Effective: 1 June 2026 · Shahtra to Stay · India DPDP Act, 2023 compliant
We do not sell your data or use it for third-party advertising.
KYC document numbers (Aadhaar, PAN) are encrypted using AES-256 (Fernet) at the application layer before storage. Encryption keys are managed via environment secrets, never committed to code. KYC document images are stored as S3 object keys (not publicly accessible URLs). Access to KYC records is logged at the field level.
No PII (email, phone, Aadhaar, PAN, bank details) is written to any application log.
No data is shared with advertisers, data brokers, or analytics platforms.
| Data type | Retention | Reason |
|---|---|---|
| Booking records | 7 years | GST / legal obligation |
| Payment records | 7 years | RBI / GST / income tax |
| Chat messages | 2 years from stay date | Dispute resolution |
| KYC document refs | Deleted 30 days after account closure | DPDP right to erasure |
| Account PII (name, phone) | Deleted on account closure | DPDP right to erasure |
| Raw KYC numbers | Encrypted at rest; never exposed | Security best practice |
Under the India Digital Personal Data Protection Act, 2023, you have the right to:
We use only functional cookies (session authentication). No tracking or advertising cookies. The platform does not use Google Analytics, Meta Pixel, or similar tracking tools.
We will notify you by email at least 14 days before any material change. Continued use of the Platform after the effective date constitutes acceptance.
Data Protection Officer: dpo@shahtra.in · legal@shahtra.in