Privacy Policy

Last updated 15 July 2026

Hridyaa is hotel management software. Hotels use it to run their front desk, which means it holds information about their guests — including photographs of government ID documents. This page explains what we hold, why, and what happens to it.

Who is responsible for guest data

This distinction matters, so it's first. When a hotel uses Hridyaa:

  • The hotel decides what guest information to collect and why. Under India's Digital Personal Data Protection Act, the hotel is the Data Fiduciary.
  • Hridyaa only processes it on that hotel's instructions, as a Data Processor. We don't decide what's collected, we don't use guest data for our own purposes, and we don't sell it to anyone. Ever.

If you are a hotel guest and want your information corrected or removed, ask the hotel you stayed at — they control it. If they ask us, we'll act on it.

What we hold

About the hotel (our customer)

  • Hotel name, address, GST number where given
  • Owner and staff names, email addresses, mobile numbers, usernames
  • Passwords — stored only as an Argon2id hash, never as text we could read
  • Sign-in times and IP addresses, so an owner can see who accessed their hotel

About guests (entered by the hotel)

  • Name, mobile, email, nationality
  • Photographs of ID documents captured at check-in
  • Booking, folio and payment records

What we don't hold

  • Card numbers. Hridyaa records that a payment happened, not the instrument.
  • Anything from advertising or tracking networks following you around the web.

Where it lives

On servers in India, hosted by Hostinger. Every connection to Hridyaa is encrypted (HTTPS). Each hotel's records are separated from every other hotel's at the database level, not by a filter someone could forget to apply.

Who can see it

  • The hotel's own staff, limited by the role their owner gave them.
  • Us, only when we need to — a support request, or diagnosing a fault. When we sign in as a hotel to help, it's recorded in an audit log with a reason, and we can't switch that off.
  • Nobody else, unless the law requires it.

How long we keep it

While the hotel's account is active. If a hotel asks us to delete their data, we delete it within 30 days — records and ID document files both, removed from disk, with no backup copy retained afterwards.

How to delete your account

You can delete your Hridyaa account and all of its data yourself, at any time:

  1. Sign in at app.hridyaa.com.
  2. Go to Settings → Delete account.
  3. Type your hotel's name to confirm, then choose Delete account permanently.

This immediately and permanently removes everything: all bookings, guests, ID document photographs, payments, the day book and cash drawer, GST invoices, and every staff login for that hotel. It cannot be undone. Only the hotel owner can do this. If you would rather we did it for you, email sales@hridyaa.com from your registered address and we will action it within 30 days.

This isn't aspirational. The deletion tool erases the database rows and unlinks the ID photographs from the server. Once it runs, it can't be undone — which is the point.

Inactive accounts are warned by email before anything happens, and warned again, with a long window to respond, before deletion.

Your data is yours

You don't have to ask us for it. The day book, profit & loss and balance sheet each have Export XLS and Export PDF buttons on the screen, and a guest's ID documents download as a single PDF. Take your records whenever you want — no ticket, no waiting on us.

Cookies

A session cookie to keep you signed in, and a security token to protect forms from being submitted by other sites. No advertising cookies. No third-party trackers following you elsewhere.

What we do to protect it — and what we can't promise

We take security seriously and we've built for it: encrypted connections, passwords hashed with Argon2id so even we can't read them, each hotel's data separated at the database level, and an audit log we can't switch off.

But no system anywhere is completely secure, and we won't claim otherwise. We can't guarantee that no incident will ever occur — what we can tell you is what we've done, what we'd do, and that we won't hide it from you.

Some of it is in your hands too: keep your password to yourself, give staff their own logins with the role they need rather than sharing the owner's, and only enter guest information you're entitled to hold.

Keep your own copy

Export your records regularly — the day book, profit & loss and balance sheet all have Export XLS and PDF buttons, and guest ID documents download as a PDF. We'd rather you had your own copy than had to rely on us having one.

If something goes wrong

If data is exposed in a way that could affect people, we'll tell the affected hotels directly and promptly, with what we know and what we're doing — not a notice buried on a webpage. Where the law requires us to notify the Data Protection Board, we will.

Your obligations as a hotel

Because you're the Data Fiduciary, the law puts these on you, not on us:

  • Collect guest information only where you're entitled to, and only what you need.
  • Tell your guests what you're collecting and why.
  • Respond to your guests if they ask about their information.
  • Keep your own access under control — passwords, roles, who has a login.

We'll help where we can, and the software is built to make these easier. But the relationship is between you and your guests.

Asking us anything

sales@hridyaa.com or WhatsApp +91 99906 66420.
Hridyaa, Forest Residency, Tower A, Malsi, Dehradun 248003, Uttarakhand, India.

Changes

If this policy changes in a way that affects you, we'll tell the hotels using Hridyaa rather than quietly updating the date at the top.