Privacy Policy

How DigiReg collects, uses, protects and respects personal data — for hotel partners, guests and all stakeholders

 DPDP Act, 2023  IT Act, 2000  Indian Law Compliant  Hotel Management Policy  Version 1.0 — April 2026
Data SecurityYour data is encrypted and protected at all times
No Data SellingWe never sell or trade personal information
India FirstAll data stored on servers located in India
TransparentClear and honest about what we collect and why
Your RightsFull support for your data rights under Indian law

 Table of Contents

1

Who We Are

DigiReg ("we", "us", "our", "Platform") is a cloud-based Hotel Management System operating at digireg.online. We provide hotel partners with digital tools for guest check-in, room management, reservations, billing, OTA channel management, and administrative operations.

DigiReg acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023, responsible for determining the purpose and means of processing personal data on the platform.

 Hotel partners using the DigiReg platform act as Data Processors under Indian law and are equally bound by the obligations outlined in this policy.
2

Scope of this Policy

This Privacy Policy applies to:

  • Hotel Partners — registered hotels and lodging establishments using DigiReg
  • Hotel Guests — individuals whose data is collected at check-in or reservation
  • Hotel Staff — front desk and management personnel accessing the platform
  • Platform Visitors — anyone visiting digireg.online
  • Admin Users — DigiReg super administrators managing the platform

This policy covers all modules: Check-In Registration, Reservations, Billing & Invoicing, Room Management, OTA Channel Management, Draft Saving, and the Admin Dashboard.

3

Information We Collect

Guest Personal Information
  • Full name, mobile number, email address
  • Home / permanent residential address
  • Government-issued photo ID type and number (Aadhaar, PAN, Passport, Driving Licence, Voter ID)
  • Photographs of ID documents — front and back
  • Digital signature captured at check-in
  • Check-in date, time, and check-out date and time
  • Room number, duration of stay, agreed room rate
  • Booking reference, payment amounts, payment mode, transaction references
  • Special requests or remarks (e.g. early check-in, dietary needs)
Hotel Partner Information
  • Hotel name, registered address, city, state
  • Contact person name, mobile number, email address
  • GST number and PAN number
  • Login username and cryptographically hashed password
  • WiFi credentials (stored in encrypted form)
  • SMS API keys (stored encrypted, never exposed in the user interface)
  • Room configuration, rates, and room type details
  • OTA channel integration settings
Technical & Usage Data
  • IP address and login timestamps
  • Browser type, device information, and operating system
  • Session identifiers and activity logs
  • Temporary draft form data (auto-cleared after 30 days or on submission)
  • API request logs for security and auditing purposes
 Data Minimisation: We collect only the minimum data necessary for lawful hotel operations and compliance with Indian regulations.
4

How We Use Your Data

PurposeData UsedWho Benefits
Guest check-in registration and record keeping as required by lawName, ID, address, photos, signatureHotel, Guest, Law
Room reservation creation, confirmation and managementName, mobile, dates, room, rateHotel, Guest
Billing, invoice generation, and payment trackingFinancial data, booking detailsHotel, Guest
Identity verification as mandated for lodging establishmentsID type, ID number, photosHotel, Law
OTA channel sync — room availability only, no guest PIIRoom IDs, dates onlyHotel
Occupancy reports and operational analyticsAggregated, anonymised dataHotel
Platform security, fraud prevention and access controlLogs, session, IP dataPlatform
Legal and regulatory complianceGuest register dataLaw, Hotel
Customer support and grievance resolutionContact details, booking infoGuest, Hotel
5

Legal Basis for Processing

Under the Digital Personal Data Protection Act, 2023 and IT (SPDI) Rules, 2011, all data processing is conducted on the following lawful bases:

Legal BasisApplication
ConsentDigital signature collected from guests at check-in. Explicit consent for data recording.
Legal ObligationHotel guest registers are mandatory under state Police Acts, The Foreigners Act 1946, and Hotel & Lodging House Rules.
Contractual NecessityProcessing required to execute reservations, manage billing, and deliver platform services.
Legitimate InterestPlatform security, activity logging, fraud detection, session management, and service improvement.
Vital InterestEmergency situations involving guest safety where data disclosure is necessary.
6

Hotel Partner Responsibilities

As Data Processors under Indian law, hotel partners using DigiReg must:

  • Collect and use guest data only for lawful lodging, compliance, and operational purposes
  • Display a physical or digital privacy notice at the reception / check-in point informing guests that their data will be recorded
  • Obtain guest consent — fulfilled via the digital signature on the DigiReg check-in form
  • Ensure all staff with platform access are trained on and bound by data protection obligations
  • Not share, sell, or disclose guest data to any third party without explicit guest consent or legal compulsion
  • Not use guest data for marketing, loyalty programmes or promotions without a separate explicit opt-in
  • Report any actual or suspected data breach to DigiReg within 72 hours of discovery
  • Maintain physical and device security for all computers and mobile devices used to access the platform
  • Cooperate fully with DigiReg in any data protection audit, investigation, or legal inquiry
  • Ensure data is not retained beyond the legally prescribed periods (see Section 9)
 Non-compliance with these obligations may result in immediate suspension of platform access and may expose the partner to legal liability under Indian law.
7

Guest Check-In & ID Compliance

Under the Hotel and Lodging House (Licensing and Control) Rules applicable in most Indian states and the Foreigners Act, 1946, hotel establishments are legally mandated to maintain a guest register recording identity proof details for every guest.

Aadhaar & ID Handling Rules
  • Aadhaar numbers are not used for authentication — recorded only for identity compliance as legally permitted
  • ID photographs are stored securely per hotel and are not shared across hotels or with any third party
  • We strongly recommend hotels record only the last 4 digits of Aadhaar where the full number is not legally required
  • DigiReg does not operate any central biometric database
  • Physical photocopying of Aadhaar cards is not recommended — use the DigiReg camera capture feature instead
  • ID data is shared with law enforcement only upon a valid legal order
Digital Signature at Check-In
  • The digital signature captured in DigiReg constitutes the guest's consent to data collection for lodging compliance
  • Signatures are stored as encrypted image data linked to the specific guest record
  • Signatures are not used for any purpose other than the guest register record
 For foreign nationals, hotels must comply with the Foreigners Act, 1946 and report guest details to the local Foreigners Registration Office (FRO) as applicable.
8

Data Storage & Security

Where Data is Stored
  • All data is stored on servers physically located in India — compliant with data localisation requirements
  • Each hotel's data is completely isolated — no cross-hotel data access is possible
  • Database backups are encrypted and stored in India
Technical Security Measures
Security MeasureDescription
Encryption in TransitAll data transmitted via HTTPS / TLS 1.2+ — no plain HTTP
Encryption at RestSensitive fields, API keys, and passwords encrypted in database
Password HashingPasswords stored using one-way cryptographic hash — never in plain text
Role-Based AccessHotel staff can only access their own hotel's data — strict RBAC
Session ManagementAutomatic session timeout after inactivity period
Audit LoggingAll logins, data access, and changes logged with timestamps and IP
API SecurityAll API endpoints require authenticated hotel session tokens
Draft SecurityDraft data cleared after successful submission or 30-day expiry
Organisational Security
  • DigiReg staff access to production data is strictly limited and logged
  • Regular security reviews and vulnerability assessments conducted
  • Partner hotel staff are responsible for device and login credential security
 Security practices comply with Rule 8 of the IT (SPDI) Rules, 2011 which mandates reasonable security practices for entities handling sensitive personal data.
9

Data Retention

We retain data only as long as legally required or necessary for platform operations:

Data TypeRetention PeriodLegal / Operational Basis
Guest check-in records (name, ID, dates)5 yearsState Police Acts / Hotel Lodging Rules
Guest ID photographs and signatures5 yearsLodging compliance requirement
Reservation records3 yearsContractual / operational
Billing and financial records7 yearsIncome Tax Act, 1961 — Section 44AA
Login and activity logs1 yearIT Act, 2000 / platform security
Hotel partner account dataDuration of partnership + 2 yearsContractual
Deleted hotel — all dataPurged immediatelyDPDP Act, 2023 — right to erasure
Draft / temporary form data30 days or on submissionLegitimate interest
OTA sync logs90 daysDebugging / operational
 After retention periods expire, data is permanently and irreversibly deleted from all systems and backups.
10

What We Never Do

As a commitment to our hotel partners and their guests, DigiReg makes the following absolute guarantees:

Never sell personal data to advertisers, data brokers, or any third party
Never use guest data for targeted advertising or marketing without explicit consent
Never allow cross-hotel data access — your guests are yours alone
Never store passwords in plain text — all passwords are one-way hashed
Never share Aadhaar or PAN data with any entity without a valid legal order
Never transmit data without HTTPS encryption — no plain HTTP allowed
Never run advertisements or allow advertisers to influence platform content
Never build individual profiles for purposes beyond hotel management operations
11

Third-Party Services

DigiReg integrates with a limited number of third-party services strictly for operational purposes. Data shared is the minimum necessary:

Third PartyPurposeData SharedGuest PII Shared?
Law Enforcement / PoliceGuest register verification per legal orderGuest register dataYes — legal obligation only
State Tourism / FRORegulatory compliance reportingAs mandated by regulationYes — legal obligation only
OTA Platforms (Booking.com, Airbnb etc.)Room availability synchronisationRoom IDs and dates onlyNo
SMS Service Provider (Fast2SMS)OTP and notification deliveryMobile number onlyMobile only
Payment ProcessorsTransaction processing if integratedMinimum requiredPartial
Cloud / Hosting ProviderServer infrastructureEncrypted database dataEncrypted only
 All third-party service providers are contractually required to maintain data protection standards at least equivalent to this policy.
12

Your Rights

Under the Digital Personal Data Protection Act, 2023, all individuals (Data Principals) have the following rights:

Right to AccessKnow what personal data DigiReg or your hotel holds about you
Right to CorrectionRequest correction of inaccurate or incomplete personal data
Right to ErasureRequest deletion of data where legally permissible
Right to GrievanceLodge a complaint about how your data is handled
Right to WithdrawWithdraw consent where processing is consent-based
Right to NomineeDesignate a nominee to exercise rights on your behalf
How to Exercise Your Rights
  • Contact your hotel directly for access or correction of your check-in record
  • Contact DigiReg at privacy@digireg.online for platform-level data requests
  • All requests acknowledged within 3 business days and resolved within 30 days
  • If unsatisfied with DigiReg's response, you may approach the Data Protection Board of India
13

Cookies & Sessions

DigiReg uses only essential session cookies required for platform functionality. We do not use advertising cookies, tracking cookies, or analytics cookies from third parties.

Cookie TypePurposeDurationCan be Disabled?
Session CookieMaintains your login session securelySession (cleared on logout)No — platform will not function
CSRF TokenPrevents cross-site request forgery attacksSessionNo — security essential
Draft StorageSaves incomplete forms for later completion30 daysYes — clear via browser settings
 DigiReg does not use Google Analytics, Facebook Pixel, or any third-party tracking scripts on the hotel management platform.
14

Children's Privacy

DigiReg's hotel management platform is designed for use by adults only — hotel partners, staff, and adult guests.

  • We do not knowingly collect personal data from individuals under 18 years of age as independent platform users
  • Guest data for minor family members may be recorded as part of a family check-in — with the consent of the accompanying adult
  • Under the DPDP Act, 2023, processing of data of children requires verifiable parental consent
  • If we discover that data of a child has been collected without parental consent, we will delete it promptly
15

Data Breach Procedure

In the event of a data breach, DigiReg follows this structured response protocol:

StepActionTimeline
1 — ContainIsolate affected systems to prevent further data exposureImmediate
2 — AssessDetermine scope, data types affected, and number of individuals impactedWithin 24 hours
3 — Notify PartnersInform all affected hotel partners with clear details of the breachWithin 72 hours
4 — Notify AuthoritiesReport to the Data Protection Board of India as required by DPDP Act, 2023Per DPB guidelines
5 — Notify IndividualsInform affected guests and individuals without undue delayAs soon as possible
6 — RemediatePatch vulnerabilities and strengthen security controlsWithin 7 days
7 — DocumentMaintain complete record of the breach and all actions takenOngoing
8 — ReviewConduct post-incident security audit to prevent recurrenceWithin 30 days
 Hotel partners must report any breach or suspected breach to DigiReg at privacy@digireg.online within 72 hours of becoming aware of it.
16

Policy Changes

This Privacy Policy may be updated periodically to reflect changes in Indian law, platform features, or operational practices.

  • Hotel partners will be notified of material changes via email at least 30 days before they take effect
  • The updated policy will always be available at digireg.online/privacy-policy
  • Continued use of the DigiReg platform after the effective date of a policy update constitutes acceptance of the revised policy
  • Version history is maintained and available upon request
  • For minor clarifications or formatting changes, no advance notice may be given — the "Last Updated" date will reflect any change
  Current: Version 1.0  |  Effective: April 2026  |  Next Review: April 2027
17

Grievance Officer

As required under Rule 5(9) of the IT (SPDI) Rules, 2011 and Section 13 of the DPDP Act, 2023, DigiReg has designated a Grievance Officer:

DigiReg Grievance & Privacy Officer

 Organisation: DigiReg Hotel Management System

 Website: digireg.online

 Email: privacy@digireg.online

 Acknowledgement: Within 3 business days

 Resolution: Within 30 days of complaint receipt

 Jurisdiction: Courts of Uttarakhand, India

If unsatisfied with our resolution, you may approach the Data Protection Board of India at meity.gov.in

18

Governing Law & Jurisdiction

This Privacy Policy is governed exclusively by the laws of the Republic of India. The following acts and regulations apply:

  • Digital Personal Data Protection Act, 2023 (DPDP Act) — primary data protection law
  • Information Technology Act, 2000 and IT (Amendment) Act, 2008
  • IT (Reasonable Security Practices) Rules, 2011
  • Indian Contract Act, 1872 — for partner agreements
  • Consumer Protection Act, 2019 — for guest rights
  • Income Tax Act, 1961 — for financial data retention
 Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the courts located in Uttarakhand, India.

Your Trust is Our Foundation

DigiReg is built on the principle that your guests' privacy matters as much as their comfort. We are committed to responsible, transparent, and secure data stewardship — so you can focus on delivering exceptional hospitality.

Questions? Contact us at privacy@digireg.online  |  digireg.online  |  Version 1.0 — April 2026