Rapido's Privacy Policy vs the DPDP Act: Can a Gig Worker Freely Refuse Consent?
Rapido collects body temperature and vaccination status from its captains, and 180 days of trip history after you delete your account. A DPDP Act teardown of a two-sided marketplace.
Every teardown in this series has asked whether a user's consent is genuinely free. Rapido raises a version of that question nobody in Indian privacy is really addressing yet, because Rapido has two kinds of users: riders, and captains whose livelihood depends on the app.
The policy states that from captains, Rapido "may collect certain health related Information and declarations such as body temperature, symptoms, vaccination status", along with call recordings, driver history, criminal records where permitted, Aadhaar, PAN, licence details, and real-time selfies.
Under §6, consent must be free. A rider who declines a permission loses a convenience. A captain who declines loses their income. Those are not the same act, and the DPDP Act does not currently distinguish between them, which is exactly why it is worth naming now rather than after the first enforcement order.
Gap 1: Consent by usage, plus amendment at sole discretion (§6)
“By accessing or using the Rapido Platform or the Services, you agree and consent to this Policy, along with any amendments made by the Company at its sole discretion and posted on the Rapido Platform from time to time.”
This is the deemed-consent pattern with an additional problem stacked on top. It asks you to consent in advance to terms that do not exist yet, changed unilaterally, with notice satisfied by posting. Under §6, consent must be informed and specific to a stated purpose. You cannot be informed about a purpose that has not been written.
Gap 2: 180 days of trip history after you leave (Rule 8)
Rapido deserves genuine credit here first: the policy contains a number, and most do not.
“Even after your account is terminated, we will retain some of your Information including Personal Information and Usage Information (including geo-location, trip history, and transaction history) for a period of 180 days”
Rule 8 asks for a defined period, and 180 days is defined. The question is whether it is justified. Trip history is a map of where you sleep, work, worship, and seek medical care. When a user deletes their account, the stated purpose is unambiguously over. Retaining a complete movement profile for six months afterwards needs a purpose beyond "we might need it", and the policy does not give one.
The clause also softens at the end: after 180 days data "may either be deleted from our database or be anonymized and aggregated, and then may be held by us as long as necessary." The number is real; what follows it is the same open-ended language the number was supposed to replace.
Gap 3: Background location collection
The policy states location is collected when the app runs "in the foreground (app is open and on-screen) or background (app is not in use)."
The captain-side treatment is actually well designed: location is collected "only when the Captains have enabled the icon On-Duty", which is a genuine purpose limitation and better than the industry norm. The rider-side language is looser, covering any time the app runs in the foreground rather than strictly the ride window. Under §8(3), collection should be limited to what is necessary for the stated purpose, and the stated purpose for a rider is completing a trip.
Gap 4: No dated policy, no rights section, no DPDP
- •No last-updated date anywhere in the document. This matters more than it sounds. If consent is to a specific version of a notice, and amendments happen at sole discretion, an undated policy makes it impossible for a user, or the Board, to establish what was agreed and when.
- •No Data Principal rights section. Correction and opt-out are mentioned in passing, but there is no consolidated statement of access, erasure, grievance redressal, or the right to nominate under §14.
- •"Nodal Officer", not Grievance Officer or DPO. Manasvi Mann is named with a working email, which meets the substance of Rule 9. But "Nodal Officer" is Information Technology Rules vocabulary, and the title signals which framework the document was written against.
- •The DPDP Act is never mentioned. The Information Technology Act, 2000 is cited by name. The statute governing all of this from November 2026 is not.
Gap 5: Deemed consent for co-branded services
“If you elect to register for products and/or services through the Co-Branded Services, you shall have deemed to have consented to providing your Information to both us and the third party”
Sharing data with a named third party is a distinct purpose requiring its own notice and its own consent under §6. "Deemed to have consented" is the precise construction the DPDP Act was written to remove from Indian privacy practice.
The gig-economy question nobody has answered yet
Ride-hailing, delivery, and logistics platforms in India collectively hold health declarations, biometric selfies, criminal record checks, call recordings, and continuous location for millions of gig workers. All of it is collected under a consent framework designed for consumers choosing whether to share an email address.
When the Data Protection Board starts testing whether consent was "free" under §6, the employment-adjacent relationship between a platform and its workers is where that question gets hardest. Platforms building now should assume the answer will not simply be "they clicked agree."
If your product collects data from workers, partners, or anyone whose income depends on the relationship, that consent needs more care than a consumer flow, not less. Our DPDP compliance checklist covers itemised consent and retention, and the free Compliance Score below will show where your policy stands in 60 seconds.
Frequently asked questions
Can gig workers freely consent under the DPDP Act?
This is an open question the Act does not directly resolve. §6 requires consent to be free, but a gig worker whose income depends on platform access is not in the same position as a consumer declining an optional permission. Platforms collecting health, biometric, or continuous location data from workers should expect this to be tested once enforcement begins.
How long can a ride-hailing app keep my location data?
Rule 8 requires a defined retention period tied to the stated purpose. For a completed trip, that purpose ends when the ride and any related dispute or payment window closes. Retaining full trip history for extended periods after account deletion requires a specific justification, not open-ended language.
Does a privacy policy need a last-updated date under the DPDP Act?
Rule 3 requires the notice to be clear, standalone, and understandable so a Data Principal can give specific and informed consent. An undated policy that can be amended unilaterally makes it impossible to establish which version a user actually consented to, which undermines that requirement in practice.