This page is maintained by DriveMate Mumbai to answer common security and privacy questions. It describes our current practices and is not an independent certification.
Security
Last updated: June 2026
Data encryption
All traffic between your device and our servers is encrypted with HTTPS/TLS. Our managed database and storage bucket are encrypted at rest by the hosting provider.
Access control
- Customers can only access their own bookings using booking code + mobile OTP.
- Drivers sign in with their own account and can only see and update trips assigned to them. They cannot modify fare, payment, or customer fields.
- Administrators have operational access for support and dispatch.
Database access rules (row-level security) enforce these boundaries at the data layer, not only in the app.
KYC document handling
Driver KYC documents — Aadhaar (front/back), driving licence (front/back), profile photo, and bank details — are stored in a private bucket. Files are never publicly readable. Only the uploading driver and authorised administrators can view them, and admin access uses short-lived signed URLs.
Booking data privacy
Customer and driver phone numbers are masked until the driver accepts the trip. Booking lookups require both the booking code and the registered mobile number.
Authentication
Customers authenticate per-booking with a 4-digit OTP delivered to the registered mobile. Drivers and admins use account-based authentication with managed sessions.
Retention
We retain booking, trip, and KYC records for as long as required to operate the service and comply with applicable Indian regulations. Personal data deletion requests are honoured subject to those obligations.
Reporting a vulnerability
If you believe you have found a security issue, please email hello@drivemate.in with details and reproduction steps. We respond to legitimate reports as quickly as possible.
Support contact
hello@drivemate.in
