Traqo.ai
Legal

Privacy Policy

What personal data we collect, why we collect it, who we share it with, and the rights you have over it.

Last updated: 16 September 2026

1. Scope and who is responsible

This policy explains how Traqo.ai (“Traqo”, “we”, “us”), based in Bengaluru, India, handles personal data. It covers visitors to traqo.ai, people who contact us or request a demo, and users of the Traqo platform.
The distinction that matters most:
  • For website visitors and prospects, we are the controller — we decide why and how your data is used, and this policy governs.
  • For data inside a customer’s platform tenant — consignments, driver details, trip and location data — our customer is the controller and we act as processor on their instructions. Their privacy notice governs; ours does not. If you are a driver, transporter or consignee asking about that data, contact the company that engaged you. We will assist them in responding.

2. Personal data we collect

Information you give us. Name, work email address, phone number, organisation, country and role, plus anything you write in a message, when you submit a form, book a demo, contact sales, apply for a role, or subscribe to updates.
Partially-completed forms. Our multi-step enquiry forms save what you have entered as you move between steps — so an email address or phone number can reach us even if you never press submit. We do this so a sales contact is not lost mid-form, and we treat that data exactly as we treat a completed enquiry. If you would rather it were deleted, ask us and we will remove it.
Gated documentation. Parts of our documentation and pricing are unlocked with a work email and a one-time code. We store that email, the verification code and its expiry, a session token, and a record of which pages were accessed and how often.
Technical and usage data. IP address, device and browser type, referring URL, pages viewed, approximate location derived from IP, campaign parameters, and interactions such as clicks and form steps. This includes session recordings, which can capture text you type into forms — see section 4. Error reports may include the URL, browser details and a stack trace.
Platform account data. For licensed users: name, business contact details, role and permissions, authentication data and audit logs of actions taken.
We do not seek special-category data (health, biometrics, religion, and so on) and ask that you do not send it through our forms.

3. Why we use it, and our lawful basis

Under the GDPR and equivalent laws we rely on the following bases:
  • Contract — to provide the platform, support and billing to customers and their authorised users.
  • Legitimate interests — to respond to business enquiries, run and secure the Site, prevent fraud and abuse, understand which content is useful, and market our services to business contacts in a proportionate way. We balance these against your rights and you can object at any time.
  • Consent — for marketing email where consent is the required basis, and where we ask for it explicitly. You can withdraw consent at any time, without affecting processing already carried out.
  • Legal obligation — to meet tax, accounting, and regulatory record-keeping duties.
Under India’s Digital Personal Data Protection Act 2023 we process personal data for these lawful purposes with notice and, where required, your consent. This policy is that notice.

4. Cookies and analytics

We use cookies and similar technologies that are strictly necessary to operate the Site, plus the following:
  • Google Analytics 4 — aggregate traffic and content performance.
  • Google Ads — measuring which campaigns produce enquiries, and conversion attribution. See section 5.
  • PostHog — product analytics and session recording. See below.
  • Sentry — error monitoring, on infrastructure we host ourselves.
  • Calendly — embedded demo scheduling; Calendly sets its own cookies when you interact with it.
Session recording. PostHog can record a replay of a browsing session — pages viewed, mouse movement, clicks, scrolling, and text typed into form fields. Password fields are masked and never recorded. Other fields are not, so if you type your name, email address or phone number into one of our forms, that text can appear in a recording. We use recordings to diagnose faults and to see where the Site confuses people. If you would prefer not to be recorded, enable your browser’s “Do Not Track” setting or block posthog.com with a tracker blocker, and tell us so we can delete recordings we already hold.
We do not currently show a cookie consent banner, so the analytics and advertising technologies above load when you visit the Site. We are stating this plainly rather than implying a consent step that does not exist. Until we add consent controls, your available opt-outs are the ones below.
You can clear or block cookies in your browser, use Google’s Analytics opt-out add-on, use a tracker blocker, or send a Global Privacy Control signal, which we honour as an opt-out of sale or sharing where that applies. Blocking essential cookies may break parts of the Site. You can also ask us to delete anything we already hold about you — see section 10.

5. Advertising and conversion measurement

We advertise on Google. So that we can tell which ads lead to genuine enquiries rather than to clicks, we use Google’s Enhanced Conversions for Leads. In plain terms:
When you submit an enquiry form, your email address is normalised and hashed in your browser using SHA-256, and only that hash is sent to Google Ads alongside the conversion event. Google compares it against its own hashed records to match the enquiry to an earlier ad click. Your email address is never sent to Google in readable form, and it is not sent to Google Analytics in any form.
A hash is still personal data, because it relates to you. If you would prefer we did not share it, do not submit the form — email us directly at admin@traqo.in instead — or ask us to delete what we hold. You can also control ad personalisation in Google My Ad Center.
We do not sell personal data for money. Sharing data with advertising partners for measurement can count as “sharing” or “selling” under some US state laws; see section 10 for how to opt out.

6. Who we share data with

We do not sell your personal data. We share it with service providers who process it on our behalf, under contract, and only for the purposes we set:
  • Amazon Web Services — hosting and storage.
  • Google (Analytics, Ads) — analytics and advertising measurement.
  • PostHog — product analytics.
  • Resend — transactional email, including verification codes and enquiry notifications.
  • Calendly — demo scheduling.
  • Sentry — error monitoring, self-hosted by us.
  • Professional advisers, auditors and insurers, where necessary and under a duty of confidence.
We may also disclose data where required by law or valid legal process, to establish or defend legal claims, to protect the rights and safety of people or our services, or to an acquirer in connection with a merger, acquisition or asset sale — in which case we will give notice before your data becomes subject to a different policy.
Customers can request our current sub-processor list for the platform, and a data processing addendum, at admin@traqo.in.

7. International transfers

We operate from India and serve customers across India, the United States, the United Arab Emirates, Singapore, Kenya and elsewhere, so personal data may be transferred to and processed in countries other than your own — including India and the United States, whose data protection laws may differ from those where you live.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant) together with additional safeguards appropriate to the transfer. Transfers from India are made in accordance with the DPDP Act and any applicable government restrictions.
Platform data residency for customer tenants is available in India and Singapore. Where your agreement specifies a residency region, we keep Customer Data in that region.
A copy of the safeguards we use is available on request.

8. How long we keep it

We keep personal data only as long as needed for the purpose it was collected for, and then delete or anonymise it. In practice:
  • Enquiries and partial form entries — up to 24 months from the last interaction, unless a customer relationship begins.
  • Documentation access records — up to 12 months. One-time verification codes expire within minutes and are deleted on a short cycle.
  • Customer account and Customer Data — for the term of the agreement, then deleted or returned as that agreement provides.
  • Billing and tax records — for the period Indian tax and company law requires, currently up to 8 years.
  • Analytics and error data — in line with each provider’s retention settings, typically 14 months or less.
Where we must keep a record for a legal reason, we keep only what is necessary for that reason.

9. How we protect it

We maintain administrative, technical and physical safeguards appropriate to the risk — encryption in transit and at rest, role-based access control on a least-privilege basis, tenant isolation, audit logging, monitoring, and access reviews for staff who can reach production systems.
Our current security certifications, audit reports, penetration test summaries and security questionnaire responses are made available to customers and prospects under NDA during procurement. Please request them from admin@traqo.in rather than relying on marketing material.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulator where the law requires it, within the applicable deadlines.
If you believe you have found a vulnerability, please report it to admin@traqo.in rather than disclosing it publicly. We will not pursue good-faith security research that respects user privacy and does not degrade the service.

10. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to its use, receive it in a portable format, withdraw consent, and not be subject to a decision based solely on automated processing that significantly affects you.
India (DPDP Act 2023). You have rights of access, correction, completion, erasure, and grievance redressal, and the right to nominate someone to exercise them if you cannot. Start with our Grievance Officer in section 11.
EEA and UK (GDPR). You have the rights listed above and the right to complain to your supervisory authority — in the UK, the Information Commissioner’s Office. We would appreciate the chance to address it first.
California and other US states. You may request disclosure of the categories and specific pieces of personal information we collect, request deletion or correction, and opt out of “sale” or “sharing” for cross-context behavioural advertising — which, as section 5 explains, is how conversion measurement may be classified. We do not discriminate against you for exercising these rights. To opt out, email us or send a Global Privacy Control signal.
UAE (PDPL). You have rights of access, correction, erasure, restriction, portability and objection, subject to the exemptions in that law.
To exercise any of these, email admin@traqo.in from the address you contacted us with, or tell us enough to locate your records. We will verify your identity proportionately and respond within the period the applicable law allows — 30 days in most cases. There is no fee unless a request is manifestly unfounded or excessive.

11. Grievance Officer

As required by India’s Digital Personal Data Protection Act 2023 and the Information Technology (Intermediary Guidelines) Rules, our Grievance Officer is:
Grievance Officer, Traqo.ai
Bengaluru, India
We acknowledge grievances within 24 hours and aim to resolve them within 15 days, or sooner where the law requires. If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India.

12. Children and automated decisions

Our Site and platform are business tools, not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.
The platform produces automated alerts, risk flags and ETA predictions to help operators prioritise. These support human decisions and do not produce legal or similarly significant effects on individuals. We do not use personal data from the Site to make automated decisions about you.

13. Changes and how to reach us

We will update this policy when our practices or the law change, and the “last updated” date above will change with it. Where a change is significant, we will take reasonable steps to tell you — and where the law requires consent for it, we will ask.
Privacy questions, requests and complaints: admin@traqo.in, or through our contact page. Our Terms of Service govern use of the Site.