By using the Platform and giving consent where we ask for it, you agree to the handling of your data described here. If you do not agree, please do not use the Platform. This Policy should be read together with our Terms of Use.
1. Who This Policy Covers
- Guests: People who search, book or stay through the Platform, including people you book for.
- Visitors: People who browse the Platform without booking.
- Hotel Owners and Partners (“Partners”): And their staff who use our dashboard, property management tools, or WhatsApp inventory commands.
If you give us details of another person (for example, a co-guest), you confirm that you are authorised to do so and that they know about this Policy.
2. Personal Data We Collect
We collect data to provide authentic, verified stays. Here is the clear classification of the personal data we collect:
| Category | Examples | When Collected |
|---|---|---|
| Identity & Contact | Name, mobile number, email, city, age/date of birth | Registration, booking, customer support |
| Government ID | Aadhaar (or masked copy), driving licence, passport, voter ID, photo on ID | Check-in verification, as required by Indian law and Property rules |
| Booking Details | Property, dates, room type, number of guests, special requests, couple/family status where relevant, check-in/check-out verification | During booking and stay operations |
| Payment Details | Payment method type, transaction ID, UPI ID reference, masked card details, refund status | Payment and refund processing |
| Device & Usage | IP address, device model, OS, app version, pages viewed, search filters, clicks, crash logs, cookies | Automatically upon use |
| Location | Approximate location from IP; precise GPS location only if permitted on your device | Nearby hotel search, map navigation |
| Communications | Messages, WhatsApp chats, emails, call recordings, feedback, ratings, reviews, photos you upload | Support and guest reviews |
| Partner Data | Business name, owner details, PAN, GST number, bank account details, property documents, staff contact details, inventory and rate data | Partner onboarding and payouts |
We do not store your full card number, CVV, UPI PIN or netbanking password. Those are handled directly by PCI-DSS certified payment providers. We do not intentionally collect sensitive data such as health, religion or biometric data. If you voluntarily share an accessibility need or dietary request, we use it only to fulfil that specific request.
3. How We Collect It
- Directly from you (registration forms, OTP login, chats, calls, WhatsApp).
- From your device and browser automatically via security logs and analytics.
- From Partners (for example, check-in and check-out confirmation, and room condition).
- From payment gateways, banks and wallet providers (payment success, failure and refund status).
- From people booking on your behalf, and from physical quality audit visits conducted by our inspection team.
4. Why We Use Your Data
We process your data only for specified purposes and, where required, with your consent or another lawful ground under the DPDP Act (such as legitimate uses, compliance with law, or responding to a medical emergency):
- Create and Secure Accounts: OTP verification, fraud prevention, login security.
- Provide Bookings: Show real-time availability, confirm reservations, sync with Property PMS systems, prevent double bookings, and arrange re-accommodation.
- Verify Guests: Verify ID at check-in, as required by Indian state laws and Property rules.
- Process Payments & Refunds: Collect payments, disburse refunds directly to your original payment source, run the live refund tracker, and handle chargebacks.
- Customer Support & Dispute Mediation: Answer queries via phone, WhatsApp or email, investigate complaints, and mediate between guests and Partners.
- Quality and Safety: Conduct property audits, verify genuine post-checkout reviews, handle safety reports, and delist unsafe or substandard properties.
- Platform Improvement: Error diagnostics, bug fixing, search ranking, and building new convenience tools (such as QR/OTP check-in).
- Transactional Communications: Send booking vouchers, arrival reminders, service updates and refund alerts.
- Marketing (With Explicit Consent): Curated offers, loyalty communications and recommendations. You can withdraw marketing consent at any time.
- Partner Management: Verification onboarding, bi-weekly payouts, commission statements, GST/TDS tax compliance and audits.
- Legal Compliance: Comply with lawful requests from law enforcement, courts, tax authorities, and enforce our Terms.
5. Consent & Withdrawal
We ask for your consent in clear language, separately for each distinct purpose where required (for example, promotional messages, precise location, optional photo uploads).
Consent is voluntary. You may withdraw it as easily as you gave it, through account settings, the “unsubscribe” link, or by contacting support@hindustaan.in. Withdrawal does not affect processing done earlier, but we may then be unable to provide services that depend on that data (for example, we cannot complete a hotel check-in without government ID verification).
Where you have chosen to contact us or book, we may process data for legitimate uses permitted by the DPDP Act without a separate consent request.
6. Cookies and Similar Technologies
We use cookies, SDKs and pixels to keep you signed in, remember your preferences, measure traffic, diagnose errors, and measure marketing performance:
- Essential Cookies: Needed for authentication, session integrity, security and checkout.
- Analytics Cookies: Help us understand interaction patterns (clicks, scrolls, page views) to fix bugs. We configure all tools not to capture payment or ID fields.
- Marketing Cookies: Used only with your consent, to measure campaign effectiveness or show relevant stay recommendations.
You can manage cookies in your browser or device settings; blocking essential cookies may affect Platform features.
7. Who We Share Data With
We do not sell your personal data. We share it only as needed:
- Partners (Hotels): Your name, contact number, booking details, number of guests and, at check-in, ID details, so they can host you and meet legal registration duties. Partners are contractually bound to use it strictly for your stay and legal compliance.
- Service Providers: Payment gateways, banks and wallets; cloud hosting (Cloudinary for media, encrypted PostgreSQL); SMS, email and WhatsApp messaging providers; customer support tools; auditors and professional advisers. They act on our instructions under strict confidentiality contracts.
- Maps and Location Services: Such as Google Maps, to display hotel locations and route directions.
- Law Enforcement & Authorities: Police, courts, tax or other government bodies where required by law or to protect life, safety, or prevent financial fraud.
- Business Transfers: In a merger, acquisition, financing or sale of company assets, subject to continued protection of your data.
- With Your Direction: Where you choose to share, for example, a friend referral or public review.
8. Reviews and Public Content
Reviews are displayed publicly with your first name or chosen display name and, where applicable, a “verified stay” badge. Do not include personal contact details, passwords, or sensitive details in public reviews. We may remove content that breaches our Terms.
9. Data Storage, Security and Transfers
9.1 Indian Data Residency: We store data on secure servers in India. Where our service providers process data outside India, we do so only to the extent permitted by the DPDP Act and government notifications in force, with suitable safeguards.
9.2 Security Safeguards: We employ industry-standard security safeguards, including TLS encryption in transit, strict role-based access control, secure storage of ID documents, tamper-evident activity logs, and periodic vulnerability reviews.
9.3 User Vigilance: Please protect your OTPs and device, and notify us immediately if you suspect unauthorized activity.
9.4 Incident Response: If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as mandated by law.
10. How Long We Keep Data
We keep data only as long as needed for the purpose it was collected, or as required by Indian law:
| Data Classification | Retention Window |
|---|---|
| Account & Profile Data | While account is active, then up to 1 year after closure |
| Booking & Invoicing Records | 8 years for tax, accounting and statutory audit compliance |
| Guest ID Documents | Only as long as needed for check-in and legal registration (normally no more than 12 months) |
| Support Chats & Call Recordings | 12–24 months for quality assurance and dispute resolution |
| Marketing Preferences | Until you withdraw consent, plus an audit record that you opted out |
| Partner KYC & Bank Payout Data | Duration of partner agreement plus 8 years |
| Security Logs & Analytics | 6–24 months, then permanently anonymised or purged |
After retention expiration, data is deleted or permanently anonymised, unless retention is required for active legal proceedings.
11. Your Rights under the DPDP Act
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Right to Access: Access a summary of personal data we process and the parties with whom it was shared.
- Right to Correction: Correct and update inaccurate or incomplete personal data.
- Right to Erasure: Erase personal data that is no longer needed for its initial purpose, unless statutory retention applies.
- Right to Withdraw Consent: Revoke consent easily at any time.
- Right to Grievance Redressal: Have your privacy concerns addressed promptly by our Data Protection Officer, and approach the Data Protection Board of India.
- Right to Nominate: Nominate another individual to exercise your rights in the event of death or incapacity.
To exercise any of these rights, email support@hindustaan.in or call 0771-299-4005 from your registered phone/email. We aim to respond within 30 days.
12. Children Protection (18+)
Our Platform is meant for adults aged 18 and over. We do not knowingly collect data from children under 18 without verifiable parental or guardian consent. Where a child stays with you, the parent or legal guardian makes the booking and provides necessary details. We do not track, profile or target advertising at children. If you believe a child has provided data without consent, contact us and we will delete it promptly.
13. Communications Preferences
Service messages (booking vouchers, checkout details, refunds, and emergency safety notifications) are essential for contract fulfillment and are sent regardless of promotional preferences.
Marketing messages via SMS, WhatsApp, email or push notifications can be toggled off at any time in app settings, using the unsubscribe link, replying “STOP”, or contacting support. Registration with the National Do Not Disturb (DND) registry is strictly respected for promotional calls and SMS, in full accordance with TRAI regulations.
14. Guidance for Partners
Partners who access guest data through our dashboard or management tools must: (a) use it strictly to provide the booked stay and meet statutory hotel registration rules; (b) collect and store ID only as required by local authorities; (c) never copy, sell, share or use guest information for their own independent marketing; (d) protect it with reasonable safeguards; (e) report any suspected data incident to us without delay; and (f) delete data when no longer needed. Breach of these fiduciary duties leads to listing suspension and legal enforcement.
15. Third-Party Links
The Platform may link to external websites or third-party tools. We are not responsible for their independent privacy practices. Please review their policies before sharing data.
16. Changes to This Policy
We may update this Policy to reflect changes in law or our services. We will post the revised version with an updated date and, for material changes, notify you via Platform banner, email or WhatsApp. Where the law requires fresh consent, we will ask for it.
17. Contact and Grievance / Data Protection Officer
For privacy questions, access requests, or grievances under the DPDP Act:
We will acknowledge complaints within 48 hours and aim to resolve them within 30 days. If you remain unsatisfied, you may approach the Data Protection Board of India as provided under the DPDP Act.