Privacy & Compliance

Privacy Policy

This policy describes how Rolpa Jaljala Yatayat (“we”, “our”, or “the Company”) collects, uses, discloses, and protects data across our web platform and the mobile apps distributed via Apple App Store and Google Play. We align every practice with the transport laws of Nepal, Apple App Privacy details, and Google Play Data Safety requirements.

Last updated: November 20, 2025Applies to iOS & Android appsTLS 1.2+ encryption
Secure by design

Encryption at rest (AES-256) and in transit (TLS 1.2+), least-privilege IAM, annual penetration tests.

Regulatory alignment

Complies with Nepal’s Privacy Act 2018, GDPR-like rights, Apple App Privacy, and Google Play Data Safety.

Transparent sharing

Data shared only with processors essential to ticketing, payments, messaging, and governmental compliance.

1. Data we collect & why

We only collect data that is necessary to provide secure, reliable transport services, comply with Apple and Google platform policies, and meet local transport regulations.

Account & Contact Information
Full name, phone number, email address • Optional profile photo or gender when you choose to share it • Government ID or license copies for drivers/operators

Create your account, verify eligibility, send booking confirmations, and meet transport regulations.

Booking Details
Trip searches, selected routes, travel dates, and seat choices • Boarding and drop-off points, passenger names, and special requests • Booking history and refund preferences

Reserve seats, modify tickets, provide customer support, and generate anonymized insights that improve schedules.

Payment & Transaction Records
Transaction reference numbers, payment method type, settlement status • Tax invoices, refund receipts, and wallet adjustments • We never store full card or wallet PIN details on our servers

Process secure payments, issue refunds, prevent fraud, and comply with accounting obligations.

Device, Diagnostic & Location Data
Device model, OS version, language, app build, and crash reports • Anonymous analytics about how you use search, booking, or tracking screens • Approximate location to pre-fill nearby routes; precise GPS only when you enable live bus tracking or driver check-ins

Keep the app functional, detect bugs, guard against misuse, and satisfy Apple App Privacy and Google Play Data Safety disclosures.

Support Conversations
Emails, in-app chat threads, and attachments shared with our care team • Proof-of-travel or identity documents you voluntarily send for issue resolution

Respond to your requests, troubleshoot bookings, and maintain an audit trail for quality control.

2. Platform-specific transparency

We align our disclosures with Apple’s App Store Review Guidelines, App Privacy details, and Google Play’s User Data & Data Safety policies to guarantee uninterrupted deployment.

Apple App Store (App Privacy & Review Guideline 5.1)
  • We disclose every data category above inside App Store Connect and specify whether it is linked to a user, used for tracking, or required for app functionality. Data is never used for cross-app tracking or advertising.
  • Apple-required privacy nutrition labels distinguish Contact Info, Financial Info, Location, Identifiers, Purchases, Usage Data, and Diagnostics. Each label matches the actual runtime collection toggles in the iOS build.
  • Sensitive data (government IDs, payment instruments) is collected via secure, encrypted forms and transmitted only over TLS 1.2+, satisfying Apple’s encryption export compliance rules.
  • Users can request deletion directly from the in-app Profile > Privacy Center screen or by emailing support; we respond within 7 days and propagate deletions to third-party processors as required by App Store Review Guideline 5.1.1.
  • Sign in with Apple is fully supported; we only use the Apple-provided relay email for transactional messages and do not attempt to re-identify the underlying address.
Google Play (Data Safety Section & User Data Policy)
  • Our Data Safety form declares collection of Contact Info, Financial Info, Location, Personal Identifiers, App Activity, and Diagnostics; each category indicates whether data is optional, required, encrypted in transit, and eligible for deletion.
  • We do not share user data with third parties for advertising; sharing occurs only with vetted processors (payment gateways, SMS providers, governmental APIs) under data processing agreements.
  • The Android build honors the new Privacy Sandbox advertising ID opt-out flags and dynamically requests runtime permissions just-in-time (e.g., `ACCESS_FINE_LOCATION` only when enabling live tracking).
  • Users can export or delete their Google Play account data from Settings > Privacy Center, and requests are actioned within 5 business days to meet Google’s User Data policy.
  • We provide an in-app disclosure before collecting background location for driver trip tracking, per Google Play’s background location requirements.
3. Security controls
Technical & organizational measures
  • Encryption: TLS 1.2+ for data in transit, AES-256 for stored documents, hardware security modules for payment tokens.
  • Access controls: Role-based access, SSO with MFA for staff, quarterly access reviews, logging via centralized SIEM.
  • Infrastructure: Hosted on ISO 27001 certified providers with automated backups, isolated environments, and region-specific data residency (Singapore primary, Nepal secondary).
  • Incident response: 24/7 monitoring, breach notification to affected users and regulators within 72 hours where legally required.
  • Third-party processors: Payment gateways, SMS/voice providers, and analytics vendors sign DPAs and undergo annual reviews.
4. Retention & deletion
How long we keep data
  • Booking & payment records: retained up to 7 years to comply with transport, tax, and anti-money laundering laws.
  • Location traces for live tracking: anonymized after 30 days unless needed for an active investigation.
  • Crash logs and diagnostics: retained for 90 days for trend analysis then aggregated.
  • Support conversations: retained 24 months; you may request earlier deletion unless legally prohibited.

5. Your rights & controls

Regardless of where you reside, we extend the privacy rights modeled on GDPR, CCPA, and Nepal’s Privacy Act. Exercise them in the app or through our support team.

Access & Portability

Download a machine-readable copy of your booking history, invoices, and personal profile from Settings > Privacy Center or by emailing our support team.

Correction

Update profile details instantly inside the app; operator/driver identity documents can be re-uploaded for manual re-verification.

Deletion

Request deletion via the in-app privacy controls or email. Core booking records may be retained for up to 7 years to meet transport and tax regulations, after which they are anonymized.

Objection & Restriction

Opt out of non-essential analytics or marketing notifications in Settings. You may also request temporary processing holds while a dispute is investigated.

Children’s Data

The service is not directed to children under 13. Accounts identified as belonging to minors are closed and any personal data is promptly deleted.

6. Third-party disclosures
When we share data & why it’s lawful

7. Contact & privacy requests
Reach us for any privacy question

Submit access, deletion, or appeal requests through the in-app Privacy Center or via the following dedicated channels:

When contacting us, include your booking reference or the email used to sign up so we can securely verify your identity.

Commitment to privacy

We update this policy whenever our features or legal obligations change. Your continued use of the platform after updates signifies acceptance.

For archived versions or additional clarifications, contact us at hello@jaljalayatayat.com.