1. Introduction
AdoraStay ("we", "us", or "our") respects your privacy and is deeply committed to protecting your personal data. This Privacy Policy outlines how we collect, use, process, and disclose your information when you use our website, mobile applications, and services. We comply with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (India).
2. Information We Collect
We collect information to provide a safe, secure, and hyper-local community experience:
- Account Data (via Google OAuth): When you register using Google, we receive and store your email address, full name, and profile picture directly from Google via secure ID Tokens.
- Profile & Verification Data: Phone numbers, physical addresses, and government-issued IDs (if submitted voluntarily for the "Verified User" badge).
- Listing Data: Photographs, location data, pricing, and descriptions of properties or items you choose to upload.
- Transaction & Wallet Data: Order history, banking details (for wallet withdrawals), and payment gateway transaction IDs.
- Technical Data: IP addresses, browser types, NextAuth session cookies, and JWT (JSON Web Tokens) used to maintain your secure login state.
3. How We Use Your Information
- To create and manage your AdoraStay account securely.
- To facilitate interactions between you and other users (e.g., sharing your masked contact info when an order is confirmed).
- To process payments, security deposits, and AdoraStay Wallet transfers.
- To verify your identity and prevent fraud, spam, and abusive activity within the community.
- To provide customer support and resolve disputes via our Help Center.
4. How We Share Your Information
We do not sell your personal data to third-party marketers. We only share data in the following circumstances:
- With Other Users: When a rental request is accepted, we may share your name, phone number, and approximate location with the other party to facilitate the handover.
- With Service Providers: Cloud hosting providers (e.g., AWS, Render), payment processors (e.g., Razorpay, Stripe), and SMS gateway providers required to run the platform.
- Legal Compliance: We may disclose data if required by law, court order, or government request (e.g., local police verification for PG tenants).
5. Data Security
We implement industry-standard security measures. Your passwords are never stored; we rely on secure OAuth 2.0 protocols and encrypted JSON Web Tokens (JWTs) generated by our Django REST Framework backend. However, no transmission of data over the internet is 100% secure, and we cannot guarantee absolute security.
6. Your Rights & Choices
Under Indian data protection laws, you possess the following rights:
- Right to Access & Correction: You can review and update your profile information directly from your Dashboard.
- Right to Erasure ("Right to be Forgotten"): You may request the permanent deletion of your account and associated data by emailing our support team, subject to any legal retention requirements (e.g., transaction records for tax purposes).
- Consent Withdrawal: You may disconnect AdoraStay from your Google Account permissions at any time via your Google settings.
7. Contact & Grievance Officer
If you have questions about this Privacy Policy or wish to file a grievance regarding data processing, please contact our Grievance Officer at: