Privacy & Data Policy
Last Updated: September 2026 • Your privacy and business confidentiality are fundamental.
End-to-End Isolation
Postgres Row Level Security ensures clients can only access their own records.
24-Hour Auto-Delete
Temporary PDF cloud files are wiped within 24h. Local storage remains on your PC.
Zero Data Selling
Your tonnage, purchaser, vehicle, and financial records are never shared or monetized.
1Information We Collect
- Account Credentials: Company name, contact person, verified email address, and phone number for authentication and administrative credential delivery.
- Hardware Identifiers: Unique device fingerprint (hashed OS/CPU serial), platform version, and device name to enforce the 1 PC + 2 Android subscription limits and prevent unauthorized device hijacking.
- Scanned Royalty Data: Information parsed from government pass verification URLs, including pass number, issue date, vehicle registration, mineral type, net weight (MT), purchaser name, destination, and driver details.
2How Your Data Is Processed & Stored
When an operator scans a QR code with our Android app, the link is sent to our Secure Cloud Backend to fetch the publicly accessible transit pass. The pass metadata is stored securely in our encrypted database under your client account. The PDF document is temporarily placed in an encrypted cloud storage bucket strictly for dispatch to your weighbridge Desktop Print Agent.
Local PC Storage Preference: If you turn on "Auto-Save PDFs" in the Desktop Agent settings, documents are saved to a directory of your choice on your local computer hard drive. If disabled, the temporary file is deleted from your PC immediately after printing.
3Device Permissions
- Camera (Android): Required exclusively for barcode/QR code scanning of physical royalty transit passes. No photos or video recordings are saved or uploaded.
- Local Storage (Windows PC): Used solely to store downloaded PDFs in your chosen folder if local archival is enabled.
- Network / Internet: Used to communicate with our Secure Cloud Backend and CGM-ATR verification portals.
4Security & Access Control
All communications utilize industry-standard Transport Layer Security (TLS 1.3 / HTTPS). Database queries are safeguarded by PostgreSQL Row Level Security (RLS) policies, ensuring strict multi-tenant isolation where no client can see, query, or print another client's records.
5Payment Information & Third-Party Processing (Cashfree)
We process subscription payments using Cashfree Payments India Private Limited (Cashfree), an RBI-authorized Payment Aggregator. RoyalScan does not collect, store, or view sensitive card details (CVV, full card numbers, expiry dates) or bank passwords/UPI MPINs.
All payment transactions are handled directly through Cashfree's PCI-DSS Level 1 certified vault and 128-bit bank-grade encryption protocols in compliance with Reserve Bank of India (RBI) tokenization guidelines.
6Grievance Redressal & Data Privacy Officer
In accordance with the Information Technology Act 2000 and the Digital Personal Data Protection (DPDP) Act, you may contact our designated Grievance Officer, Bharat Ambaliya (Proprietor, RoyalScan), for data removal, inquiries, or corrections at grievance@royalscan.in, phone: +91 70164 09014, or write to: RoyalScan, At: Modpur, Taluka: Lalpur, District: Jamnagar, Gujarat – 361170, India.