1. Introduction
Hotel Mitra ("Hotel Mitra", "we", "us", or "our") is a software platform that helps hotels, guest houses, and other hospitality properties (each, a "Property") manage day-to-day operations - guest check-in and check-out, room and booking management, staff access, billing, and, where a Property chooses to enable it, restaurant/menu management and WhatsApp-based guest messaging.
This Privacy Policy explains what information Hotel Mitra collects, how it is used, stored, protected, and disclosed, across the Hotel Mitra website and the Hotel Mitra application (together, the "Services"). It applies to two distinct groups of people, described separately throughout this policy: (a) the Property staff and owners who hold a Hotel Mitra account ("Property Users"), and (b) the guests whose information a Property enters into Hotel Mitra as part of running its business ("Guests").
Hotel Mitra is operated by [LEGAL ENTITY NAME OPERATING HOTEL MITRA] ([COMPANY REGISTRATION / GSTIN NUMBER, IF APPLICABLE]). References to "Hotel Mitra" in this policy mean that operating entity.
2. Information We Collect
A. Information from Property Users (hotel/restaurant staff and owners)
When someone creates or uses a Hotel Mitra account on behalf of a Property, we collect:
- Account details: name, username, email address, phone number, and a securely hashed password (Hotel Mitra never stores your password in plain text).
- Role and access information: your role at the Property (e.g. Owner, Admin, Manager) and which Property/Properties or restaurant you are linked to.
- Property/business information entered into the platform: hotel or restaurant name, address, city, state, pincode, and GST details; room inventory and pricing; and, where applicable, restaurant menu and order data.
- Subscription and configuration information: which modules/packages are active for the Property, module entitlement status, and settings you configure (e.g. checkout policy, notification preferences, branding).
- Technical and log information: IP address, browser/device type, and request logs (method, URL, status code, timestamp) generated automatically as you use the Services, used for security, troubleshooting, and abuse prevention.
B. Information about hotel Guests
Hotel Mitra is a property-management system: Properties (not Hotel Mitra) collect and enter Guest information into the platform as part of check-in, stay management, and legally required guest records. Depending on how a Property uses the Services, this can include:
- Identity details: full name, date of birth, age, gender, nationality, and country of residence.
- Contact details: phone number, email address, and address (including city, state, pincode).
- Government identification: ID type (e.g. Aadhaar, passport, driving licence, voter ID, PAN, or another government-issued ID), the associated ID number, and an uploaded image/scan of the identification document - see Section 3 below, which covers this category specifically.
- A guest photo and/or signature captured at check-in, and consent acknowledgement with a timestamp.
- Travel-related details, where recorded: passport number, visa number and expiry date, city travelling from, and next destination.
- Stay and booking details: room number and type, number of guests, check-in and check-out date/time, booking source, purpose of visit, and (visible only to the Property Owner) the room price/booking amount.
- Additional-guest details for multi-guest stays: name, date of birth/age, relationship to the primary guest, gender, nationality, and their own ID type/number/document, where the Property records these.
- Emergency contact and vehicle details, where a Property chooses to record them.
- If the Property enables WhatsApp messaging (Section 5): the guest's WhatsApp number and the content of messages exchanged with the Property through Hotel Mitra.
Hotel Mitra does not independently collect Guest information from any source outside of what a Property enters or a Guest submits directly to the Property (for example, by uploading a document via a QR-code link the Property's staff shares during check-in).
3. Guest Identification Documents
Hotel Mitra allows a Property's authorized staff to upload and store Guest identification documents (such as an Aadhaar card, passport, driving licence, voter ID, PAN, or other government-issued ID) as part of the check-in and guest-record process.
These documents are used for:
- Verifying guest identity at check-in.
- Completing the Property's check-in/check-out process and maintaining its guest records.
- Meeting the Property's applicable legal, regulatory, and law-enforcement record-keeping obligations as a hospitality business.
Access to uploaded identification documents is restricted to authorized users of the relevant Property, based on Hotel Mitra's role-based access-control model (for example, front-desk and management roles that need the document to do their job) - documents for one Property are not visible to another Property, and are not publicly accessible. Hotel Mitra applies reasonable technical and organizational measures, described in Section 7 (Data Security), to protect these documents; no method of storage or transmission can be guaranteed to be completely secure.
Properties are responsible for collecting and handling Guest identification documents appropriately, in line with their own operational practices and the legal obligations that apply to them as a hospitality business.
Retention of guest identification documents
Guest identification documents and the guest records associated with them are intended to be retained for up to 5 years from the date of the guest's stay. This is Hotel Mitra's platform retention target, applied subject to applicable law, contractual requirements, a Property's legitimate business needs, and the Property's own data-retention configuration or requests.
After the applicable retention period, information may be deleted, anonymized, or securely disposed of - subject to any longer retention Hotel Mitra or the Property is required or entitled to apply because of an ongoing legal obligation, dispute, investigation, audit, backup cycle, or other legitimate retention need. A Property Owner can also request permanent deletion of a specific check-in record and its associated documents at any time through the Services; this action is irreversible.
4. How We Use Information
Information described in Section 2 is used to:
- Provide, operate, and maintain the Hotel Mitra Services.
- Support Property operations, including room, booking, and staff management.
- Process guest check-in and check-out, and manage a guest's stay.
- Maintain guest records for identification, verification, and compliance/record-keeping purposes.
- Provide customer support and respond to account-related requests.
- Administer accounts, roles, and module/subscription entitlements.
- Protect the security of the Services, including detecting and preventing fraud, abuse, and unauthorized access.
- Monitor, troubleshoot, and maintain system performance and reliability.
- Improve and develop the Services.
- Send account-related notifications and, where a Property enables it, guest-facing communications (e.g. a check-in confirmation, or WhatsApp messages the Property sends through the integration described in Section 5).
- Manage billing and module/package subscriptions for a Property's account.
- Operate integrations a Property specifically requests or enables, including the WhatsApp/Meta integration described in Section 5.
- Meet applicable legal, regulatory, and law-enforcement obligations.
5. WhatsApp / Meta Integration
Hotel Mitra offers an optional integration that lets a Property connect its own WhatsApp Business Account (via Meta's Embedded Signup flow) to communicate with its guests over WhatsApp. This integration is off by default - a Property chooses whether to connect it.
Where a Property enables this integration, Hotel Mitra:
- Stores identifiers for the Property's connected WhatsApp Business Account and phone number, and stores the Meta access credentials needed to operate the connection in encrypted form.
- Stores message templates the Property creates for Meta's approval.
- Stores the conversation thread and messages exchanged between the Property and a guest over WhatsApp through Hotel Mitra - including message content, delivery/read status, and timestamps - so the Property can see and continue that conversation.
- Receives and verifies delivery/status webhook events from Meta for messages sent through the integration.
To operate this integration, relevant information (such as the guest's WhatsApp number and message content) is exchanged with Meta/WhatsApp as required for WhatsApp messaging to function. That exchange, and Meta's own handling of the data once it reaches Meta's systems, is also subject to Meta/WhatsApp's own applicable terms and policies, in addition to this Privacy Policy.
Hotel Mitra does not access a Property's WhatsApp data for any purpose other than operating the integration the Property itself enabled and requested.
6. Data Sharing and Disclosure
Hotel Mitra may share information described in this policy with:
- The Property using Hotel Mitra, and its authorized staff - a Property's own users see the Guest and operational data relevant to their role at that Property.
- Service providers that help operate the Services, currently: Amazon Web Services (AWS) for cloud hosting, database, and file storage; and, where a Property enables the relevant feature, Amazon SES for transactional email.
- Meta/WhatsApp, where a Property enables the WhatsApp integration described in Section 5.
- Legal or regulatory authorities, where Hotel Mitra is required to disclose information to comply with applicable law, legal process, or a valid governmental request.
- Professional advisers (such as legal or accounting advisers), where necessary for Hotel Mitra's legitimate business purposes.
- A successor entity, in connection with a merger, acquisition, financing, or sale of some or all of Hotel Mitra's assets, subject to that entity continuing to honor the commitments in this policy.
Hotel Mitra does not sell personal information to third parties for advertising purposes.
7. Data Security
Hotel Mitra applies a number of technical and organizational safeguards, including:
- Passwords are stored using industry-standard one-way hashing, never in plain text.
- Sessions are authenticated using signed tokens stored in HTTP-only cookies, so they are not directly accessible to page scripts.
- Role-based access control limits what data a user can see and act on, scoped to the Property (or Properties) they belong to.
- Sensitive third-party credentials used by integrations (such as WhatsApp access tokens) are encrypted before being stored, rather than kept as plain text.
- Inbound webhook requests from Meta are cryptographically verified before being processed.
- State-changing requests require additional request verification (CSRF protection) on top of a restricted list of allowed origins.
- An audit trail records key changes made within the platform, including who made them and when.
- Automated request throttling (rate limiting) helps guard against abusive or automated access patterns.
These measures are designed to provide a reasonable level of protection, but no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security, and we encourage Property Users to use a strong, unique password and to keep their account credentials confidential.
8. Data Retention
Guest data and identification documents
As described in Section 3, guest records and identification documents are intended to be retained for up to 5 years, subject to applicable law, contractual requirements, legitimate business needs, and the Property's own retention decisions or requests (including a Property Owner's ability to permanently delete a specific check-in record at any time).
Property account and business data
Account and business information is retained for as long as the Property's account with Hotel Mitra is active, and for a reasonable period afterward as needed for legitimate business, legal, or dispute-resolution purposes.
Logs and technical data
Technical/request logs are retained for as long as reasonably needed for operational monitoring, security, troubleshooting, and any applicable legal requirement.
Where no specific retention period is stated for a category of data in this policy, Hotel Mitra retains it only for as long as reasonably necessary for the purposes described in Section 4.
9. Your Rights
Subject to applicable law, you may have rights to request access to, correction of, or deletion of your information, to ask how it is being processed, to withdraw consent where consent is the basis for processing, and to raise a complaint with an applicable data protection authority.
If you are a Property account holder
You can contact us using the details in Section 15 (Contact Us) regarding your own account and account data.
If you are a hotel Guest
Your information was entered into Hotel Mitra by the Property where you stayed, in the context of that Property's own operations and legal obligations as a hospitality business. Because the Property controls that record, requests relating to Guest data (such as access or correction) are generally best directed to the Property first. Hotel Mitra will support a Property in responding to such requests, and can also be contacted directly using the details in Section 15.
11. Children's Data
The Hotel Mitra Services are software provided to hospitality businesses and their staff, and are not directed to or intended for use by children. Property Users must be adults authorized to act on behalf of the Property.
Because hotel guests can include minors travelling with family, a Property's guest records may include information about a minor (for example, as part of a room booking that includes children). In that context, the Property is responsible for collecting and processing that information appropriately, including obtaining any consent required under applicable law from a parent or guardian.
12. International Data Processing
Hotel Mitra's application and database infrastructure is hosted on Amazon Web Services in the Mumbai (India) region. Uploaded files, including guest identification documents, are stored on Amazon Web Services in the N. Virginia (United States) region.
This means information - including guest identification documents - may be processed and stored outside your country of residence, including in the United States. Where a Property enables the WhatsApp integration (Section 5), relevant information is also processed by Meta in accordance with Meta's own infrastructure and policies.
13. Third-Party Services We Use
Hotel Mitra currently relies on the following third-party service providers:
- Amazon Web Services (AWS) - cloud hosting, database, and file/document storage.
- Amazon Simple Email Service (SES) - transactional email, for Properties that enable email-based guest messaging.
- Meta / WhatsApp Cloud API - guest WhatsApp messaging, only for Properties that connect their own WhatsApp Business Account (Section 5).
- Web Push (VAPID) - browser push notifications used to alert Property staff (for example, of a new room-service order); this is a staff-facing notification channel, not guest tracking.
Hotel Mitra does not currently use a payment gateway, SMS provider, third-party analytics platform, or advertising network. This section will be updated if that changes.
14. Data Breach / Security Incidents
Hotel Mitra maintains processes intended to identify, investigate, and respond to security incidents affecting the Services. If we become aware of a security incident that affects your information in a way that requires notification under applicable law, we will notify affected parties and/or the relevant authority as required by that law.
No system can be guaranteed to be immune from security incidents; this section describes our process for responding to one, not a guarantee that one will never occur.
15. Changes to This Policy
We may update this Privacy Policy from time to time, including to reflect changes in the Services, applicable law, or our data practices. The "Last Updated" date at the top of this policy shows when it was last revised. Material changes will be reflected by updating this page; we encourage you to review this policy periodically.
16. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or your information, you can reach us at:
- Email: hotelmitra.co.in@gmail.com
- Phone: +91 98292 70744
- Address: IHDP Business Park, Noida-Greater Noida Expy, Sector 127, Noida, Uttar Pradesh 201313, India
If you are a hotel Guest with a question about your stay or your information at a specific Property, please also consider contacting that Property directly, as explained in Section 9.