Nivasik is a hotel operations platform. Guests scan a QR code to raise a request; hotel staff receive it, track it, and resolve it. To make that work, a small amount of personal data passes through the platform. This policy explains what that data is, who is responsible for it, and what rights you have under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
The hotel you are staying at (or working for) decides why and how personal data is processed on Nivasik. Under the DPDP Act, the hotel is the Data Fiduciary and is your first point of contact for anything concerning your data.
Nivasik processes personal data only on the hotel's instructions, solely to operate the platform on the hotel's behalf. Under the DPDP Act, Nivasik acts as a Data Processor for the hotel.
What is collected depends on which parts of Nivasik the hotel uses. A property running only the request queue holds far less than one running the front desk.
| Who | Data | Why |
|---|---|---|
| Guests — raising a request | Room number; request category and description; phone number (optional — only if the guest chooses to provide it) | To create the request ticket, route it to the right staff member, and update the guest on progress |
| Guests — staying at a property that uses the front desk | Name; phone number; email address; postal address; nationality and date of birth; the type and number of an identity document, and an image of that document where the hotel uploads one; stay history; the charges on the bill and the payments made against it (amount, method and date — the database will not store a card number) | To take a booking, check the guest in, hold the bill for the stay, issue a GST invoice, and meet the record-keeping the law places on the hotel — including the foreign-national register and Form C |
| Staff | Name; phone number; device push-notification tokens; role and module permissions. Where the hotel uses the people-and-pay module: attendance, salary, advances, payslips and an identity-document number | To assign tickets, send notifications, place escalation calls when a service-level target is at risk, and — where used — to run the hotel's own payroll |
Guests do not create accounts and do not log in. An identity document is personal data of the most sensitive kind: the image is held in a private store, is never publicly addressable, is fetched only through a link that expires in two minutes, and an Aadhaar number is shown masked to its last four digits everywhere in the product. Deleting it removes the image and the record that it existed. Nivasik does not collect card numbers, and does not use any of this for advertising or profiling — see section 4.
Personal data on Nivasik is used for hotel operations only — creating, routing, tracking, and resolving requests, and measuring service performance for the hotel. Specifically:
Data is stored in Supabase, our managed database and backend provider, and is encrypted in transit (TLS/HTTPS) between guests, staff devices, and our servers. Access is restricted: staff see only the tickets relevant to their role, and administrative access is protected by authentication.
Limited data passes through the third-party services needed to deliver notifications — for example push-notification services (such as Firebase Cloud Messaging) and telephony providers (such as Twilio) for escalation calls — strictly to deliver those messages and calls.
Guest request data is retained as part of the hotel's operational records — the hotel needs its request history for service tracking, audits, and performance reporting. The hotel controls this retention: on the hotel's request, we purge guest request data — including any identity-document image — from the platform. When a hotel's subscription ends, its data is retained for 90 days for export and then permanently deleted (see our Terms of Service).
As a guest (a "Data Principal" under the DPDP Act), you have the right to:
How to exercise these rights: contact the hotel where you made the request — as the Data Fiduciary, the hotel handles guest rights requests. Nivasik carries out the hotel's instructions (access, correction, or deletion) promptly. If you are unsure whom to contact, write to support@nivasik.com and we will route your request to the right hotel.
If we become aware of a personal data breach affecting data processed on Nivasik, we commit to notifying the affected hotel without undue delay, with the details known at the time, so that the hotel can meet its obligations to affected individuals and to the Data Protection Board of India under the DPDP Act. We will cooperate fully with the hotel's response, including containment and remediation.
We may update this policy from time to time. Material changes will be notified to hotels with reasonable advance notice, and the "Last updated" date above will always reflect the current version.
For privacy questions, data export, or purge requests:
Anmol Dhamija (sole proprietor) · India
Email: support@nivasik.com