Insurers and regulated fleets ask where their data lives before they ask almost anything else. We run programs across India, Colombia, Israel, South Africa, Southeast Asia, and the US — markets with different, sometimes conflicting, data-localization expectations. This page is the straight answer to where data sits, who can see it, and what your options are.
Detection, scoring, and behavioral analysis run on-device, after the trip ends, by default. The phone does the work; the backend is for upload and reporting, not for primary analysis. That means the raw sensor stream — accelerometer, gyroscope, GPS — never has to leave the device at all for scoring to happen. Only the completed trip record and derived scores are queued for upload.
Some enrichment — map matching, posted speed limits — needs data the device can’t bundle, so it happens server-side after the trip is already scored. A trip is complete and usable without it; enrichment augments the record later if and when it lands.
Hastle Free is multi-tenant by design, and each tenant runs in its own isolated database schema — not a shared table with a tenant-ID column. One customer’s data is never queryable from another tenant’s context, and there’s no cross-tenant query path to misconfigure. An insurance pricing program and a consumer app can run on the same system, side by side, without either one able to see so much as a row of the other’s data.
Where local law requires data to stay in-country — India’s Digital Personal Data Protection Act being the most immediately relevant example across our footprint — we work with the customer to meet that requirement, either through regional hosting or self-hosted deployment. We evaluate this case by case at contracting time rather than making a blanket claim here, because the right answer depends on your specific regulator and program.
Hosted deployments run on established cloud infrastructure providers with regional data-center options, under data-processing agreements consistent with our Privacy Policy. A current list of sub-processors for your program is available on request.
When a hosted deployment does move data across a border — for backup, support, or engineering access — we rely on contractual safeguards consistent with the source market’s transfer requirements. Self-hosted and regionally pinned deployments are the way to avoid cross-border movement entirely, where that’s the requirement.
If data residency is a gating requirement for your program — a regulator sign-off, a board policy, an RFP line item — raise it on the first call. We’d rather confirm feasibility up front than after a pilot is underway. Reach us at hello@sastram.in.