1. Who this policy covers
Atithi Pro is used by two kinds of people, and their data is treated differently:
- Hotel users — owners, admins and staff who create an account and operate the app. For this data, we are the data fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
- Hotel guests — people whose details a hotel records during check-in. Here the hotel is the data fiduciary (it decides to collect the data to meet its legal obligations), and Atithi Pro processes that data on the hotel's behalf. Guests should direct requests about their data to the hotel they stayed at; we assist hotels in fulfilling them.
2. Data we collect
From hotel users
- Name, mobile number and role, verified via SMS OTP at login.
- Property details you configure: hotel name, address, GSTIN, logo, rooms, pricing, invoice settings, staff list and permissions.
- Your hotel's location — only if you ask for it. If you tap “Use my current location” while setting up the property, the app reads your device's location once, converts it into a street address to fill the form for you, and saves that address (with its coordinates) to your property profile. You can always skip it and type the address yourself. See section 3.
- Subscription and payment status. Payments are processed by Razorpay — we never see or store your card, UPI or bank credentials.
- Basic diagnostic data needed to keep the app working reliably.
About hotel guests (entered by the hotel)
- Guest register details: name, address, date of birth, mobile number, ID document type and number, travel details, room, stay dates and payment records.
- Images of identity documents (such as Aadhaar, PAN, Driving Licence, Voter ID or Passport) captured by hotel staff during check-in.
3. Device permissions
The app asks for a device permission only when a feature actually needs it, at the moment you use that feature. You can refuse any of them, or withdraw them later in your phone's settings — only the feature that needs the permission stops working, not the rest of the app.
- Camera — to scan and photograph guest ID documents at check-in. The camera opens only when staff start a scan.
- Photos, media & files — to let staff pick an existing ID photo from the gallery instead of scanning, and to save the documents the app produces (guest register PDFs, GST invoices, reports) to the device so they can be printed or shared. A hotel can also switch on Auto-Save ID Images (off by default, set per device), which keeps a copy of each scanned ID in that phone's own photo gallery. Those copies belong to the hotel and never leave its device — so the hotel decides how long to keep them and is responsible for securing and deleting them.
- Location — used once, during property setup, and only if you tap “Use my current location”. It fills in your hotel's address so you don't have to type it. The address — and the coordinates it came from — are then saved to your property profile; the address is what prints on your invoices and reports. We do not track your location in the background, do not collect location from guests, and never use location for advertising or profiling.
- Notifications — to send operational reminders only: a govt guest report still pending, the monthly guest-register download before older ID images are cleared, offline entries finishing sync, and subscription or service notices. We never send marketing pushes.
- Microphone — reserved for an optional voice search inside the app. The feature is not enabled in the current release; no audio is recorded, stored or transmitted. If we switch it on, the microphone is used only while you hold the search button, purely to turn speech into your search text.
4. How we use data
- To operate the guest register, room board, daybook and invoicing.
- To auto-fill your state's official guest-reporting portal (for example, Gujarat's Pathik system) at the hotel's explicit direction — this is the hotel submitting its own legally required record, with typing automated.
- To extract text from ID images using AI (see section 5).
- To provide support, process subscriptions and send service messages (OTP, billing, critical notices).
We do not sell personal data. We do not use guest data for advertising or marketing. Ever.
5. AI processing of ID images
When staff scan an ID, the image is sent to Google's Gemini API solely to extract the text fields (name, address, document number) for the entry form. This happens under Google's paid API terms, under which submitted content is not used to train Google's models. The extracted text is shown to staff for review before anything is saved.
6. Storage & security
- Data is stored in a managed cloud database (Supabase) with encryption in transit and at rest.
- Every hotel's data is isolated by row-level security — one property can never read another's records.
- Staff access is limited by per-screen permissions set by the hotel admin.
- Aadhaar numbers are masked to the last four digits wherever they are printed or exported (registers, reports).
7. Retention & automatic deletion
Retention follows the principle of the DPDP Act: keep data only as long as its purpose requires.
- Guest register text (name, address, document number, dates) is retained for the period state lodging and guest-reporting rules require hotels to keep guest records (typically 3–5 years), then purged.
- ID images are deleted from our systems after a short retention window (90 days after checkout by default) — long-term storage of Aadhaar copies is a risk, not a feature. Hotels download a monthly Guest Register PDF beforehand so their legal record stays complete. This covers the copies we hold; if a hotel has switched on Auto-Save ID Images (section 3), the copies sitting in its own device gallery are the hotel's to keep or delete.
- Hotel user accounts are kept until deleted — see Delete your account.
8. Sharing
We share data only with the services needed to run Atithi Pro:
- Official state guest-reporting portals (such as Gujarat's Pathik system) — at the hotel's direction, for its legally required guest reports.
- Razorpay — subscription payments.
- Google (Gemini API) — ID text extraction, as described above.
- Google Firebase — OTP delivery for login.
- Supabase — database and file storage infrastructure.
Each provider receives only what its function requires. We may disclose data if required by law or a valid government request, and we will tell the affected hotel unless legally barred from doing so.
9. Your rights
Under the DPDP Act you may:
- Access a summary of your personal data we hold;
- Correct inaccurate or incomplete data (most of it is editable in-app);
- Request erasure, subject to the legal retention duties above;
- Nominate a person to exercise these rights on your behalf;
- Raise a grievance and, if unresolved, complain to the Data Protection Board of India.
Guests should contact the hotel they stayed at first (it controls the record); we support hotels in responding.
10. Children
Atithi Pro accounts are for adults operating a lodging business. Guest records may include children's counts or details where law requires — entered by the hotel for compliance only.
11. Grievance officer
Vishal Patel · support@atithipro.in · +91 95582 86341 · India. We acknowledge grievances within 72 hours and aim to resolve them within 7 working days.
12. Changes
We will update this policy as the product and law evolve. Material changes are announced in-app and the “last updated” date revised. Continued use after a change means acceptance.