Last updated: 2 October 2026
Owners use Google Sign-In, which provides their verified email address, display name, profile picture and Google account identifier. Each owner account has one organization. Drivers use a separate phone-number login enabled by their transport owner in the same Munshi app. A driver's account is limited to that business and cannot access owner billing, backups or other drivers' records.
Munshi stores challans, invoices, clients, vehicles, locations, signatures, settings, document history, driver profiles, route assignments, and driver salary, payment, advance and due entries on your device. These records sync automatically to your organization on Cloudflare when a connection is available. Android can queue edits offline and schedules network-connected background sync, subject to operating system restrictions.
Conflicting changes are held for your review. Recovery copies are stored locally before conflict resolution and backup restoration. Browser storage can be removed by clearing site data, and local app data can be removed by uninstalling the app. Export recovery copies you need to retain.
Back up now creates a separate restore point. The latest ten backups are retained. Restoring a backup replaces local records and syncs the restored state to other devices. Backups and synchronized records are not end-to-end encrypted by Munshi. Cloudflare processes and stores them as our infrastructure provider.
Organization owners enter driver profiles, assigned challans and salary, payment, advance, deduction and due entries. Drivers can read their own profile, assigned route without freight pricing, and their personal ledger. Internal owner profile notes are not shared with drivers. Drivers may update an emergency contact and upload PDF, JPG or PNG licence and health documents, up to 10 MB per file. Documents are stored in a private Cloudflare R2 bucket. Only the driver and their own organization's owner can download them through authenticated requests; there are no public document links. Documents and emergency contacts are not included in ordinary owner record sync or legacy backups.
Driver documents remain until removed by the driver or until the organization's cloud account is deleted. Owners are responsible for obtaining permission to store and use personal and health information. Driver login initially uses the profile's phone number as its password by the owner's chosen setup. This is predictable; drivers should change it in Settings. Passwords are salted and hashed, login attempts are limited, and owners can disable access. Password changes and access disable revoke existing driver sessions.
Android drivers may explicitly enable route sharing and grant location and notification permissions. The app shows an ongoing notification. While a route is assigned, it collects location coordinates, accuracy and recording time approximately once per minute and sends them to the server. The owner can see the latest location and trail for their assigned driver. Web does not collect background location. Location is not collected when no route is known to be active.
If connectivity is lost during a route, the device may continue recording based on its last known assignment, because it cannot receive an owner's completion or revocation while offline. Offline points are encrypted with an Android Keystore key. On reconnect, the server rejects points captured outside the recorded assignment window, after consent is withdrawn or after login is revoked. Location reads and uploads exclude points older than seven days; server cleanup runs every 15 minutes. The local queue discards expired points while the service runs and is cleared on sign-out or stopping sharing. Force-stopped devices cannot execute cleanup until the app or service runs again.
Drivers can stop sharing in Settings or revoke Android permission. Signing out, disabling driver access or clearing the assignment stops authorized sharing. Android battery restrictions, force-stop, revoked permission or disconnected devices may interrupt updates; a displayed last location is not a guarantee of the driver's current position. Map backgrounds come from OpenStreetMap. Loading a map sends tile requests and the viewing device's IP address to its tile service.
When an owner selects an image for AI challan scanning, it is sent to Google's Gemini API for extraction. The original image is not included in sync or backups by scanning. Saved extracted fields are part of the organization records. Munshi uses PostHog for owner application diagnostics; analytics and session replay are disabled in driver mode. Account, session and service usage records support authentication and operations. Private document contents and location request bodies are not included in application analytics.
Owners can sign out without deleting their local office records. Delete cloud account in owner Settings removes the organization, synchronized records, driver logins, documents, location history, backups, sessions and account history. It does not delete owner records or recovery copies already on devices. Drivers may delete their own uploaded documents and request access removal from their owner. Driver profile and ledger data are held in memory for the signed-in session rather than copied into the owner's local database. Downloaded files may remain wherever you saved or shared them. Clear app storage or browser site data to erase local app data.
We do not sell personal data. Questions can be sent to munshi+ankit@dagar.in.