Ellite Sphere Mobility Pvt. Ltd.
Privacy policy
This describes exactly what the Ellite Rider app and our staff console collect, why each item is needed, who else sees it, and when it is deleted. It covers the platform run by Ellite Sphere Mobility Pvt. Ltd. â not the Yango app, which is Yango’s own.
In effect 2 September 2026 · Last updated 2 September 2026
Who this applies to
It applies to riders who hold an account in the Ellite Rider app, customers who buy from our parts store, and Ellite Sphere staff who use the console. Ellite Sphere Mobility Pvt. Ltd. is responsible for the information described here.
The Yango driver app is a separate product with its own privacy terms. This policy does not cover it. What we receive from Yango is described in section 4.
What we collect
When you create a rider account
- Your mobile number. It is your login, and the only way we can send a one-time passcode.
- Your name and, once documents are checked, your verified name and date of birth.
- A rider ID we issue.
When you are verified
- Driving licence number and a photograph or scan of it.
- Bluebook (vehicle registration) number and document.
- Insurance policy number, expiry date and document.
- Vehicle make, model, year and plate number.
- A photograph of you, for the rider record.
- An emergency contact name and phone number, used if you are in an accident.
While you use the platform
- Support tickets: the category, what you wrote, any trip reference, files you attach, every message on the ticket and its full status history.
- Trip records received from Yango or imported under a controlled process, and whether each trip passed verification.
- Ellite Points: every entry in your points ledger, with its reason, reference, the balance before and after, and who approved it.
- Orders: what you bought, your delivery address, the tax invoice and the order’s progress.
- Payments: the reference and result Khalti returns for each payment, and any refund.
- Notifications we sent you and whether they were delivered.
Automatically, for security
- Sessions: a one-way hash of your session token, the device and browser string, the IP address the session started from, and its times. The token itself is never stored, so a copy of our database cannot be used to sign in as you.
- One-time passcodes: your number, a one-way hash of the code, its five-minute expiry, how many attempts were made and the IP address that requested it.
- An audit record of actions taken on tickets, points, payments, orders, refunds and accounts: who did what, when, and what changed.
Staff accounts
Name, work email, a one-way hash of the password, an encrypted second-factor secret, failed sign-in counts, and the audit record of everything the account does.
What we never collect
We never hold your card number, CVV, PIN, wallet password or online banking credentials. Those are entered on Khalti’s own screens and never reach our systems. We receive only the transaction reference and whether it succeeded.
We do not track your location in the background, and we do not sell personal information or use it for advertising to anyone.
Why we need each of these
- Mobile number
- To sign you in, to reach you about a ticket, and to keep one number to one account.
- Documents and vehicle
- To verify you are entitled to ride, to issue a rider ID, and to track insurance expiry.
- Emergency contact
- To reach someone on your behalf after an accident.
- Tickets and messages
- To resolve what you raised and to show a complete history if it is disputed.
- Trips and points
- To allocate points only for verified trips, and to prove how a balance was reached.
- Orders and payments
- To fulfil what you ordered, issue a tax invoice, and reconcile against the gateway.
- Session and passcode records
- To detect abuse, block brute-force attempts, and let you end sessions on lost devices.
- Audit records
- So that no staff action on your money, points or account is untraceable.
Who else sees it
Only these, and only for the reason named:
- Yango
- Completed-trip records come from Yango so that trips can be verified and Ellite Points allocated. Ellite Sphere is a Yango partner agency; Yango operates its own app and its own privacy terms.
- Khalti
- Store payments are processed by Khalti. Card and bank details are entered on Khalti's own screens and never reach us. We receive only the transaction reference and its result.
- Sparrow SMS
- One-time passcodes and ticket notifications are delivered as SMS. The gateway receives the mobile number and the message text.
- Amazon Web Services
- The application, its database and uploaded documents run on AWS in the Mumbai region (ap-south-1), the closest region to Nepal.
We also disclose information where Nepali law requires it, for example a valid order from a court or a competent authority. We will tell you when we are permitted to.
Where it is stored
The application, its database and uploaded documents run on Amazon Web Services in the Mumbai region (ap-south-1), the closest AWS region to Nepal. This means your information is stored outside Nepal. It is encrypted in transit and at rest, and access is restricted to the staff roles that need it.
How long we keep it
- One-time passcodes
- Expire five minutes after they are issued and are cleared thereafter.
- Sessions
- Sixty days for riders, twelve hours for staff. Signing out ends the session immediately.
- Documents and profile
- Kept while your account is open. Erased within 30 days of an approved deletion request.
- Tickets and messages
- Kept while your account is open and for as long as needed to settle any dispute they relate to.
- Orders, invoices and payments
- Retained for the period Nepali tax and company law requires, even after an account is closed. We cannot delete a tax invoice on request.
- Audit records
- Kept permanently and cannot be altered. After erasure they refer to you only by an internal identifier, not by name, number or document.
Your choices
- See what we hold. Ask us and we will tell you what is on your record.
- Correct it. If a name, number, document or vehicle detail is wrong, we will fix it. Corrections are logged.
- Close your account. The process, what is erased and what must be kept are set out in full on the account deletion page.
- End a session. If you lose your phone, tell us and we will revoke its sessions.
- Complain. If you think we have handled your information wrongly, tell us first, because we would rather fix it, and you retain your right to complain to the relevant Nepali authority.
Riders under 18
The platform is for people who hold a valid Nepali driving licence, which is not issued to anyone under 18. We do not knowingly create accounts for children. If we learn that we have, we close the account and erase what we hold.
Changes to this policy
When this changes we update the date at the top of the page. If a change materially affects what we collect or who sees it, we will tell riders in the app and by SMS before it takes effect.
Contact us
- Address
- Shankhamul, Lalitpur, Nepal
- Phone
- 9712604900 · 9712604901
- Message us