Cuberoote

Privacy Policy & Security Overview

Last updated: February 27, 2026

1. Who We Are

PurpleDrone Supplychain Solutions ("Cuberoote", "we", "us", "our") operates the Cuberoote logistics management platform. We are committed to protecting your personal information and your right to privacy in compliance with applicable Indian laws including the Digital Personal Data Protection Act, 2023 (DPDP Act).

Registered Address: Plot No. 216, Village Bamnoli, Sector 28, Dwarka, New Delhi - 110077

Contact: care@purpledrone.in

2. Information We Collect

We collect personal information that you provide when using our platform:

Data TypePurposeLegal Basis
Name, phone, emailAccount creation, communicationContract performance
Shipping addressesOrder fulfilment, deliveryContract performance
Login credentialsAuthentication, access controlSecurity / contract
Device informationSecurity (trusted device recognition)Legitimate interest
IP address, timestampsSecurity logging, fraud preventionLegitimate interest

3. How We Use Your Information

4. Data Sharing

We do not sell your personal data. We may share information only in these circumstances:

5. Data Storage & Retention

6. Your Rights (DPDP Act 2023)

As a data principal under the DPDP Act, you have the right to:

To exercise these rights, contact us at care@purpledrone.in. We will respond within 30 days.

7. Cookies

We use essential cookies for session management and authentication. We do not use third-party tracking cookies or advertising cookies. Session cookies expire when you close your browser or after 30 minutes of inactivity.

8. Children's Data

We do not knowingly collect data from individuals under 18 years of age. If you believe a minor has provided us with personal information, please contact us immediately.

9. Security Overview

We implement multiple layers of technical and organizational security measures to protect your data:

Authentication & Access Control

MeasureDescription
Multi-Factor Authentication (MFA)TOTP-based MFA required for all user accounts
Strong password policyMinimum 10 characters with complexity requirements
Password rotationMandatory password change every 15 days
Session managementAutomatic timeout after 30 minutes of inactivity
Brute force protectionAccount lockout after repeated failed login attempts

Data Protection

MeasureDescription
Encryption in transitAll data transmitted over HTTPS/TLS
Encryption at restSensitive personal data encrypted using format-preserving encryption
PII maskingPersonal data automatically masked in logs and API responses
Access-controlled downloadsFile downloads require authentication and are audit-logged

Monitoring & Audit

MeasureDescription
Security monitoringAutomated monitoring for anomalies and suspicious activity
Audit loggingAll access to sensitive data and admin actions are logged
Rate limitingProtection against abuse on all sensitive endpoints
Incident responseDocumented incident response plan with defined escalation procedures

Infrastructure

Compliance

We are actively working towards compliance with:

CERT-In Directions 70B ISO 27001:2022 DPDP Act 2023

10. Changes to This Policy

We may update this policy from time to time. The updated version will be indicated by an updated date at the top of this page. We encourage you to review this page periodically.

11. Contact Us

If you have questions about this privacy policy or our security practices, please contact us: