ryder Privacy Policy
Last updated: September 18, 2026
On this page
1. Who we are and who this policy covers
- ryder is operated by Carnatic Foods Private Limited, CIN U56100TN2025PTC180902, with its registered office at Plot No. 87, Sun Garden, Morattandi, Auroville, Vanur, Villupuram, Tamil Nadu 605101, India (the Company, we, us or our).
- This policy explains how we collect, use, disclose, store and protect personal information in connection with the ryder delivery personnel application, its onboarding and verification screens, and related operational and support services. The Android application package is com.carnaticfoods.ryder.
- It applies to applicants, employees and independent delivery partners who use ryder, and to emergency contacts whose information is provided to us. ryder is intended for individuals aged 18 or above providing delivery services in India. The description “delivery personnel” does not determine or change anyone’s employment or contractual status.
- This is a separate notice for ryder. The raagas customer privacy policy applies separately when you use raagas to order food. This policy explains information handling; it does not itself create an insurance benefit or replace your engagement terms.
2. Information we collect and its sources
We receive information from you, authorised onboarding and operations personnel, your use of the app, and providers involved in verification and delivery operations. Customers and outlet personnel may provide delivery feedback, ratings or incident information.
2.1 Account and profile information
- Your name, mobile number, date of birth, rider identifier, account and verification status, authentication records, and profile photograph.
- Sex information, blood group, marital status, and the name and telephone number of your nominated emergency contact. Blood group and marital status are mandatory fields in the current onboarding process. The purposes of these fields are explained in Section 4.
2.2 Identity, bank and face verification
- PAN, driving licence information, bank account number, IFSC, account-holder details, verification references and results. A verification provider may return additional identity details, including registered name, date of birth, gender, address, email, mobile number, masked Aadhaar details and Aadhaar-linking status.
- Information shared through DigiLocker Aadhaar verification, including name, date or year of birth, photograph, address, gender, care-of details, masked Aadhaar details or last four digits, and the electronic document package returned by the verification service.
- Live camera images and video processed for selfie and liveness verification. The process also generates reference and audit photographs, facial comparison results and confidence scores. A reference selfie may also be used as your rider profile photograph.
2.3 Shift, location, delivery and earnings records
- Shift and break status; precise location coordinates, accuracy, speed, heading and time; mock-location indicators and battery level associated with location updates. Section 5 explains when location tracking starts and stops.
- Delivery assignments, acceptance and status events, pickup and delivery timestamps, confirmation codes, proof-of-delivery photographs and relevant coordinates, ratings, incident reports and SOS requests.
- Earnings, incentives, adjustments, settlement records and information needed to investigate a payment or delivery discrepancy.
2.4 Device, diagnostics and communications
- Device and operating-system information, app version, network and IP information available to our services, notification tokens, session and error records, and diagnostic logs.
- Sampled diagnostic session replays that reconstruct app interactions and error sessions, together with feedback submitted through diagnostic or support features. These are used to investigate app failures and reliability issues.
- Diagnostic collection can begin when the app opens, including on sign-in and onboarding screens. It is separate from location tracking during a shift.
- Information in support messages, complaints, safety reports and other communications, and records of our response.
3. Identity and onboarding checks
- ryder onboarding includes PAN, bank account, driving licence, DigiLocker Aadhaar and selfie/liveness checks. We use Cashfree verification services for relevant document and bank checks, and AWS Rekognition for liveness and facial comparison.
- The current onboarding process requires Aadhaar verification through DigiLocker. This describes the business process and is not a statement that Aadhaar is required by law for every delivery engagement. The verification flow requests authorisation to obtain the relevant documents and information. Contact support@carnaticfoods.com if you cannot complete verification or wish to raise a concern about the information requested.
- Face verification checks whether the person completing the process is present and matches the relevant identity photograph. The process generates reference or audit images and verification results. Verification information is used for identity, eligibility and impersonation checks, and to address verification disputes.
- A verification result may require another attempt or further assessment. You may ask support to review an inaccurate result or explain a difficulty with the verification process. A link to this policy does not replace any specific consent required for sensitive information or Aadhaar-related processing.
4. How we use information
4.1 Delivery operations and administration
- Create and administer rider accounts, authenticate access, carry out onboarding checks and maintain engagement records.
- Manage shifts, allocate and coordinate deliveries, provide order progress and arrival information, confirm delivery and investigate complaints or discrepancies.
- Calculate and reconcile earnings, incentives and adjustments; verify the nominated bank account; and maintain relevant settlement, accounting and tax records.
- Provide operational notifications and support, investigate app failures, protect accounts and systems, and address suspected impersonation, location manipulation or other misuse.
- Respond to safety incidents, comply with applicable legal requirements and lawful requests, and handle disputes involving the Company or delivery personnel.
4.2 Safety, emergency contacts and benefit-related information
- Sex information is collected to inform assignment arrangements for women that consider delivery distance and timing for safety purposes. These considerations are not a guarantee that a particular route, time or delivery is safe. You may contact support about how profile information has affected an assignment.
- Blood group is collected for use in responding to an accident or other emergency. Emergency-contact information is collected so that the nominated person can be contacted in connection with a safety incident or emergency.
- Marital status is collected in anticipation of possible future family or medical insurance arrangements. No insurance programme or cover is promised by this policy. If a programme is introduced, its applicable terms and information-sharing arrangements will need to be communicated separately, with any further consent required by law.
- If you provide another person’s emergency-contact details, inform them of that purpose and give them access to this policy. They may contact us about their information. This does not remove our own notice and consent obligations.
5. Precise and background location
- Location tracking starts when you start a shift after granting the relevant permission. During the shift, tracking can continue while you are delivering, waiting for an order, taking a break, using another app or leaving ryder in the background. Minimising or closing the app does not necessarily end the shift or stop tracking.
- The app stops location tracking after a successful shift end. It does not intentionally continue collecting new shift-tracking locations while you are off duty after that successful shift end. Previously collected locations may still be uploaded as a final batch; that is different from collecting new locations after the shift.
- If the request to end a shift fails, the shift may remain active and location tracking may continue. Check that the shift has ended successfully. Logout also attempts to stop tracking, and you can revoke location permission through your device settings.
- During a shift, location helps coordinate assignments and deliveries, provide progress and arrival information, support safety assistance and investigate delivery or suspected location-manipulation issues. Relevant information is available to authorised operations and outlet personnel. Customers receiving a delivery can see your live location, name and actual phone number to coordinate that delivery.
- Without the location permissions needed for delivery operations, you may be unable to start a shift or use dispatch and tracking features. Revoking permission does not automatically erase information already collected. Retention and privacy requests are addressed below.
6. Device permissions and local storage
- Precise and background location permissions support the shift-related purposes described above. A location permission request may appear after sign-in; permission alone does not mean that a shift has started.
- Camera access supports selfie/liveness verification and proof-of-delivery photographs. Notification permission supports assignments, delivery changes and other operational messages. Where a verification screen requests an additional device permission, the purpose must be explained in that flow.
- You can manage permissions through your device settings. Refusing or withdrawing a permission may prevent the associated feature from working. Contact support if you need help understanding the effect on your account or delivery work.
- The app stores sign-in tokens, remembered settings and queued delivery updates on your device to maintain the session and handle temporary connectivity interruptions. Queued updates may be sent when connectivity returns. Uninstalling the app does not by itself close the account or remove records already held on our systems.
7. Who receives information
We disclose information for the purposes described in this policy, subject to the consent, contractual arrangements or other legal authority required for the disclosure.
7.1 Operational recipients and customers
- Authorised Company and outlet personnel receive information relevant to onboarding, shifts, dispatch, delivery supervision, earnings, support and safety.
- Customers receiving a delivery can see your name, live location and actual phone number. The contact number is not described as a masked or proxy number. Customer information provided to you must likewise be used only for authorised delivery, support or safety purposes.
- In an emergency, relevant information may be provided to your nominated emergency contact, responders or authorities where necessary and permitted by applicable law. Information collected for a possible future insurance programme is not a representation that an insurer currently receives it.
7.2 Technology, verification and settlement services
- Amazon Web Services, Google Cloud Platform and Microsoft Azure support cloud services. AWS services also support account authentication and face verification. Cashfree verification services support relevant identity and bank checks.
- Google Maps supports maps and location-related features. Expo and Firebase Cloud Messaging support notifications. Sentry supports diagnostic events, logs, feedback and sampled session replays.
- Banks and providers involved in an actual earnings settlement receive the information needed for that transaction and reconciliation. Verifying your bank account and transferring earnings are separate activities.
- The information supplied to a provider depends on its function. A provider’s own privacy notice may also apply to services it operates independently. We remain responsible for our own processing and for meeting applicable obligations when engaging providers.
7.3 Legal requirements and business transactions
- Relevant information may be disclosed to professional advisers, courts, regulators, law-enforcement agencies or other authorised recipients where necessary for advice, proceedings, a lawful request or a legal obligation. A request for information does not give unrestricted access to every rider record.
- If a merger, restructuring or transfer of the relevant business affects ryder, relevant information may be provided to those involved, subject to applicable confidentiality, notice, consent and other legal requirements.
8. Hosting, transfers and security
- We use AWS, Google Cloud Platform and Microsoft Azure. Our hosting approach is primarily to use services in India; where a required service is unavailable in India, processing may take place abroad. Verification, diagnostics, support and other service-provider processing may involve locations outside the principal hosting region.
- Overseas processing remains subject to the transfer conditions and protections required by applicable Indian law. Use of a global cloud provider does not mean that every category of information is stored in the same country.
- Safeguards include protected account authentication and controlled access to documents. The verification-document storage uses encryption and time-limited access links. Security measures must be appropriate to the information and risks involved; no system can eliminate every security risk.
- Suspected misuse, unauthorised access or disclosure should be reported to support@carnaticfoods.com. Security incidents and required notifications are handled under the law applicable to the incident. This policy does not claim a particular security certification or an absolute guarantee against a breach.
9. Retention and account closure
- The retention period depends on the information, its lawful purpose and any applicable legal requirement. Account and engagement records, identity-verification material, detailed location history, delivery photographs, earnings records, diagnostic information and security logs do not necessarily have the same retention period.
- Relevant records may need to remain available to complete verification, administer the engagement, reconcile earnings, resolve a specific delivery dispute or safety incident, investigate misuse, or meet accounting, tax, employment, cybersecurity or other legal obligations.
- A binding preservation requirement or legal hold may require particular records to be retained beyond their ordinary period. Its scope depends on the matter and the applicable requirement. Possible future law-enforcement interest is not, by itself, a statutory requirement to retain every record indefinitely.
- Account deactivation or closure does not automatically erase all records. You may request closure or deletion by contacting support@carnaticfoods.com. The request is assessed against the information concerned, the purpose still served and any obligation to retain it. This policy does not promise immediate deletion of all system, provider and backup copies.
- You may ask which categories remain after closure and the reasons or criteria for their retention. An applicable legal restriction may limit the details that can be provided. Information must not be retained longer than its lawful purpose or an applicable legal requirement permits.
10. Your choices and privacy requests
- Write to support@carnaticfoods.com to request review or correction of information you supplied, withdraw consent for a specified use, request account closure or deletion, or raise a concern about collection, sharing or retention.
- We may need proportionate information to verify that a request comes from the relevant person or an authorised representative. In your initial message, describe the request and a safe way to contact you. Do not send passwords, one-time login codes or complete identity and bank documents unless a secure, necessary verification step is specifically arranged.
- You can decline to provide information or withdraw consent. Where information is necessary for a particular feature or to lawfully administer your engagement, the affected feature or process may be unavailable. Ask us to explain the consequence for the particular use rather than assuming every service must stop.
- Withdrawal concerns processing that depends on that consent. It does not invalidate past lawful processing or remove an independent legal retention obligation. Relevant provider processing and retained copies must be considered when handling the request.
- If you believe inaccurate profile information, a verification result or a delivery record has affected an assignment, earnings or an account decision, you may ask support to review the issue. This policy does not create a general right to obtain another person’s private information or confidential internal material.
11. Applicable law and changes to this policy
- Information handling is subject to applicable Indian law, including the Information Technology Act, 2000 and the rules governing sensitive personal data or information while those provisions remain applicable.
- The Digital Personal Data Protection Act, 2023 and its rules have phased commencement. Their obligations, statutory rights and complaint procedures apply when the relevant provisions take effect and apply to the processing concerned. This policy does not treat future provisions as already operational or postpone obligations that are already in force.
- The current version of this policy is available at https://raagas.co.in/legal/ryder/privacy. Material changes will be communicated through an appropriate channel. If a changed purpose requires a further notice or consent, merely continuing to use the app does not replace that requirement.
12. Privacy contact and grievances
- Address privacy requests and grievances to the Director, Carnatic Foods Private Limited, at support@carnaticfoods.com or the registered office shown below. Include enough information to identify the concern without unnecessarily including sensitive documents.
- Privacy grievances are to be addressed expeditiously and within one month of receipt under the currently applicable sensitive-personal-information rules, or within a shorter period where required for the particular matter. This is separate from any record-specific legal retention requirement.
Contact
For questions about this policy, contact:
Carnatic Foods Private Limited
CIN: U56100TN2025PTC180902
Registered Office: Plot No. 87, Sun Garden, Morattandi, Auroville, Vanur, Villupuram, Tamil Nadu 605101, India
Email: support@carnaticfoods.com
Designation: Director