This page is published in English at launch. Hindi (हिंदी) versions will follow — legal text is translated last, deliberately, so nothing is lost in wording.
We collect little, deliberately. This policy says exactly what we hold, why, who sees it, and what we refuse to hold. It is part of our Terms & Conditions, and we handle your data in line with India's Digital Personal Data Protection Act, 2023.
1. What we collect from guests
- Account: your mobile number (your login identity) and name. Email is optional — added only if you choose, and used for booking copies and formal notices.
- Booking details: for each guest, their name, and — if you give them — their age and gender (for the property's guest register), plus your dates, rooms, and amounts.
- Saved travellers: if you choose to save co-travellers to your account for faster booking, their name, age, and gender.
- Payment records: payment references (gateway payment IDs or UPI transaction references/UTR) and amounts, and — if you pay by UPI directly to the property — the screenshot of the payment you upload, which can show your name and UPI ID. We never receive or store card numbers, bank credentials, or UPI PINs — online payments are processed by Razorpay under their own privacy policy.
- Sign-in and devices: a short description of the device and browser you signed in from, and when it was last used — you can see this list under Logged-in Devices. To stop abuse of sign-in codes we also count requests per network address; that count is kept for one hour and never stored with your account. Separately, for security, our servers log each request to the site — the network address, the page asked for, and the time.
- Your consents: when you tick the box at sign-in or at booking, we record that you did, when, and which version of these terms you agreed to.
2. What we collect from hotel owners
- Account and business details: name, mobile number, email (required for booking records and payout summaries), the business's legal name and type, and the WhatsApp number guests can reach the property on.
- Payout details: your UPI ID and a masked bank account number, for transferring your earnings.
- Verification documents: government ID (we ask for a masked Aadhaar, showing only the last 4 digits, or a passport), PAN, and tourism registration certificate — used only to check who runs the property. Only you and our admin team can open them, and every time one is opened it is recorded.
- Listing content: property details, room information, prices, and photos you upload.
- Notifications: if you allow push notifications on the owner app, the browser address needed to deliver them.
- Activity record: changes made from the owner panel are logged, so that every change to a booking or listing can be traced.
3. What we deliberately do NOT collect
Guests' government ID numbers, or which ID they carry. Card or bank credentials of guests. Your location. Date of birth, marital status, or other profile data unrelated to a stay. No advertising, analytics, or tracking cookies — the only cookie we set keeps you signed in. We do not buy data about you, and we do not sell or rent your data to anyone.
4. How we use it
To create and manage bookings and vouchers; to sign you in with a one-time password sent on WhatsApp; to send booking messages on WhatsApp and SMS (and email if you've added one); to let the property host you; to process payments, refunds, and payouts to owners; to verify listings; to meet legal and tax record requirements; and to prevent fraud (for example, a reused payment reference). We use your data for nothing else.
5. Who sees it
- The property you book — your booking and the guest details on it. Hotel owners do not see your phone number or email.
- Razorpay — to process online payments and refunds.
- Our service providers, each seeing only what its job needs: Twilio (WhatsApp and SMS delivery, including your sign-in code), Google (email delivery, and push notifications to hotel owners through Firebase), and DigitalOcean (the servers that host the site, its database, and uploaded files).
- Government or judicial authorities, where the law requires it.
No one else. Twilio and Google may process data outside India, for example in the United States; Indian law allows this, except to countries the Government restricts, and we will stop using any provider in a country that is restricted.
6. How long we keep it, and deleting your account
We delete data automatically once its purpose is served:
| What | Kept for |
|---|---|
| Booking, payment, and refund records | 8 years after the stay, as tax law requires. After that the guest names, ages, and genders on the booking are erased; the amounts and dates stay. |
| Guest details on a booking that was never paid | 30 days after the hold expired |
| UPI payment screenshots | 180 days after the stay |
| Hotel owners' verification documents | 30 days after one is rejected or replaced; otherwise 1 year after the owner's last listing closes |
| Signed-out or expired sign-ins, and switched-off notification addresses | 90 days |
| Messages we sent you (booking updates) | 1 year |
| Records of changes made in the owner and admin panels, and of who opened a document | at least 1 year |
| Server logs (network address, page requested, time) | 1 year, as Indian security rules require |
| Records of the consents you gave | as long as we hold any data the consent covered |
You can delete your account from your profile. When you do, we remove your phone number, email, and name from the account, erase your saved travellers, and sign you out on every device. Past bookings stay for the period above, but are no longer linked to any phone number or email.
You cannot delete your account while you have an upcoming or ongoing stay, or a payment still being verified — complete or cancel it first. Hotel owners who want to close their account should contact us, because a live listing depends on it. Backup copies of our database are kept for up to 14 days and then deleted.
7. Your choices and rights
- See and correct your details in your account at any time; add or remove your email; save or delete travellers.
- Sign out of any device under Logged-in Devices.
- Choose your language (Hindi or English) for the site.
- Download your data: under My Profile → Your data, a file with everything we hold about you and who we share it with.
- Withdraw your consent: by deleting your account (section 6). Withdrawing does not undo what was lawfully done before it, and a booking already made stays on record for the period above, because the law requires it.
- Ask us to correct or erase your data, or to name someone to act for you if you die or become unable to — and raise any privacy concern.
Our Grievance Officer is [name of grievance officer]. Write to [email] or WhatsApp +91 84393 31979. We acknowledge within 48 hours and respond within 30 days. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
8. Security
OTP-only sign-in (no password database to breach), sign-in tokens stored only in hashed form, encrypted connections (HTTPS), access limited to the people who run the Platform, and a record of every time a verification document or payment screenshot is opened. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.
9. Children
Accounts are for adults (18+), and you confirm you are one when you sign in. Children stay as guests under a booking made by an adult, who gives consent for them as their parent or guardian when booking; we hold only the name, age, and gender given for the stay, use it for nothing else, and never use it for tracking or advertising.
10. Changes and contact
When this policy changes, the "Last updated" date changes; material changes will be announced on the site and by message. Questions: [email] · WhatsApp +91 84393 31979 · [address], Rudraprayag, Uttarakhand.