1.Introduction and scope
[TODO: Registered Legal Entity Name] Private Limited (“TrueHostel”, “we”, “us”) operates the TrueHostel platform. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
This policy is issued as the notice required under Section 5 of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Rules made under it, as the privacy policy required under Rule 3(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and as the policy required under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
In DPDP Act terms, TrueHostel is a Data Fiduciary in respect of the data it decides the purpose and means of processing, and you are a Data Principal. Where a Hostel Partner independently determines how to use data you give it, that Hostel Partner is a separate Data Fiduciary and is responsible for its own compliance.
2.Personal data we collect
Account data
- Name, email address and mobile number.
- Password, stored only as a salted one-way hash — we never see it in plain text.
- Profile photograph, if you upload one.
- If you sign in with Google or Facebook, the account identifier, name, email address and profile picture that the provider returns. We do not receive your Google or Facebook password.
Booking data
Because hostel accommodation involves residence, the information required at booking is more extensive than for an ordinary online purchase. When you book we collect:
- Applicant details — name, mobile number, email address and permanent or personal address.
- An identity document that you upload for verification, and a photograph with specimen signature.
- Parent or guardian details — name, mobile number, email address, and a signature confirming consent to the booking.
- Emergency contact — name, mobile number, address and relationship.
- School, college or workplace — name, contact number and address.
- Co-occupant details — name and age of each guest included in the booking.
- Check-in date, room and bed allotted, tariff, deposit and instalment schedule, and payment status.
Stay records
Where a Hostel Partner operates attendance or gate registers through the Platform, we store the date and the entry and exit times recorded against your booking, and whether you were marked present, absent or late. These records are created and used by the Hostel Partner for the safety and security of residents and to meet its own record keeping obligations.
Payment data
Payments are processed by an RBI-authorised payment aggregator. We do not collect or store your card number, CVV, UPI PIN or net-banking credentials. We store only the transaction and order identifiers returned by the aggregator, the amount, and the status, so that we can reconcile and support your booking.
Content and usage data
- Reviews and ratings you post, and hostels you save or like.
- Notification preferences, and — if you enable browser notifications — the push subscription endpoint issued by your browser.
- Technical data generated when you use the Platform: IP address, browser and device type, pages viewed and timestamps. This is used for security, fraud prevention and diagnostics.
- Support and grievance correspondence with us.
3.Why we process your data, and on what basis
Under the DPDP Act, personal data may be processed for a lawful purpose for which you have given consent, or for certain legitimate uses specified in Section 7. Our processing maps as follows:
| Purpose | Data used | Basis |
|---|---|---|
| Creating and securing your account | Account data | Consent |
| Processing a booking and passing it to the Hostel Partner | Booking data, payment references | Consent |
| Identity verification, resident safety and guest registration | Identity document, photograph, parent and emergency contacts | Consent, and compliance with law by the Hostel Partner |
| Taking payment, issuing invoices and processing refunds | Payment references, booking data | Performance of the service you requested |
| Service messages about your booking | Email, mobile, push subscription | Performance of the service you requested |
| Offers and promotional messages | Email, mobile, push subscription | Consent — you can withdraw it at any time |
| Fraud prevention, security and abuse investigation | Technical data, account and booking data | Legitimate use under Section 7 |
| Meeting legal, tax and regulatory obligations | Transaction and booking records | Compliance with law |
| Responding to grievances and legal claims | Correspondence and related records | Legitimate use under Section 7 |
We do not sell your personal data. We do not use your identity documents for profiling or advertising.
5.Children and persons with guardians
Section 9 of the DPDP Act imposes specific obligations on us where a Data Principal is a child — that is, a person who has not completed eighteen years of age.
Accounts on the Platform may only be created by persons aged 18 or above. Where a booking is made for a person under 18, it must be made by a parent or lawful guardian, who must supply their own details, their signature, and verifiable consent to the processing of the child’s personal data.
In relation to children’s data we:
- process it only after obtaining verifiable consent of the parent or lawful guardian;
- do not undertake tracking or behavioural monitoring of children, and do not direct advertising at children;
- do not undertake any processing likely to cause a detrimental effect on the well-being of a child.
The same protections apply to a person with a disability who has a lawful guardian. If you believe a child’s data has been collected without proper consent, write to Info@truehostel.com and we will delete it.
6.How we protect your data
Section 8(5) of the DPDP Act requires us to take reasonable security safeguards to prevent a personal data breach. We maintain, among other measures:
- encryption of data in transit using TLS;
- one-way hashing of passwords, so they cannot be recovered even by us;
- token-based authentication with expiry, and role-based access control so that staff and Hostel Partners see only what their role requires;
- restriction of uploaded identity documents to the Hostel Partner concerned and authorised personnel;
- access logging, and periodic review of access rights;
- contractual security obligations on the service providers listed in Section 4.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal in the form and within the timeframe prescribed under the DPDP Act and the Rules made under it.
You also have a part to play: keep your password confidential, do not share one-time passwords, and sign out on shared devices.
7.How long we keep your data
We keep personal data only for as long as the purpose for which it was collected is served, and thereafter only where retention is required by law.
| Category | Retention |
|---|---|
| Account data | Until you delete your account, then erased within 30 days |
| Booking and payment records | 8 years from the end of the relevant financial year, to meet obligations under the Companies Act, 2013 and tax law |
| Identity documents and signatures | Until the stay ends and any deposit is settled, then erased — unless a dispute or legal requirement makes retention necessary |
| Stay and attendance records | Duration of the stay plus 1 year |
| Reviews | Until you delete them; we may retain an anonymised rating so aggregate scores stay accurate |
| Content removed on a legal complaint | 180 days, as required by Rule 3(1)(j) of the IT Intermediary Guidelines, 2021 |
| Grievance correspondence | 3 years from resolution |
8.Your rights as a Data Principal
Under Sections 11 to 14 of the DPDP Act you have the right to:
- Access — obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Data Processors with whom it has been shared.
- Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and data updated.
- Erasure — have your personal data erased, unless retention is necessary for the purpose for which it was collected or for compliance with law.
- Withdraw consent — as easily as you gave it. Withdrawal does not affect processing already carried out, and we may have to stop providing a service that depends on the data.
- Grievance redressal — a readily available means of registering a grievance with us, which you must use before approaching the Data Protection Board of India.
- Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these rights, email Info@truehostel.com from your registered email address. We will respond within the period prescribed under the DPDP Rules, and in any event without undue delay. We may ask you to verify your identity before acting, to make sure we are not disclosing your data to someone else.
Your duties. Section 15 of the DPDP Act requires you not to impersonate another person when providing data, not to suppress material information, and not to register a false or frivolous grievance. Furnishing false particulars can attract a penalty.
10.Transfers outside India
Some of our hosting, storage and communication providers process data on servers located outside India. Section 16 of the DPDP Act permits transfer of personal data outside India except to a country restricted by notification of the Central Government. We transfer personal data only to providers that offer appropriate contractual protection, and we do not transfer to any restricted territory. Where a sectoral law imposes a stricter localisation requirement on any category of data, that requirement prevails and we comply with it.
11.Grievances and contact
For any question, request or complaint about your personal data, contact the person below. Section 13 of the DPDP Act requires us to publish these details.
Data Protection Contact
[TODO: Full Name]
[TODO: Registered Legal Entity Name] Private Limited
205, NRK Biz Park
Vijay Nagar, PU4
Indore, Madhya Pradesh 452010
India
Email: Info@truehostel.com
Complaints that are not resolved to your satisfaction may be escalated to our Grievance Officer at Info@truehostel.com, who will acknowledge within 24 hours and respond within 15 days. Full details are in the Terms and Conditions.
If you remain dissatisfied after exhausting our grievance process, you may complain to the Data Protection Board of India under the DPDP Act.
12.Changes to this policy
We may update this Privacy Policy. The revised version will be posted here with a new “last updated” date. Where a change materially affects how we use data you have already given us, we will notify you by email or in-app notice and, where the law requires it, seek your fresh consent before the change takes effect.