Skip to content
HO HotelOS
Features Reservations, direct booking engine, payments, housekeeping, r… Booking engine Take direct bookings on your own domain with live availability… Staff & payroll A weekly roster, attendance with late marks and overtime, hous… Designs Eight complete website designs for beach resorts, hill retreat…
For hotels & resorts Built for 20 to 200-room independent hotels and resorts in Ind… For hostels Per-bed dorm inventory, mixed and female dorms, a backpacker-r… For lodges & guest houses Simple software for family lodges, guest houses, homestays and…
Pricing FAQ About Contact Sign in Get started

Home · Privacy policy

Privacy policy

Last updated 12 September 2026 · Applies to https://eresbooking.com

This notice explains what personal data we collect when you use this website and buy a licence, why we collect it, and what you can do about it. We have written it to meet the notice requirements of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

The one thing worth knowing first

HotelOS runs on your server, under your domain, against your database. Your guests' names, stays, payments and documents never reach us. In the language of the DPDP Act, you are the Data Fiduciary for your guest data and we are not a Data Processor for it — we have no access to it at all, unless you deliberately give us access during a support request. What we hold is the commercial relationship: your account, your orders and your licence.

1. Who we are

HotelOS, a private limited company , is the Data Fiduciary for the personal data described here. Our particulars are at the end of this page.

2. What we collect, and why

DataWhy we hold itHow long
Name, company, email address, mobile number, city and country To create and run your account, verify that we can reach you, issue your licence and provide support While your account is open, then 8 years
Password To let you sign in. Stored only as a one-way hash — we cannot read it and cannot tell you what it is Until changed or the account is closed
One-time verification codes sent to your email and mobile To confirm the address and number are yours before we send a licence to them 30 minutes, then marked used
Order and payment records — reference, plan, amounts, tax, gateway identifiers, GSTIN To take payment, raise a tax invoice and meet our tax and company-law obligations 8 years (Companies Act s.128, GST s.36, Income-tax Rule 6F)
Installation details — hotel name, address, contact person, and the web address the software runs on To issue a licence bound to the right domain and to support the installation For the life of the licence, then 8 years
Licence activity — licence key, domain, IP address, software and PHP version, timestamps To authenticate your installation, enforce the plan and diagnose activation problems Successful checks pruned after 90 days; denials kept for the life of the licence
Support and chat conversations, including the name, email and mobile you give when starting a chat To answer you, and so the next person to help has the context 2 years
Website and server logs Security, fraud prevention and fault diagnosis 180 days, as the CERT-In directions of 28 April 2022 require

What we deliberately do not collect

  • Your guests' data. It stays in your database on your server.
  • Card numbers. Payment details go straight to Razorpay. Under the Reserve Bank of India's card-on-file tokenisation rules, merchants may not store card credentials, and we do not.
  • Children's data. This is a business service and is not directed at anyone under 18. If you believe a child's data has reached us, tell our data protection contact and we will erase it.

3. Our lawful basis

We process most of this data because you gave it to us voluntarily for a purpose you asked us to carry out — creating your account, issuing your licence, supporting your installation — which is a certain legitimate use under section 7 of the DPDP Act. Where we rely on consent, such as product emails you subscribe to, you gave it by a clear affirmative action and can withdraw it as easily as you gave it. We also process some data because the law obliges us to, such as retaining invoices for tax.

4. Who else sees it

RecipientWhat they see
Razorpay Software Private Limited (payment aggregator, authorised by the RBI) Your name, email, mobile, the amount and the order reference. They handle the card or UPI details; we never receive them
Our email and SMS providers The address or number a message goes to and its contents. Transactional SMS is sent through DLT-registered headers and templates as the TRAI regulations require
The support platform behind our live chat What you type in the chat, plus the name, email and mobile you gave when starting it
Our hosting provider and professional advisers Only what their role requires, under confidentiality obligations
Government agencies Only when the law requires it, such as a lawful order, a tax assessment or a CERT-In direction

We do not sell personal data. We do not share it for anyone else's advertising.

5. Where it is held

Our servers and backups are in India. Some of the providers above may process data outside India in the ordinary course of their service. Section 16 of the DPDP Act permits transfer outside India except to countries the Central Government restricts, and we do not transfer to any restricted country.

6. How we protect it

  • Passwords are stored as salted one-way hashes; secret keys are never displayed in plain text without a deliberate action.
  • Traffic is served over HTTPS. Every state-changing request carries an anti-forgery token, and all database access uses parameterised statements.
  • Payment results are accepted only after the gateway's cryptographic signature verifies on our server, so a forged confirmation changes nothing.
  • Access to the back office is role-based, timed out after two hours idle, throttled after failed sign-ins, and every administrative action is logged with the actor and IP address.
  • We keep ICT logs for 180 days within India and synchronise our clocks to NPL/NIC time, as the CERT-In directions of 28 April 2022 require.

7. If something goes wrong

If a personal data breach affects you we will inform you and the Data Protection Board of India as section 8(6) of the DPDP Act requires. Where the incident falls within the CERT-In directions we also report it to CERT-In within six hours of noticing it.

8. Your rights

As a Data Principal under the DPDP Act you may:

  • Know what personal data we hold about you, what we do with it and who we have shared it with.
  • Correct, complete, update or erase it. Most of it you can edit yourself under My details.
  • Withdraw consent where we relied on it. Product emails have an unsubscribe link in every message.
  • Nominate someone to exercise your rights if you die or become incapacitated.
  • Complain — first to us, and then to the Data Protection Board of India.

Write to our data protection contact below. We will respond within 30 days. Erasure has limits: we must keep invoices and licence records for the statutory periods in the table above, and we will tell you when that applies rather than quietly refusing.

This notice is available in English. If you would rather have it in any language in the Eighth Schedule to the Constitution, ask our data protection contact and we will provide it.

9. Cookies and tracking

We set a session cookie so you stay signed in, an anti-forgery token, and one entry in your browser's local storage so a chat survives a page reload. That is all. There are no advertising cookies, no cross-site tracking and no third-party analytics scripts on this site.

10. Your duties

Section 15 of the DPDP Act asks Data Principals to give authentic information and not to file false or frivolous complaints. Please keep your email address and mobile number current — your licence key and your renewal reminders go there.

11. Changes

If we change this notice materially we will email account holders and update the date at the top. Continuing to use the service after that means the updated notice applies.

12. Contact

Grievance Officer

administron@emails.com
+91 00000 00000
We acknowledge a complaint within 48 hours and aim to resolve it within one month, as the Consumer Protection (E-Commerce) Rules 2020 and the IT Rules require.

Data protection contact

administron@emails.com
For anything about your personal data under the Digital Personal Data Protection Act, 2023. If we do not resolve it, you may complain to the Data Protection Board of India.

HotelOS
Private Limited Company

Registered office:
Bengaluru, India

https://eresbooking.com
administron@emails.com
+91 00000 00000

This policy covers this portal. The licence agreement governs the software itself, and the payment policy covers billing, invoices and refunds.

HO HotelOS

The complete hotel management system

Product

Features Booking engine Staff & payroll Designs Pricing & plans

Who it's for

For hotels & resorts For hostels For lodges & guest houses FAQ

Company

About us Contact Website terms Licence agreement Privacy policy Payment policy

Customers

Create an account Sign in My licences administron@emails.com +91 00000 00000

© 2026 HotelOS. All rights reserved.

Bengaluru, India

P
Priya HotelOS support desk

Talk to us

Tell us who you are and we will pick this up straight away.

We use these to reply if we get cut off. See our privacy policy.

This conversation has ended.