Legal · v2026-05
Privacy Policy
Last updated: May 8, 2026
1. What we collect
- Account. Phone number (for OTP login), name, email, role.
- Pilot KYC. DGCA licence number and category, certifications, drone fleet (UIN, make, model), bank or UPI details, PAN — collected only from PILOT accounts.
- Mission data. Booking details, scheduled date, location (GPS coordinates and reverse-geocoded text), evidence photos, pre-flight checklist, final acres flown.
- Device telemetry. App version, crash reports (when enabled). We do not collect background location.
2. Why we collect it
Personal data is processed for the legitimate operation of the Sortie marketplace: authentication, dispatch, evidence gating, payments, dispute resolution, and DGCA compliance.
3. Where it lives
Account and mission data is stored in PostgreSQL on managed infrastructure inside India. Evidence photographs and KYC artifacts are stored in AWS S3 with server-side encryption. Backups are retained for 30 days.
4. Your rights (DPDP §11–§13)
- Right to access. Use
GET /users/me/exportfrom the app to download a JSON dump of every record we hold about you. Bank account numbers are masked to last4. - Right to correction. Profile and KYC fields are editable from the app at any time.
- Right to erasure.Use the "Delete account" option in Settings. We anonymise PII immediately and retain only ledger / audit rows necessary for legal obligations.
5. Sharing
We do not sell personal data. We share booking details with the assigned pilot, KYC artifacts with Sortie Admin reviewers, and payment metadata with Razorpay (or the payment processor of record) for settlement.
6. Retention
- Account: until deletion request, then anonymised.
- Mission and evidence: 7 years (regulatory).
- Audit log: 1 year hot, then archived.
7. Security
OTP-only authentication, JWT with short-lived access tokens and rotated refresh tokens, TLS in transit, AES-GCM for sensitive fields, and presigned URLs for direct-to-S3 uploads (no file bytes flow through our servers).
8. Contact
Data protection officer: dpo@sortie.in.