1. What we collect
We collect three broad classes of information: what you tell us directly, what we record from the way you use the platform, and what our payments partner Razorpay shares back with us after a booking.
Given directly by you
- Name, phone number and email address at sign-in and at the checkout step of the booking funnel.
- For partner accounts: the business name, registered address, venue photographs and bank / UPI details required for payouts.
- Anything you type into the "Special requests" field of a booking, up to 1,000 characters.
Recorded from your session
- Device type, browser fingerprint, IP address, approximate geolocation from the browser Geolocation API (only after you allow it), and referral source (e.g. Instagram vs direct).
- Time-stamped logs of each booking event — created, paid, checked-in, cancelled, refunded — for audit and dispute resolution.
Shared back by Razorpay after payment
- A tokenised card or UPI VPA reference — never the full card number or CVV.
- Payment status, transaction id, and (for refunds) the refund id.
2. How we use it
- To operate the booking flow: create orders, verify payments, mint the 6-digit arrival PIN, notify the partner of confirmed bookings, and issue refunds when a customer cancels.
- To keep the platform secure — rate-limit brute-force attempts against the check-in endpoint, flag suspicious payment patterns, and investigate customer or partner reports.
- To provide customer support when you write to us; we look up your bookings, verify identity from your registered phone/email, and resolve the issue.
- To improve the product — aggregated, anonymised metrics of which venues fill fastest, which occasions are most requested, which cities to expand to next.
3. Who we share it with
We share only what's necessary, only with:
- The partner venue you booked with — enough information to fulfil the booking: room, slot, group size, occasion, special requests, and the 6-digit arrival PIN. Partners never see your saved payment methods or card details.
- Razorpay — the transaction amount, order id and identifying information required for payment processing and refunds under RBI regulations.
- Firebase — for authentication, push notification delivery, and crash reporting.
- Government or law-enforcement bodies — only when compelled by a valid legal order.
We do not sell or lease your personal data to any third party.
4. Cookies & similar technologies
We use two cookies: __session to keep you signed in without repeatedly asking for the phone OTP, and a__locale cookie to remember your language choice. We do not run marketing / advertising cookies today.
5. How long we keep it
- Active accounts — for as long as the account exists.
- Booking history — 7 years, so we can produce records for tax, audit or dispute-resolution purposes.
- Payment transaction identifiers — 7 years as required by Razorpay's PCI-DSS obligations.
- Anonymous session logs — 90 days, then aggregated only.
6. Your choices
You can, at any time, ask us to:
- Show you every piece of data we hold about you.
- Correct anything that's wrong.
- Delete your account and every non-audit record tied to it.
- Stop marketing messages (we send very few; a single "STOP" reply covers all channels).
Reach us at the address on the Contact Us page. We respond within seven working days.
7. Security practices
Data at rest is stored on managed Postgres (Neon) with encryption enabled. Data in transit is TLS 1.3 across the whole stack. Secrets like the Razorpay Key Secret and webhook secret live in Google Cloud Secret Manager, not in the codebase. Access to production is limited to a small set of engineers, all with 2FA.
8. Children
The platform is not directed at children under 13. If you believe a minor has created an account, write to us and we'll delete it.
9. Changes to this policy
Material changes get a bumped "Last updated" date and, where practical, an email to registered users. Continuing to use the platform after a change counts as acceptance of the new terms.