Privacy Policy
How we handle personal data, written for Indian readers using the terms of the Digital Personal Data Protection Act, 2023.
Last updated: 11 August 2026
1.Who we are
legal name, registered address. Contact: privacy@beddesk.in.
Grievance Officer — required under the DPDP Act and the IT Rules: name, privacy@beddesk.in, phone. We respond within 30 days of any request or complaint.
2.Our two roles — read this first
| Whose data | Our role |
|---|---|
| Hostel owners and their staff who sign up | Data Fiduciary — we decide why and how it is processed |
| Residents whose details a hostel enters | Data Processor only — the hostel is the Data Fiduciary; we act on its instructions |
3.What we collect
From hostel owners (as Fiduciary): name, business name, phone, email, address, GSTIN, staff names and roles, login credentials (passwords stored hashed, never in plain text), payment records, usage logs, IP address and device information.
From residents (as Processor, entered by the hostel): name, phone and WhatsApp number, alternate phone, email, gender, date of birth, permanent address, occupation and institution, emergency contact details, identity document images and the last four digits of the identity number, room and bed allocation, rent and payment history, meal opt-out records, WhatsApp message history with the Service, and exit and settlement details.
We do not collect: biometrics, location tracking, card or bank credentials, or data from anyone under 18 without the verifiable parental consent the DPDP Act requires.
4.Why we process it
To provide the Service; to authenticate users; to send transactional WhatsApp and email messages; to bill subscriptions; to provide support; to detect abuse and secure the platform; and to comply with the law.
5.Identity documents — a specific disclosure
Hostels may upload images of identity documents, including Aadhaar. We handle them as follows:
- Stored in a private, encrypted store, never publicly accessible.
- Reachable only through links that expire in 60 seconds, and only for the hostel’s owner and manager roles.
- Only the last four digits of an identity number are stored in readable form.
- Every view, download and deletion is logged, and that log is available to the hostel.
- Deleted three months after the resident leaves, automatically. The hostel is reminded 7 days beforehand.
- Sent to our AI provider only to read the printed fields — not retained by them, never used to train a model, and full identity numbers are never transmitted.
6.Who we share it with
| Recipient | Purpose |
|---|---|
| Vercel | Application hosting |
| Supabase | Database and file storage — Mumbai, India |
| Meta Platforms | WhatsApp message delivery |
| Anthropic | AI document reading and message understanding |
| Resend | Transactional email |
| Cloudflare | DNS and email routing |
Also disclosed where required by law or valid legal process, and to a successor on a business transfer, with notice.
7.How long we keep it
| Data | Kept for |
|---|---|
| Identity document images | 3 months after the resident exits, then auto-deleted |
| Resident records (non-document) | Duration of stay + 3 years |
| Financial records (invoices, payments) | 8 years — statutory requirement |
| WhatsApp message logs | 12 months |
| Owner account data | Duration of subscription + 1 year |
| Access and audit logs | 12 months |
8.Security
Encryption in transit and at rest; database-level tenant isolation using row-level security; role-based access; private document storage with short-lived signed links; audited access to identity documents; hashed passwords; daily backups.
No system is perfectly secure. In a breach we will notify the Data Protection Board of India and affected persons as the DPDP Act requires.
9.Your rights under the DPDP Act 2023
Access, correction, completion, updating and erasure; nomination of someone to exercise your rights on your behalf; grievance redressal; and withdrawal of consent.
- Hostel owners: write to privacy@beddesk.in.
- Residents: contact your hostel — they are your Data Fiduciary. We will help them act on your request.
10.WhatsApp
Residents receive messages only where their hostel has recorded their consent. Reply STOP at any time to stop notifications. Messages are delivered by Meta and are subject to WhatsApp’s own privacy terms.
11.Cookies
Essential cookies only — session and security. We do not use advertising or tracking cookies. If we add analytics we will disclose the tool here first.
12.Children
The Service is not intended for anyone under 18. A hostel accommodating a minor must obtain verifiable parental consent before entering their data, as the DPDP Act requires.
13.Changes to this policy
Material changes are notified 15 days in advance, by email and in the app.
Questions about this document: privacy@beddesk.in