Legal

Privacy Policy

How J.RUUPSHILAA PRIVATE LIMITED, operator of Asyncotel, collects, uses and protects your data. Written to be readable — not to hide behind jargon.

Last updated · 24 April 2026

This Privacy Policy describes how J.RUUPSHILAA PRIVATE LIMITED (registered at 967/1, C.P. Mission Compound, Sipri Bazar, Jhansi, Uttar Pradesh – 284003; GSTIN 09AAGCJ5051K1ZF) handles personal and business data on our Asyncotel SaaS platform.

We comply with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDP Act). For data processing on behalf of your hotel (e.g. guest records), Asyncotel acts as a Data Processor and the hotel is the Data Fiduciary.

1. Information We Collect

Account information

Name, email, phone, organisation name, role, and login credentials (stored as salted hashes, never in plaintext).

Business information

Property name, address, GSTIN, PAN, room inventory, tariffs, and other operational data you configure in the platform.

Guest & transaction data

Bookings, check-ins, guest IDs (for GRC/Form-C compliance), invoice records, payment references and communication history — stored on your behalf as Data Processor.

Payment information

Card/UPI details are handled entirely by Razorpay (PCI-DSS certified). We store only the Razorpay payment/order IDs and masked references — not full card numbers or CVVs.

Technical & usage data

IP address, browser, device type, pages visited, feature usage and diagnostic logs — used for security, debugging and product improvement.

WhatsApp Business data

When a hotel connects its WhatsApp Business number, we store the message body, sender/recipient phone numbers, contact names (where provided by WhatsApp), delivery status and timestamps for each conversation. This data is used to power the hotel's operator inbox and AI assistant. Retained for the life of the hotel's account, subject to the deletion process on our Data Deletion page.

2. How We Use Your Data

  • Provide, operate and maintain the Services under your subscription.
  • Process payments, raise GST-compliant invoices and manage billing cycles.
  • Authenticate users, prevent fraud, and investigate security incidents.
  • Send transactional email (receipts, trial expiry, security alerts) and operational notifications.
  • Improve the platform through aggregated, de-identified usage analytics.
  • Comply with Indian legal obligations (IT Act 2000, DPDP Act 2023, GST law).

We do not sell your data, and we do not share it with third parties for their own marketing.

3. Third Parties We Work With

To deliver the Services we rely on a small number of trusted sub-processors. Each is contractually bound to handle your data only on our instructions and to uphold appropriate security standards:

ProviderPurpose
RazorpayPayment gateway (PCI-DSS compliant)
Supabase / AWSDatabase, object storage (data hosted in Mumbai, India)
RailwayApplication hosting
Resend / PostmarkTransactional email (receipts, alerts)
PostHogProduct analytics (de-identified usage)
OTAs & channel managersOnly when you connect one (Booking.com, MMT, Agoda, Aiosell, etc.)
Meta / WhatsApp BusinessOnly when you connect a WhatsApp Business number — message delivery and webhook routing via Meta's Cloud API
Google (Gemini API)AI assistant for WhatsApp replies — guest message text sent per-turn, no training on your data

We may also disclose data where required by law, a valid court order, or to protect the rights and safety of our users.

4. Data Security

  • All traffic encrypted over TLS 1.2+; HSTS enabled on production domains.
  • Passwords stored using industry-standard one-way hashing (bcrypt/argon2 with salt).
  • Role-based access control within the platform; principle of least privilege for our engineers.
  • Daily encrypted database backups; 30-day retention.
  • Regular dependency security scanning; incident response protocol in place.

5. Data Retention

We retain your data for as long as your account is active. On cancellation, data is available in read-only export mode for 30 days. After that, it is purged from production within a further 60 days, subject to the following exceptions:

  • • Financial records (invoices, GST filings) — retained for 8 years as required by Indian tax law.
  • • Audit logs for security investigations — retained for up to 2 years.
  • • Anonymised aggregate statistics may be retained indefinitely.

6. Cookies & Tracking

We use strictly-necessary cookies for authentication (session tokens) and a small set of first-party analytics cookies via PostHog to understand product usage. We do not run third-party advertising trackers or sell cookie data.

7. Your Rights (DPDP Act 2023)

Right to access

Request a copy of the personal data we hold about you.

Right to correction

Update inaccurate or outdated information directly in-app, or by emailing us.

Right to erasure

Request deletion of your account and associated personal data after any statutory retention period. See our Data Deletion page for step-by-step instructions for hoteliers and for guests whose WhatsApp messages we hold.

Right to data portability

Export your data in machine-readable form at any time from the in-app export tools.

Right to grievance redressal

Raise a complaint to our Grievance Officer (details below) — we respond within 30 days as required by DPDP Act 2023.

8. Children's Data

Asyncotel is a B2B tool for hospitality operators. We do not knowingly collect personal data from individuals under 18 as account holders. If you believe a minor has created an account, please contact us and we will remove the record.

9. Grievance Officer

In line with Rule 3(11) of the IT Rules, 2011 and the DPDP Act 2023, our designated Grievance Officer is:

Rishabh Raj

J.RUUPSHILAA PRIVATE LIMITED

967/1, C.P. Mission Compound, Sipri Bazar, Jhansi, UP – 284003

Email: admin@asyncotel.com

Phone: +91 88893 65318

We aim to acknowledge grievances within 48 hours and resolve them within 30 days.

10. Updates to this Policy

We may update this Policy to reflect changes in law, product features or security practices. Material changes are notified by email to the account owner and posted here with a revised "Last updated" date. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

Privacy or data request?

Write to our Grievance Officer — we reply within 48 hours.