Home · Privacy policy
Privacy policy
This notice explains what personal data we collect when you use this website and buy a licence, why we collect it, and what you can do about it. We have written it to meet the notice requirements of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
The one thing worth knowing first
HotelOS runs on your server, under your domain, against your database. Your guests' names, stays, payments and documents never reach us. In the language of the DPDP Act, you are the Data Fiduciary for your guest data and we are not a Data Processor for it — we have no access to it at all, unless you deliberately give us access during a support request. What we hold is the commercial relationship: your account, your orders and your licence.
1. Who we are
HotelOS, a private limited company , is the Data Fiduciary for the personal data described here. Our particulars are at the end of this page.
2. What we collect, and why
| Data | Why we hold it | How long |
|---|---|---|
| Name, company, email address, mobile number, city and country | To create and run your account, verify that we can reach you, issue your licence and provide support | While your account is open, then 8 years |
| Password | To let you sign in. Stored only as a one-way hash — we cannot read it and cannot tell you what it is | Until changed or the account is closed |
| One-time verification codes sent to your email and mobile | To confirm the address and number are yours before we send a licence to them | 30 minutes, then marked used |
| Order and payment records — reference, plan, amounts, tax, gateway identifiers, GSTIN | To take payment, raise a tax invoice and meet our tax and company-law obligations | 8 years (Companies Act s.128, GST s.36, Income-tax Rule 6F) |
| Installation details — hotel name, address, contact person, and the web address the software runs on | To issue a licence bound to the right domain and to support the installation | For the life of the licence, then 8 years |
| Licence activity — licence key, domain, IP address, software and PHP version, timestamps | To authenticate your installation, enforce the plan and diagnose activation problems | Successful checks pruned after 90 days; denials kept for the life of the licence |
| Support and chat conversations, including the name, email and mobile you give when starting a chat | To answer you, and so the next person to help has the context | 2 years |
| Website and server logs | Security, fraud prevention and fault diagnosis | 180 days, as the CERT-In directions of 28 April 2022 require |
What we deliberately do not collect
- Your guests' data. It stays in your database on your server.
- Card numbers. Payment details go straight to Razorpay. Under the Reserve Bank of India's card-on-file tokenisation rules, merchants may not store card credentials, and we do not.
- Children's data. This is a business service and is not directed at anyone under 18. If you believe a child's data has reached us, tell our data protection contact and we will erase it.
3. Our lawful basis
We process most of this data because you gave it to us voluntarily for a purpose you asked us to carry out — creating your account, issuing your licence, supporting your installation — which is a certain legitimate use under section 7 of the DPDP Act. Where we rely on consent, such as product emails you subscribe to, you gave it by a clear affirmative action and can withdraw it as easily as you gave it. We also process some data because the law obliges us to, such as retaining invoices for tax.
4. Who else sees it
| Recipient | What they see |
|---|---|
| Razorpay Software Private Limited (payment aggregator, authorised by the RBI) | Your name, email, mobile, the amount and the order reference. They handle the card or UPI details; we never receive them |
| Our email and SMS providers | The address or number a message goes to and its contents. Transactional SMS is sent through DLT-registered headers and templates as the TRAI regulations require |
| The support platform behind our live chat | What you type in the chat, plus the name, email and mobile you gave when starting it |
| Our hosting provider and professional advisers | Only what their role requires, under confidentiality obligations |
| Government agencies | Only when the law requires it, such as a lawful order, a tax assessment or a CERT-In direction |
We do not sell personal data. We do not share it for anyone else's advertising.
5. Where it is held
Our servers and backups are in India. Some of the providers above may process data outside India in the ordinary course of their service. Section 16 of the DPDP Act permits transfer outside India except to countries the Central Government restricts, and we do not transfer to any restricted country.
6. How we protect it
- Passwords are stored as salted one-way hashes; secret keys are never displayed in plain text without a deliberate action.
- Traffic is served over HTTPS. Every state-changing request carries an anti-forgery token, and all database access uses parameterised statements.
- Payment results are accepted only after the gateway's cryptographic signature verifies on our server, so a forged confirmation changes nothing.
- Access to the back office is role-based, timed out after two hours idle, throttled after failed sign-ins, and every administrative action is logged with the actor and IP address.
- We keep ICT logs for 180 days within India and synchronise our clocks to NPL/NIC time, as the CERT-In directions of 28 April 2022 require.
7. If something goes wrong
If a personal data breach affects you we will inform you and the Data Protection Board of India as section 8(6) of the DPDP Act requires. Where the incident falls within the CERT-In directions we also report it to CERT-In within six hours of noticing it.
8. Your rights
As a Data Principal under the DPDP Act you may:
- Know what personal data we hold about you, what we do with it and who we have shared it with.
- Correct, complete, update or erase it. Most of it you can edit yourself under My details.
- Withdraw consent where we relied on it. Product emails have an unsubscribe link in every message.
- Nominate someone to exercise your rights if you die or become incapacitated.
- Complain — first to us, and then to the Data Protection Board of India.
Write to our data protection contact below. We will respond within 30 days. Erasure has limits: we must keep invoices and licence records for the statutory periods in the table above, and we will tell you when that applies rather than quietly refusing.
This notice is available in English. If you would rather have it in any language in the Eighth Schedule to the Constitution, ask our data protection contact and we will provide it.
9. Cookies and tracking
We set a session cookie so you stay signed in, an anti-forgery token, and one entry in your browser's local storage so a chat survives a page reload. That is all. There are no advertising cookies, no cross-site tracking and no third-party analytics scripts on this site.
10. Your duties
Section 15 of the DPDP Act asks Data Principals to give authentic information and not to file false or frivolous complaints. Please keep your email address and mobile number current — your licence key and your renewal reminders go there.
11. Changes
If we change this notice materially we will email account holders and update the date at the top. Continuing to use the service after that means the updated notice applies.
12. Contact
Grievance Officer
administron@emails.com
+91 00000 00000
We acknowledge a complaint within 48 hours and aim to resolve it within one month, as the Consumer Protection (E-Commerce) Rules 2020 and the IT Rules require.
Data protection contact
administron@emails.com
For anything about your personal data under the Digital Personal Data Protection Act, 2023. If we do not resolve it, you may complain to the Data Protection Board of India.
HotelOS
Private Limited Company
Registered office:
Bengaluru, India
https://eresbooking.com
administron@emails.com
+91 00000 00000
This policy covers this portal. The licence agreement governs the software itself, and the payment policy covers billing, invoices and refunds.