Independent civic-tech prototype — Not an official government or NMC platform.
Nagpur RoadWatch Logo
Back to Home

Privacy Policy

How Nagpur RoadWatch handles information submitted through the platform.

Last updated:28 August 2026
Independent Civic-Tech InitiativeNagpur RoadWatch is an independent civic-tech initiative and is not an official government, NMC, or Nagpur Traffic Police platform.

Note: Privacy Policy is maintained in clear English for legal precision.

1. Information We Receive

Depending on how you interact with Nagpur RoadWatch, the platform receives and stores information submitted when generating a report:

  • Report details: problem category, text description, date and time of observation
  • Location data: latitude, longitude, landmark, and street address in Nagpur
  • Vehicle registration details (optional, where provided for traffic issues)
  • Evidence media: uploaded photos, videos, or external evidence link URLs
  • User Interface preferences: selected language preference (English, Hindi, or Marathi)
  • Technical server logs: basic server log entries (such as HTTP request headers and IP addresses) standard for web hosting infrastructure

2. Location Information

Location details are provided voluntarily as part of submitting a report. Location information helps the platform map where road and traffic issues occur across Nagpur to visualize problem clusters.

RoadWatch does NOT continuously track your location or monitor device background location.

Geographic coordinates are only captured when you explicitly select a map location or grant browser location access while submitting a report.

3. Media Processing & EXIF Metadata Removal

Uploaded photo evidence is processed via automated media tools before being saved to storage (./public/uploads).

EXIF Metadata Stripping

Uploaded photos undergo image optimization via Sharp, which automatically rotates the image according to original orientation and strips embedded EXIF metadata (such as camera serial numbers, camera settings, and raw camera GPS metadata) before public serving.

4. Vehicle Registration Numbers

Where users include a vehicle number in a report, RoadWatch handles the number with dedicated privacy controls:

  • Admin View: Authorized administrators can view normalized vehicle numbers for moderation and verification purposes.
  • Public View: Vehicle numbers are automatically masked on public APIs and report detail pages (e.g., MH31AB1234 is displayed publicly as MH31XX1234).

Vehicle masking reduces public visibility of registration details, though it does not represent complete mathematical anonymization.

5. External Evidence Links

If you submit a link from a supported external platform (Instagram, Facebook, X/Twitter, Reddit, LinkedIn, or Google Drive), RoadWatch stores the URL string to display external evidence. RoadWatch does not automatically claim ownership or host external third-party content. Opening external links takes you to third-party services governed by their own privacy policies.

6. Public Visibility & User Guidance

Submitted report descriptions, categories, public location names, timestamps, and evidence media are designed to be publicly visible on the RoadWatch map and feeds.

Do NOT Submit Sensitive Personal Information

Please do NOT include personal sensitive details in report descriptions or photos, such as phone numbers, home street addresses, Aadhaar numbers, PAN numbers, passwords, financial details, or private personal conversations.

7. Data Usage

Information collected on RoadWatch is used strictly to:

  • Display public reports and map visualizer entries
  • Generate civic statistics (Traffic Pulse metrics and category counts)
  • Identify geographic clusters of road and traffic issues
  • Moderate and verify citizen reports
  • Improve platform operation and usability

RoadWatch does NOT sell, trade, or rent user data to third-party advertisers or data brokers.

8. Infrastructure & Service Providers

RoadWatch utilizes technical infrastructure services required to host and run the application, including local/disk file storage for media uploads, database hosting for structured report records, and standard open tile providers (e.g., OpenStreetMap / MapLibre) to render map interface layers.

9. Cookies & Local Storage

RoadWatch uses minimal, essential browser storage mechanisms:

  • nagpur_roadwatch_lang (Local Storage): Stores your selected UI language preference (EN/HI/MR).
  • rw_admin_token (HTTP-only Cookie): Secure authentication token used exclusively for administrative session management.

RoadWatch does NOT use third-party advertising cookies or cross-site tracking scripts.

10. Data Security

RoadWatch implements practical technical security controls to safeguard data, including:

  • HTTPS encryption in production deployments
  • bcrypt password hashing for administrative access
  • HTTP-only cookies for admin token storage
  • Strict file MIME-type validation and size restrictions (10MB photo / 50MB video)
  • EXIF metadata removal for uploaded photos
  • Public vehicle registration number masking

11. Data Retention

Reports and uploaded evidence may be retained for as long as reasonably necessary to operate, maintain, analyze, and demonstrate the RoadWatch project. A formal data retention schedule will be published prior to large-scale public rollout.

12. User Privacy Requests

As RoadWatch expands from prototype status, formal procedures for requesting content removal, data correction, or privacy inquiries will be established and detailed on this page.

13. Children's Privacy

RoadWatch is a general audience civic platform and is not directed at children under the age of 13. We do not knowingly collect personal information from children.

14. Third-Party Services

External platforms linked by users (Instagram, Facebook, X, Reddit, LinkedIn, Google Drive) are independent services governed by their own privacy policies. RoadWatch is not responsible for the privacy practices of external platforms.

15. Policy Updates

This Privacy Policy may be updated periodically to reflect application enhancements. The current revision will always be posted at /privacy.

This document is intended to describe how this prototype currently operates and should be reviewed by qualified legal counsel before large-scale public deployment.