Razorpay.

No system is perfectly secure, but we work continuously to reduce risk and to investigate any anomaly.

11. Breach notification

In the event of a security incident that compromises sensitive personal data, we will:

  • Begin investigation immediately and contain the incident;
  • Notify the Indian Computer Emergency Response Team (CERT-In) within the timelines required by the CERT-In Directions of 28 April 2022;
  • Notify the Data Protection Board of India (once operational), per the Digital Personal Data Protection Act, 2023;
  • Notify affected users and agents with a clear description of what happened, what data was affected, what we are doing, and what they should do;
  • Publish a post-incident report on this page where the incident materially affects users.

We will not delay notification to perform unnecessary internal investigation — we will notify as soon as we have a reasonable basis to believe the incident is real and significant.

12. Children

TatkalDone is not intended for use by anyone under 18, and accounts cannot be created by minors. Minors may travel as passengers under a booking made by an adult; in that case we collect only the passenger details necessary for the IRCTC booking and treat them with the same access controls as other passenger PII.

13. Changes

We will update this disclosure as our processing changes, new providers are added, retention periods are revised, or the law evolves. Material changes will be notified in-app before they take effect, with a meaningful window for you to review and, where appropriate, opt out.

14. Contact

For any question about this disclosure, your data, or to exercise your rights, contact:

  • Grievance Officer — [PLACEHOLDER: name]
  • Emailsupport@tatkaldone.in
  • Postal address — [PLACEHOLDER: registered office address], India

Questions? Email us at support@tatkaldone.com