QafilaaBack to the ride
LegalPrivacyTermsCookies
SafetyCommunity guidelinesChild safetyReport contentSecurity
Your dataData safetyPermissionsSubprocessorsDelete dataDelete account
HelpSupportContactAccessibility
qafilaa.in/security
How we hold the things you trust us with

Security

Qafilaa holds a live map of where people are and, if they filled it in, their blood group. We take that seriously. No system is perfectly secure, so here is what we actually do rather than a claim that nothing can go wrong.

In plain English
  • Everything travels encrypted, and documents are stored encrypted at rest.
  • Accelerometer samples never leave your phone. Only the resulting alert does.
  • There is no public map, and no endpoint that returns a stranger's position.
  • Deleting your account removes the stored files too, not just the database rows.
  • Found a hole? Tell us at admin@qafilaa.in. We will not come after you for reporting it in good faith.

In transit and at rest

All traffic between the app and our servers runs over TLS. Position updates publish on a channel separate from application traffic, with a retained snapshot per rider so a late joiner receives the current state of the convoy on connect. Documents and images you upload — licence, RC, insurance, permits, trip photos — are stored encrypted, and the stored file is removed when you delete the record, not orphaned in a bucket.

What never leaves your phone

Crash detection reads the accelerometer continuously while you ride. Those samples are processed on the device and are never uploaded. What reaches us is the conclusion — an alert with your position, bearing and blood group — not the raw motion stream. Your phonebook is the same: if you grant contacts access, it is read locally so you can pick an emergency contact, and the address book is not uploaded.

Who can reach your position

Location is scoped to a ride, not to an account. Riders in your active ride can see you while that ride is active; nobody else can, and there is no public map and no endpoint that will return a stranger's position. When the ride ends, sharing stops. Access to production data inside Qafilaa is limited to the people who need it to run the service.

Working offline, safely

Every screen reads from the phone's own storage first, and writes are queued locally with a client-generated key so a retry after a dropped connection can never double-post. Cached data on your device is protected by the operating system's app sandbox and your device lock. If you lose the phone, delete your account and the sign-in sessions and position credentials go with it, so nothing can reconnect afterwards.

Retention, deletion and backups

Raw location traces delete automatically after 90 days, or 7 if you shorten the window. Server logs and routine backups age out within 30 days. Account deletion runs as a single transaction — it either all goes or none of it does — so an account is never left half-erased. The detail is in Delete your account and section 6 of the Privacy Policy.

Reporting a vulnerability

If you find something, email admin@qafilaa.in with enough detail to reproduce it. We will acknowledge within three working days and keep you posted while we fix it. Please do not test against other people's accounts or rides, do not exfiltrate data, and give us a reasonable window before disclosing publicly. We will not pursue legal action against anyone who reports in good faith and follows this.

If something goes wrong

In the event of a personal data breach we will notify the Data Protection Board of India and affected users as required under the Digital Personal Data Protection Act, 2023, and we will tell you what happened, what data was involved and what we are doing about it. Our Grievance Officer is admin@qafilaa.in.

Qafilaa.in · Kolhapur, Maharashtraadmin@qafilaa.in