1. Overview
Meghalaya Cabs ("we", "us", or "our") operates the website https://www.meghalayacabs.com and related mobile applications (collectively, the "Platform"). We are a private cab and tour service based in Shillong, Meghalaya, India.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights over it. It is compliant with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act).
By using our Platform or booking our services, you consent to the practices described in this policy.
2. Data We Collect
A. Data you provide directly:
- Full name, mobile number, email address
- Pickup and drop-off locations
- Travel dates, number of passengers, vehicle preference
- Special requests (e.g., child seat, dietary needs, health conditions)
- Account registration details (email, password — stored as a bcrypt hash)
- Messages sent via our contact form or WhatsApp
- Review or testimonial content if submitted
B. Data collected automatically:
- Browser type, operating system, device type
- IP address and approximate geographic location (country/state level)
- Pages visited, time spent, referring URL
- Booking reference generated for your session
C. Sensitive Personal Data (SPDI) under Indian law:
We do not collect financial information such as bank account numbers, credit/debit card details, or passwords to third-party accounts. Health-related information (e.g., motion sickness, wheelchair access needs) is collected only when voluntarily provided by you in the special requests field, and is used solely to fulfil your booking.
3. Purpose & Legal Basis for Processing
We process your data for the following purposes:
- To fulfil bookings — confirming trip details, sending booking references, coordinating driver assignment
- To communicate with you — sending confirmation emails, trip reminders, driver details, and cancellation notices
- To manage your account — maintaining login credentials, saved itineraries, and booking history
- To improve our services — analysing usage patterns (in aggregate, non-personally identifiable form)
- To comply with legal obligations — responding to lawful requests from Indian government authorities
- To prevent fraud — detecting and blocking suspicious activity on our Platform
Our legal basis for processing is your consent (given at the time of booking or account creation), contractual necessity (to provide the service you requested), and legitimate interest (to operate and improve our business).
5. Data Retention
We retain your personal data for the following periods:
- Booking records — 3 years from the date of travel (for accounting and dispute resolution)
- Account data — for the duration your account is active, plus 12 months after deletion request
- Communication logs (contact form, enquiries) — 12 months
- Analytics data — 24 months in aggregate, anonymised form
You may request deletion of your account and associated data at any time by visiting your dashboard or emailing us. We will fulfil verified requests within 30 days, except where retention is required by law.
6. Security Practices
We implement reasonable security practices and procedures as required under Rule 8 of the IT (SPDI) Rules, 2011, including:
- HTTPS/TLS encryption for all data transmitted between your browser and our servers
- Passwords hashed using bcrypt (never stored in plain text)
- Database access restricted to authorised personnel only
- Email verification required for account activation
- Vercel's enterprise-grade infrastructure with automated security updates
While we take all reasonable precautions, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of data transmitted to our Platform.
7. Your Rights as a Data Principal
Under the DPDP Act 2023 and IT (SPDI) Rules 2011, you have the following rights:
- Right to Access — request a copy of the personal data we hold about you
- Right to Correction — request correction of inaccurate or outdated personal data
- Right to Erasure — request deletion of your account and personal data (subject to legal retention requirements)
- Right to Withdraw Consent — withdraw consent for marketing communications at any time
- Right to Grievance Redressal — lodge a complaint with our Grievance Officer (see Section 12)
- Right to Nominate — nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act, s.14)
To exercise any of these rights, email us at meghalayacabs@gmail.com with subject line "Data Rights Request – [Your Name]". We will respond within 30 days.
9. Children's Privacy
Our Platform is not directed at children under the age of 18 years. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it promptly.
Bookings that include children as passengers are made by the adult responsible for the booking, who consents on behalf of all passengers.
10. Third-Party Links
Our Platform may contain links to third-party websites (e.g., Google Maps, WhatsApp, Instagram). We are not responsible for the privacy practices of these external sites. We encourage you to review their respective privacy policies before sharing any personal data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the Effective Date at the top of this page and, where appropriate, notify registered users by email.
Your continued use of the Platform after the updated policy is posted constitutes your acceptance of the changes.
12. Grievance Officer
As required under Rule 5(9) of the IT (SPDI) Rules, 2011 and Section 13 of the DPDP Act 2023
| Name | Raj Kiranata Garaha |
| Designation | Grievance Officer / Director |
| Organisation | Meghalaya Cabs |
| Address | Police Bazar, Shillong, Meghalaya – 793001, India |
| meghalayacabs@gmail.com | |
| Phone | +91 8855853857 |
| Response Time | Within 30 days of receipt of complaint |
You may also escalate unresolved complaints to the Data Protection Board of India once constituted under the DPDP Act 2023.
13. Contact Us
For all privacy-related queries, write to us at: