ErryGoBack to home

ErryGo Privacy Policy

Version 2.0
Effective date 29 August 2026
Jurisdiction India
Replaces Version 1.0, 10 August 2026

This policy explains what personal data ErryGo collects, why, who it is shared with, where it goes, and how long it is kept. It is written to describe what our systems actually do.


1. Who we are and what this covers

ErryGo Private Limited ("ErryGo", "we", "us", "our") — CIN U63120DL2026PTC468269 — operates a hyperlocal technology marketplace that connects customers with independent ErryGo Partners for on-ground errands.

This policy applies to:

  • the ErryGo customer app (Android com.errygo.customer, iOS com.errygo.customer);
  • the ErryGo Partner app (Android com.errygo.partner, iOS com.errygo.partner);
  • errygo.com and our support channels.

Together we call these the "Platform". ErryGo is the Data Fiduciary for the personal data described here, under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

ErryGo currently operates in Delhi and Gwalior (Madhya Pradesh).

This policy covers two different people, and it says clearly which is which:

  • a Customer — someone who books an errand;
  • a Partner — an independent ErryGo Partner who accepts and performs errands.

Partners give us substantially more data than customers do, because verifying identity and paying people requires it. Section 4 is about Partners only.


2. The short version

  • We ask for your mobile number and verify it with a one-time SMS code. That is your account.
  • We use your location to place your errand, to route your Partner, and to show you where they are. The Partner app also collects location in the background while a Partner is online — with a permanent, visible notification saying so.
  • What you type when you describe an errand is sent to an AI provider outside India so it can be understood, categorised and priced. Section 6 says exactly who and for how long.
  • When a job is live, the customer and the Partner see each other's real mobile numbers. This is not masked. Section 7 explains it.
  • We use a product-analytics provider hosted in the United States. Section 9 lists every processor and where it is.
  • You can export your data and delete your account from inside both apps. Section 12 says precisely what deletion does and does not remove.

3. What we collect from Customers

3.1 Account and identity

  • Mobile number (Indian numbers only, +91). This is the account identifier.
  • One-time passcodes you are sent to sign in. We store a hash of the code, the number it went to, the IP address the request came from, and the number of attempts — for 30 days.
  • Name, and an email address and profile photo if you choose to add them.

3.2 Where you are and where the errand goes

  • Saved addresses: the label you gave it, the address text, and its coordinates.
  • Your device location, when you allow it, to set a pickup or drop point and to show your Partner's position on the map. The customer app requests location only while you are using it. It never collects location in the background.
  • For each errand: the pickup, destination and any intermediate stops — address text, coordinates, your notes about the floor, gate or landmark, and the Google Place ID where you chose a place from search rather than dropping a pin.
  • The road distance used to price the job, stored as it was at the moment you were quoted.

3.3 The errand itself

  • What you typed to describe the errand, in your own words.
  • Your answers to the clarifying questions the app asks before quoting.
  • The category, price, timing and any scheduled time.
  • The declared value of an item, where you give one. We use it only to decide whether we can accept the errand at all — there is a ceiling above which we decline. It is not insurance and it does not create any cover. See the Terms.
  • Photos you attach to an errand, a chat message or a dispute; bills and receipts photographed during the errand; PDFs attached to a dispute.
  • In-app chat messages between you and your Partner — text, image attachments, and which quick-reply you tapped.
  • The 4-digit completion code for the errand. We store it hashed, not in readable form, and delete it when the errand ends.

3.4 Payments

  • The amount, method, status and reference of each payment, refund, tip and cash collection.
  • Whether an errand was prepaid or paid in cash.
  • We do not store your card number, UPI PIN, CVV, or bank credentials. Card and UPI details are handled by Cashfree and by your own bank or UPI app. We receive the outcome and a reference, not the credential.

3.5 Ratings, disputes and support

  • The rating and review you leave for a Partner, which you can give within 48 hours of the errand ending.
  • Disputes you raise, and the evidence attached to them.
  • Your correspondence with support and any grievance you file.

3.6 Consent records

Each time you accept these policies we write an append-only record of who consented, to which version, when, and from which IP address. Withdrawal is recorded as a further row rather than by deleting the original — an audit trail that erases itself is not one.


4. What we collect from Partners (in addition to Section 3)

A Partner gives us more than a customer does. This section exists so that is stated plainly rather than buried.

4.1 Identity verification (KYC)

Verification is performed by Cashfree Verification Services. Depending on the step, that involves DigiLocker, the Aadhaar issuing authority, the income-tax PAN database, your bank, and a face-match check.

What ErryGo stores afterwards:

We store We do not store
A masked Aadhaar number (e.g. xxxxxxxx1234) The full 12-digit Aadhaar number — never, anywhere
The name, date of birth and address returned by the Aadhaar record The Aadhaar XML or e-KYC payload
The photograph held on the Aadhaar record, used as the face-match reference —
A masked PAN (e.g. ABCxxxxx1F) and the name on it The full PAN
Your selfie, and the face-match result and score —
Bank: account holder name, IFSC, and the last four digits. The full account number is stored encrypted (AES-256-GCM) and used only to pay you The account number in readable form
UPI: a masked VPA and the name your bank holds for it —

We also keep the outcome of each step, and — where no automated verdict was possible — the reason, so that a human reviewer can tell "the vendor could not check this" apart from "this did not match".

If a KYC application is rejected, a further attempt is blocked for 30 days.

4.2 Location — including in the background

This is the most significant collection on the Platform, so it is described in full.

While you are online in the Partner app, we collect your position. Each reading contains:

  • latitude and longitude,
  • GPS accuracy,
  • speed and heading,
  • your phone's battery percentage,
  • the errand you are on, if any.

Collection happens in two ways:

  • While the app is open — frequently, so the customer's map moves.
  • While the app is in the background or closed — roughly once a minute, or every 100 metres. This is what keeps you visible to dispatch when your phone is in your pocket. If we cannot see a recent position we stop offering you work after 10 minutes.

You can always see when this is happening. On Android a permanent notification sits in your shade for as long as tracking runs. On iOS the status bar turns blue. Going offline stops it, and the app stops sending positions the moment you do.

We do not collect your location when you are offline.

Battery level is read because the app slows its reporting rate on a low battery. It is not used for anything else.

4.3 Optional matching attributes — separate consent

Gender and languages spoken are optional and self-declared. They exist so a customer who asks for, say, a woman Partner to accompany an elderly relative can actually be matched.

  • They are collected under a separate, purpose-specific consent, not the general terms.
  • They are never shown to a customer and never leave ErryGo.
  • They are used only to rank offers, never to filter them. Declining costs you no work — you receive exactly the same offers.
  • You can withdraw at any time. Withdrawal takes effect on the very next job broadcast.

4.4 Work, conduct and safety

  • GPS trails for errands you performed, as above.
  • Before and after photos you submit as proof of work. We also compute a fingerprint of each photo (a cryptographic and a perceptual hash) and keep it for 180 days, so we can detect the same photo being submitted for a different job. The fingerprints are compared only against your own past submissions.
  • Fraud signals — for example an implausible travel speed, or a duplicate photo.
  • Strikes and conduct records, and the reason for each.
  • SOS alerts: when you press SOS we send our operations team your name, phone number, your coordinates at that moment, and the job you were on. If you have not granted location permission the alert still goes through, without coordinates.
  • Ratings customers leave you, your average, your tier and your completed-job count.

4.5 Money

Your earnings, wallet balance, cash dues, withdrawal requests, and the payout references returned by our payout provider.


5. What is collected automatically, in both apps

  • Device and app information: device model, operating system version, app version, language.
  • IP address, recorded with sign-in records, sessions and consent records.
  • Session records: a hashed refresh token, device information and IP address, kept for 30 days.
  • Product analytics. Both apps send usage events — screens opened, actions taken, errors — to PostHog. Our PostHog instance is hosted in the United States. Session replay is switched off in both mobile apps: we do not record your screen. (Our internal staff admin panel does record staff sessions; no customer or Partner uses it.)
  • Crash and error reporting. Both apps send crash reports to Sentry. These are configured not to send personal data: request bodies are dropped before sending, URLs are stripped of identifiers, and completion codes, one-time passcodes and tokens are never included.
  • Push notification token, one per user, so we can reach your handset.
  • On errygo.com: Google Analytics and standard web logs.

On Android, the customer app can read the one login SMS we send you, using the Android SMS User Consent API, so the code fills itself in. It reads only that single message, only when you are waiting for a code, and only if you allow it. We do not have permission to read your SMS inbox, and we do not read any other message.


6. Artificial intelligence — what leaves our systems

When you describe an errand, we need to understand it well enough to categorise it, ask you the right follow-up questions, price it, and tell your Partner what "done" looks like.

To do that, the text you type and the answers you give are sent to a third-party AI model.

  • The model is OpenAI GPT-4.1, reached through the Vercel AI Gateway.
  • Both are outside India.
  • We send the description, your answers and the task context. We do not send your name, mobile number, payment details or your saved addresses to the model.
  • We keep a record of the exchange — what you typed, the questions asked, the options you chose, the model used and its confidence — for two years, so that a price or a dispute can be explained afterwards.

Your use of the errand-description feature is what causes this transfer. If you do not want your text sent to an AI provider, do not use the app to describe an errand.


7. What the customer and the Partner see of each other

This section describes a real exchange of personal data between two users, so it is set out directly.

Your Partner is shown: your name, your exact addresses and coordinates for the errand, your instructions and notes, and a masked form of your phone number on the job card.

You are shown: your Partner's name, photograph, rating, tier, completed-job count, vehicle, their ErryGo Partner ID, and a masked form of their phone number.

Phone numbers are revealed in full when either of you taps to call. ErryGo used to bridge calls through a masking service. That was removed on 13 August 2026. The two of you now dial each other directly, which means:

  • each side learns the other's real mobile number;
  • that is permanent — the number can be called after the errand ends;
  • a number is only released while the job is live (from assignment until completion), and only to the customer or the assigned Partner on that job;
  • every disclosure is logged — who received whose number, and when.

The phone number itself is never written to the job record and never appears in our logs.

Each of you may use the other's contact details only for that errand and legitimate follow-up about it. Using them for anything else — marketing, personal contact, harassment — is a breach of the Terms and we will act on it.


8. Why we use personal data, and on what basis

Purpose What it uses
Create and secure your account Mobile number, one-time code, device, IP
Understand, price and confirm an errand Description, answers, locations, distance
Find and assign a Partner Location of the errand, Partner locations, ratings, optional matching attributes (with consent)
Let you follow the errand Partner location, task events
Let the two of you communicate Chat, phone-number disclosure
Take payment, pay Partners, handle refunds Payment records, wallet, bank/UPI details
Verify Partners KYC data (Section 4.1)
Prevent fraud and keep people safe Location trails, photo fingerprints, device and IP, SOS
Support, disputes and grievances Everything connected to the errand
Meet tax, accounting and legal obligations Transaction records
Improve the service Analytics, crash reports

Under the DPDP Act we rely on your consent, recorded as described in Section 3.6, and on legitimate uses permitted by the Act — including responding to an emergency and complying with law. Where we must keep records by law, we keep them regardless of a later withdrawal, and Section 11 says which.


9. Who we share data with

We share only what a given recipient needs.

9.1 The other party to your errand

As set out in Section 7.

9.2 Merchants and third parties on an errand

Where an errand involves a shop, tailor, repairer, bank counter, courier or public office, your Partner will pass on what that errand requires — for example your name or your instruction.

9.3 Our processors

Processor What it does Where it processes
Cashfree Payments Card, UPI and netbanking collection India
Cashfree Payouts Paying Partners India
Cashfree Verification Services Partner Aadhaar, PAN, bank, UPI and face verification India
MSG91 Sends the login SMS India
Pusher (Mumbai cluster) Live updates in the apps India
Google Firebase Cloud Messaging Push notifications Google infrastructure
Google Maps Platform Maps, place search, routing Google infrastructure
Supabase Storage Stores photos, bills, voice notes Hosting provider
Railway Runs our servers and databases Hosting provider
Vercel AI Gateway → OpenAI Understanding an errand description (Section 6) Outside India
PostHog Product analytics United States
Sentry Crash reporting Error-monitoring provider
Google Analytics errygo.com website only Google infrastructure

Each is engaged under contract, may use the data only to provide its service to us, and may not use it for its own purposes.

9.4 Others

  • Law enforcement, courts, regulators and government authorities, where required or permitted by law.
  • Professional advisers, auditors and insurers.
  • A successor or purchaser, in a genuine corporate transaction.

We do not sell personal data, and we do not share it for third-party advertising.


10. Where your data goes

Our core operational data — accounts, errands, payments, locations, messages — is held in our own databases with our hosting provider, and our payment, verification, SMS and real-time providers process it in India.

Some processing happens outside India, and we would rather say so than imply otherwise:

  • product analytics (PostHog) is hosted in the United States;
  • errand descriptions sent for AI understanding go to a gateway and model outside India (Section 6);
  • crash reporting and parts of our hosting and storage infrastructure may process data outside India;
  • Google services (push, maps, website analytics) operate on global infrastructure.

Transfers are made under contract with each provider and in accordance with the DPDP Act and any restriction the Central Government notifies under it.


11. How long we keep things

Data Kept for
Login OTP records (number, hashed code, IP) 30 days
Sign-in sessions (device, IP) 30 days
Partner location trails 90 days
Fraud flags 90 days
Photo fingerprints 180 days
AI errand-understanding records 2 years
Pricing correction records 2 years
Errands, payments, wallet and payout records, disputes, ratings At least 7 years (we work to 8)

The last line is a legal floor, not a preference: order and financial records are books of account, and the Income-tax Act and the Companies Act, 2013 require them to be preserved. Deleting your account does not delete them — instead we strip the personal data out of them, so what remains is a transaction record that is no longer about an identifiable person.

We do not currently run an automatic deletion job on records past that window; when we do, it will archive the financial record before removing anything.


12. Your rights, and exactly what they do

Under the DPDP Act you may ask for access to your data, correction of it, erasure, and you may withdraw consent or nominate someone to act for you.

12.1 In the app, right now

Customer app → Settings → Privacy & Data

  • Download my data produces a file containing your profile, your saved addresses and your last 50 errands.
  • Delete my account does all of the following, in one transaction:
    • replaces your phone number with a placeholder and clears your name, email and profile photo;
    • marks the account closed;
    • revokes every session, which signs you out everywhere and removes the stored device and IP;
    • deletes your login OTP records;
    • deletes your saved addresses;
    • removes your push token;
    • replaces the address and coordinates on your past errands with a marker.

Partner app → Profile → Delete account offers the same route.

12.2 What in-app deletion does not do

We would rather tell you than let you assume. The self-service deletion above does not currently remove in-errand chat messages, notification records, or the AI record of how your request was interpreted. Those stay attached to the errand record described in Section 11.

If you want everything removed across every one of our systems, email help@errygo.com and ask for a full erasure. Our operations team runs an erasure that reaches all of our services and removes those records too. We will verify your identity first.

We are closing the gap between the two routes; until we do, this section describes the difference honestly.

12.3 Withdrawing consent

Withdrawing consent for a purpose stops that use going forward. Withdrawing consent to the core terms means we can no longer operate your account. Partners can withdraw consent for the optional matching attributes (Section 4.3) without any effect on the work they are offered.

12.4 How to ask

Email help@errygo.com from your registered address, or write to the address in Section 16. We will ask you to verify your identity — we will not act on an unverified request to release or delete someone's data. See Section 16 for our response times.


13. Security

  • All traffic between the apps and our servers is encrypted in transit.
  • Partner bank account numbers are encrypted at rest with AES-256-GCM.
  • One-time codes and completion codes are stored as hashes, never in readable form.
  • Aadhaar numbers are never stored in full, in any system.
  • Access to our operations tools is role-based and every action is recorded.
  • Push tokens, one-time codes, completion codes and access tokens are excluded from our logs and from crash reports by design.

No system is completely secure and we do not claim otherwise. If a breach affects you, we will notify you and the Data Protection Board as the DPDP Act requires.


14. Children

The Platform is not for people under 18. You must be 18 or older to create an account, book an errand or work as a Partner. We do not knowingly collect a child's personal data. A child may receive incidental assistance during an errand only under the supervision of a responsible adult. If we learn that we hold a child's data without proper authority, we will remove it.


15. Changes

We will update this policy when the law, our technology or our service changes. The current version and its effective date are always published here.

Where a change is material we will tell you in the app or on a registered contact channel before it takes effect, and where the law requires fresh consent we will ask for it — the apps will require you to accept again before you can continue.


16. Contact and grievance redressal

ErryGo Private Limited
B-9/6353, Vasant Kunj, New Delhi 110070, Delhi, India

Grievance Officer and Nodal Person: Gandharv Mahajan, Director
Email: help@errygo.com
Phone: +91 96677 06299

We acknowledge complaints within 24 hours and aim to resolve them within seven days, or sooner where the law requires it. For complaints under Rule 3(2)(b) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we take reasonable and practicable measures within two hours.

If you are not satisfied you may complain to the Data Protection Board of India under the DPDP Act, or to the Grievance Appellate Committee under the IT Rules.


© 2026 ErryGo Private Limited
CIN: U63120DL2026PTC468269 · GSTIN: 07AAJCE8214C1ZV

© 2026 ErryGo Private Limited
CIN: U63120DL2026PTC468269 | GSTIN: 07AAJCE8214C1ZV
SupportTerms and ConditionsAccount deletion