We design, build and operate our Services with security in mind, in line with the security obligations of India's Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable advertising-platform requirements. We aim to protect data against unauthorized access, disclosure, alteration, loss and destruction.
Our Services run on cloud infrastructure providers that maintain recognised industry certifications (such as ISO 27001 and SOC 2) for their own operations. Production environments are kept logically separated from development and testing environments, and infrastructure limits public exposure of servers, databases and internal services.
In transit: the Services run over HTTPS/TLS with strong, modern cipher suites. At rest: sensitive data and backups use industry-standard encryption. Credentials: passwords are stored using strong one-way hashing and are never kept in plain text.
Firewalls and security groups restrict traffic to necessary levels. We address common vulnerabilities including XSS, SQL injection and CSRF, and user-submitted data is validated and sanitised as part of our development and release process.
Access follows least-privilege, need-to-know principles. Administrative access is restricted to authorised personnel using strong authentication, including multi-factor authentication where available, with periodic access reviews and prompt revocation.
We maintain activity and access logs across our systems for monitoring, troubleshooting and investigation, and monitor for anomalies, abuse, invalid traffic and security events. Logs are protected against tampering and kept for a reasonable retention period.
We collect and retain only the data necessary for our operations and legal obligations. Data that is no longer needed is deleted or de-identified in line with our Privacy Policy.
Automated, regular backups of critical data are taken with encryption and secure storage. Restoration capability is periodically tested, and we maintain measures to support availability and recovery during disruptions.
Operating systems, web servers, databases, libraries and dependencies receive security patches on an ongoing basis, and identified vulnerabilities are addressed on a risk-prioritised basis.
Third-party advertising and analytics technologies are integrated using official SDKs, tags and APIs. Configurations aim to meet platform requirements for invalid-traffic detection and identifier handling. We are not responsible for the internal security practices of third-party platforms.
We maintain an incident-response process to identify, contain, investigate and remediate security incidents. Where a personal-data breach is likely to cause risk to individuals, we will notify the relevant supervisory authority and affected individuals as required by applicable law within prescribed timelines.
Security is a shared responsibility. Please maintain a strong, unique password, keep your devices and software up to date, avoid phishing attempts, and use only our official communication channels.
If you believe you have found a security vulnerability, please report it to info@activecargomovers.online with reproduction steps, and allow us reasonable time to investigate before any public disclosure. Testing must not access unauthorised data or disrupt our Services.
No method of transmission or storage is completely secure. While we apply the protective measures above, absolute security cannot be guaranteed. Use of our Services remains governed by our Terms of Service and Privacy Policy. We do not currently claim to hold any specific security certification (such as ISO 27001 or SOC 2) ourselves — the certifications referenced above relate to our infrastructure providers, not to Active Cargo Movers.
Security reports and general enquiries: info@activecargomovers.online.
Last updated: this document is a template adapted for Active Cargo Movers and has not been reviewed by a lawyer. Please have it reviewed by a qualified professional before relying on it.