Back to Portal LoginEffective Date: August 10, 2026

CenturyMudra Vahan Assistant

Official Privacy Policy & Chrome Web Store Compliance Disclosure for Century Mudra Tech Private Limited.

Operating Entity

Century Mudra Tech Private Limited

CIN: U62013GJ2025PTC170532 | RoC-Ahmedabad

Registered Office & Contact

Pandya Hotel, Shastri Bridge, Fateganj,

Vadodara, Gujarat – 390002, India

Email: connect@centurymudra.com

1. Overview

Century Mudra Tech Private Limited ("Company", "we", "us", or "our") operates the CenturyMudra Vahan Assistant Chrome Extension (the "Extension"). This Privacy Policy explains how we collect, use, store, and protect information when authorized two-wheeler dealers and their agents ("Users", "Dealers") use the Extension to automate vehicle registration form data and document uploads on the official Vahan portal (vahan.parivahan.gov.in).

2. Authentication, Local Storage & Key Revocation

  • API Key Issuance: Authorized dealers generate unique API keys (formatted with prefix vrk_...) via their secure account management dashboard at vahan.centurymudra.com.
  • Key Storage & Device Binding: Upon entering the API key into the Extension popup interface, the key and an associated hardware device fingerprint (X-Device-Fp, X-Device-Id) are validated and bound to authorized client hardware.
  • Storage Location: API keys and device credentials are stored strictly on the user’s local machine using chrome.storage.local (under key vahan_api_key). We do not use chrome.storage.sync, and your authentication tokens are never synced across Google user accounts or devices.
  • Self-Service Key Revocation: Dealers can view, unbind, or instantly revoke active API keys at any time directly through their account dashboard on vahan.centurymudra.com. Once revoked, any subsequent API request from the extension using that key is immediately rejected.

3. Customer Data Processing & Document Handling

The Extension acts purely as an automated bridging tool between the dealer’s backend repository and the official Vahan vehicle registration portal.

  • Data Types Processed: During an active automated entry session, the Extension fetches dealer-uploaded customer details—including names, mobile numbers, physical addresses, vehicle identification numbers (VIN/Chassis numbers), and government identification proof numbers (Aadhaar, PAN, Voter ID, Driving License, Passport)—as well as uploaded document files (PDFs/Images).
  • Transient In-Memory Processing: Customer personal data and vehicle documents fetched securely from backend databases or Cloudflare R2 storage are processed dynamically in the browser's transient memory (RAM) as Blob/File objects.
  • Direct DOM Upload: Data and document files are injected directly into the corresponding fields and upload forms of the official Parivahan portal (vahan.parivahan.gov.in).
  • Locally Cached Data — Scope Limited: Customer personal documents, Aadhaar/PAN/ID numbers, names, and addresses are never saved or retained locally inside Chrome browser extension storage — those remain transient, RAM-only, as described above. The Extension does locally cache non-personal Vahan application-status metadata (application number, vehicle/registration number, review stage, and status remarks, sourced from the portal's own "pending work" list) inside browser extension storage, purely to display current case status within the Extension's own interface and queue it for sync to our backend (see Section 4). This cache contains no customer names, contact details, or government ID numbers.
  • Backend Document Retention: Documents stored in Cloudflare R2 via our dealer portal are retained permanently as official client records unless explicitly deleted by the dealer.

4. Operational Logging & Security Auditing

To maintain system security, verify active subscriptions, prevent key misuse, and support operational debugging, our backend servers (vahan.centurymudra.com and vahan1.centurymudra.com) maintain secure audit logs.

  • What We Log: Request timestamps (lastUsedAt), dealer account IDs, API key identifiers, user IP addresses (lastUsedIp), hardware device fingerprints (X-Device-Fp, X-Device-Id), extension version headers (X-Ext-Version), and VIN automation status updates (e.g., submission status, generated application numbers, error diagnostics).
  • Purpose: Audit logs are used exclusively for system security, preventing unauthorized API key sharing across unverified devices, providing real-time submission progress on the dealer dashboard, and software troubleshooting.
  • Vahan Application Status Sync: To help dealers track a registration case through stages our own systems can't otherwise observe (Vahan's internal review, verification, document-upload, and tax-payment stages), the Extension also transmits application-status metadata it captures from the portal's own "Get Pending Work" list — application number, vehicle/registration number, review stage, disposition, and status remarks — to our backend for the dealer's own case tracking. No customer-identifying or personal data is included in this sync.
  • No Third-Party Telemetry: The Extension contains zero third-party tracking scripts, analytics tools (such as Google Analytics or Mixpanel), or external error-logging SDKs. Network permissions are strictly restricted in the extension manifest to vahan.centurymudra.com, vahan1.centurymudra.com, and vahan.parivahan.gov.in.

5. Third-Party Sharing & Chrome Web Store Disclosures

In strict compliance with Chrome Web Store Developer Program Policies:

Limited Use Disclosure:The use of information received from Chrome APIs adheres strictly to the Chrome Web Store User Data Policy, including the Limited Use requirements.
No Data Monetization / Resale:We do NOT sell, rent, lease, trade, or monetize customer data, dealer credentials, or vehicle information to any third party under any circumstances.
No Unrelated Uses:Customer data processed by the Extension is never used for targeting advertisements, evaluating creditworthiness, or financial lending purposes.
Approved Single Purpose Use:User and customer data is processed strictly and solely to fulfill the single purpose of automating vehicle registration workflows on the official Parivahan portal as initiated by the dealer.

6. Security Measures

We implement industry-standard encryption protocols (HTTPS/TLS) for all network requests made between the Extension, our API endpoints, and the Vahan portal. Device binding mechanisms prevent unauthorized access to dealer API keys.

7. Compliance, User Choice & Rights

Dealers and end customers may request data account deletion or request details on processed records by contacting our privacy compliance team at connect@centurymudra.com. Additionally, dealers can manage or revoke API key credentials self-service at any time via the web portal dashboard.

8. Contact Us

If you have any questions or concerns regarding this Privacy Policy or data processing practices, please contact us at:

Century Mudra Tech Private Limited

Pandya Hotel, Shastri Bridge, Fateganj,

Vadodara, Gujarat – 390002, India

CIN: U62013GJ2025PTC170532

Email: connect@centurymudra.com