Legal

Privacy policy

Last updated: 7 September 2026

This policy explains how BLAZING BULLET PRIVATE LIMITED, D-62, Phase 2, Sector 80, Noida, Uttar Pradesh 201305, India — the data fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") — collects and uses personal data on the "BookMyHost" portal.

1. What we collect

  • Account data — name, email, phone, company details, addresses, GSTIN.
  • Identity verification (KYC) — for Indian individuals, name, masked Aadhaar number, date of birth, gender, address and photograph received from DigiLocker with your consent (we never see your full Aadhaar number); for businesses, GST registration details; for international customers, identity-document verification results from our KYC provider.
  • Billing data — orders, invoices, wallet ledger, and payment references from our payment gateway. We never store card numbers, UPI PINs or banking credentials.
  • Technical data — IP addresses, login and API activity, service allocation records, and resource-usage metering.
  • Support data — tickets and correspondence.

2. Why we process it

  • To provide, meter and bill the services you order (performance of contract).
  • To comply with Indian law — GST invoicing, the IT Act 2000, and CERT-In directions (which require identity verification of cloud customers, 180-day retention of system logs on Indian infrastructure, and reporting of cyber incidents within 6 hours).
  • To secure the platform: fraud prevention, abuse detection, login protection.
  • To send service messages — invoices, payment reminders, incident and maintenance notices. Marketing mail is sent only with consent and always with an opt-out.

3. Who we share it with

We do not sell personal data. It is shared only with processors needed to run the service:

  • Cashfree Payments (payment processing; GSTIN and Aadhaar/DigiLocker verification),
  • Didit (identity-document verification for international customers),
  • Cloudflare (bot protection on the login page, where enabled),
  • and with government agencies where Indian law compels disclosure.

Your account data, KYC records, logs and hosted content are stored on our own infrastructure located in India.

4. How long we keep it

  • System, access and API logs — 180 days (CERT-In direction).
  • Subscriber identity, KYC and service-allocation records — 5 years after account closure (CERT-In direction).
  • Invoices and financial ledgers — 8 years (GST and Companies Act requirements).
  • Everything else — deleted or anonymised when the account closes or on your valid request.

5. Your rights

Under the DPDP Act you may access a summary of your personal data, correct or update it (most of it directly in the panel), withdraw consent, nominate a person to exercise your rights, and request erasure — which we honour except for records we must keep under clause 4. Write to the grievance contact below; we respond within the statutory timelines. Unresolved complaints may be escalated to the Data Protection Board of India.

6. Security and breach notification

Access to personal data is role-restricted and audit-logged. KYC responses are stored encrypted; passwords are held by our identity provider using strong hashing; two-factor authentication is available on every account. Reportable cyber incidents are notified to CERT-In within 6 hours and affected users are informed without undue delay.

7. Cookies

The panel sets only functional cookies: a session cookie, a CSRF token, and (if you choose "remember me") a login cookie. No advertising or cross-site tracking cookies are used.

8. Grievance and contact

Grievance Officer, BLAZING BULLET PRIVATE LIMITED, D-62, Phase 2, Sector 80, Noida, Uttar Pradesh 201305 — [email protected], +91 99999 97462. This policy may be updated with notice per the Terms of Service.

Terms of service →