Privacy Policy – AUTOSherpa Auction

Table of Contents


Privacy Policy

Application: AUTOSherpa Auction
Operated by: Yocoya Technologies & Services LLP
Last Updated: 08-09-2026
Effective Date: 08-09-2026

1. Introduction

AUTOSherpa Auction (“App,” “Service,” “Platform,” “We,” “Us,” “Our”) is a product of Yocoya Technologies & Services LLP (“Yocoya”). This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use the App (iOS and Android) and related web administration platforms.

By using the App, you consent to the collection and processing of your personal information as described here. If you do not agree, please do not use the App.

1.1 KYC Verification and What We Still Do Not Collect

We want to be upfront about this. As of the date of this Policy:

  • We collect and verify KYC (identity and business verification) documents from Buyers — specifically an Aadhaar card, GST registration certificate, PAN card, and a signed Dealer Trade Agreement — before a Buyer can bid on an Auction. See Section 4.1.1 for how these documents are collected, used, protected, and retained. Sellers are not currently required to provide KYC documents.
  • We do not collect or process any payment or Security Deposit information within the App. All deposit and vehicle-payment amounts are agreed and settled directly between Buyers and Sellers, outside the App (see our Terms and Conditions, Section 6).

We may introduce in-app payment collection, and may extend KYC verification to Sellers, in the future — if we do, we will update this Policy in advance and, where required by law, obtain your fresh consent before collecting that additional data.

2. Definitions

“Personal Information” means any information that identifies, relates to, or could reasonably link to you.

“User” means any person who registers for and uses the App, including Buyers and Sellers.

“Buyer” means a registered User who participates in Auctions to purchase vehicles.

“Seller” means a registered User (individual or dealership business) who lists vehicles for Auction.

“KYC” means Know Your Customer identity and business verification. For Buyers, this currently means an Aadhaar card, GST registration certificate, PAN card, and signed Dealer Trade Agreement — see Section 1.1 and Section 4.1.1.

“Dealership Operator” / “Tenant” means a dealership that licenses a white-labelled instance of the Platform and operates its own Super Admin/Admin over its own Buyers and Sellers.

“Data Controller” means the entity responsible for determining the purposes and means of processing personal data — for this App, that is Yocoya (or, for a white-labelled instance, jointly Yocoya and the relevant Dealership Operator, as described in Section 7.1).

“Data Processor” means a third-party service provider that processes personal data on our behalf.

3. Applicability and Scope

This Policy applies to personal information collected through the AUTOSherpa Auction mobile application, our web administration platforms, and information automatically collected by our systems.

Geographic Scope: Currently available in India. If we expand internationally, the applicable privacy laws of your jurisdiction will apply in addition to this Policy.

Applicable Law: This Policy is designed to comply with India’s Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable Indian privacy regulations.

Multi-Tenant / White-Label Notice: AUTOSherpa Auction may be licensed to individual dealerships as a white-labelled platform. If you register under a specific dealership’s instance of the App, that dealership’s Super Admin will be able to see the personal information and activity of Users registered under their instance, for the purpose of operating and moderating that instance (see Section 7.1).

4. Information We Collect

4.1 Information You Provide

Registration & Account Information:

  • Full name / contact person name (or business name, for Sellers/dealers)
  • Email address
  • Mobile phone number
  • Password (securely hashed — never stored in plaintext)
  • State, city, PIN code, and address
  • Username

We do not currently collect date of birth. Age eligibility (18+) is a self-declaration made when you agree to our Terms, for both Buyers and Sellers.

KYC Documents (Buyers only):

  • Aadhaar card (or other accepted government-issued identity proof)
  • GST registration certificate
  • PAN card
  • Signed Dealer Trade Agreement

See Section 4.1.1 immediately below for how this category of information is specifically protected, and Section 1.1 for who this applies to.

4.1.1 KYC Documents — Additional Safeguards

Because KYC documents include a government identity number (Aadhaar) and business tax identifiers (GST, PAN), we apply additional safeguards beyond our general security measures (Section 9):

  • Purpose limitation: KYC documents are used only to verify your identity and business legitimacy as a condition of granting bidding access, and for fraud/regulatory investigations described in these Terms. They are not used for marketing, profiling, or any other purpose.
  • Restricted access: KYC documents are visible only to the Admin/Super Admin responsible for reviewing your registration (and, for a white-labelled instance, your Dealership Operator’s Admin — see Section 7.1). They are never shown to other Buyers or Sellers, including the Seller(s) you transact with.
  • Aadhaar handling: where reasonably possible, we display and store only a masked version of your Aadhaar number (showing the last 4 digits) once verification is complete, consistent with UIDAI guidance for private entities. [Confirm with your engineering team whether the current upload flow already masks the stored Aadhaar number, or stores the full document image — see the Legal Review Notice.]
  • Retention: see Section 8 for how long KYC documents are retained.
  • No automated Aadhaar authentication: we do not use UIDAI’s Aadhaar-based OTP/biometric authentication system; KYC review is a manual document check performed by an Admin.

Vehicle Information (provided by Sellers, and viewable by approved Buyers):

  • Vehicle photographs and videos
  • Vehicle specifications (make, model, year, variant, fuel type, mileage, etc.)
  • Registration number and RC status
  • Inspection/condition ratings (engine, transmission, chassis, and other systems)
  • Loan/hypothecation status and legal/police-case status (as disclosed by the Seller)
  • Accident/damage history (as disclosed by the Seller)

Financial Information: We do not currently collect Security Deposit amounts, payment details, bank account information, or any other financial/payment data — see Section 1.1. Any deposit amount shown in the App is informational only.

Communication Data:

  • Chat messages between Buyers and Sellers, including any documents/attachments shared (e.g., a PDF of a vehicle’s RC)
  • Support messages sent to Admin/Super Admin
  • Ratings and reviews you provide about a counterparty or transaction

4.2 Information Automatically Collected

Device Information: device model/manufacturer, operating system and version, app version, device language.

Network & Usage Information: IP address, mobile network/ISP information, screens accessed, features used, bidding history and bid amounts, auction browsing history, session duration.

We will confirm before publication whether the App uses any additional analytics or crash-reporting tools beyond the Firebase push-notification service described in Section 4.5 below; if so, this section will be updated to list them precisely (this must match the “App Privacy” declaration made in App Store Connect).

4.3 Location Information

  • Precise location (GPS): collected only during Buyer/Seller registration, and only if you grant location permission.
  • If you do not grant permission: you can enter your location manually instead — location is never a blocker to registration or auction participation.
  • How to control: you can disable location permission at any time via iOS Settings → Privacy → Location Services → AUTOSherpa Auction (or the Android equivalent).

We do not use Google Maps or any third-party mapping/geocoding service.

4.4 Device Permissions

Camera / Photo Library: used by both Buyers and Sellers to upload vehicle photos, inspection images, and documents shared in chat (e.g., an RC as a PDF or image). Access occurs only when you actively choose to take or select a photo/file.

Location: see Section 4.3 — registration only, and only with your permission.

Contacts: we do not access your device contacts.

4.5 Third-Party Services That Process Data On Our Behalf

Provider What It Processes Purpose
MongoDB Atlas All account, vehicle, auction, and chat data Database hosting
Firebase (Google) Device push-notification tokens Delivering push notifications (auction alerts, messages)
Zoho Mail Your email address, message content Sending transactional emails (e.g., login credentials, notices)
Socket.IO (self-hosted, our own servers) Chat messages, live bid updates Real-time chat and live auction updates

A payment-gateway integration (PhonePe) exists in our backend but is not currently active and is hidden from Users. If we activate in-app payment collection in the future, this table and the relevant consent flow will be updated first (see Section 1.1).

We process your personal information based on:

  • Contractual necessity: creating and managing your account, enabling auction participation, facilitating Buyer–Seller communication.
  • Legitimate interests: platform security and fraud prevention (e.g., detecting shill bidding, fake listings, or fraudulent KYC submissions), service improvement, and protecting our legal rights.
  • Legal obligations: responding to lawful court orders or regulatory requests, DPDPA compliance, and verifying Buyer identity/business legitimacy via KYC documentation before granting bidding access.
  • Consent: collection of your KYC documents (Section 4.1.1), optional push notifications, and any future optional analytics or marketing.

Because we do not currently process in-app payment data, RBI payment-aggregator-related legal-obligation bases do not currently apply; we will add them if we introduce in-app payments (Section 1.1).

6. How We Use Your Information

  • Service delivery: creating/maintaining your account, enabling auction discovery and bidding, facilitating Buyer–Seller chat, providing customer support, sending auction/transaction notifications.
  • Buyer identity & business verification: reviewing the KYC documents described in Section 4.1.1 to confirm a Buyer’s identity and business legitimacy before granting bidding access.
  • Security & fraud prevention: detecting and preventing fraud, fake listings, shill bidding, fraudulent KYC submissions, or other Platform abuse; investigating reported content; suspending/terminating violating accounts.
  • Legal & compliance: responding to lawful requests and maintaining records required by applicable law.
  • Service improvement: understanding usage patterns to improve app performance and features (using the usage data described in Section 4.2).
  • Communications: sending transactional notices (account, security, auction-related, KYC status updates) and, only with your opt-in, optional marketing or push notifications.

We do not use your KYC documents for marketing, profiling, or any purpose other than identity/business verification and the fraud-prevention and legal-compliance purposes described above.

We do not use your information for KYC/AML verification or payment processing, because we do not currently perform those activities.

7. Data Sharing & Disclosure

7.1 With Your Dealership Operator (Multi-Tenant / White-Label)

If you are registered under a dealership’s white-labelled instance of the Platform, that dealership’s Super Admin/Admin can see your account information, listings, bids, reported chat content, and your Buyer KYC documents (where applicable), to the extent needed to operate, moderate, and verify registrations on their instance (e.g., reviewing your KYC submission, reviewing a reported message, marking a vehicle sold). Each Dealership Operator is responsible for how it uses and safeguards this access under its own agreement with Yocoya and applicable law.

7.2 Between Platform Users

Visible to other Users:

  • Seller business name, location (state/city), and vehicle listings/ratings.
  • Buyer identity is anonymized during bidding and revealed to the Seller only if/when that Buyer wins the auction.
  • Chat messages are visible only to the two participants in that conversation and, if reported, to the relevant Admin.

Never shared with other Users (including your transaction counterparty): your password, your KYC documents (Aadhaar, GST certificate, PAN card, Dealer Trade Agreement — see Section 4.1.1), and your full address (except with the specific counterparty of a transaction you’re party to, where relevant to arranging delivery).

7.3 Service Providers (Data Processors)

We share personal information with the third-party providers listed in Section 4.5, strictly to enable them to provide the services described there. We do not permit them to use your data for their own independent purposes.

7.4 Legal & Regulatory Disclosures

We may disclose personal information where required by court order, law enforcement request, or applicable regulation (including DPDPA-related requests from the Data Protection Board of India, once constituted).

7.5 Business Transfers

In the event of a merger, acquisition, or asset sale involving Yocoya, or in the ordinary course of licensing the Platform to a new Dealership Operator, personal information may be transferred as part of that transaction/arrangement; we will notify you of any material change in who controls your data.

7.6 What We Do Not Do

We do not sell your personal information to data brokers or advertisers, and we do not share it with unrelated third parties without a legal basis or your consent.

8. Data Retention

Data Category Retention Period Reason
Active account data (name, email, phone, address) Duration of your account, plus any applicable legal hold Service delivery
Buyer KYC documents (Aadhaar, GST certificate, PAN card, Dealer Trade Agreement) [Placeholder — up to 5 years after account closure] Regulatory/audit trail, fraud investigation — confirm exact period with counsel; see Legal Review Notice
Vehicle listing data Duration of listing/auction, plus a reasonable period for dispute handling Platform record-keeping
Chat messages Up to 2 years, or until you delete your account (subject to reported-content investigation needs) Dispute resolution, safety investigation
Usage/device data Up to 1 year Service improvement, debugging
Deleted accounts Grace period of 30 days for recovery, then permanent deletion (except any active legal hold, and except KYC documents, which follow the separate retention period above) Recovery window, legal requirements

We do not currently retain payment/financial records, because we do not collect them (Section 1.1).

8.1 Deleting Your Account (Self-Service)

You can permanently delete your Buyer or Seller account directly within the App (Account → Delete Account) — no need to email us. Upon deletion:

  1. Your profile information, password, and device tokens are deleted immediately.
  2. Some records (e.g., past auction/bid history with your identifying details removed, or chat records under active dispute review) may be retained for a limited period as described above.
  3. Your KYC documents are retained separately, per the table above, for regulatory/audit purposes even after account deletion, and are not restored to visibility for any other User.
  4. Backups are purged on our normal backup-rotation cycle (up to 30 days).

9. Data Security

  • Encryption: data in transit is encrypted via HTTPS/TLS; data at rest in our database is encrypted.
  • Authentication & Access Control: passwords are hashed (never stored in plaintext); we use token-based API authentication and role-based access control for Admin functions.
  • Infrastructure: cloud-hosted with regular security patching and automated encrypted backups.
  • KYC document safeguards: Buyer KYC documents are stored encrypted at rest, access is restricted to the Admin/Super Admin roles responsible for verification (Section 4.1.1), and access is logged. We recommend (and this draft assumes, pending engineering confirmation) that Aadhaar numbers are masked in the admin-facing UI wherever the full number is not strictly necessary.
  • Security limitations: no system is completely secure. We cannot guarantee absolute protection against all cyberattacks, and your own account security (Section 3.4 of our Terms) is an important part of keeping your data safe.
  • Breach notification: if a confirmed security incident affects your personal information, we will notify affected Users via email and/or in-app notification, and regulators where required by law.

10. Your Privacy Rights

Under the DPDPA and applicable law, you have the right to:

  • Access: request a copy of the personal information we hold about you.
  • Correction: update inaccurate information (most fields can be edited directly in App Settings → Profile).
  • Deletion/Erasure: delete your account and associated data (self-service in-app, or via email request) — see Section 8.1.
  • Data portability: request your data in a structured, machine-readable format (JSON/CSV).
  • Withdraw consent: for any optional processing (e.g., push notifications), at any time via App Settings.
  • Complain: you may raise a grievance with us first (Section 12), and if unresolved, with the Data Protection Board of India once constituted under the DPDPA.

How to exercise these rights: through the relevant in-App setting, or by emailing us at support.auctions@autosherpa.net. We will respond within 30 calendar days.

11. Children’s Privacy

The App is intended for Users 18 years and older only. We do not knowingly collect data from anyone under 18; account registration requires you to confirm you are 18+ when accepting our Terms. If we become aware that we have collected data from a minor, we will delete it promptly — contact us at support.auctions@autosherpa.net if you believe this has occurred.

12. International Data Transfers

Some of our service providers (Section 4.5) may process data outside India — for example, Firebase (Google Cloud, US/international) and MongoDB Atlas (AWS data centers, which may be located in India or internationally). Where data is transferred outside India, we rely on our providers’ standard data-protection safeguards (encryption, access controls, and their own contractual commitments). By using the App, you consent to such transfers as necessary to provide the Service.

The App may, from time to time, contain links to third-party websites (for example, if you choose to open a shared document link). We do not control and are not responsible for the privacy practices of third-party sites; please review their policies separately.

14. Sensitive Information We Handle

We handle the following categories of sensitive information:

  • Government identity information (Buyers only): Aadhaar card details, as part of KYC verification (Section 4.1.1). We do not currently handle any other biometric data, and we do not perform Aadhaar-based biometric or OTP authentication (Section 4.1.1).
  • Business tax identifiers (Buyers only): GST registration certificate and PAN card, as part of KYC verification.
  • Location data: only at registration, only with permission (Section 4.3).
  • Vehicle ownership/condition: information you or the counterparty share about a specific vehicle.

We do not currently handle financial/banking or payment card information, because we do not collect payment data (Section 1.1).

A note on Aadhaar specifically: private companies collecting Aadhaar as identity proof are subject to specific restrictions under the Aadhaar Act, 2016, including limits on how the Aadhaar number itself may be stored, displayed, and shared. See the Legal Review Notice at the end of this Policy — this section should not be treated as finalized until counsel confirms our Aadhaar handling practices meet these requirements.

15. Platform Moderation & Reporting

15.1 Vehicle Listing Review

Vehicle listings are reviewed by an Admin before becoming visible to Buyers, and may be edited or removed for policy violations.

15.2 Reporting Objectionable Content

You can report abusive, fraudulent, or objectionable chat messages or user behavior using the in-app “Report” function; reports are routed to the relevant Super Admin/Dealership Operator Admin for review and action.

15.3 Blocking Other Users

You can block another Buyer or Seller directly from within the chat window, which stops that User from sending you further messages. You can unblock a User at any time from the same interface. We recommend also using the Report function (Section 15.2) where the behavior is abusive or fraudulent, so an Admin can take account-level action where appropriate.

15.4 Chat Is Not Pre-Screened

Chat messages between Users are not automatically pre-screened before delivery; they are reviewed only if reported.

16. Marketing & Communications

  • Cannot be disabled (transactional): auction notifications, account security alerts, password resets, Terms/Policy update notices.
  • Can be disabled (optional): any promotional communications, if and when we introduce them, via App Settings → Notifications, or by emailing support.auctions@autosherpa.net.
  • Push notifications: configurable per category (auction alerts, messages) in App Settings → Notifications.

17. Policy Changes

We may update this Policy from time to time. Material changes will be posted in the App and, where they affect your rights, communicated via email or in-app notification in advance. Continued use of the App after such notice constitutes acceptance of the updated Policy. This Policy will also be updated before we introduce KYC verification or in-app payment collection (Section 1.1).

18. Contact Information & Grievance Redressal

Yocoya Technologies & Services LLP
3rd Floor, No. 19/3, Srinivasa Industrial Estate, Kanakapura Main Road,
Konankunte, Bengaluru, Bengaluru Urban, Karnataka, 560062, India

  • In-App Support: contact your platform’s Super Admin/Admin directly through the App.
  • Privacy inquiries / data requests: support.auctions@autosherpa.net
  • General support: support.auctions@autosherpa.net

We do not currently operate a support phone line.

Grievance process: email us your complaint with relevant details → we acknowledge within 7 days → we investigate and respond within 30 days → if unresolved, you may escalate to the Data Protection Board of India (once constituted) or pursue applicable legal remedies.

19. Acknowledgment

By using the App, you acknowledge that you have read and understood this Privacy Policy, including that we do not currently collect KYC or payment data (Section 1.1), and you consent to the collection and processing of your information as described.

Version 1.0 (Draft) — [DATE]


This is a working draft aligned to the App’s current model — Buyer KYC verification, no in-app payment collection — and to the data types actually confirmed as in use (Section 4.5). Before publication, please confirm:

  1. Actual working contact emails (privacy, support) — Section 10, 18.
  2. Any additional analytics/crash-reporting tools beyond Firebase push notifications, so this Policy and Apple’s App Privacy (“nutrition label”) questionnaire in App Store Connect match exactly (Section 4.2). Note that adding KYC document collection also changes your App Privacy questionnaire answers in App Store Connect — you will need to declare “Government ID” and “Other Financial Info”-type data categories there as well.
  3. Aadhaar handling — priority item: confirm with counsel whether accepting/storing Aadhaar as a private company complies with the Aadhaar Act, 2016 and the Puttaswamy judgment’s restrictions on mandating Aadhaar; confirm whether the current upload flow masks the stored Aadhaar number (showing only last 4 digits) as recommended in Section 4.1.1, or stores the full document/number; and confirm the KYC document retention period proposed in Section 8 (currently a placeholder).
  4. Confirm whether Seller KYC should also be added — this draft currently applies KYC only to Buyers, per your instructions.
  5. This draft should be reviewed by qualified counsel for full compliance with the DPDPA, 2023, and any other applicable Indian data-protection requirements before publishing.

Do not publish without legal review in your specific jurisdiction.