Effective 17 July 2026

Privacy Policy

How USETOO Logistics Private Limited collects, uses, and protects personal data.

1. Introduction and Scope

Logistics Private Limited, a company incorporated under the Companies Act, 2013, bearing Corporate Identification Number U52290MR2026PTC473613, having its registered office at Office No. 05, Pooja Complex, Hanuman Nagar, Bhayander East – 401105, Maharashtra, India ("Company", "USETOO", "we", "us" or "our"), is committed to protecting the privacy and Personal Data of every individual who interacts with its business, Platform, and operations.

This Privacy Policy ("Policy") describes how the Company, acting as a Data Fiduciary, collects, uses, discloses, stores, retains, secures, transfers and otherwise processes Personal Data in connection with its logistics and supply chain business, including Full Truck Load, Part Truck Load, Express Logistics, Warehousing, 3PL, Distribution, Freight Forwarding, Import-Export Logistics, Event Logistics, Film Logistics, Project Cargo, Industrial Logistics, Last-Mile Delivery, Vendor Marketplace, Technology Platform, Fleet Management, Transport Aggregation, Customs Coordination and Digital Logistics operations.

This Policy is framed in accordance with, and is intended to operate in conformity with, the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and rules made thereunder including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable during the transition to the DPDP Act framework), directions issued by the Indian Computer Emergency Response Team ("CERT-In") under Section 70B of the Information Technology Act, 2000 (including the CERT-In Cyber Security Directions dated 28 April 2022), the Indian Contract Act, 1872, and the Consumer Protection Act, 2019.

This Policy applies to Personal Data collected from, or relating to, Customers, Vendors, employees, Drivers, consignors, consignees, warehouse visitors, website and mobile application users, and any other individual who interacts with the Company (each a "Data Principal"), through any physical, digital, or automated channel, whether in India or otherwise, where such processing relates to offering of goods or services to Data Principals within the territory of India, or profiling of Data Principals within India, in each case as contemplated under Section 3 of the DPDP Act.

This Policy should be read together with the Company's Terms and Conditions of Service and any specific consent notice, employment agreement, vendor agreement, or contractual arrangement applicable to the relevant Data Principal. In the event of any conflict between this Policy and a specific contractual data-processing provision agreed in writing, the specific provision shall prevail to the extent of the conflict.

2. Definitions

(a)

"Biometric Data" means facial recognition data, fingerprint data, or other physiological identifiers used for attendance verification, access control, or identity authentication.

(b)

"Consent Manager" means a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform, as contemplated under Section 6(9) of the DPDP Act.

(c)

"Data Principal" means the individual to whom the Personal Data relates, and where such individual is a child, includes the parent or lawful guardian of such child.

(d)

"Data Processor" means any person who processes Personal Data on behalf of the Company pursuant to a contract, including cloud service providers, payment gateways, CRM/ERP vendors, and analytics providers.

(e)

"Data Fiduciary" means the Company, which alone or in conjunction with other entities, determines the purpose and means of processing Personal Data.

(f)

"Personal Data" means any data about an individual who is identifiable by or in relation to such data, and "Sensitive Personal Data" (for the purposes of continuing applicability of the IT Rules, 2011) includes financial information, biometric information, health data, and official identifiers such as PAN and Aadhaar (where collected).

(g)

"Processing" means the entire cycle of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, disclosure, dissemination, restriction, erasure or destruction.

(h)

"Data Breach" means any unauthorised processing of Personal Data or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to Personal Data that compromises its confidentiality, integrity or availability.

(i)

"Driver" means any individual, whether directly engaged by the Company or through a Sub-Contractor/fleet owner, who operates a vehicle for the transportation of Cargo under the Company's Services.

(j)

"Vendor" means any transporter, fleet owner, warehouseman, customs house agent, freight forwarder, supplier, or other business partner engaged by the Company.

(k)

"Platform" means the Company's website, mobile application(s), customer portal, Transport Management System, Warehouse Management System, CRM, ERP, and any other digital interface operated by or on behalf of the Company.

(l)

Capitalised terms not defined in this Policy shall bear the meanings assigned to them in the Company's Terms and Conditions of Service.

3. Applicability

This Policy applies to all Personal Data processed by the Company in both digital and non-digital form where such non-digital Personal Data is subsequently digitised, in accordance with Section 3(a) and 3(b) of the DPDP Act.

This Policy applies uniformly across all business verticals, geographies, and touchpoints of the Company, including its registered office, warehouses, transshipment hubs, field operations, and digital channels, and binds all employees, Drivers, Vendors, contractors and agents who process Personal Data on the Company's behalf.

Where the Company processes Personal Data as a Data Processor on behalf of a Customer (for example, consignee data furnished by the Customer for delivery purposes), the Company shall process such Personal Data strictly in accordance with the Customer's instructions and the terms of the applicable Rate Contract or Service Order, without prejudice to the Company's independent obligations as a Data Fiduciary in respect of Personal Data it collects for its own purposes (such as Platform account data, invoicing, and compliance records).

4. The Company as Data Fiduciary

Logistics Private Limited is the Data Fiduciary in respect of Personal Data processed under this Policy. The Company's contact details for privacy-related queries are set out below: Registered Office: Office No. 05, Pooja Complex, Hanuman Nagar, Bhayander East – 401105, Maharashtra, India Contact Numbers: +91 9152351616 / +91 9321213822 Where the Company engages Data Processors or Significant Data Fiduciary-level safeguards become applicable to it under a future notification of the Central Government, the Company shall comply with the additional obligations prescribed under Section 10 of the DPDP Act, including appointment of a Data Protection Officer and independent data audits, as and when such obligations become applicable to the Company.

5. Categories of Personal Data Collected — Customer Data

In connection with the provision of Services, the Company collects the following categories of Personal Data relating to Customers, their authorised representatives, consignors and consignees:

identity information, including full name, designation, and organisation details;

contact information, including registered address, delivery address, mobile number, and e-mail address;

business and tax identifiers, including GSTIN, PAN, and business registration details;

transactional data, including booking history, invoices, payment records, and credit terms;

communication records, including e-mails, WhatsApp Business API messages, call recordings (where notified), and Platform chat logs;

Platform account credentials and usage data; and

where relevant, bank account and payment instrument details for invoicing and refund processing.

6. Categories of Personal Data Collected — Vendor Data

In connection with vendor empanelment, the Vendor Marketplace, and procurement, the Company collects the following categories of Personal Data relating to Vendors and their authorised representatives:

identity and contact information of proprietors, partners, directors, or authorised signatories;

KYC documentation, including PAN, GSTIN, certificate of incorporation, partnership deed, and identity/address proof;

bank account details, cancelled cheques, and payment instrument information for vendor payouts;

fleet and asset details, including vehicle registration certificates, permits, fitness certificates, and insurance documents;

commercial and performance data, including rate cards, service-level performance, and empanelment history; and

digital signatures and e-signed vendor agreements executed through the Platform or third-party e-signing services.

7. Categories of Personal Data Collected — Employee Data

In connection with employment and human resource administration, the Company collects the following categories of Personal Data relating to its employees:

identity and contact information, including full name, date of birth, address, mobile number, and personal e-mail address;

statutory identifiers, including PAN, Aadhaar (where furnished for statutory compliance such as Provident Fund/ESI, subject to applicable Aadhaar-linking regulations), UAN, and bank account details for salary disbursement;

employment records, including offer letters, appraisals, disciplinary records, and termination/resignation documentation;

biometric attendance data, including fingerprint or facial recognition templates captured for time and attendance management at the Company's offices and warehouses;

emergency contact details and, where voluntarily furnished, medical or health information relevant to workplace safety and insurance enrolment; and

CCTV footage captured at Company premises, to the extent an employee is present within the monitored area.

8. Categories of Personal Data Collected — Driver Data

In connection with fleet operations, the Company (directly or through empanelled Vendors) collects the following categories of Personal Data relating to Drivers:

identity information, including full name, photograph, and date of birth;

licensing and regulatory documentation, including driving licence number, badge, and any state transport authority permits;

contact information, including mobile number, for coordination of pickup, in-transit updates, and delivery;

KYC documentation, including PAN and address proof, where the Driver is directly empanelled or paid by the Company;

real-time location data captured through the driver mobile application or vehicle-mounted GPS device during active trips, as further described in Clause 9; and

performance and compliance data, including trip completion records, delay incidents, and safety compliance history.

Location data of Drivers is collected solely for the duration of an active trip or duty period for the purposes of trip monitoring, ETA computation, safety, and Customer visibility, and is not collected or retained outside such active operational window, save for historical trip logs retained in accordance with Clause 20 (Retention Policy).

9. Fleet GPS Data, Vehicle Tracking and Live Location

The Company utilises GPS-enabled tracking devices installed in vehicles, and location services within the driver-facing mobile application, to capture vehicle location, route, speed, halts, and geofence entry/exit events ("Fleet GPS Data").

Fleet GPS Data is processed for the purposes of: real-time shipment tracking and Customer visibility; ETA computation and delay management; route optimisation and fuel efficiency monitoring; safety and driving-behaviour monitoring; theft/diversion prevention; and dispute resolution in relation to delivery timelines and route deviations.

Live location data shared with Customers through the Platform or tracking links reflects the real-time position of the vehicle carrying the relevant consignment and is shared solely for the duration of the Transit Period, or such other window as is reasonably necessary for the Customer to track its shipment.

Drivers and Vendor-fleet owners are informed, at the time of onboarding, of the categories of location data collected, the purpose of such collection, and the retention period applicable thereto, in accordance with the notice requirements under Section 5 of the DPDP Act. Location tracking is limited to duty hours and active trips, and the Company does not track Driver location outside of assigned duty periods.

10. Data Collected via Website, CRM, ERP, WMS and TMS

The Company collects and processes Personal Data through the following internal systems, each of which is subject to access controls and security measures described in Clause 23:

Website — contact form submissions, enquiry details, cookies, and browsing/usage data as described in Clause 12;

Customer Relationship Management (CRM) system — Customer and lead contact details, communication history, sales pipeline data, and interaction notes;

Enterprise Resource Planning (ERP) system — invoicing, procurement, payroll, and vendor payment data, including PAN, GSTIN and bank details;

Warehouse Management System (WMS) — inventory records, consignee delivery details, and warehouse personnel access logs; and

Transport Management System (TMS) — booking data, route plans, Driver assignment data, and Fleet GPS Data as described in Clause 9.

Data flowing between these systems is limited to what is reasonably necessary for the specific business function performed by each system, and access is restricted on a role-based, need-to-know basis to authorised personnel in accordance with the Company's internal information security policy.

11. WhatsApp Business API Communications

The Company uses the WhatsApp Business API to send booking confirmations, tracking updates, delivery notifications, invoices, and payment reminders to Customers, Vendors and, where relevant, consignees, and to receive booking requests and service-related queries.

Messages exchanged over the WhatsApp Business API are processed by WhatsApp/Meta Platforms, Inc. and the Company's authorised Business Solution Provider as Data Processors, in accordance with WhatsApp's Business Terms of Service and the Company's contractual arrangements with its Business Solution Provider, and may involve processing or storage of Personal Data outside India, subject to the cross-border transfer safeguards described in Clause 22.

The Company does not use WhatsApp Business API communications for unsolicited marketing outside the scope of transactional and service-related communication, save where the Data Principal has separately opted in to promotional communications in accordance with Clause 29.

12. Cookies and Tracking Technologies

The Company's website and Platform use cookies, web beacons, local storage, and similar tracking technologies to: enable core website functionality and session management; remember user preferences; measure website performance and usage patterns; and, where consented to, support analytics and personalisation.

Cookies used by the Platform are categorised as:

(i)

strictly necessary cookies, required for the Platform to function and not subject to opt-out;

(ii)

functional cookies, which enhance user experience; and

(iii)

analytics cookies, which are deployed only upon the user's consent, obtained through a cookie consent banner presented on first visit.

Users may manage or disable non-essential cookies through their browser settings or the Platform's cookie preference centre, provided that disabling strictly necessary cookies may impair the functionality of the website.

13. Analytics

The Company uses website and application analytics tools to understand usage patterns, measure Platform performance, and improve Service delivery. Analytics data may include IP address, device type, browser type, pages visited, time spent, and referral source.

Analytics data is processed on an aggregated or pseudonymised basis wherever feasible, and is used solely for internal business intelligence, product improvement, and operational planning, and is not sold or shared with third parties for their independent marketing purposes.

14. CCTV Surveillance

The Company operates closed-circuit television (CCTV) surveillance at its warehouses, offices, and other operational premises for the purposes of physical security, asset protection, incident investigation, and monitoring of loading/unloading operations.

CCTV surveillance is limited to common areas, entry/exit points, loading bays, and storage areas, and does not extend to washrooms, changing areas, or other locations where a reasonable expectation of privacy exists. Notice of CCTV surveillance is displayed at monitored premises.

CCTV footage is accessed only by authorised security and compliance personnel on a need-to-know basis, and is retained in accordance with the retention schedule set out in Clause 20, save where footage is required to be preserved for a longer period in connection with an ongoing investigation, legal proceeding, or law enforcement request.

15. Biometric Attendance Data

The Company may use biometric attendance systems (fingerprint or facial recognition) at its offices and warehouses to record employee attendance and regulate access to secure areas.

Biometric templates are stored in encrypted form and are used solely for attendance and access-control purposes; raw biometric images are not retained beyond the period necessary to generate the corresponding encrypted template, where technically feasible. Biometric Data is not shared with any third party save where legally compelled.

Employees are provided a non-biometric alternative (such as a manual register or card-based access) for attendance and access control where they decline to enrol in the biometric system, to the extent operationally feasible, and biometric enrolment is undertaken only with the employee's informed consent, communicated at the time of onboarding.

16. KYC, PAN, GST and Bank Details

The Company collects Know-Your-Customer (KYC) documentation, PAN, GSTIN, bank account details, and cancelled cheques from Customers, Vendors, Drivers and employees for the purposes of: contractual onboarding; statutory tax compliance under the Income-tax Act, 1961 and the GST Act; invoicing and payment processing; anti-fraud and financial due diligence; and compliance with know-your-customer norms prescribed by applicable regulators or the Company's bankers.

Bank account details are used solely for the purpose of processing payments, refunds, salary disbursement, or vendor payouts, and are stored in encrypted form with access restricted to authorised finance personnel. The Company does not store full debit/credit card details in unencrypted form, and payment card transactions are processed through PCI-DSS compliant payment gateways as described in Clause 18.

PAN and GSTIN details are retained for the statutory period prescribed under the Income-tax Act, 1961 and the GST Act respectively, and are shared with tax authorities only as required for statutory compliance, including TDS return filing and e-invoicing.

17. Digital Signatures and Video Verification

Where Customers, Vendors or employees execute agreements, Consignment Notes, or other documents electronically, the Company may capture digital signatures, click-wrap acceptances, or Aadhaar-based e-signatures through third-party e-signing service providers, in accordance with the Information Technology Act, 2000 and the Second Schedule thereto.

The Company may conduct video-based verification (V-CIP or equivalent) for Vendor or high-value Customer onboarding, capturing a short video recording together with a government-issued identity document, for the purpose of identity verification and fraud prevention. Such video recordings are stored securely and are accessed only by authorised compliance personnel.

Digital signature certificates and video verification records are retained for the period necessary to establish the validity of the underlying transaction and to meet evidentiary requirements under the Bharatiya Sakshya Adhiniyam, 2023, and are thereafter deleted or anonymised in accordance with Clause 20.

18. Payment Gateway Data

Where Customers make payments through the Platform, such payments are processed through third-party, PCI-DSS compliant payment gateway providers. The Company does not store complete card numbers, CVV, or card expiry details on its own systems; such data is processed and, where applicable, tokenised directly by the payment gateway in accordance with Reserve Bank of India tokenisation guidelines.

The Company receives and retains only transaction-level data (such as transaction ID, amount, status, and masked payment instrument reference) necessary for reconciliation, invoicing, and dispute resolution.

19. Cloud Storage

The Company stores Personal Data, operational records, and business data on cloud infrastructure provided by reputable third-party cloud service providers, which may include storage on servers located in India and, in limited cases, outside India.

Cloud service providers engaged by the Company act as Data Processors and are contractually bound to implement appropriate technical and organisational security measures, process Personal Data strictly in accordance with the Company's instructions, and not use such data for their own independent purposes.

The Company undertakes reasonable due diligence in the selection of cloud service providers, having regard to their security certifications (such as ISO/IEC 27001), data residency options, and compliance track record.

20. Third-Party Integrations

The Platform may integrate with third-party services, including mapping and geolocation APIs, SMS/e-mail service providers, WhatsApp Business API providers, payment gateways, e-signing platforms, accounting software, and logistics-technology partners, each of which processes Personal Data only to the extent necessary to perform its designated function.

The Company undertakes due diligence prior to onboarding any third-party integration partner and enters into data-processing arrangements requiring such partners to maintain confidentiality, implement adequate security safeguards, and process Personal Data solely for the specified purpose and in accordance with Applicable Law.

The Company is not responsible for the independent privacy practices of third-party websites or services that may be linked from the Platform but are not operated by the Company, and Data Principals are encouraged to review the privacy policies of such third parties separately.

21. Artificial Intelligence Systems

The Company may deploy artificial intelligence and machine-learning based systems (including the Company's internal intelligence layer) for purposes such as route optimisation, demand forecasting, fraud detection, automated customer support, and operational analytics.

Where AI systems process Personal Data, such processing is limited to the purposes for which the underlying data was collected, and the Company implements reasonable safeguards to minimise bias, ensure explainability of material automated outputs, and provide for human review of any AI-generated decision that produces a legal or similarly significant effect on a Data Principal, upon request.

The Company does not use AI systems to make solely automated decisions that produce a legal or similarly significant effect on a Data Principal (such as denial of Services or blacklisting) without an avenue for human review, and Data Principals may request such review by contacting the Grievance Officer under Clause 28.

Where feasible, Personal Data used to train or fine-tune internal AI/analytics models is anonymised or pseudonymised, and the Company does not knowingly submit identifiable Personal Data of Data Principals to third-party, publicly hosted AI tools without appropriate contractual and technical safeguards.

22. Purpose of Processing and Lawful Grounds

The Company processes Personal Data only for specified, lawful purposes for which the Data Principal has given consent, or for which processing is permitted under Section 7 of the DPDP Act, including: performance of a contract with the Data Principal; compliance with a legal obligation; response to a medical emergency; provision of employment-related benefits; and purposes related to safety and security of Company premises and assets.

Specific purposes of processing include: onboarding and KYC verification; booking, execution, and tracking of Services; invoicing, payment processing, and statutory tax compliance; vendor and fleet management; employee administration and payroll; safety, security, and asset protection; grievance redressal and dispute resolution; regulatory compliance and reporting; and, where separately consented to, marketing communications.

The Company does not process Personal Data for any purpose incompatible with the purpose for which it was originally collected, save with fresh notice and consent, or where otherwise permitted under Applicable Law.

24. Children's Data

The Company's Services are intended for use by persons who are eighteen (18) years of age or older, and the Company does not knowingly collect Personal Data of children (individuals below the age of eighteen years) except where such data is incidentally furnished by a parent or lawful guardian in connection with an emergency-contact or nominee detail, or is otherwise necessary and processed with verifiable parental/guardian consent in accordance with Section 9 of the DPDP Act.

The Company does not undertake tracking, behavioural monitoring, or targeted advertising directed at children, and does not process children's Personal Data in any manner likely to cause detrimental effect on their well-being, in accordance with Section 9 of the DPDP Act.

If the Company becomes aware that it has inadvertently collected Personal Data of a child without verifiable parental/guardian consent, it shall take reasonable steps to delete such data at the earliest opportunity, save where retention is otherwise required under Applicable Law.

25. Data Retention Policy

The Company retains Personal Data only for so long as is necessary to fulfil the purpose for which it was collected, to comply with statutory retention obligations, or to establish, exercise, or defend legal claims, whichever is longer, subject to the specific retention periods indicated below:

Booking, invoicing and transactional records: retained for a minimum of eight (8) years in accordance with the GST Act and the Income-tax Act, 1961;

Consignment Notes and Proof of Delivery: retained for the limitation period applicable to carriage-related claims under the Limitation Act, 1963, and in any event not less than three (3) years;

Employee records: retained for the duration of employment and thereafter for the period prescribed under applicable labour welfare legislation (such as the Payment of Wages Act, 1936, the Employees' Provident Funds and Miscellaneous Provisions Act, 1952, and allied statutes);

Biometric attendance templates: retained for the duration of employment and deleted within ninety (90) days of cessation of employment, save where a longer period is required for a pending investigation or legal proceeding;

CCTV footage: retained for thirty (30) to ninety (90) days on a rolling basis, save where extended retention is necessary for an ongoing investigation or legal proceeding;

Fleet GPS and live location data: trip-specific location data retained for twelve (12) months for operational analytics, safety review and dispute resolution, after which it is aggregated or anonymised;

KYC, PAN and GSTIN records: retained for the statutory period prescribed under the applicable tax and anti-money-laundering legislation; and

Marketing consent and communication preference records: retained until withdrawal of consent, and for a reasonable period thereafter to evidence compliance with the withdrawal request.

Upon expiry of the applicable retention period, and in the absence of a continuing lawful purpose, the Company shall erase or anonymise the relevant Personal Data in accordance with Section 8(7) of the DPDP Act, save where continued retention is required under any other Applicable Law.

26. Data Sharing and Disclosure

The Company may share Personal Data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate contractual safeguards:

Sub-Contractors and empanelled Vendors, to the extent necessary for performance of the Services (such as sharing consignee contact details with the assigned Driver for delivery coordination);

Data Processors, including cloud service providers, payment gateways, WhatsApp Business Solution Providers, e-signing platforms, and analytics providers, engaged under written data-processing terms;

professional advisors, including auditors, legal counsel, and insurers, for the purposes of compliance, dispute resolution, and claims processing;

Group companies and affiliates, where necessary for consolidated business administration, subject to equivalent confidentiality and security obligations;

Government and regulatory authorities, where disclosure is mandated under Applicable Law, as further described in Clause 30; and

a prospective acquirer, investor, or successor entity, in connection with a bona fide corporate transaction (such as merger, acquisition, or restructuring), subject to confidentiality obligations.

The Company does not sell, rent, or trade Personal Data to third parties for their independent marketing purposes, and does not share Personal Data with any third party except as set out in this Policy or as separately consented to by the Data Principal.

27. Cross-Border Data Transfers and International Transfers

The Company primarily stores and processes Personal Data within India. Where operational necessity requires transfer of Personal Data outside India, including where third-party service providers such as WhatsApp/Meta Platforms, Inc., cloud infrastructure providers, or analytics platforms process data on servers located outside India, the Company shall ensure that such transfer is undertaken in accordance with Section 16 of the DPDP Act.

As on the date of this Policy, Section 16 of the DPDP Act permits transfer of Personal Data outside India save to countries restricted by the Central Government by notification. The Company shall keep this Policy updated to reflect any country-specific restrictions notified by the Central Government from time to time, and shall not transfer Personal Data to a restricted jurisdiction.

Where Personal Data is transferred to a Data Processor located outside India, the Company shall ensure that such transfer is governed by a written agreement imposing data protection obligations at least equivalent to those applicable under this Policy and Applicable Indian Law, including confidentiality, security, and purpose-limitation obligations.

28. Data Security Measures

The Company implements reasonable security safeguards to protect Personal Data against unauthorised access, use, alteration, disclosure, or destruction, in accordance with Section 8(5) of the DPDP Act and the reasonable security practices contemplated under the Information Technology Act, 2000.

Such safeguards include, without limitation: role-based access controls and least-privilege access provisioning; multi-factor authentication for administrative and privileged access to Platform systems; network security controls, including firewalls and intrusion detection/prevention systems; periodic vulnerability assessments and penetration testing; secure software development practices for the Platform; physical security controls at warehouses, offices, and data centres; employee background verification and confidentiality undertakings; and periodic information security awareness training for personnel handling Personal Data.

The Company maintains logs of access to critical systems, and reviews such logs periodically for anomalous activity, in furtherance of its obligations under the CERT-In Cyber Security Directions, as described in Clause 30.

29. Encryption

Personal Data classified as sensitive (including bank account details, biometric templates, KYC documents, and payment-related data) is encrypted at rest using industry-standard encryption algorithms, and data transmitted over the Platform, including between the Company's systems and third-party integrations, is encrypted in transit using Transport Layer Security (TLS) protocols.

Access to encryption keys is restricted to authorised personnel, and the Company maintains key-management practices designed to prevent unauthorised decryption of protected Personal Data.

Notwithstanding the foregoing, the Company cannot guarantee absolute security of data transmitted over the internet or stored electronically, and any transmission is undertaken at the Data Principal's own risk, save to the extent the Company has failed to implement the reasonable security safeguards described in this Policy.

30. CERT-In Compliance and Incident Response

The Company maintains an incident response framework designed to detect, contain, investigate, and remediate cybersecurity incidents affecting its systems and Personal Data, in accordance with the CERT-In Cyber Security Directions issued under Section 70B(6) of the Information Technology Act, 2000.

In accordance with the CERT-In Directions, the Company shall report specified categories of cybersecurity incidents (including data breaches, unauthorised access, malware infection, and denial-of-service attacks affecting its systems) to CERT-In within six (6) hours of noticing or being brought to notice of such incident, through the reporting channels prescribed by CERT-In.

The Company synchronises system clocks of its ICT systems with the Network Time Protocol (NTP) server maintained by National Informatics Centre or National Physical Laboratory, as prescribed under the CERT-In Directions, and maintains logs of ICT systems for a rolling period of one hundred and eighty (180) days, stored within India, in compliance with the CERT-In Directions.

The Company's incident response team is responsible for coordinating the investigation of any suspected or confirmed cybersecurity incident, preserving relevant forensic evidence, and liaising with CERT-In and other regulatory authorities as required.

31. Data Breach Notification

In the event of a Data Breach, the Company shall, without delay, undertake a preliminary assessment of the nature and scope of the breach, and shall notify the Data Protection Board of India and the affected Data Principals in accordance with Section 8(6) of the DPDP Act, in such form and manner as may be prescribed by the Central Government.

Notification to affected Data Principals shall, to the extent known at the time of notification, describe the nature and scope of the breach, the likely consequences, the measures taken or proposed to be taken by the Company to mitigate the risk, and the steps the Data Principal may take to protect their interests, along with contact details of the Grievance Officer for further information.

Where the breach also qualifies as a reportable cybersecurity incident under the CERT-In Directions, the Company shall separately comply with the six-hour reporting timeline described in Clause 30, without prejudice to its notification obligations under the DPDP Act.

The Company shall document all Data Breaches, the Company's response thereto, and remedial measures undertaken, and shall use such documentation to strengthen its security posture and prevent recurrence.

32. Data Principal Rights

Subject to the provisions of the DPDP Act and the exemptions available thereunder, a Data Principal has the following rights in respect of their Personal Data processed by the Company:

(a)

Right to Access Information: the right to obtain a summary of the Personal Data being processed by the Company and the processing activities undertaken with respect to such Personal Data, in accordance with Section 11 of the DPDP Act.

(b)

Right to Correction and Erasure: the right to request correction of inaccurate or misleading Personal Data, completion of incomplete Personal Data, updating of Personal Data, and erasure of Personal Data that is no longer necessary for the purpose for which it was processed, in accordance with Section 12 of the DPDP Act.

(c)

Right to Grievance Redressal: the right to have a readily available means to register a grievance with the Company in respect of any act or omission regarding the processing of Personal Data or the exercise of the Data Principal's rights, in accordance with Section 13 of the DPDP Act.

(d)

Right to Nominate: the right to nominate another individual to exercise the Data Principal's rights in the event of death or incapacity, in accordance with Section 14 of the DPDP Act.

(e)

Right to Withdraw Consent: the right to withdraw consent at any time, as described in Clause 23.

A Data Principal may exercise the above rights by submitting a written request to the Grievance Officer at the contact details specified in Clause 33. The Company shall respond to such requests within a reasonable time and in any event within the timelines prescribed under the DPDP Act and rules made thereunder, subject to verification of the identity of the requester and the exemptions available under Section 17 of the DPDP Act (including processing necessary for enforcement of legal rights, prevention of offences, and processing by courts/regulatory bodies).

The Company reserves the right to charge a reasonable fee for repetitive or manifestly unfounded requests, to the extent permitted under Applicable Law, and to decline requests that would infringe the rights of other individuals or violate Applicable Law.

33. Grievance Officer

In accordance with Section 13 of the DPDP Act and Rule 3 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (to the extent applicable to the Company's Platform), the Company has designated a Grievance Officer to address queries, requests, and grievances relating to the processing of Personal Data.

Grievance Officer contact details: Office No. 05, Pooja Complex, Hanuman Nagar, Bhayander East – 401105, Maharashtra, India; Telephone: +91 9152351616 / +91 9321213822. Data Principals may address written grievances marked "Attention: Grievance Officer — Data Privacy" to the above address.

The Grievance Officer shall acknowledge receipt of a grievance within a reasonable period and shall endeavour to resolve the grievance within thirty (30) days of receipt. If the Data Principal remains dissatisfied with the resolution provided by the Grievance Officer, the Data Principal may escalate the grievance to the Data Protection Board of India, constituted under the DPDP Act, in accordance with the procedure prescribed thereunder.

34. Marketing Communications

The Company may send promotional or marketing communications, including information about new Services, offers, and industry updates, to Customers and Vendors who have opted in to receive such communications, through e-mail, SMS, WhatsApp Business API messaging, or other channels.

Data Principals may opt out of marketing communications at any time by using the unsubscribe mechanism provided in the relevant communication, replying "STOP" to SMS/WhatsApp communications where such mechanism is available, or by writing to the Grievance Officer. The Company shall give effect to an opt-out request within a reasonable time, and in any event within the timelines prescribed under the Telecom Commercial Communications Customer Preference Regulations, where applicable.

Opting out of marketing communications does not affect the Company's ability to send transactional, service-related, or statutorily required communications, including booking confirmations, invoices, and delivery updates, which are necessary for the performance of the Services.

35. Government and Regulatory Requests

The Company may disclose Personal Data to government agencies, law enforcement authorities, or regulatory bodies where required to do so:

(i)

under Applicable Law, including in furtherance of Section 36 of the DPDP Act, the Information Technology Act, 2000, and rules made thereunder;

(ii)

pursuant to a valid court order, summons, or lawful directive; or

(iii)

to protect the rights, property, or safety of the Company, its employees, Customers, or the public.

The Company shall, to the extent legally permissible, verify the legitimacy of any government or regulatory request prior to disclosure, and shall disclose only the minimum Personal Data reasonably necessary to comply with the specific request.

Where legally permissible and not prohibited by the requesting authority (such as under a gag order or ongoing investigation confidentiality requirement), the Company shall endeavour to notify the affected Data Principal of the disclosure.

36. Data Deletion

A Data Principal may request deletion of their Personal Data by writing to the Grievance Officer, and the Company shall erase such Personal Data upon expiry of the specified purpose (including any retention period specified under Clause 25) unless retention is necessary for compliance with a legal obligation, in accordance with Section 8(7) of the DPDP Act.

Where the Data Principal withdraws consent, or the specified purpose is no longer being served, and the Data Principal does not approach the Company for exercise of any right within a period as may be prescribed under the DPDP Rules, the Company shall, in accordance with such rules, erase the Personal Data, save where retention is required for compliance with any Applicable Law.

Deletion requests relating to Personal Data embedded in statutory records (such as tax invoices, TDS certificates, or Consignment Notes required to be retained under the GST Act or Income-tax Act, 1961) shall be given effect only upon expiry of the applicable statutory retention period.

37. Consumer Protection and Fair Processing

Where a Customer qualifies as a "consumer" under the Consumer Protection Act, 2019, the Company shall process such Customer's Personal Data fairly and transparently, and shall not engage in unfair trade practices, misleading data-collection representations, or deceptive consent mechanisms (including dark patterns) in connection with the Platform, in accordance with the Consumer Protection (E-Commerce) Rules, 2020 and the Guidelines for Prevention and Regulation of Dark Patterns, 2023, to the extent applicable to the Company's Platform.

This Policy, and the notices provided at the point of data collection, are intended to constitute clear and adequate disclosure for the purposes of Section 2(47) of the Consumer Protection Act, 2019 (unfair trade practice) and to enable Customers to make informed decisions regarding the sharing of their Personal Data.

38. Changes to this Policy

The Company reserves the right to amend or update this Policy from time to time to reflect changes in Applicable Law, business practice, or the categories or purposes of Personal Data processing. The updated Policy shall be published on the Company's website and/or Platform, together with the date of the last revision.

Material changes that affect the rights of Data Principals or expand the categories or purposes of Personal Data processing shall be notified through appropriate means (such as e-mail, Platform notification, or website banner), and, where required under the DPDP Act, fresh consent shall be sought prior to giving effect to such change.

Continued use of the Platform or Services following publication of an updated Policy shall constitute acknowledgement of the updated Policy, without prejudice to the Data Principal's right to withdraw consent at any time in accordance with Clause 23.

39. Governing Law and Jurisdiction

This Policy shall be governed by and construed in accordance with the laws of India. Any dispute arising out of or in connection with this Policy shall be subject to the dispute resolution and jurisdiction provisions set out in the Company's Terms and Conditions of Service, namely resolution by arbitration seated at Mumbai, Maharashtra, under the Arbitration and Conciliation Act, 1996, subject to the exclusive jurisdiction of the courts at Mumbai, Maharashtra for matters not required to be arbitrated.

Nothing in this Clause shall preclude a Data Principal from approaching the Data Protection Board of India or any other competent regulatory authority in accordance with the DPDP Act and rules made thereunder.

40. Contact Us

For any questions, requests, or grievances relating to this Policy or the processing of Personal Data by the Company, please contact: USETOO Logistics Private Limited — Grievance Officer, Data Privacy Office No. 05, Pooja Complex, Hanuman Nagar, Bhayander East – 401105, Maharashtra, India Telephone: +91 9152351616 / +91 9321213822 ACKNOWLEDGEMENT This Privacy Policy is published by USETOO Logistics Private Limited as a unilateral notice to Data Principals in accordance with Section 5 of the Digital Personal Data Protection Act, 2023, and does not require a countersignature to be effective. By interacting with the Company, its Platform, or its Services, a Data Principal acknowledges having had the opportunity to review this Policy.

This Policy was last reviewed and published with effect from 17 July 2026. For queries regarding this Policy, please refer to Clause 40 (Contact Us).

Issued for and on behalf of USETOO Logistics Private Limited Ayush Pandey — Co-Founder & Managing Director Date: 17 July 2026