Privacy Policy
Last Updated: July 23, 2026
1. Introduction
ARSA ("we", "us", "our") is a product of Sarcare Marketing Private Limited (incorporated on 20th July 2021, PAN: ABGCS4755E). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, our website at www.arsacar.in, and our ARSA Car Advisor connector for third-party AI assistants (such as Claude and ChatGPT). This policy is published in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules") notified on 14 November 2025.
2. Information We Collect
We collect information you provide directly when you create an account, use our services, or contact us:
- Identity Data: Name, email address, phone number.
- Account Data: Login credentials (stored as bcrypt hashes), profile picture.
- Payment Data: Transaction IDs and subscription status. Card numbers, UPI IDs, and net banking credentials are handled entirely by Razorpay and are never received or stored on our servers.
- Usage Data: Car searches, comparisons, favourites, consultation history, and in-app interactions.
- Device Data: Device type, OS version, IP address, and browser type (recorded in server request logs for security and debugging).
- Preference Data: Car preferences you set in the app (budget, fuel type, body type, must-have features, safety priority).
- User Documents: Files you choose to upload (e.g. driving licence, insurance) via the document upload feature. These are stored on Cloudinary under your account.
- AI Chat Messages: The text of messages you send to the AI car advisor, so we can generate replies and show your chat history.
3. Data We Do NOT Collect
We do not collect, request, or process the following:
- Payment card numbers, CVVs, UPI PINs, or net-banking passwords (handled by Razorpay).
- Protected health information (PHI) or medical records.
- Government-issued identifiers such as Aadhaar numbers, PAN, passport numbers, or social security numbers.
- Precise real-time GPS location or continuous location tracking.
- Biometric data (fingerprint, face scan, voiceprint).
- Contacts, SMS messages, or call logs from your device.
- Authentication secrets such as API keys, one-time passwords, or multi-factor codes belonging to other services.
4. How We Use Your Information
We process your personal data for the following specific purposes:
- Provide and maintain our car advisory services and the ARSA connector for third-party AI assistants.
- Process subscription payments and expert consultation bookings via Razorpay.
- Personalize car recommendations based on your saved preferences.
- Send OTP verification, booking confirmations, password-reset emails, and service updates via Resend.
- Generate AI replies in the car advisor chat by forwarding your message to our AI providers (see Section 6).
- Respond to support requests, investigate abuse, and resolve platform issues.
Your consent is the legal basis for processing your personal data. Consent is obtained at the point of data collection and is free, specific, informed, and unconditional.
5. AI Model Training
We do not use your personal data, chat messages, preferences, or any other user content to train machine-learning or AI models. Messages you send to the AI car advisor are forwarded to third-party inference providers solely to generate a real-time reply; we do not retain them for model improvement and we do not contribute them to any training dataset.
6. Data Sharing & Third-Party Processors
We do not sell your personal data. We share limited information only with the following processors, each acting on our behalf as a Data Processor under the DPDP Act:
- Razorpay — payment processing. See Razorpay's Privacy Policy.
- Google — Google Sign-In authentication. See Google's Privacy Policy.
- Cloudinary — hosting of profile pictures and user-uploaded documents. See Cloudinary's Privacy Policy.
- Resend — transactional email delivery (OTPs, booking confirmations). See Resend's Privacy Policy.
- AI inference providers — to generate AI replies in the car advisor chat, message contents are sent to one of: Cerebras (privacy), Modal (privacy), or SiliconFlow (privacy) depending on availability. Only the message text and a short system prompt are sent; no identity data is attached.
- Expert Advisors — for bookings, only your display name and booking details are shared so the expert can prepare for the consultation.
- Legal Authorities — when required by law or to protect our rights, users, or the public.
7. Third-Party AI Assistants & MCP Connectors
ARSA publishes a Model Context Protocol (MCP) connector that allows third-party AI assistants such as Claude, ChatGPT, and any other MCP-compatible client to query our public car catalogue, expert directory, and pricing information. When you use the ARSA connector inside one of these assistants:
- Public tools (car search, car details, compare, brands, body types, fuel types, experts, pricing) do not require an ARSA account and do not transmit any personal data from you to us.
- The personalized-recommendations tool requires you to supply your ARSA access token. When you do, we use your saved preferences to build the feed and return it to the assistant. Your ARSA password is never sent.
- Your conversation with the AI assistant is governed by that assistant's own privacy policy. We cannot access your chat history with Claude, ChatGPT, or any other assistant.
- The ARSA connector is read-only. It cannot change your ARSA account, place bookings, or make payments.
8. Payment Information
All payments are processed securely through Razorpay. We do not store your credit/debit card details, UPI IDs, or net banking credentials on our servers. Razorpay's privacy policy governs the handling of your payment data. Please refer to Razorpay's Privacy Policy for details.
9. Children's Privacy
Under the DPDP Act and Rules, a "child" is any person under 18 years of age. ARSA is not directed to children and we do not knowingly collect personal data from anyone under 18. Our services are intended for users aged 18 and above (see our Terms & Conditions for account eligibility). If we learn that we have collected personal data of a child under 18 without verifiable parental consent, we will delete it promptly. If you believe a child under 18 has provided personal information to us, please contact our Grievance Officer at the details below.
10. Analytics & Tracking
We do not use third-party analytics, behavioural profiling, or advertising trackers. We do not integrate Google Analytics, Mixpanel, Amplitude, Firebase Analytics, Hotjar, Sentry, or similar SDKs in the ARSA mobile app or the www.arsacar.in website. Our server keeps rolling request logs (IP address, endpoint, status code, user-agent) for up to 30 days for security, debugging, and abuse prevention; these are not used for profiling or marketing.
11. Cookies
Our website uses only strictly necessary cookies and similar local storage to keep you signed in, remember your theme preference, and protect against CSRF attacks. We do not set advertising cookies, retargeting pixels, or cross-site tracking cookies. Authentication tokens are stored in your browser's local storage and are sent only to our API. You can clear cookies at any time through your browser settings without affecting your account data.
12. International Data Transfers
ARSA is operated from India, but several of our processors operate globally and may store or process your data in other jurisdictions: Cloudinary and Resend primarily in the United States and the European Union; Google in its global data-centre network; Razorpay within India; and our AI inference providers (Cerebras, Modal, SiliconFlow) in the United States. In all cases, transfers are made under the processors' standard contractual terms and with safeguards appropriate to the data involved. We will comply with any cross-border transfer restrictions notified by the Central Government under Section 16 of the DPDP Act.
13. Data Security
We implement industry-standard security measures including encrypted data transmission (HTTPS/TLS 1.2+), bcrypt-hashed passwords, short-lived signed JSON Web Tokens for authentication, strict input validation, rate limiting, and least-privilege access to our databases. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
14. Personal Data Breach Notification
In the event of a personal data breach, we will notify each affected Data Principal without delay through their registered user account or contact method, describing the nature of the breach, its likely consequences, the measures we are taking to mitigate it, and steps you can take to protect yourself. We will also report the breach to the Data Protection Board of India within 72 hours of becoming aware of it, as required by Rule 7 of the DPDP Rules, 2025.
15. Data Retention & Deletion
We retain your account data while your account is active. You can permanently delete your account and all associated data from inside the ARSA mobile app (Profile → Settings → Delete Account) or from our web page at www.arsacar.in/delete-account. Upon deletion:
- Profile, preferences, chat history, favourites, and uploaded documents are removed within 30 days.
- Payment transaction records are retained as long as required by Indian tax and financial regulations.
- Server request logs age out automatically within 30 days regardless of account status.
16. Your Rights Under the DPDP Act
As a Data Principal, you have the following rights under the DPDP Act, 2023:
- Access: Request a summary of your personal data and the processing activities it is undergoing.
- Correction & Completion: Request correction of inaccurate or incomplete personal data from within the app or by contacting us.
- Erasure: Request permanent deletion of your account and associated personal data.
- Grievance Redressal: Lodge a complaint with our Grievance Officer. We will respond within 90 days as required by Rule 14 of the DPDP Rules, 2025.
- Withdraw Consent: Withdraw consent for optional data processing at any time. The mechanism to withdraw consent is as easy as giving it — you can delete your account or adjust preferences in the app at any time, or contact us via the details below.
- Nomination: Nominate one or more individuals to exercise your data protection rights on your behalf, in accordance with Section 14 of the DPDP Act.
To exercise any of these rights, contact us at the email address below. If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India through its online portal.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app and on our website at least 7 days before they take effect. The "Last Updated" date at the top of this page always reflects the current version.
18. Grievance Officer & Contact Us
Under Section 13 of the DPDP Act, 2023 and Rule 9 of the DPDP Rules, 2025, we have appointed a Grievance Officer to address any questions or complaints about the processing of your personal data. You may reach out at:
Sarcare Marketing Private Limited
5th Floor, Mantri Sterling, Plot No. 341, Survey No. 997/8,
Model Colony, Near Deep Bungalow Chowk, Pune - 411016, India
Email: armaansco@gmail.com
Phone: +91 96678 03366
Grievance Officer: Armaan Sarkar, Sarcare Marketing Private Limited
armaansco@gmail.com | +91 96678 03366