Privacy Policy

How HospitPro collects, uses, and protects your business and customer data. We are committed to transparency and compliance with Indian data protection law.

Last updated: May 28, 2026·Version 2.1

1. Who We Are

HospitPro is a hospitality management SaaS platform operated by Madhava Creation, a sole proprietorship registered in India. Our registered office is at D-8, K.D. Compound, Gulshan Nagar, Kandivali West, Mumbai – 400067, Maharashtra, India.

For the purposes of the Digital Personal Data Protection Act, 2023 (DPDPA), Madhava Creation is the Data Fiduciary — the entity that determines the purpose and means of processing personal data. When you use HospitPro to manage your customers, you act as a Data Fiduciary for your customers' data, and HospitPro acts as a Data Processor on your behalf.

Contact our Grievance Officer: Email madhavacreation3108@gmail.com | Phone: +91 79774 06204

📖 Definition

Data Fiduciary means any person who alone or in conjunction with other persons determines the purpose and means of processing personal data (DPDPA 2023, Section 2(i)).

2. Information We Collect

2.1 Account & Business Information

When you register on HospitPro, we collect: business name, owner name, email address, phone number, business address, city, state, PIN code, and business type. This information is required to create your account and configure your dashboard.

2.2 Financial & Tax Information

We collect your GSTIN, legal business name, and registered state for GST invoice generation. We also collect your bank account details (if you set up Razorpay Route payouts) and billing address for subscription invoices.

2.3 Customer Data You Upload

As part of operating your business on HospitPro, you upload or generate customer data: guest names, phone numbers, email addresses, booking histories, dietary preferences, and payment records. You are the Data Fiduciary for this data. HospitPro processes it solely on your instructions.

2.4 Usage & Technical Data

We automatically collect: IP address, browser type, operating system, pages visited, features used, session duration, and error logs. This data is used to improve the platform, debug issues, and detect abuse.

2.5 Payment Information

HospitPro does not store credit or debit card numbers. Subscription payments are processed via Razorpay. We store only the Razorpay payment ID, order ID, and payment status. Your customers' payment card data flows directly to Razorpay and is never stored on HospitPro servers.

✅ Good to know

We never store raw card numbers, CVVs, or full UPI credentials. All payment tokenisation is handled by Razorpay, which is PCI-DSS Level 1 certified.

4. How We Use Your Information

  • To create and manage your HospitPro account and business profile
  • To process your subscription payments and generate GST-compliant invoices
  • To operate all sector dashboards (Hotel, Restaurant, Gym, Salon, etc.) you have subscribed to
  • To generate GST returns (GSTR-1, GSTR-3B) from your transaction data
  • To send WhatsApp and email notifications to your customers on your behalf (when you enable these features)
  • To send you renewal reminders, subscription updates, and support communications
  • To improve and develop new features through anonymised usage analytics
  • To detect and prevent fraud, abuse, and security threats on our platform

🔴 Critical

We do not sell your data or your customers' data to any third party, ever. We do not use your data for advertising or marketing beyond communications directly related to your HospitPro subscription.

5. Data Sharing & Disclosure

We share data only with the following categories of recipients, and only to the extent necessary:

  • Razorpay Financial Solutions: For processing subscription payments and, if you enable Razorpay Route, for routing customer payments to your bank account. Governed by Razorpay's privacy policy.
  • Twilio Inc.: For WhatsApp message delivery via the Twilio Business API. Only your customers' phone numbers and message content are transmitted. Used only when you enable WhatsApp notifications.
  • MongoDB Atlas (MongoDB, Inc.): For cloud database storage. Data is stored in servers located in India or Singapore, governed by MongoDB's DPA and SCCs.
  • Vercel Inc.: For web hosting and edge computing. Request logs may be processed on Vercel's infrastructure.
  • Cloudinary: For image storage and optimisation (menu photos, hotel images, etc.).
  • Legal authorities: We disclose data to courts, regulators, or government agencies when required by Indian law, a valid court order, or a lawful government request. We will notify you unless legally prohibited.

ℹ Note

All third-party service providers are bound by data processing agreements that require them to protect your data and use it only for the purposes we specify.

6. Data Retention

Data TypeRetention PeriodReason
Account & business dataDuration of subscription + 3 years after closureGST compliance, legal disputes
Transaction & billing records7 yearsGST Act 2017 requirement (Section 36)
GST invoices8 yearsGST audit requirement
Customer booking/order data3 yearsBusiness continuity, dispute resolution
Usage logs & analytics12 monthsSecurity, debugging
WhatsApp message logs90 daysDelivery confirmation

You may request deletion of your account at any time by emailing us. We will delete all personal data within 30 days, except data we are legally required to retain under Indian tax law.

⚠ Important

GST transaction records (7–8 years) and subscription invoices cannot be deleted on request due to mandatory retention requirements under the Goods and Services Tax Act, 2017.

7. Security Measures

We implement industry-standard technical and organisational measures to protect your data:

  • TLS 1.3 encryption for all data in transit between your browser and our servers
  • AES-256 encryption for sensitive credentials (API keys, webhook secrets) stored in the database
  • Role-based access controls — staff can only access data relevant to their role (RECEPTIONIST, WAITER, MANAGER, CHEF)
  • JWT session management with short-lived tokens and secure cookie settings (HttpOnly, SameSite=Strict)
  • Rate limiting on all authentication endpoints to prevent brute-force attacks
  • Audit logs for all sensitive operations (status changes, payments, subscription modifications)
  • Tenant isolation — every database query includes a mandatory businessId filter; no cross-tenant data access is possible

✅ Good to know

If you discover a security vulnerability, please report it responsibly to madhavacreation3108@gmail.com. We commit to acknowledging reports within 48 hours.

8. Your Rights Under DPDPA 2023

Under the Digital Personal Data Protection Act, 2023, you have the following rights as a Data Principal (individual whose data is processed):

RightWhat It MeansHow to Exercise
Right to AccessKnow what personal data we hold about youEmail grievance officer
Right to CorrectionCorrect inaccurate or incomplete personal dataDashboard settings or email
Right to ErasureRequest deletion of personal data (subject to retention obligations)Email grievance officer
Right to Grievance RedressalRaise a complaint about data processingEmail within 30 days for response
Right to NominateNominate a person to exercise rights in case of death or incapacityEmail grievance officer

We respond to all rights requests within 30 days. If we cannot fulfill a request (e.g., due to legal retention obligations), we will explain the reason. You may also approach the Data Protection Board of India if your grievance is not resolved.

ℹ Note

To exercise any right, email madhavacreation3108@gmail.com with subject “DPDPA Rights Request” and your registered email address. We will verify your identity before processing the request.

9. Cookies & Tracking

HospitPro uses only essential cookies required for the platform to function:

  • Session cookie: Keeps you logged in to your dashboard (JWT stored as HttpOnly cookie, expires in 90 days)
  • CSRF token: Prevents cross-site request forgery attacks on form submissions
  • Theme preference: Remembers your light/dark mode setting (local storage, not transmitted to our servers)

✅ Good to know

We do not use advertising cookies, tracking pixels, third-party analytics scripts (like Google Analytics), or any technology that tracks you across other websites.

10. Children's Privacy

HospitPro is a B2B SaaS platform intended exclusively for business owners and their staff. The platform is not designed for, marketed to, or intended to be used by persons under 18 years of age.

We do not knowingly collect personal data from children. If you believe a minor has created an account, please contact us immediately and we will delete the account and associated data within 72 hours.

🔴 Critical

You must be at least 18 years old to register and use HospitPro. By registering, you confirm that you are 18 years of age or older and have the legal authority to enter into binding contracts.

11. WhatsApp & Communications

HospitPro offers optional WhatsApp notification features powered by the Twilio Business API (Meta-approved BSP). When you enable WhatsApp notifications:

  • Your customers' phone numbers are transmitted to Twilio solely to deliver the notification
  • Message content is determined by you (e.g., booking confirmation, gym membership expiry reminder)
  • Twilio processes the data under their privacy policy and your WhatsApp Business policy agreement
  • You are responsible for obtaining your customers' consent to receive WhatsApp messages under applicable regulations
  • Opt-out requests from customers should be honoured by disabling notifications for that phone number in your HospitPro settings

HospitPro also sends transactional emails for: subscription renewal reminders, invoice delivery, GST package exports to your CA, and password reset. These are non-promotional and cannot be unsubscribed from (they are essential service communications).

12. Razorpay & Payment Data

HospitPro integrates with Razorpay in two modes:

  • Platform payments (our subscriptions): We use Razorpay to process your subscription fees. Razorpay handles all card and UPI data. We receive only the payment ID and status.
  • Razorpay Route (your customer payments): If you enable Razorpay Route, your customers' payments flow directly to your linked bank account. HospitPro facilitates the routing but does not hold funds. This requires you to complete Razorpay's KYC and sign their merchant agreement.

If you add your own Razorpay API keys to HospitPro, those keys are stored AES-256 encrypted in our database and are used solely to initiate payment orders on your behalf. We never use your Razorpay keys for any other purpose.

⚠ Important

Never share your Razorpay API Secret Key with anyone. HospitPro only requires your Key ID and Key Secret to process payments — we will never ask for your Razorpay dashboard login credentials.

13. Multi-Tenant Architecture

HospitPro is a multi-tenant SaaS platform where multiple businesses share the same infrastructure. We implement strict tenant isolation to ensure your data is never accessible to other businesses:

  • Every database query includes a mandatory businessId filter — it is structurally impossible to retrieve another business's data
  • API routes verify session ownership before every data operation
  • Staff members are scoped to their employer's business and cannot access data from other businesses
  • Database access is through a connection pool with read-only replicas; no raw database credentials are exposed to application code

✅ Good to know

Your business data on HospitPro is logically isolated from all other tenants. No other business owner, staff member, or platform user can see your hotel rooms, restaurant orders, gym members, or any other business data.

14. Changes to This Policy

We may update this Privacy Policy as our platform evolves, new features are added, or legal requirements change. When we make significant changes:

  • We will notify you via email at least 14 days before changes take effect
  • We will display a prominent notice on your dashboard
  • The “Last Updated” date at the top of this page will be updated
  • The version number will be incremented (currently v2.1)

Continued use of HospitPro after the effective date of changes constitutes your acceptance of the updated policy. If you do not accept the changes, you must stop using the platform and request account deletion.

15. Grievance Officer & Contact

Grievance Officer — Madhava Creation

Name: Durgesh Prajapati

Address: D-8, K.D. Compound, Gulshan Nagar, Kandivali West, Mumbai – 400067, Maharashtra, India

Email: madhavacreation3108@gmail.com

Phone: +91 79774 06204

Response time: Within 30 days of receiving your complaint

ℹ Note

If your grievance is not resolved within 30 days, you may approach the Data Protection Board of India (once established under DPDPA 2023) or the Consumer Forum as appropriate.