Sewak Sawari ("the Platform", "we", "us", "our") is a government ride-sharing and fleet-management system owned and operated by the Office of the Prime Minister and Council of Ministers (OPMCM), Government of Nepal. It connects government drivers and authorised passengers for official transport, and provides administrative oversight through a secure management portal.
We are committed to protecting the privacy of every person who uses the Platform. This Policy describes what information we collect, why we collect it, how it is used and safeguarded, and the rights available to you under the laws of Nepal. By using the Platform, you acknowledge the practices described here.
👥 Who This Applies To
Government Employees
Authorised passengers who book and take official rides through the mobile app.
Drivers & Operators
Government drivers who provide rides and share live location while on duty.
System Administrators
OPMCM staff who manage fleet, users, reports and oversight via the portal.
The following terms are used throughout this Policy with the meanings given below.
| Term | Definition |
|---|---|
| Platform | The Sewak Sawari system — mobile applications (Driver & Passenger) and the OPMCM administration web portal. |
| Personal Data | Any information relating to an identified or identifiable natural person (e.g. name, employee number, phone number, location). |
| Processing | Any operation performed on personal data — collection, storage, use, disclosure, or deletion. |
| Data Controller | OPMCM, Government of Nepal, which determines the purposes and means of processing personal data. |
| Trip Data | Information generated by a ride — pickup/drop locations, route, distance, fare, timing and the parties involved. |
| OTP | One-Time Password — a temporary numeric code sent by SMS to verify a user's identity. |
| GPS Data | Geolocation coordinates (latitude/longitude), speed, bearing and accuracy collected from a device. |
We collect only the information needed to operate an official transport service securely. Categories of data are described below.
🪪 Identity & Registration Information
- Employee number and full name, used as the primary government identity.
- Mobile phone number for OTP verification and ride coordination.
- Email address and gender (where provided in your profile).
- Profile photo (optional), for identification.
- Office / department and grade, retrieved from the government Personnel Information System (PIS).
🚗 Driver & Vehicle Information
- Driving licence number, expiry date and licence photo.
- Vehicle details — registered number, brand, model, colour, type and service type.
- Blue-book (registration) documents and expiry dates.
- Online/offline duty status and assigned vehicle linkage.
📍 Location & Trip Data
- Real-time GPS location of drivers while on duty (latitude, longitude, speed, bearing, accuracy).
- Pickup and drop-off addresses and coordinates for each ride request.
- Route, distance, duration, fare and trip history.
- Saved addresses (e.g. Home / Office) added by passengers.
📱 Device & Technical Data
- Device model, OS version, app version and battery level (for ride reliability).
- Firebase Cloud Messaging (FCM) token for push notifications.
- IP address and request logs for security and abuse prevention.
- Platform integrity signals (Play Integrity / App Attest) to block tampered apps.
🔐 Authentication & Security Data
- Hashed passwords and OTP verification records — plaintext passwords are never stored.
- Session and refresh tokens (JWT) and login/activity timestamps.
- API access records used to detect and prevent unauthorised use.
Your information is used strictly for the purposes below and never for advertising or commercial profiling.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Service delivery — match rides, navigate, calculate fare | Identity, location, trip & vehicle data | Public task / consent |
| Authentication — verify identity, secure login | Phone, OTP, password hash, tokens | Legal obligation |
| Administrative oversight — fleet & duty management | Driver, vehicle, trip & status data | Public task |
| Reporting & analytics — aggregated usage reports | Trip history, distance, counts (aggregated) | Public task |
| Service improvement — reliability & safety | Device & technical data | Legitimate interest |
| Legal compliance — respond to lawful requests | As required by law | Legal obligation |
We process personal data under one or more of the following legal bases recognised by the laws of Nepal:
- Performance of a public task — operating an official government transport service.
- Consent — for optional features such as location sharing and push notifications, which you may withdraw.
- Legal obligation — compliance with the Individual Privacy Act, 2075 (2018), the Electronic Transactions Act, 2063 (2008), and related directives.
- Legitimate interest — securing the Platform and preventing fraud or misuse, balanced against your rights.
Location data is central to a ride-sharing service. We handle it with particular care.
📡 Collection
- A driver's live location is collected only while on active duty (online) and stops when they go offline.
- A passenger's location is used at the moment of requesting a ride to set pickup and to track the assigned vehicle.
- Coordinates are stored transiently in a fast geo-cache and as trip history for completed rides.
🎛️ Your Control
- Drivers can stop location sharing at any time by going offline.
- Passengers control location through their device's OS permission settings.
- Background location is used only when necessary to complete an active ride.
Sewak Sawari is a closed government system. We share personal data only in the limited circumstances described below.
- Within OPMCM & authorised agencies — for fleet management, oversight and reporting.
- Between ride participants — a driver and passenger see each other's name, phone and live location only for the duration of an active ride.
- Service providers (processors) — trusted infrastructure used strictly to operate the Platform (see Section 13), bound to protect data.
- Law enforcement / courts — when required by a valid legal order under Nepali law.
We keep personal data only as long as necessary for the purpose it was collected, or as required by government records policy.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & identity data | While the account is active | Service delivery |
| Live GPS location | Transient (short-lived cache) | Real-time tracking only |
| Trip history | Up to 5 years | Audit, reporting & oversight |
| OTP & session tokens | Minutes to hours | Short-lived authentication |
| Security & access logs | Up to 1 year | Security & incident investigation |
We apply layered technical and organisational safeguards to protect your information.
🔧 Technical Safeguards
- Encryption in transit via
TLS / HTTPSfor all connections. - AES-256 encryption for sensitive values and an encrypted, time-bound mobile API-key handshake.
- Hashed passwords and short-lived
JWTtokens with refresh rotation. - Mandatory API-key on every mobile request, with anti-replay nonces and rate limiting.
- Security headers, CSRF protection and app-integrity attestation.
🏛️ Organisational Safeguards
- Role-based access control — staff access only the data their role requires.
- Least-privilege database access and audit logging of administrative actions.
- Periodic security assessment (VAPT) and remediation.
Under the Individual Privacy Act, 2075, you have the following rights over your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Correction
Ask us to correct inaccurate or incomplete information.
Right to Explanation
Understand how and why your data is processed.
Right to Erasure
Request deletion where retention is no longer required by law.
Right to Restrict
Limit processing of your data in certain circumstances.
Right to Portability
Receive your data in a structured, commonly used format.
The Sewak Sawari mobile applications request the following device permissions, each used only for the stated purpose.
| Permission | Why it is requested |
|---|---|
| 📍 Location | Required for ride matching, navigation and live tracking during active trips. |
| 📷 Camera | To capture document/profile photos during KYC and registration. |
| 🖼️ Storage / Photos | To upload licence, vehicle and profile images. |
| 🔔 Notifications | To deliver ride requests, status updates and alerts via push. |
| 📞 Phone | To enable in-app calling between driver and passenger during a ride. |
Sewak Sawari is an official government service available only to authorised government employees and drivers. It is not directed at or intended for children under 18 years of age, and we do not knowingly collect personal data from minors.
The Platform relies on the following trusted services to function. Each processes only the data necessary for its role.
| Service | Role | Data Shared |
|---|---|---|
| Government SMS Gateway (DoIT) | Delivers OTP and notification SMS. | Phone number, OTP |
| Maps & Routing (Geo / OSRM) | Geocoding, route and distance calculation. | Coordinates only |
| Firebase Cloud Messaging | Delivers push notifications to devices. | Device FCM token |
| Personnel Information System (PIS) | Validates government employee identity. | Employee number |
We may update this Privacy Policy from time to time to reflect changes in the service, technology, or the law. The latest version, with its effective date and version number, is always published on this page.
- Material changes will be communicated through the app and/or the portal notice board.
- The "Effective Date" and version at the top of this document indicate the current revision.
- Continued use of the Platform after an update constitutes acknowledgement of the revised Policy.
For any question, request, or complaint regarding this Privacy Policy or your personal data, please contact us.