Security and your data
Access control, identity data, one-time links and codes, immutable field evidence, support access and payment handling.
DriveDesk holds three things that matter: your customers' personal data, your staff's identity documents, and the operational record of who took which vehicle where. Here is how each is handled.
Access control
- Permission is checked before a page renders, not after — a member without a permission never receives the data behind it.
- Removing a permission takes effect on the next request. There is no cached grace period.
- Marketplace customer details are withheld on the server while a lead is locked, so the data is genuinely absent from the browser rather than merely hidden.
- Public tracking links carry position and progress only — never staff details or internal identifiers.
Identity data
- Staff identity comes from DigiLocker, signed by the issuing authority. Raw Aadhaar numbers are not stored.
- Customer licence checks run against the transport authority with the customer's consent recorded.
- Where a document was approved manually rather than automatically, the record says so — a manual approval never masquerades as a government verification.
Links and codes
- Every customer link is single-use and expires. Only a hash of the token is stored, so the link cannot be reconstructed from the database.
- One-time codes are randomly generated per use, scoped to one customer and one stop, and cannot be reused elsewhere.
- Gate passes are cryptographically signed; a modified QR code fails verification.
- Code sending is rate-limited per recipient and per source.
The operational record
Support access
DriveDesk support staff can view your account as you for troubleshooting, but only platform super-admins can do so, every session is recorded, and a banner is displayed the entire time saying whose account is being viewed. There is no invisible access.
Payments
Card and UPI details are handled by Razorpay and never touch DriveDesk's systems. DriveDesk stores the transaction record, not the instrument.
Common questions
- Do you store Aadhaar numbers?
- No. Verification records what was confirmed and when. The document number itself is not persisted.
- Can a manager alter what staff recorded in the field?
- No. Field-captured evidence is append-only. A manager can override a decision or resolve an issue, and that action is recorded as a separate, attributed entry.
- Can DriveDesk staff see our data?
- Only with super-admin authority, always recorded, and always with a visible banner for the duration. It exists for support, not for browsing.
- What happens if we delete our dealership?
- Deletion is reversible on our side — your records are retained rather than destroyed — so a mistake or a change of mind does not cost you your history. Talk to us about a permanent export or erasure.
Related guides
- Staff identity verification (KYC)Aadhaar and driving-licence verification for the staff who drive your vehicles — DigiLocker, fallbacks, and the review queue.
- Customer driving-licence checksLicence validity and identity are separate questions — pre-checks, the review queue, manager overrides and what cannot be overridden.
- Roles, permissions and who can do whatHow roles, individual permissions and ownership work — including the driver / sales-rep split and the full permission list.
Still stuck?
Check the FAQ for a quick answer, or ask us — we reply within one business day.