CenturyMudra Vahan Assistant
Official Privacy Policy & Chrome Web Store Compliance Disclosure for Century Mudra Tech Private Limited.
Century Mudra Tech Private Limited
CIN: U62013GJ2025PTC170532 | RoC-Ahmedabad
Pandya Hotel, Shastri Bridge, Fateganj,
Vadodara, Gujarat – 390002, India
Email: connect@centurymudra.com
1. Overview
Century Mudra Tech Private Limited ("Company", "we", "us", or "our") operates the CenturyMudra Vahan Assistant Chrome Extension (the "Extension"). This Privacy Policy explains how we collect, use, store, and protect information when authorized two-wheeler dealers and their agents ("Users", "Dealers") use the Extension to automate vehicle registration form data and document uploads on the official Vahan portal (vahan.parivahan.gov.in).
2. Authentication, Local Storage & Key Revocation
- API Key Issuance: Authorized dealers generate unique API keys (formatted with prefix
vrk_...) via their secure account management dashboard atvahan.centurymudra.com. - Key Storage & Device Binding: Upon entering the API key into the Extension popup interface, the key and an associated hardware device fingerprint (
X-Device-Fp,X-Device-Id) are validated and bound to authorized client hardware. - Storage Location: API keys and device credentials are stored strictly on the user’s local machine using
chrome.storage.local(under keyvahan_api_key). We do not usechrome.storage.sync, and your authentication tokens are never synced across Google user accounts or devices. - Self-Service Key Revocation: Dealers can view, unbind, or instantly revoke active API keys at any time directly through their account dashboard on
vahan.centurymudra.com. Once revoked, any subsequent API request from the extension using that key is immediately rejected.
3. Customer Data Processing & Document Handling
The Extension acts purely as an automated bridging tool between the dealer’s backend repository and the official Vahan vehicle registration portal.
- Data Types Processed: During an active automated entry session, the Extension fetches dealer-uploaded customer details—including names, mobile numbers, physical addresses, vehicle identification numbers (VIN/Chassis numbers), and government identification proof numbers (Aadhaar, PAN, Voter ID, Driving License, Passport)—as well as uploaded document files (PDFs/Images).
- Transient In-Memory Processing: Customer personal data and vehicle documents fetched securely from backend databases or Cloudflare R2 storage are processed dynamically in the browser's transient memory (RAM) as Blob/File objects.
- Direct DOM Upload: Data and document files are injected directly into the corresponding fields and upload forms of the official Parivahan portal (
vahan.parivahan.gov.in). - Locally Cached Data — Scope Limited: Customer personal documents, Aadhaar/PAN/ID numbers, names, and addresses are never saved or retained locally inside Chrome browser extension storage — those remain transient, RAM-only, as described above. The Extension does locally cache non-personal Vahan application-status metadata (application number, vehicle/registration number, review stage, and status remarks, sourced from the portal's own "pending work" list) inside browser extension storage, purely to display current case status within the Extension's own interface and queue it for sync to our backend (see Section 4). This cache contains no customer names, contact details, or government ID numbers.
- Backend Document Retention: Documents stored in Cloudflare R2 via our dealer portal are retained permanently as official client records unless explicitly deleted by the dealer.
4. Operational Logging & Security Auditing
To maintain system security, verify active subscriptions, prevent key misuse, and support operational debugging, our backend servers (vahan.centurymudra.com and vahan1.centurymudra.com) maintain secure audit logs.
- What We Log: Request timestamps (
lastUsedAt), dealer account IDs, API key identifiers, user IP addresses (lastUsedIp), hardware device fingerprints (X-Device-Fp,X-Device-Id), extension version headers (X-Ext-Version), and VIN automation status updates (e.g., submission status, generated application numbers, error diagnostics). - Purpose: Audit logs are used exclusively for system security, preventing unauthorized API key sharing across unverified devices, providing real-time submission progress on the dealer dashboard, and software troubleshooting.
- Vahan Application Status Sync: To help dealers track a registration case through stages our own systems can't otherwise observe (Vahan's internal review, verification, document-upload, and tax-payment stages), the Extension also transmits application-status metadata it captures from the portal's own "Get Pending Work" list — application number, vehicle/registration number, review stage, disposition, and status remarks — to our backend for the dealer's own case tracking. No customer-identifying or personal data is included in this sync.
- No Third-Party Telemetry: The Extension contains zero third-party tracking scripts, analytics tools (such as Google Analytics or Mixpanel), or external error-logging SDKs. Network permissions are strictly restricted in the extension manifest to
vahan.centurymudra.com,vahan1.centurymudra.com, andvahan.parivahan.gov.in.
5. Third-Party Sharing & Chrome Web Store Disclosures
In strict compliance with Chrome Web Store Developer Program Policies:
6. Security Measures
We implement industry-standard encryption protocols (HTTPS/TLS) for all network requests made between the Extension, our API endpoints, and the Vahan portal. Device binding mechanisms prevent unauthorized access to dealer API keys.
7. Compliance, User Choice & Rights
Dealers and end customers may request data account deletion or request details on processed records by contacting our privacy compliance team at connect@centurymudra.com. Additionally, dealers can manage or revoke API key credentials self-service at any time via the web portal dashboard.
8. Contact Us
If you have any questions or concerns regarding this Privacy Policy or data processing practices, please contact us at:
Century Mudra Tech Private Limited
Pandya Hotel, Shastri Bridge, Fateganj,
Vadodara, Gujarat – 390002, India
CIN: U62013GJ2025PTC170532
Email: connect@centurymudra.com