Legal
Privacy Policy
Last updated: 18 July 2026
Smart Hostel Pilot("we", "our") provides software that hostel organizations use to manage admissions, safety, attendance, and fee collection. This policy explains what data we process and how we protect it.
1. Who this policy covers
This Privacy Policy applies to hostel organizations that use Smart Hostel Pilot ("Organizations"), and to the residents, guardians, and staff whose data Organizations manage on the platform (collectively, "you"). Each Organization is the data controller for its own resident and staff records; Smart Hostel Pilot acts as a data processor operating the platform on the Organization's behalf.
2. Information we collect
Account information: name, email, phone number, and password for staff, residents, and guardians who sign in to the platform.
Resident records: admission details, room and bed allocation, attendance, leave and gate-pass history, emergency contacts, and fee/payment records maintained by the hostel.
Safety and incident data: SOS alerts, incident reports, visitor logs, and gate entry/exit timestamps, created in the course of hostel safety operations.
Usage data: device and browser information, IP address, and activity logs (who did what, when) used for security, audit, and troubleshooting.
We do not collect biometric data. We do not require Aadhaar or other government ID uploads to operate the platform, though an Organization may separately request such documents for admission purposes outside the platform.
3. How we use information
To operate core hostel workflows: admissions, room allocation, attendance, leave approvals, gate access, fee invoicing, notices, and complaint tracking.
To respond to safety events: routing SOS alerts and incidents to the relevant wardens, guards, and hostel admins in real time.
To give guardians visibility into attendance, approved leave, and fee status when an Organization enables guardian access for a resident.
To secure the platform: authentication, rate-limiting, fraud prevention, and maintaining audit logs of sensitive actions.
We do not sell personal data, and we do not use resident or staff data to serve advertising.
4. Data isolation between organizations
Smart Hostel Pilot is multi-tenant: many Organizations use the same platform, but each Organization's data is isolated using database-level Row Level Security (RLS). Staff and residents can only access records belonging to their own organization and hostel, enforced by policy — not just application logic.
5. Payments
When an Organization enables UPI QR fee collection, resident payments are made directly to the Organization's own UPI-linked bank account. Smart Hostel Pilot records the invoice and payment confirmation but does not hold, route, or have access to the underlying funds.
Where an Organization enables online checkout, payments are processed by our payment gateway partner (Razorpay) under its own privacy and PCI-DSS compliance terms. We store payment status and identifiers required for reconciliation, not full card or bank details.
6. Data retention
Operational records (attendance, leave, gate passes, invoices) are retained for the duration of an active organization subscription and for a reasonable period afterward to support audits, disputes, and legal obligations, after which they are anonymized or deleted on request.
Safety-critical records (SOS alerts, incident reports, audit logs) are retained for a minimum retention period defined in an Organization's settings, to support safety reviews and legal compliance.
7. Your rights
Subject to applicable law, including India's Digital Personal Data Protection Act, 2023, you may request access to, correction of, or deletion of your personal data by contacting your hostel's admin, who can action most requests directly from the platform, or by writing to us at privacy@smarthostelpilot.in.
Where a request requires action beyond what an Organization's admin can perform, we will assist in fulfilling it in accordance with applicable law.
8. Security
We use encryption in transit (TLS) and at rest, role-based access control, rate limiting on sensitive endpoints, and immutable audit logs for sensitive actions. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected Organizations without undue delay.
9. Grievance officer
For privacy questions, complaints, or data requests, contact our Grievance Officer at privacy@smarthostelpilot.in. We aim to acknowledge requests within 3 business days and resolve them within 30 days.
10. Changes to this policy
We may update this policy as the platform evolves. Material changes will be communicated to Organization admins in advance of taking effect.
