PRIVACY POLICY OF CALLMEASSIST

How CALLMEASSIST LLP collects, uses, protects and shares your personal data

Last updated: 01/08/2026

Summary at a Glance

  • We collect only what the service needs: name, vehicle number, mobile number, emergency contact number, email, delivery address, and support ticket details. Nothing more.
  • Login is OTP-based. We never store passwords, and we never store your card/UPI/banking details — payments are handled by Razorpay.
  • When someone scans your QR code, they reach you through number masking — your phone number is never shown to them, and theirs is never shown to you.
  • We do not sell your personal data to anyone.
  • You can access, correct, or ask us to delete your data, and withdraw consent, at any time by writing to support@callmeassist.com.

1. Introduction, Acceptance and Summary

This Privacy Policy is published by CALLMEASSIST LLP, a limited liability partnership having its registered office at Office No. 203, 2nd Floor, Vikas Surya Plaza, CU Block Market, Pitam Pura, Delhi – 110034 ("CALLMEASSIST", the "Company", "we", "us" or "our"), in its capacity as a Data Fiduciary, in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), the Information Technology Act, 2000 ("IT Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and other applicable laws of India.

This Privacy Policy applies to our website www.callmeassist.com, our mobile application ("CALLMEASSIST App"), our vehicle QR code products, and all related services (collectively, the "Services"). It constitutes an electronic record under the IT Act and the rules made thereunder, is generated by a computer system, and does not require any physical, electronic or digital signature.

PLEASE READ THIS PRIVACY POLICY CAREFULLY. By accessing or using the Services, registering an account, activating a QR code, scanning a QR code, raising a support ticket, or otherwise submitting your details to us, you confirm that you are competent to contract under the Indian Contract Act, 1872, that you have read and understood this Privacy Policy, and that you consent to the collection, use, storage, disclosure and other processing of your personal data in the manner described here. If you do not agree, please do not use the Services.

2. Definitions

In this Privacy Policy, unless the context otherwise requires:

  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data;
  • "Data Principal" means the individual to whom the Personal Data relates;
  • "Data Fiduciary" means CALLMEASSIST LLP, which determines the purpose and means of processing of Personal Data;
  • "Data Processor" means any person who processes Personal Data on behalf of the Data Fiduciary;
  • "Processing" means any operation performed on Personal Data, including collection, recording, organisation, storage, use, sharing, disclosure, restriction and erasure;
  • "Consent Manager" means a person registered with the Data Protection Board of India who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent;
  • "Board" means the Data Protection Board of India;
  • "Specified Purpose" means the purpose mentioned in the notice given by the Data Fiduciary;
  • "Services" means the website www.callmeassist.com, the CALLMEASSIST App, our vehicle QR code products, and all related services;

Terms not defined here have the meanings given under the DPDP Act, the DPDP Rules, the IT Act or the General Clauses Act, 1897, as applicable. Headings are for convenience only and do not affect interpretation; words importing the singular include the plural and vice versa.

3. Who This Policy Applies To

  • Registered Users — vehicle owners who purchase and activate our QR codes and create an account;
  • Scanners / Road Users — members of the public who scan a QR code affixed to a vehicle in order to contact the vehicle owner;
  • Website Visitors — persons who browse our website or raise support tickets/enquiries through forms on our website; and
  • Emergency Contacts — persons whose contact details are provided to us by a Registered User.

If you provide us the Personal Data of any other individual (such as an emergency contact), you represent and warrant that you are lawfully authorised to do so, that you have informed that individual of this Privacy Policy, and that you act as their authorised agent for the purpose of providing consent on their behalf. We process such data in good faith on the basis of your representation, and you shall be solely responsible for any claim arising from the absence of such authority.

4. Personal Data We Collect — Itemised Notice

In line with the notice requirements under the DPDP Act and Rule 3 of the DPDP Rules, the table below sets out an itemised description of the Personal Data we process, the specific purpose, and the service enabled by such processing:

Personal Data Specific Purpose Service Enabled
Full nameAccount creation; identification of the QR code ownerQR code registration and account management
Vehicle registration numberLinking the QR code to your vehicleVehicle identification on scan
Mobile numberOTP-based login; masked call connection; service alertsSecure login; scanner-to-owner contact
Emergency contact numberReaching your designated contact where you have configured thisEmergency contact facility
Email addressOTP login; order and service communicationsLogin; receipts and updates
Delivery addressShipping of physical QR code productsProduct delivery (via Shiprocket)
Support ticket details (name, mobile, email, message)Responding to and resolving your issueCustomer support
QR scan data (timestamp; scan-time approximate location, as and when enabled)Connecting scanner and owner; safety; service records on your dashboardScan alerts and dashboard history
Masked call logsService records; safety; fraud and abuse preventionCall history on your dashboard
Device, usage and cookie data (IP address, device type, pages visited)Security, analytics and service improvementWebsite and App functionality

We do not collect blood group, RC/insurance documents, financial account credentials, biometric information or health information. Payments are collected and processed directly by Razorpay; we do not receive or store your card number, CVV, UPI PIN or banking credentials. We do not store passwords of any kind. We do not track your live location on a continuous basis; location, if collected, is limited to the approximate location at the time of a QR scan only, as and when that feature is enabled.

5. Purposes of Processing

We process Personal Data only for the specified purposes set out in Section 4 and for the following closely connected purposes: operating, maintaining and securing the Services; printing/encoding QR codes and fulfilling orders; processing payments, invoices and refunds through our payment gateway; sending service communications (OTPs, order updates, scan/contact alerts, renewal reminders); responding to support tickets; sending marketing communications with your consent and subject to opt-out (Section 8); analytics and service improvement; detecting, preventing and investigating fraud, misuse, impersonation, spam and security incidents; enforcing our terms and protecting our legal rights; complying with applicable law and lawful requests of governmental authorities; and establishing, exercising or defending legal claims. We will not use your Personal Data for any purpose incompatible with these specified purposes without fresh notice and, where required, fresh consent.

6. Legal Basis, Consent and Withdrawal

We process Personal Data on the basis of: (a) your free, specific, informed, unconditional and unambiguous consent, given by clear affirmative action when you register, activate a QR code, place an order, raise a ticket or otherwise use the Services; and (b) certain legitimate uses recognised under Section 7 of the DPDP Act, including processing of data you have voluntarily provided for a specified purpose, compliance with law or judgments, and responding to medical emergencies involving a threat to life or health — which is inherent to the emergency-contact function of the Services.

We maintain records of consent received, including the time and manner of consent, and we will support consent management mechanisms (including registered Consent Managers) as and when operationalised under the DPDP Rules.

You may withdraw your consent at any time, with effect for the future, by writing to the Grievance Officer (Section 27). The ease of withdrawal shall be comparable to the ease with which consent was given. On withdrawal, we will stop the related processing within a reasonable time, unless continued processing is required or authorised by law; however, withdrawal may make it impossible for us to provide some or all of the Services, including deactivation of your QR code, and shall not affect the lawfulness of processing carried out before withdrawal. Any consequence of such withdrawal shall be borne solely by you.

7. How the QR Service Works — Disclosure, Masking and Recording

The core purpose of the Services is to let a member of the public contact a vehicle owner without either party's phone number being revealed. When your QR code is scanned, the scanner is connected to you through a masked calling/messaging system: your name, mobile number and other details are not displayed to the scanner, and the scanner's number is not displayed to you, unless you have expressly chosen through your settings to make any detail visible. Your emergency contact number is used only in the situations configured by you.

For safety, quality, fraud prevention and dispute resolution, we may log, monitor and — where permitted by law and notified at the time — record communications routed through our masked-calling infrastructure. Communication logs form part of your service records and are visible on your dashboard. All call recordings, where made, are retained for a period of six (6) months from the date of the call only, after which they are permanently deleted from our systems, and such recordings shall be disclosed to no person except as required under applicable law or pursuant to an order of a court or other competent authority.

Important: the Services are a communication-facilitation tool. We do not and cannot guarantee that a vehicle owner, scanner or emergency contact will answer, respond or act on any communication. The Services are not a substitute for police, ambulance or other emergency services, and must not be relied upon as such. To the extent permitted by law, the Company shall not be responsible for the acts, omissions, statements or conduct of any user, scanner or third party, or for any consequence of a call or message not being placed, connected, answered or acted upon.

8. Marketing Communications and Opt-Out

With your consent, we may send you promotional communications about our products, offers and features by SMS, WhatsApp, email or in-app notification. Marketing consent is optional and is not a condition for using the Services. You may opt out at any time — through the unsubscribe/opt-out mechanism in the communication, or by writing to support@callmeassist.com — and we will endeavour to give effect to your opt-out within a reasonable period, and in any event within the period required by applicable law. Service and transactional communications (OTPs, order updates, scan alerts, renewal notices) are not marketing and will continue as long as you use the Services. We send commercial communications in accordance with applicable law, including the telecom commercial-communication regulations issued by TRAI.

9. Sharing and Disclosure

We do not sell or rent your Personal Data. We share Personal Data only as follows:

  • Data Processors: with vendors who process data on our behalf, under our instructions and under contractual confidentiality and data-protection obligations, namely: Razorpay (payment processing), Airtel (SMS/OTP delivery), Shiprocket (delivery and logistics of physical products), Hostinger (website and data hosting), Google Analytics (website analytics), and our masked-calling/telephony providers — in each case only to the extent necessary for their function. We remain responsible under the DPDP Act for processing carried out by our Data Processors on our behalf;
  • Between users, as designed: limited data is exchanged between a scanner and an owner strictly through the masked system described in Section 7, and with your emergency contact where configured by you;
  • Legal and regulatory: where disclosure is required by law or court order, or requested by a governmental, tax, or law-enforcement authority acting within its lawful powers, including under the DPDP Act, the IT Act, the CrPC/BNSS or the Motor Vehicles Act;
  • Protection of rights: where reasonably necessary to enforce our terms, collect amounts owed, or protect the rights, property or safety of the Company, our users or the public, including in cases of fraud, impersonation or abuse;
  • Business transfers: to a successor entity in connection with any merger, amalgamation, acquisition, restructuring, or sale of all or part of our business or assets, subject to the successor honouring commitments at least as protective as this Policy;
  • With your consent: in any other case, with your prior consent.

If, in future, we propose to share leads or user data with dealers, resellers or business partners for their own purposes, we will do so only after notifying you and obtaining your consent as required by law.

10. Storage, Cross-Border Transfers and Future International Operations

Your Personal Data is stored on servers located in India. The Services are presently offered in India and this Policy is drafted under Indian law.

If we expand the Services outside India, or transfer Personal Data outside India, we will: (a) comply with Section 16 of the DPDP Act and the DPDP Rules, including any restrictions or conditions notified by the Central Government; (b) ensure the recipient provides a standard of protection comparable to Indian law; and (c) where the data of individuals located in other jurisdictions (such as the EU/UK under the GDPR, or other applicable regimes) is processed, publish supplemental region-specific privacy terms addressing the requirements of those laws. Until such supplemental terms are published, the Services are intended for use in India only, and any person accessing the Services from outside India does so at their own initiative and consents to their data being processed in India under Indian law.

11. Cookies and Analytics

Our website and App use cookies, SDKs, pixels, local storage and similar technologies falling broadly into the following categories: (a) strictly necessary cookies, required for login sessions, security and core functionality, which cannot be disabled through our Services; (b) functional cookies, which remember your preferences and settings; and (c) analytics cookies, which help us understand usage patterns and improve the Services. We use Google Analytics, which collects usage information through its own cookies in accordance with Google's privacy policy. You can control or delete cookies in your browser settings; disabling cookies may impair parts of the Services. We do not currently respond to "Do Not Track" browser signals.

12. Security and Breach Notification

We implement reasonable security safeguards as required under Section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules, and reasonable security practices under Section 43A of the IT Act and the SPDI Rules. These include SSL/TLS encryption of data in transit, access controls on a need-to-know basis, number-masking of communications, OTP-based authentication (no stored passwords), logging and monitoring, and vendor contracts imposing security obligations. We strengthen these measures from time to time as the Services evolve.

In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act and the DPDP Rules.

No method of internet transmission or electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your registered mobile number, SIM and email account secure, since OTPs are delivered to them; for not sharing OTPs with anyone (we never ask for your OTP); and for promptly informing us of any suspected unauthorised use of your account. To the extent permitted by law, the Company shall not be liable for loss arising from your failure to protect your OTPs, devices or accounts, or from events beyond our reasonable control.

13. Data Retention and Erasure

We retain Personal Data only for as long as necessary for the specified purpose, and thereafter as required or permitted by law. Indicative periods:

  • Account and QR activation data: for as long as your account remains active, and up to 3 years thereafter;
  • Scan and masked call logs: for as long as your account remains active (accessible on your dashboard), and up to 12 months after account closure;
  • Payment and transaction records: for the life of the account and thereafter as required under tax and accounting laws (generally 8 years);
  • Support ticket and website enquiry data: up to 12 months after resolution;
  • Consent records and processing logs: for at least 1 year, in line with the DPDP Rules, and thereafter as required for legal compliance.

Notwithstanding the above, we retain Personal Data, traffic data and associated logs for the minimum periods required under the DPDP Rules and other applicable law (including for responding to lawful requests), and for so long as reasonably necessary for the establishment, exercise or defence of legal claims. Upon expiry of the applicable period, or upon a valid erasure request, Personal Data is deleted or irreversibly anonymised; anonymised data that can no longer identify you may be retained and used without restriction.

14. Your Rights as a Data Principal

  • Right to access: obtain a summary of your Personal Data being processed and the processing activities undertaken, and the identities of Data Fiduciaries/Processors with whom it has been shared;
  • Right to correction, completion and updating: have inaccurate or incomplete Personal Data corrected, completed or updated;
  • Right to erasure: have your Personal Data erased where it is no longer necessary for the specified purpose, subject to retention required by law;
  • Right to withdraw consent: at any time, as described in Section 6;
  • Right of grievance redressal: have grievances addressed by our Grievance Officer, and thereafter approach the Data Protection Board of India if unsatisfied;
  • Right to nominate: nominate another individual to exercise your rights in the event of your death or incapacity.

How to exercise: write to the Grievance Officer (Section 27) from your registered email or mobile number, describing your request. Account and data deletion is presently processed on request through our support team. We may require information reasonably necessary to verify your identity before acting. We may decline requests that are manifestly unfounded, excessive or made by a person we cannot verify, and we will inform you of the reasons where we do so.

We respond to verified requests within the timelines prescribed under the DPDP Act and the DPDP Rules; this timeline obligation is statutory and applies notwithstanding anything else in this Policy.

15. Duties of Data Principals

Under Section 15 of the DPDP Act, you must, while exercising rights under this Policy or using the Services: comply with applicable law; not impersonate another person; not suppress any material information while providing Personal Data (including vehicle ownership details); not register a false or frivolous grievance or complaint; and furnish only information that is verifiably authentic when exercising the right to correction or erasure. Breach of these duties may attract penalties under the DPDP Act, and the Company reserves its rights and remedies in respect of any loss caused to it by such breach.

16. Accuracy and Your Responsibilities

You are responsible for the accuracy, completeness and lawfulness of all information you provide, including your name, vehicle registration number, mobile number, email and emergency contact details, and for keeping them updated through your account or by writing to support. The Company processes such information as furnished by you and, to the extent permitted by law, is not responsible for consequences arising from information that is false, outdated, incomplete or provided without authority — including OTPs, alerts or calls being delivered to a number or email that no longer belongs to you. You confirm that the vehicle for which a QR code is activated is owned by you or is one you are lawfully authorised to manage.

17. Misuse, Suspension and Safety

The Services must be used only for their intended purpose. We may, after such review as we consider appropriate, suspend or deactivate a QR code or account, restrict features, or refuse service, where we reasonably believe there is: impersonation or false vehicle/ownership information; abusive, threatening, obscene or unlawful communication through the masked system; spam, telemarketing or commercial solicitation directed at users; fraud, chargeback abuse or payment misuse; scraping, reverse engineering or attempts to unmask numbers or breach security; or any use in violation of law or our terms. Fees are not refundable on account of suspension for misuse, except as required by law. We may preserve and share records connected with misuse in accordance with Section 9 (Legal and regulatory).

18. Indemnity

You agree to indemnify, defend and hold harmless the Company, its partners, designated partners, officers, employees, agents and Data Processors from and against any and all claims, demands, actions, proceedings, losses, damages, liabilities, penalties, costs and expenses (including reasonable legal fees) arising out of or in connection with: (a) your breach of this Privacy Policy, our Terms of Use or applicable law; (b) any information provided by you that is false, inaccurate, outdated, incomplete, misleading or provided without lawful authority, including the details of any emergency contact or any vehicle; (c) your misuse of the Services or of any information received through the Services, including any unlawful, abusive or harassing communication made through the masked-calling system; (d) any violation by you of the rights of any third party, including privacy, intellectual property or statutory rights; and (e) any grievance, complaint or claim raised against the Company by any person whose data you provided to us. This indemnity survives the termination or deletion of your account.

19. Limitation of Liability

To the maximum extent permitted by applicable law: (a) the Services and all information provided through them are made available on an "as is" and "as available" basis, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, uninterrupted availability or error-free operation; (b) the Company shall not be liable for any indirect, incidental, special, consequential, punitive or exemplary damages, or for loss of profits, revenue, goodwill, data or opportunity, arising out of or in connection with this Privacy Policy or the Services, even if advised of the possibility of such damages; (c) without prejudice to the foregoing, the aggregate liability of the Company for all claims arising out of or relating to this Privacy Policy or the processing of your Personal Data shall not exceed the total fees actually paid by you to the Company for the Services during the twelve (12) months immediately preceding the event giving rise to the claim; and (d) the Company shall not be liable for any delay, failure, unavailability or degradation of the Services, or for any loss of or unauthorised access to data, attributable to telecom operators, payment gateways, hosting providers, logistics partners, internet or power failure, or any other third party or cause beyond the Company's reasonable control. Nothing in this Section excludes or limits any liability that cannot be excluded or limited under applicable law, including liability under the DPDP Act to the extent it cannot be contractually limited.

20. Children's Privacy

The Services are intended only for persons aged 18 years and above who are competent to contract. We do not knowingly process the personal data of children (persons under 18). We do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If we learn that a child's personal data has been collected without the verifiable consent of a parent or lawful guardian as required under Section 9 of the DPDP Act, we will delete it promptly, as required under the DPDP Act. Concerns may be reported to the Grievance Officer.

21. Third-Party Links and Services

The Services may contain links to, or operate in conjunction with, third-party websites, applications and services — including our payment gateway, logistics partner and analytics provider. Such third parties operate under their own privacy policies, which we encourage you to review. To the extent permitted by law, we are not responsible for the privacy practices, content, availability, or acts or omissions of third parties, including any downtime, error or deficiency in payment, telecom, hosting or delivery services provided by them.

22. Intellectual Property and Feedback

All intellectual property in and relating to the Services — including the CALLMEASSIST name and marks, the QR code designs and encoding, the website, App, software, dashboards, databases, compilations of data, and all content other than your Personal Data — is and remains the exclusive property of the Company or its licensors. No right or licence in any intellectual property is granted to you except the limited right to use the Services for their intended personal purpose. If you provide suggestions, ideas or feedback regarding the Services, you grant the Company a perpetual, irrevocable, worldwide, royalty-free licence to use them without restriction or attribution, and such feedback shall not be treated as your confidential information.

23. Force Majeure

The Company shall not be considered in breach of this Privacy Policy, and shall not be liable for any failure or delay in performance, to the extent caused by events beyond its reasonable control, including acts of God, natural disasters, epidemics, war, terrorism, civil disturbance, strikes, governmental action or orders, changes in law, failure or degradation of telecommunications, internet, electricity or hosting infrastructure, cyber-attacks, or failures of third-party service providers. The Company shall endeavour to resume performance and to protect Personal Data during any such event, without any liability for the period of disruption.

24. Notices and Electronic Communications

You consent to receive all communications from us — including notices under this Privacy Policy, service and transactional messages, and legal notices — electronically, by SMS, WhatsApp, email, in-app notification or posting on the website, at the contact details registered with your account. A communication sent to your registered mobile number or email address shall be deemed to have been duly delivered to you, whether or not actually read, and it is your responsibility to keep those details current. Notices to the Company must be sent in writing to the registered office address or to support@callmeassist.com, and shall be deemed received on actual receipt.

25. Assignment

You may not assign or transfer your rights or obligations under this Privacy Policy or your account to any person without our prior written consent, and any purported assignment in violation of this Section is void. The Company may assign or transfer its rights and obligations under this Privacy Policy, in whole or in part, to any affiliate or successor entity, including in connection with the events described in Section 9 (Business transfers), without your further consent, subject to applicable law.

26. Reservation of Rights; Severability; Entire Understanding

Nothing in this Privacy Policy transfers to any person any intellectual property or proprietary rights of the Company. Our failure or delay in enforcing any provision of this Policy shall not operate as a waiver. If any provision of this Policy is held invalid or unenforceable, the remaining provisions shall continue in full force, and the invalid provision shall be deemed modified to the minimum extent necessary to make it valid and enforceable. In the event of any inconsistency between this Policy and our Terms of Use, the document that is more specific to the subject matter shall prevail to the extent of the inconsistency. This Privacy Policy, together with the Terms of Use and any supplemental notices published by us, constitutes the entire understanding between you and the Company regarding the processing of your Personal Data, and supersedes all prior communications on that subject.

27. Grievance Officer and Grievance Redressal

In accordance with the DPDP Act, the DPDP Rules, and the IT Act and rules thereunder, the contact details of our Grievance Officer (who is also our designated point of contact for data-related questions) are:

Name: Mr. Gaurav

Designation: Grievance Officer

Email: support@callmeassist.com

Phone: +91 87965 57713

Address: CALLMEASSIST LLP, Office No. 203, 2nd Floor, Vikas Surya Plaza, CU Block Market, Pitam Pura, Delhi – 110034

Grievances will be acknowledged and redressed within the timelines prescribed under applicable law, which is a statutory obligation. If you are not satisfied with the resolution, you may escalate your grievance to the Data Protection Board of India in the manner provided under the DPDP Act, after first exhausting this grievance redressal mechanism.

28. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in law (including the phased commencement of the DPDP Rules), technology, or our business practices. The updated Policy will be posted on our website and App with a revised "Last Updated" date, and material changes will be notified through reasonable means such as email, SMS or in-app notice. Your continued use of the Services after the effective date of an updated Policy constitutes your acceptance of it; if you do not agree, you must stop using the Services and may exercise your rights under Section 14.

29. Governing Law and Jurisdiction

This Privacy Policy shall be governed by and construed in accordance with the laws of India, without reference to conflict-of-laws principles. Subject to applicable law and the jurisdiction of the Data Protection Board of India and appellate authorities under the DPDP Act, the competent courts at Delhi alone shall have exclusive jurisdiction over all disputes, claims and proceedings arising out of or in connection with this Privacy Policy, the Services, or the processing of Personal Data, to the exclusion of all other courts, and you expressly waive any objection to such forum on grounds of convenience or otherwise. All communications, notices and legal proceedings shall be deemed to originate from and be addressed to the Company at its registered office at Delhi.

30. Survival

The provisions of this Privacy Policy which by their nature are intended to survive — including Sections 13 (Retention), 15 (Duties of Data Principals), 16 (Accuracy), 18 (Indemnity), 19 (Limitation of Liability), 22 (Intellectual Property), 26 (Reservation; Severability), 29 (Governing Law) and this Section — shall survive the closure or deletion of your account, the deactivation of your QR code, and the termination of your use of the Services.

31. Contact Us

For any questions, concerns or requests regarding this Privacy Policy or our data practices, contact us at support@callmeassist.com, write to our registered office, or reach the Grievance Officer identified in Section 27.