Privacy Policy
Your privacy is paramount. This policy explains what data we collect, how we use it, and the controls you have over your information.
1. Information We Collect
- Account data: name, email, phone, role — provided when your hotel admin creates your account.
- Guest data: name, contact details, ID proof type & number, co-traveller details, stay preferences.
- Transaction data: booking records, folio charges, payments, invoices (with GST breakdown).
- Usage data: IP address, browser type, pages visited — collected via standard server logs for security & analytics.
- Communication data: emails sent (booking confirmations, invoices), WhatsApp messages dispatched.
2. How We Use Your Data
- To operate the hotel management platform — bookings, billing, POS, housekeeping, CRM.
- To send transactional emails (booking confirmations, check-in/out alerts, invoices, Wi-Fi credentials).
- To send WhatsApp notifications (booking, check-in, checkout, feedback requests).
- To generate reports and analytics for hotel management.
- To comply with Indian GST regulations and maintain audit logs.
- To prevent fraud, abuse, and unauthorized access (rate limiting, activity logging).
3. Data Security
We employ industry-standard security measures: HTTPS/TLS encryption in transit, Content-Security-Policy headers, X-Frame-Options DENY (clickjacking protection), X-Content-Type-Options nosniff, input validation & sanitization on all endpoints, rate limiting on authentication (10 attempts/minute), and role-based access control (RBAC). Sensitive operations (checkout, payment recording) are logged in an immutable audit trail. Passwords are stored using hashed comparisons. API keys and SMTP credentials are never exposed to the client side.
4. Data Sharing & Third Parties
We do not sell your data. We share data only with: (a) your hotel's authorized staff who have role-based access, (b) OTA channel partners when you explicitly enable sync (MakeMyTrip, Goibibo, Booking.com, etc.), (c) email/WhatsApp service providers you configure (your own SMTP server, WhatsApp Business API), and (d) legal authorities when required by Indian law. All third-party integrations are opt-in and controlled by the hotel admin.
5. Your Rights (DPDP Act 2023 & GDPR)
- Access: Request a copy of your personal data held by us.
- Correction: Update or correct inaccurate information via the Guest CRM or Settings.
- Erasure: Request deletion of your account and associated data (subject to GST record retention requirements).
- Portability: Export your data in CSV/XLS format via the Reports module.
- Objection: Opt out of marketing communications at any time.
- Withdrawal: Revoke portal access or OTA sync at any time from Settings.
6. Data Retention
Booking and invoice data is retained for 7 years as required by Indian tax law (GST records). Guest profiles are retained while the guest has an active relationship with the hotel. Activity logs are retained for 1 year. Deleted records are permanently removed from the database within 30 days.
7. Cookies & Tracking
We use essential cookies for authentication and session management. We do not use third-party advertising cookies or tracking pixels. Analytics, if enabled, uses privacy-first first-party tracking only.
8. Legal Basis & Jurisdiction
This policy is governed by the Digital Personal Data Protection (DPDP) Act, 2023 (India) and GDPR (for EU guests). Disputes are subject to the jurisdiction of the courts of Mumbai, India. The Data Protection Officer can be reached at privacy@theoretichotels.com.
9. Contact Us
Theoretic Hotels is owned and operated by Theoretic Softnet Pvt Ltd. For privacy questions, data requests, or to exercise your rights, contact us at privacy@theoretichotels.com or call/WhatsApp +91 92679 70157, or write to: Theoretic Softnet Pvt Ltd, Data Protection Officer, Mumbai, India. We respond to all requests within 30 days.