Privacy Policy & Data Security
Last Updated: August 31, 2026. This policy outlines how DriveSync Infotech handles, de-identifies, and encrypts telemetry logs.
1. Telemetry Data We Collect
DriveSync Cyber Assistant (DCA) is a security platform. We collect information related to cyber fraud incidents reported to our system to train our threat engines and protect our infrastructure:
- Transaction Hashes & Details: Transfer amounts, debit banks, transaction times, and UTR reference numbers.
- Suspect Identifiers: Reported phone numbers, suspect UPI addresses (VPAs), bank account details, and phishing links.
- Evidence Documentation: Uploaded chat logs, screenshots of conversations, and files containing context of fraud (stored securely in public buckets).
- Security Logs & IP Addresses: We log the client's network IP address on report submission for security audits, bot containment, and rate-limiting enforcement.
- UX Performance metrics: We record anonymous durations (time in seconds) spent on website pages and specific steps of the reporting form to help identify layout complexities and optimize usability.
2. Security & Zero-Knowledge Architecture
We employ military-grade security standards to protect all submitted parameters:
- PII Scrubbing: Any Personally Identifiable Information (PII) of the reporter is scrubbed or encrypted prior to network database synchronization.
- Supabase Encryption: Data is stored in secure database nodes protected with AES-256 encryption at rest and TLS 1.3 transit tunnels.
- Evidence Files: Uploaded evidence screenshot files are stored in an isolated, secure object storage bucket with strictly managed permissions.
- IP Rate-Limit Caches: IP addresses logged in the in-memory submission limiter are kept temporarily to prevent spam attacks and are not cross-referenced with public search engines.
3. Data Distribution & Access
Reported suspect indicators (like malicious UPI IDs and scam websites) directly train our threat assessment index.
This index aggregates anonymous hazard scores. When other users scan a UPI handle via the **UPI Risk Scanner**, they check it against these aggregates to warn them of potential digital arrest, investment, or loan app scams.
We do not sell, trade, or share raw files or reporter identities with any marketing networks or commercial credit rating agencies.
4. User Rights and Data Control
If you have logged an incident in our database and wish to request its removal, correction, or audit review, you can contact our privacy desk directly at info@drivesyncinfotech.com.
