Privacy Policy

Last updated 2 August 2026

Experience Sathi (“we”, “the platform”) is a hospitality management product operated by Growth System. It is used by hotels, restaurants and bars (“properties”) to run their operations, and by their staff through our web dashboard and the Experience Sathi staff mobile app. This policy explains what we collect, why, and what control you have.

Who controls the data

Each property is the data controller for the guest and staff records it enters. We act as a data processor— we store and process that information on the property's behalf, under their instructions. If you are a guest or an employee of a property, please direct access or deletion requests to that property first; we will support them in fulfilling your request.

What we collect

Staff / employee data (entered by the property, used for access control, HR and payroll):

  • Name, staff code, email, phone, designation, department, property
  • Password (stored only as a salted bcrypt hash — never in plain text)
  • Attendance, shifts, leave and payroll figures where the HR module is enabled
  • Where the property chooses to record them for statutory payroll: PAN, bank account details, and uploaded ID documents

Guest data (entered by property staff to deliver the booking and meet Indian legal obligations):

  • Name, phone, email, nationality, city
  • Stay details — dates, room, rate plan, folio charges and payments
  • ID proof type/number and, where uploaded, a scan or photograph of the ID (required for hotel guest registration and Form C / FRRO reporting for foreign nationals)
  • Restaurant, bar and service orders linked to the guest's folio

Technical data: we keep server logs (including IP address) for security, abuse prevention and troubleshooting.

The staff mobile app collects no analytics, contains no advertising SDKs and no third-party trackers. It stores your login session securely on the device (iOS Keychain / Android Keystore) so you stay signed in, and clears it on sign-out.

Why we use it

To operate the service the property has signed up for: authenticating staff, managing bookings and check-ins, producing GST/VAT-compliant invoices, running HR and payroll, maintaining statutory registers (such as bar excise stock registers and Form C), and providing support. We also use aggregate, non-identifying usage data to improve the product.

We do not sell personal data, and we do not use guest or staff data for advertising.

Payments

Card, UPI and netbanking payments are processed by Razorpay. Full payment instrument details are handled by the payment provider and are never stored on our servers — we retain only the transaction reference, amount, method and status needed for reconciliation and invoicing.

Who we share it with

We share data only where necessary to run the service:

  • Infrastructure: OVHcloud (servers hosted in Mumbai, India)
  • Payments: Razorpay
  • Messaging: WhatsApp / SMS / email providers, only when the property enables those notifications
  • Optional integrations the property switches on — for example OTA channel partners or an accounting system such as ERPNext, Tally or Zoho
  • Authorities, where disclosure is required by Indian law (for example police/FRRO guest reporting or state excise inspection)

Where it is stored, and for how long

Data is stored on servers located in Mumbai, India, with encrypted backups retained on a rolling schedule. We keep records for as long as the property's account is active and thereafter only as long as Indian tax, hospitality and labour law require (statutory registers and invoices generally must be retained for several years). When a property closes its account, we delete or irreversibly anonymise data that we are not legally required to keep.

Security

All traffic is encrypted in transit over HTTPS. Passwords are stored as bcrypt hashes. Access is tenant-isolated — a property's staff can only reach that property's data, enforced server-side with signed session tokens. Sign-in attempts are rate-limited. Database backups are encrypted and stored separately from the application server.

Your rights

Subject to Indian law, including the Digital Personal Data Protection Act, 2023, you may request access to, correction of, or deletion of your personal data, and may withdraw consent where processing relies on it. Guests and staff should contact the property that holds their record; properties may contact us at care@experiencesathi.com. We respond to verified requests within 30 days.

Children

The platform is a business tool and is not directed at children. We do not knowingly collect data directly from anyone under 18.

Changes and contact

If we make a material change to this policy we will update the date above and notify account administrators. Questions or complaints: care@experiencesathi.com, Experience Sathi by Growth System, Jaipur, Rajasthan, India.