Privacy Policy

Last Updated: July 26, 2026

OpenStays Private Limited (“OpenStays”, “we”, “us”, or “our”) is committed to protecting your privacy and handling Personal Data in compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules framed thereunder, along with other applicable Indian laws.

This Privacy Policy explains how we collect, use, process, disclose, store, and protect Personal Data when you access or use our website (openstays.org, openstays.in), mobile applications (when launched), WhatsApp AI booking agent, voice AI agents, booking engine, and any related services (collectively, the “Platform”).

By using the Platform, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.This Privacy Policy is incorporated into and forms part of our Terms & Conditions. Please read both documents together.

1. Scope

This Policy applies to:

  • Guests (individuals making inquiries or bookings)
  • Hosts (property owners/managers using the Platform)
  • Partners (authorized travel agents, affiliates, and integrated AI agents)
  • Any other users interacting with the Platform, including through WhatsApp or voice calls

2. Personal Data We Collect

We collect the following categories of Personal Data:

A. Data provided by you or generated during use:

  • Contact information (name, phone number, email)
  • Government-issued identity documents (Aadhaar, passport, etc.) collected with OCR extraction
  • Booking details, dates, number of guests, special requests
  • Guest preferences (e.g., vegetarian food, EV vehicle charging, family details, bedding preferences)
  • Conversation logs and transcripts with WhatsApp AI and voice AI agents
  • Payment confirmation references (we do not store full payment card, UPI, or bank details — these are processed directly by third-party gateways)

B. Automatically collected data:

  • Device and usage information (IP address, browser type, device ID, operating system)
  • Interaction data with the booking engine, calendar, and AI agents
  • Auditable activity logs for compliance and security

C. Data from third parties:

  • Information received from integrated Partners, Google, Meta or payment gateways (limited to what is necessary for service provision)

We collect only the data that is necessary for the purposes outlined below (data minimisation).

3. Purposes of Processing

We process Personal Data solely for the following lawful purposes:

  • Providing and improving the Platform services, including AI-driven end-to-end reservations (inquiry, negotiation, confirmation, check-in, and follow-ups)
  • Identity verification and management (OCR extraction, one-time storage, and reuse across properties only with your explicit consent)
  • Facilitating direct payments and generating booking confirmations
  • CRM functionality — storing and using preferences for personalised communication
  • Statutory and regulatory compliance (Form C filing for foreign guests, police verification, printable export of records, and other hospitality/tourism requirements)
  • Dynamic pricing, revenue optimisation, occupancy analysis, and AI nudges
  • Communicating service updates, reminders, and one-click consent-based actions
  • Integrating with approved Partners (travel agents and other AI agents) to enable seamless booking distribution
  • Internal business operations (auditing, analytics in de-identified form, security, and product improvement)
  • Responding to legal requests and enforcing our Terms & Conditions

4. Consent

Under the DPDP Act, we rely on your free, specific, informed, unconditional, and unambiguous consent for processing Personal Data.

  • For most Platform features (including WhatsApp/voice AI interactions), consent is obtained through your continued use and affirmative actions (e.g., initiating a conversation or submitting a booking).
  • Explicit verifiable consent is obtained for:
    • Reuse of Guest ID across multiple properties
    • Sharing with Partners where required
    • Any other sensitive or secondary processing

You may withdraw consent at any time. Withdrawal will not affect the lawfulness of processing done prior to withdrawal and may result in limited or terminated access to certain features.

5. Sharing and Disclosure of Personal Data

We do not sell Personal Data. We may share Personal Data with:

  • Hosts — only the data necessary for fulfilling a confirmed booking and compliance (with your consent for ID reuse)
  • Approved Partners (travel agents and integrated AI agents) — limited to what is required to facilitate bookings, subject to contractual safeguards
  • Service providers (AI infrastructure, cloud hosting, payment gateways, Google, Meta) under strict data processing agreements
  • Regulatory and law enforcement authorities — when required for Form C, police verification, or other legal obligations
  • Successors — in the event of a merger, acquisition, or sale of assets

All third-party recipients are contractually bound to process data only for the specified purposes and in compliance with the DPDP Act.

6. Data Retention

We retain Personal Data only as long as necessary for the purposes for which it was collected or as required by applicable law.

  • Identity data and booking records are retained for the periods mandated by hospitality, tourism, and law-enforcement regulations (including police verification and Form C requirements).
  • Other data (preferences, conversation logs) is retained for the duration of the relationship or as needed for service provision and analytics.
  • Upon expiry of the retention period or upon valid request (where legally permitted), we will erase or anonymise the data.

Erasure rights under the DPDP Act are not absolute where retention is required by law.

7. Your Rights as a Data Principal (DPDP Act)

You have the following rights:

  • Access — obtain a summary of your Personal Data
  • Correction / Completion — request rectification of inaccurate or incomplete data
  • Erasure — request deletion (subject to legal retention obligations)
  • Nomination — nominate another person to exercise rights on your behalf
  • Withdrawal of Consent — at any time (with effect on future processing)
  • Grievance redressal

To exercise any of these rights, please email us at [email protected]
We will respond within the timelines prescribed under the DPDP Act.

8. Grievance Redressal

We have appointed a Grievance Officer. Any grievance relating to Personal Data processing may be addressed to:
Grievance Officer
Email: [email protected]

The Grievance Officer will acknowledge your complaint within 48 hours on working days and resolve it within one month (or such period as prescribed by the DPDP Act).

9. Data Security

We implement appropriate technical, organisational, and administrative safeguards to protect Personal Data from unauthorised access, alteration, disclosure, or destruction. These include encryption, access controls, regular audits, and secure AI infrastructure.

In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act.

10. Children’s Privacy

The Platform is not directed at children under 18 years of age. If we become aware that Personal Data of a minor has been collected without verifiable parental or guardian consent, we will take steps to delete such data.

11. Third-Party Services and Links

The Platform integrates with third-party services (Meta, Google, payment gateways, etc.). Their privacy practices are governed by their own policies. We are not responsible for the privacy practices of such third parties.

12. International Data Transfers

If any processing involves cross-border transfer of Personal Data, we ensure appropriate safeguards (binding contracts or approved mechanisms) are in place to maintain the same level of protection as under the DPDP Act.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Continued use of the Platform after such changes constitutes your acceptance of the revised Policy.

14. Contact Us
For any queries regarding this Privacy Policy or your Personal Data:

Registered Office:
OpenStays Private Limited,
No. 3985, 3rd Floor, 80 Feet Road, 4th Phase Girinagar, Bengaluru, Karnataka, India – 560085

Thank you for trusting OpenStays with your data. We are committed to transparency, security, and full compliance with the DPDP Act while delivering a seamless accommodation booking experience for Indian stays.

WhatsApp Us