Last updated: 30 August 2026
Who runs this service
The DL Card Generator (“the service”, “we”) is operated by the individual or entity that deployed this instance and configured its payment details (“the operator”). The operator is the data fiduciary for the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”). Their contact and grievance details are on the contact page.
What we collect
Account & profile
- Email, username, full name and (optional) display name — provided at sign-up.
- Optional phone number and profile photo, if you add them.
- A password, stored only as a salted hash by our authentication provider.
- If you enable two-factor authentication: a TOTP secret and/or passkey public keys, plus hashed single-use recovery codes.
Wallet & payments
- Your credit balance and an append-only ledger of every credit and debit.
- For a manual top-up: the amount, the UPI/UTR reference number you enter, a screenshot of your payment that you upload, a checksum of that image, and the approve/reject decision and any admin note.
Card generation
- Non-identifying metadata for each card you generate: the template, the last four digits of the DL number, a two-letter state code, the number of vehicle classes, the price paid, status and timestamps.
- The rendered card images (front & back PNG) — stored only if you tick “save this card”. If you do, they are held in private object storage and auto-deleted after the retention window (30 days by default). If you don't, the images are produced and handed to you and not stored.
- The full DL number, name, address, date of birth, photo and signature you enter or fetch are used to draw the card in your browser and are not written to our database.
The Sarathi fetch feature
- If you use auto-fill, the DL number and date of birth you enter are sent to our server, used once to query the public verification page at sarathi.parivahan.gov.in, and returned to your browser. The record itself is not stored; only a “you ran a fetch” entry (with the last four digits) is written to your activity log.
Usage & technical data
- An activity log of meaningful actions (sign-in, profile change, generation, top-up, admin action) with a short summary, your IP address and user agent.
- Short-lived rate-limit counters and one-time-code challenges.
- Standard hosting request logs (IP, timestamp, path, user agent), rotated automatically.
- If you accept the cookie banner: Google Analytics measurement data. Nothing analytics- related loads until you accept.
Why we process it (purposes)
- To provide the service — accounts, sign-in, the wallet, generating and (optionally) storing your cards.
- To take payment — verifying your manual top-up against the reference and screenshot you submit, and crediting your wallet.
- Security & abuse prevention — rate limiting, bot checks (Cloudflare Turnstile), two-factor authentication, fraud checks on duplicate payment references.
- Support & record-keeping — responding to you, and keeping financial and audit records we are required to keep.
- Product analytics — only with your consent, to understand aggregate traffic.
Our lawful basis is your consent (given at sign-up and, separately, for analytics), performance of the contract for the service you asked for, and our legitimate interest in keeping the service secure and meeting legal obligations.
Where your data is stored (processors)
We use these sub-processors. The operator selects the specific providers and regions:
| Provider | What it holds |
|---|---|
| Supabase (Postgres + Auth) | Accounts, profile, wallet ledger, generation metadata, UTR numbers, activity & audit logs |
| AWS S3 or Cloudflare R2 | Private object storage: saved card images, payment screenshots, profile photos |
| Cloudflare | CDN/DNS and the Turnstile bot-check challenge |
| Resend (if enabled) | Sends transactional email (confirmation codes, notices) |
| Telegram (if enabled) | Operational alerts to the operator's admin chat — includes your username, amount and UTR for a pending top-up |
| Google Analytics (consent only) | Aggregate traffic measurement |
| Hosting provider (VPS) | Runs the application; short-lived request logs |
Some of these providers process data outside India. Where that happens it is on the basis permitted under the DPDP Act and the provider's own safeguards.
How long we keep it
- Account & profile — until you delete your account.
- Saved card images — the retention window set by the operator (30 days by default), then automatically deleted from storage.
- Payment screenshots — up to ~180 days, then automatically deleted. The row and UTR are kept longer as a financial record.
- Wallet ledger & approved top-ups — retained for as long as needed for accounting and tax.
- Activity log — about 400 days.
- Admin audit log — retained (tamper-evident) as a compliance record.
- Non-saved generation metadata — deleted after the retention window.
- One-time codes, rate-limit counters, WebAuthn challenges — minutes to hours.
Your rights
Under the DPDP Act and comparable laws you can:
- Access & correct — most fields are editable at /account/profile; email, username and phone changes are confirmed by an emailed code. Download a machine-readable copy of your account data any time from Account → History → Export my data.
- Erase — /account/security → Delete account (confirmed by an emailed code) removes your profile, wallet, history and any saved cards. Minimal financial-ledger and audit entries may be retained where the law requires, with identifiers reduced.
- Withdraw consent — reject analytics in the cookie banner, or contact us. Withdrawing consent needed to run your account means we can no longer provide it.
- Nominate — you may nominate another individual to exercise your rights in the event of death or incapacity; contact the grievance officer.
- Grievance & complaint — raise a concern with the operator's grievance officer (contact page). If unresolved, you may complain to the Data Protection Board of India.
Security
- All traffic over HTTPS/TLS, with HSTS and a standard set of security headers.
- Passwords are hashed by the auth provider; optional TOTP and passkey two-factor auth; sensitive changes need an emailed one-time code.
- Row-level security on every database table; object storage buckets are private and served only through short-lived signed links; data is encrypted at rest by the storage provider.
- Rate limiting and a bot-check on sign-up, sign-in and payment submission.
- In the event of a personal-data breach that is likely to cause harm, we will notify affected users and the Data Protection Board as the DPDP Act requires.
Children
The service is not directed at children. You must be old enough to hold the licence you are formatting (generally 16+, and 18+ for most classes) and at least 18 to hold an account and make payments.
Changes
If this policy changes materially we will update the date above and, for significant changes, notify account holders by email. Continuing to use the service after a change means you accept the updated policy.
Contact & grievance officer
For any privacy request or complaint, contact the operator through the contact page. The operator is responsible for designating a grievance officer under the DPDP Act and publishing that person's name and contact there.
This page is provided for transparency and is not legal advice. If you need a policy tailored to a specific jurisdiction or business, consult a qualified lawyer.