Back to Hustl

Data Compliance and Cookies

Last updated: August 2026

1. DPDPA compliance commitment

Hustl complies with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable rules. Implementation is phased per government notification:

  • Phase I (effective): Data Protection Board framework
  • Phase II (from 13 November 2026): Consent manager framework
  • Phase III (from 13 May 2027): Full substantive obligations and data principal rights enforcement

We are preparing systems for consent records, grievance handling, and erasure workflows before Phase III.

2. Lawful basis for processing

  • Consent: marketing communications, optional features, and the identity and business documents you submit for verification
  • Contract: providing the marketplace service you signed up for
  • Legal obligation: tax, statutory identity and record-keeping requirements, lawful government orders
  • Legitimate uses under DPDPA: fraud prevention, security, and safety as permitted

3. Data processors (sub-processors)

We engage processors under agreements requiring security safeguards and purpose limitation:

  • Google Cloud Platform / Firebase (India regions) — hosting, database, authentication, file storage
  • Sentry (error monitoring, minimised data)
  • Vercel (hosting and analytics)

Two further providers are built into our software but switched off during the public beta, and receive no data from us today. We list them so the picture is complete: MasterGST (optional GSTIN lookup against the public GST registry — not enabled; no GSTIN is sent to it, and GSTINs are reviewed by the Hustl team by hand) and Slack (optional internal operational alerts to the Hustl team — not enabled). If we enable either, we will move it into the list above and give notice first. This matches section 5 of our Privacy Policy.

No identity-verification provider, payment gateway or payout provider processes your data today. During the public beta, the Hustl team reviews every account and the documents submitted with it manually. There is no external verification provider, no automated identity check, no liveness check and no background check. Verified Partners post shifts using free beta credits, so no payment gateway collects payment from them. Hustler payouts are released manually by the Hustl team to the UPI ID saved on the Hustler's profile, because the payment gateway is not integrated yet.

If we later engage an identity-verification provider, a payment gateway or a payout provider, we will update this page to name that processor and the data it receives.

We do not authorise processors to use your data for their own marketing.

4. Cross-border transfers

We store and process personal data in India, on Google Cloud Platform in the asia-south1 (Mumbai) region, with one exception: the live-location channel runs on Firebase Realtime Database in the asia-southeast1 (Singapore) region, because that product is not offered in an Indian region. Live coordinates carried on that channel while a Hustler is checked in, or during the limited windows described in section 3 of our Safety Policy, are therefore processed outside India. No other category of personal data is sent outside India. This matches section 8 of our Privacy Policy.

Apart from that channel, we do not intentionally transfer personal data outside India. If this changes, or if we move the live-location channel into an Indian region, we will update this policy and obtain any required approvals or safeguards.

5. Cookies and tracking technologies

What we use

  • Strictly necessary: Firebase authentication session, security tokens
  • Security: Google reCAPTCHA Enterprise / Firebase App Check
  • Analytics: Vercel Analytics (first-party, aggregated page performance)
  • Local storage: app preferences, navigation stack on PWA

What we do not use

  • Google Analytics (GA4)
  • Meta Pixel / Facebook tracking
  • Advertising cookies or cross-site profiling
  • Session replay tools that record keystrokes or form fields

Because we do not use non-essential advertising cookies, we do not sell personal data under definitions used in foreign privacy laws (e.g. CCPA "sale"). Our business model is the marketplace itself, not data sales. During the public beta, verified Partners post shifts using free beta credits and no payment gateway collects payment from them.

6. Marketing and commercial communications (India)

India does not have CAN-SPAM, but commercial communications are regulated under TRAI guidelines, the IT Act, and DPDPA consent requirements.

  • Transactional messages (booking updates, OTP, payout alerts) are sent without separate marketing consent where necessary for the service.
  • Promotional SMS, WhatsApp, or email require your opt-in consent before we send them.
  • Every marketing message will include sender identification and an opt-out mechanism.
  • Opt-out is honoured within 7 business days.

7. Data breach response

We maintain incident response procedures. If a breach likely affects your rights, we will:

  1. Contain and investigate the incident
  2. Notify the Data Protection Board of India as required under DPDPA Section 8
  3. Notify affected users without undue delay with recommended protective steps
  4. Document remediation and preventive measures

8. Grievance officer

Name: Grievance Officer, Hustl
Email: grievance@hustl.today
Privacy requests: privacy@hustl.today
Response SLA: acknowledgement within 24 hours; resolution target 15 days

If unresolved, you may escalate to the Data Protection Board of India as provided under the DPDPA.

9. Data Protection Officer

As we scale, Hustl will appoint a Data Protection Officer (DPO) as required under DPDPA. Until formal appointment, privacy and grievance queries are handled by privacy@hustl.today.