Legal

Privacy Policy

Last updated: 13 August 2026

This Privacy Policy explains how SaiStay Shirdi ("we", "us", "our") collects, uses, stores and protects information when you use our website and booking services. This policy is provided for general informational purposes; please have it reviewed by a qualified legal professional before relying on it for compliance purposes.

1. Information We Collect

  • Contact details: full name, mobile number, alternate mobile number, email address and postal address, collected when you make a booking or submit an inquiry.
  • Identity documents: a copy of a government-issued identity proof (such as Aadhaar, Driving Licence, Passport or Voter ID), collected only with your explicit consent, for booking and verification purposes.
  • Payment information: we do not store your card, UPI or bank details. Payments are processed by our payment gateway partner; we retain only the transaction reference, amount and status.
  • Booking information: stay dates, room preferences, number of guests, and booking/communication history.
  • Technical information: IP address and browser user-agent, used for security and fraud-prevention purposes (for example, rate-limiting login and lookup attempts).
  • Cookies: we use essential session cookies required for the website and booking process to function (for example, to keep you logged into the booking-status lookup and to protect forms with CSRF tokens). We do not use these cookies for third-party advertising.

2. How We Use Your Information

  • To process and manage your room booking, including calculating pricing and advance payments.
  • To verify your identity in coordination with our partner properties, where required.
  • To communicate booking confirmations, property/stay details, and support messages via WhatsApp, SMS, email or phone.
  • To detect and prevent fraud, abuse, and unauthorized access to our systems.
  • To comply with applicable legal and regulatory obligations.

3. Identity Document Security

Identity documents are stored outside our public website directory, encrypted at rest, and are never publicly accessible. Access is restricted to authorized administrative staff who require it for booking verification, and every access is logged. Identity documents are never included in email, SMS, WhatsApp messages, booking confirmations, or any customer-facing page.

4. Who Can Access Your Information

Your information is accessible only to authorized staff members based on their role (for example, booking managers handle stay and payment details; verification staff handle identity documents). Property/hotel identity, contact and location details are visible only to authorized administrators and are shared with you only after your booking is confirmed.

5. Third-Party Services

We use third-party services to operate our platform, including a payment gateway (for processing advance payments) and, where configured, WhatsApp/SMS providers (for sending booking-related messages). These providers process your information solely to deliver their respective service to us and are bound by their own privacy and security practices.

6. Data Retention

We retain booking and customer information for as long as necessary to fulfil the purposes described in this policy and to meet legal, accounting, or reporting requirements. Identity documents may be retained for a limited period after your stay for verification and dispute-resolution purposes, after which they may be securely deleted upon request or as per our internal retention schedule.

7. Your Choices

You may request access to, correction of, or deletion of your personal information (subject to our legal and legitimate business retention needs) by contacting us at help@saistayshirdi.example.

8. Security Measures

We apply administrative and technical safeguards including encrypted storage of identity documents, role-based access control, audit logging of sensitive data access, secure password storage, and CSRF/session protections. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

10. Contact Us

For privacy-related questions, please reach out via our Contact page.