Privacy Policy

Last updated: 24 July 2026

Who We Are

MotoDXR is a business-to-business SaaS platform for used vehicle dealerships in India, operated by DXR Tech, a sole proprietorship of Adnan (“we”, “us”, “our”). This Privacy Policy explains how we collect, use, and protect personal information across our platform, including the dealer mobile applications for Android and iOS, the admin panel, and the public vehicle catalogs we host.

Data Fiduciary details

Entity: DXR Tech (sole proprietorship)

Proprietor: Adnan

GSTIN: 32CCQPV3793M1ZM

Registered address: 72/375, Deshabhimani Road, Kaloor, Kochi, Kerala - 682017

Email: contact@motodxr.com

MotoDXR is a product and brand operated by DXR Tech. References to “MotoDXR” in this policy mean DXR Tech acting through its proprietor.

Who This Policy Covers

This policy applies to three different groups of people, and different parts of it will be relevant to you depending on which you are:

  • Dealers — the dealership owners and businesses who register for and subscribe to MotoDXR (Sections 2 to 5)
  • Team members— managers and staff invited to a dealer's account (Section 6)
  • Catalog visitors— members of the public who browse a dealer's catalog at yourname.motodxr.com or at a connected custom domain (Section 7)

1. Roles: Who Is Responsible for What

For personal data relating to dealers and their team members, MotoDXR is the Data Fiduciary and determines how that data is used.

For personal data that a buyer or enquirerprovides to a dealer through the dealer's catalog, the dealeris the Data Fiduciary and MotoDXR acts as a Data Processor on that dealer's behalf. If you have enquired about a vehicle and wish to exercise your rights over that enquiry, contact the dealership directly. You may also contact us and we will assist in directing your request.

2. Information We Collect from Dealers

Account and Identity

  • Mobile phone number (required for login via OTP)
  • Full name (optional, provided by you during setup)
  • Email address (optional, provided by you)

Dealer and Business Information

  • Business name and dealer slug (your catalog subdomain)
  • Business address and city
  • GSTIN, if provided — stored as supplied and not independently verified at this time
  • Google Maps location URL (optional)
  • Brand colour preference
  • Any custom domain you connect to your catalog

Vehicle Inventory Data

  • Vehicle registration numbers, make, model, year, fuel type, and specifications
  • Vehicle photographs you upload
  • Listing prices and ownership history

Device Permissions

The mobile application requests the following permissions. Each is optional, is requested only at the point it is needed, and may be declined or later revoked in your device settings:

  • Camera — to photograph vehicles for your listings. We access the camera only while you are actively adding or editing a listing.
  • Photo library — to select existing vehicle photographs for your listings. We access only the images you specifically choose; we do not scan or index your photo library.
  • Notifications — to send you alerts about enquiries, listings, and account activity.

We do not request or collect device location, contacts, microphone, calendar, or health data.

Usage and Technical Data

  • Pages and features used, collected via PostHog
  • Application crash reports and error details, collected via Sentry
  • Device model, operating system version, and app version, included in crash reports
  • Push notification tokens, used to deliver notifications through Apple Push Notification service and Firebase Cloud Messaging
  • Session and authentication tokens (see Section 10)

Payment Data

  • Transaction identifiers and payment status from Razorpay
  • Your subscription and billing history
  • Name and email address where required to issue an invoice

We do not store card numbers, UPI IDs, CVVs, or banking credentials. All payment processing is handled directly by Razorpay.

3. How We Use Dealer Information

We use the information we collect to:

  • Create and manage your dealer account
  • Operate and display your public vehicle catalog
  • Provision and renew SSL certificates for any custom domain you connect
  • Send one-time passwords by SMS for login
  • Process your subscription payments through Razorpay
  • Send service notifications by SMS and push notification, such as trial expiry reminders and payment confirmations
  • Diagnose and fix technical problems using crash reports
  • Understand how the platform is used so we can improve it
  • Respond to your support requests and grievances
  • Comply with our legal, tax, and regulatory obligations

We do not sell your personal data. We do not use your data for advertising, and we do not share it with advertisers or data brokers.

4. Legal Basis

We process dealer personal data on the basis of your consent, given when you register, and on the basis of the legitimate uses recognised under the Digital Personal Data Protection Act, 2023 — including performing our contract with you, complying with legal obligations, and maintaining the security of the platform.

You may withdraw consent at any time by deleting your account, as described in Section 9. Withdrawing consent does not affect processing carried out before withdrawal.

5. Third-Party Services

We use the following processors to operate MotoDXR. Each receives only the data necessary for its function.

ServicePurpose
SupabaseDatabase, authentication, and file storage hosting
RazorpayPayment processing
MSG91SMS OTP and notification delivery
PostHogProduct analytics
SentryError monitoring
CloudflareCDN, image delivery, DNS and SSL
Apple Push Notification servicePush delivery on iOS
Firebase Cloud MessagingPush delivery on Android

Transfers Outside India

Several of these providers process data on servers located outside India. Where this occurs we rely on the transfer mechanisms permitted under the Digital Personal Data Protection Act, 2023 and require our processors to apply appropriate safeguards. Vehicle images and catalog content are served through Cloudflare's global network so that catalogs load quickly for buyers. Our database, authentication, and file storage are hosted on Supabase, whose infrastructure may process data outside India, subject to the same transfer safeguards described above.

6. Team Members

A dealer may invite managers and staff to their account by submitting that person's mobile number.

What we collect: the mobile number submitted by the dealer, the role assigned, the name the team member provides on first login, and the same usage and technical data described in Section 2.

Who is responsible: the dealer decides who to invite and what role to assign. We process team member data in order to provide the account access the dealer has granted.

Your rights as a team member: you may ask us for access to, correction of, or erasure of your personal data using the contact details in Section 14. You may also ask the dealer who invited you to remove your access at any time. If you receive an invitation you did not expect, contact us and we will remove your number.

7. Catalog Visitors

You do not need an account to browse a dealer's catalog, and we do not ask visitors to register.

What we collect when you visit a catalog

  • Pages viewed, vehicles viewed, and general interaction data, collected via PostHog
  • IP address, browser type, and device type, processed by Cloudflare to deliver the page and to protect against abuse and attack
  • Error and crash information if a page fails to load, via Sentry

What we use it for: to deliver and secure the catalog, to measure which listings are viewed so dealers can understand interest in their stock, and to improve the platform. We do not build advertising profiles and we do not sell this data.

Enquiries: if you contact a dealership using the WhatsApp or call button on a catalog, that conversation takes place directly between you and the dealership on WhatsApp or by telephone. We do not intercept, store, or have access to the contents of those conversations. Any information you give the dealership is held by that dealership, which is responsible for it as Data Fiduciary.

Your rights: you may exercise the rights described in Section 11 in respect of visitor data by contacting us at the address in Section 14.

This section applies equally when you visit a catalog at a dealer's connected custom domain.

8. Reporting Content

If you believe a listing on a MotoDXR catalog is fraudulent, unlawful, infringing, or otherwise objectionable, email contact@motodxr.com with the catalog address and details of the listing. We acknowledge reports within 24 hours and aim to resolve them within 15 days.

9. Data Retention and Deletion

While Your Account Is Active

Your data is retained for as long as your account is active.

If You Cancel

If you cancel your subscription, your account and data are retained for 2 years so that you can reactivate and recover your inventory history. After 2 years of inactivity, retained data is permanently deleted.

If You Delete Your Account

Deletion is different from cancellation, and it is permanent. You may delete your account at any time from within the mobile application, or by emailing contact@motodxr.com.

On deletion:

  • Your account, listings, uploaded images, team records, and catalog are permanently removed
  • Your catalog address and any connected custom domain stop resolving
  • Your data is not retained for reactivation and cannot be recovered
  • Deletion takes effect immediately, and removal from routine backups completes within 30 days

We retain only what the law requires us to retain, such as invoice and transaction records kept for tax and accounting purposes, and any records needed in connection with a legal claim or regulatory obligation. Records retained on this basis are not used for any other purpose.

Other Retention Periods

  • Listing images: permanently deleted from storage when you remove a listing
  • Push notification tokens: deleted when you log out or uninstall the application
  • Analytics data: retained in aggregated and pseudonymised form
  • Crash reports: retained for 90 days

10. Cookies, Local Storage, and Session Data

On the web:access and refresh tokens are stored in your browser's localStorage to keep you signed in. PostHog sets cookies to measure usage patterns and page views.

In the mobile applications: authentication tokens are stored in the operating system's secure storage — Keychain on iOS and the Android Keystore — rather than in localStorage.

We do not use third-party advertising cookies and we do not participate in cross-site advertising networks.

11. Your Rights Under the DPDP Act 2023

Under India's Digital Personal Data Protection Act, 2023, you have the right to:

  • Access the personal data we hold about you and a summary of how it is processed
  • Correct inaccurate or incomplete personal data, and complete or update it
  • Erase your personal data, subject to our legal retention obligations
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
  • Grievance redressal — to raise a complaint with us and receive a response, as set out in Section 14

To exercise any of these rights, email our Grievance Officer at contact@motodxr.com. We may ask you to verify your identity before acting on a request. Dealers can exercise access, correction, and erasure directly using the controls in the mobile application and admin panel.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

12. Security

We apply reasonable security safeguards to protect personal data, including:

  • Encryption of data in transit using TLS across the platform and on all catalog domains
  • Authentication by one-time password, with no stored passwords to be compromised
  • Storage of authentication tokens in secure operating system storage on mobile devices
  • Access controls limiting which of our personnel can access production data
  • Role-based access within dealer accounts, so team members see only what their role permits
  • Use of established infrastructure and payment providers who maintain their own security programmes

No system can be guaranteed completely secure. You are responsible for keeping your registered mobile number and device secure, since account access depends on receiving one-time passwords.

13. Data Breach Notification

If a personal data breach occurs, we will notify the Data Protection Board of India and each affected data principal without undue delay, in the manner and within the timelines required by the Digital Personal Data Protection Act, 2023 and rules made under it. Our notification will describe the nature of the breach, its likely consequences, and the measures we have taken.

14. Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have designated a Grievance Officer. If you have any concern about the collection, storage, or use of your personal data, please contact:

Grievance Officer, DXR Tech (MotoDXR)

Name: Adnan

Designation: Proprietor and Grievance Officer

Email: contact@motodxr.com

Address: 72/375, Deshabhimani Road, Kaloor, Kochi, Kerala - 682017

Complaints will be acknowledged within 24 hours of receipt and resolved within 15 days.

15. Children's Privacy

MotoDXR is a business platform intended for use by adults operating vehicle dealerships. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have collected personal data from a person under 18, we will delete it. If you believe this has happened, contact us at the address above.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by SMS, email, or in-app notification at least 14 days before the change takes effect. The “Last updated” date at the top of this page indicates when the current version was published.

17. Contact

For any privacy-related question, email us at contact@motodxr.com.