Privacy Notice & Data Protection Policy
1. Identity of the Data Fiduciary
FindHostel is a digital platform operated by Dormico ("we", "our", or "us"), having its registered operations at:
Dormico (Data Fiduciary)
Near Hi-Tech Diagnostic Centre, Palarivattom, Ernakulam, Kerala 682025, India
Email: privacy@findhostel.dormico.in | Phone: +91 7902299476
2. Personal Data We Collect & Specific Purposes [LEGAL REVIEW REQUIRED]
In accordance with Section 6 of the DPDP Act 2023, we collect only necessary personal data for specified, lawful purposes:
| Data Principal Category | Personal Data Collected | Specified Lawful Purpose | Legal Basis |
|---|---|---|---|
| Hostel Owners / Managers | Full name, email address, mobile/WhatsApp number, property physical address, geo-coordinates, property photos, pricing, UPI mandate/payment tokens. | Account setup, authenticating listings, publishing property in public search directory, routing seeker inquiries, automated subscription billing, fraud prevention. | Consent & Contractual fulfillment (Sections 6 & 7(b)) |
| Visitors & Seekers | Search location queries, GPS coordinates (if explicitly permitted via browser), WhatsApp click logs, contact details (when submitting inquiry or review). | Matching nearby hostels, routing contact requests directly to property owners via WhatsApp/call, verifying review authenticity. | Voluntary disclosure & Consent (Section 6) |
| Website Visitors | IP address, browser user-agent, device metadata, anonymized page interaction logs (Google Analytics, Microsoft Clarity). | Platform security, rate limiting, preventing automated DDoS/bot abuse, measuring search performance (gated behind consent). | Consent & Legitimate security use (Section 7) |
3. Third-Party Data Processors [LEGAL REVIEW REQUIRED]
We engage vetted Data Processors under strict confidentiality and data protection obligations:
- Supabase Inc. (Cloud Database & Authentication): Securely stores encrypted user accounts, listings, and consent records.
- Razorpay Software Private Limited (PCI-DSS Payment Processor): Processes ₹1 verification and UPI Autopay subscriptions. We never store credit/debit card numbers or UPI PINs.
- Cloudflare Inc. (Edge Infrastructure & CDN): Provides SSL/TLS encryption in transit, DDoS mitigation, and global edge caching.
- Google Analytics & Microsoft Clarity (Analytics Processors): Usage analytics — strictly disabled until explicit user consent is granted via our consent banner.
- OpenStreetMap / Nominatim: Resolves search coordinates for map view without linking to individual user accounts.
4. Data Principal Rights under DPDP Act 2023
As a Data Principal residing in India, you hold the following statutory rights under Chapter III of the DPDP Act 2023:
1. Right to Access (Section 11)
Obtain a summary of personal data being processed and identities of Data Processors with whom data has been shared.
2. Right to Correction & Erasure (Section 12)
Correct misleading or incomplete data, update contact details, or request permanent deletion of your account and personal listings.
3. Right of Grievance Redressal (Section 13)
File a complaint with our Grievance Officer and receive an official resolution within 30 calendar days.
4. Right to Withdraw Consent (Section 6(4))
Withdraw consent for non-essential processing at any time via cookie banner or dashboard settings without retroactive penalty.
Need to exercise any of these rights?
Submit a direct request with your registered email.
5. Data Retention & Erasure Schedule [LEGAL REVIEW REQUIRED]
Under Section 8(7) of the DPDP Act 2023, we retain personal data only for as long as necessary to satisfy the purpose for which it was collected:
- Active Hostels & Owner Accounts: Retained while your subscription or account is active.
- Account Deletion: Personal profile and hostel listings are purged from live databases within 30 calendar days of a verified erasure request.
- Statutory Tax & Financial Records: Invoices, payment receipts, and GST transaction records are retained for 7 years in compliance with the Indian Income Tax Act, 1961.
- Security & Access Logs: IP and server access logs are retained for 180 days in compliance with CERT-In cybersecurity directives.
6. Security Measures
We implement comprehensive technical and organizational safeguards:
- Strict HTTPS/TLS 1.3 encryption across all platform endpoints.
- PostgreSQL Row Level Security (RLS) ensuring owners can only view and mutate their own listings.
- Zero plain-text password storage (handled via Supabase secure Argon2/Bcrypt hashing).
- Tokenized payment mandates handled via PCI-DSS certified Razorpay gateway.
7. Grievance Officer & Redressal Mechanism
In compliance with Section 8(9) & Section 13 of the Digital Personal Data Protection Act, 2023, you may address any concerns or complaints to our designated Grievance Officer:
Designation: Data Protection & Grievance Officer
Entity: Dormico (Operating FindHostel)
Email: contact@dormico.in
Postal Address: Near Hi-Tech Diagnostic Centre, Palarivattom, Ernakulam, Kerala 682025, India
Response Timelines: Acknowledgment within 48 hours; complete investigation and resolution within 30 calendar days.
If your grievance is not resolved to your satisfaction within 30 days, you have the statutory right to escalate your complaint to the Data Protection Board of India (DPBI).