How J.RUUPSHILAA PRIVATE LIMITED, operator of Asyncotel, collects, uses and protects your data. Written to be readable — not to hide behind jargon.
Last updated · 16 August 2026
This Privacy Policy describes how J.RUUPSHILAA PRIVATE LIMITED (registered at 967/1, C.P. Mission Compound, Sipri Bazar, Jhansi, Uttar Pradesh – 284003; GSTIN 09AAGCJ5051K1ZF) handles personal and business data on our Asyncotel SaaS platform.
We comply with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDP Act). For data processing on behalf of your hotel (e.g. guest records), Asyncotel acts as a Data Processor and the hotel is the Data Fiduciary.
Account information
Name, email, phone, organisation name, role, and login credentials (stored as salted hashes, never in plaintext).
Business information
Property name, address, GSTIN, PAN, room inventory, tariffs, and other operational data you configure in the platform.
Guest & transaction data
Bookings, check-ins, guest IDs (for GRC/Form-C compliance), invoice records, payment references and communication history — stored on your behalf as Data Processor.
Payment information
Card/UPI details are handled entirely by Razorpay (PCI-DSS certified). We store only the Razorpay payment/order IDs and masked references — not full card numbers or CVVs.
Technical & usage data
IP address, browser, device type, pages visited, feature usage and diagnostic logs — used for security, debugging and product improvement.
WhatsApp Business data
When a hotel connects its WhatsApp Business number, we store the message body, sender/recipient phone numbers, contact names (where provided by WhatsApp), delivery status and timestamps for each conversation. This data is used to power the hotel's operator inbox and AI assistant. Retained for the life of the hotel's account, subject to the deletion process on our Data Deletion page.
Google Business Profile data
When a hotel connects Google Business Profile through Google OAuth, we store the OAuth tokens needed to maintain that connection, the selected Google account and location identifiers, a cached copy of listing profile fields, and synced reviews/replies. This is separate from any Google Gemini / generative-AI processing used in other product features. See the dedicated section below.
We do not sell your data, and we do not share it with third parties for their own marketing.
To deliver the Services we rely on a small number of trusted sub-processors. Each is contractually bound to handle your data only on our instructions and to uphold appropriate security standards:
| Provider | Purpose |
|---|---|
| Razorpay | Payment gateway (PCI-DSS compliant) |
| Supabase / AWS | Database, object storage (data hosted in Mumbai, India) |
| Railway | Application hosting |
| Resend / Postmark | Transactional email (receipts, alerts) |
| PostHog | Product analytics (de-identified usage) |
| OTAs & channel managers | Only when you connect one (Booking.com, MMT, Agoda, distribution partners, etc.) |
| Meta / WhatsApp Business | Only when you connect a WhatsApp Business number — message delivery and webhook routing via Meta's Cloud API |
| Google (Gemini API) | AI assistant for WhatsApp replies — guest message text sent per-turn, no training on your data. This is not the Google Business Profile connection. |
| Google OAuth / Google Business Profile APIs | Only when an authorised hotel user connects Google Business Profile — OAuth, listing profile, locations, reviews/replies, and (where the product calls them) Business Profile Performance APIs |
We may also disclose data where required by law, a valid court order, or to protect the rights and safety of our users.
Asyncotel can connect a hotel's Google Business Profile when an authorised organisation user starts Google OAuth from the PMS. This integration is optional. It is not the same as Google Gemini / generative-AI features, which are a separate Google API used for assistant replies.
The OAuth scope requested is Google's business.manage scope. Based on the current implementation, Asyncotel may access:
The product also contains a client for Google's Business Profile Performance (insights) API. Those metrics are not currently fetched, stored, or shown in the live PMS UI. We do not claim daily performance time-series collection today. If that surface is enabled later, this policy will be updated.
Purpose. We use this data for hotel listing/profile management, review monitoring, review response management, profile synchronisation, and hotel operational/reputation intelligence. We do not sell Google Business Profile data and do not use it to train general-purpose AI models.
Storage. Asyncotel stores, per organisation: the connection row (Google account and location identifiers, listing title, connection status, last sync time), encrypted OAuth tokens, a cached JSON snapshot of the listing profile, and a local cache of synced reviews and replies. We store this so staff can work in the PMS without calling Google on every page load, and so replies can be posted back to the correct review.
Access. Only authenticated users in the same organisation can use the integration, and only according to Asyncotel role-based access control. Connecting, disconnecting, choosing a location, and pushing profile updates to Google are limited to hotel settings-admin roles. Front-desk operational roles may view connection status, read/sync the profile cache, list/sync reviews, and post review replies. Other organisations cannot read another organisation's Google connection or reviews.
Security. OAuth access and refresh tokens are sealed at rest with AES-256-GCM when the production encryption key is configured. Production refuses to store new tokens if that key is missing. Tokens are not written to application logs. Google passwords are never collected.
Retention. There is currently no separate automatic purge timer for Google Business Profile caches while the connection remains active. Connection tokens, profile cache and synced reviews are retained for the life of the connection (and otherwise follow the account retention rules in section 5). Google's Limited Use / data minimisation expectations may require a future retention improvement (for example, a maximum cache lifetime after disconnect or inactivity). That improvement is not claimed as implemented today.
Disconnect and deletion. An authorised settings-admin user can disconnect Google Business Profile in the PMS. Disconnect deletes the locally stored connection (including tokens and profile cache) and cascaded review/post rows for that organisation. Asyncotel also attempts to revoke the Google OAuth token at Google when disconnecting; if Google-side revoke cannot be completed, local credentials are still deleted. Additional deletion can be requested as described on our Data Deletion page.
We retain your data for as long as your account is active. On cancellation, data is available in read-only export mode for 30 days. After that, it is purged from production within a further 60 days, subject to the following exceptions:
We use strictly-necessary cookies for authentication (session tokens) and a small set of first-party analytics cookies via PostHog to understand product usage. We do not run third-party advertising trackers or sell cookie data.
Right to access
Request a copy of the personal data we hold about you.
Right to correction
Update inaccurate or outdated information directly in-app, or by emailing us.
Right to erasure
Request deletion of your account and associated personal data after any statutory retention period. See our Data Deletion page for step-by-step instructions for hoteliers and for guests whose WhatsApp messages we hold.
Right to data portability
Export your data in machine-readable form at any time from the in-app export tools.
Right to grievance redressal
Raise a complaint to our Grievance Officer (details below) — we respond within 30 days as required by DPDP Act 2023.
Asyncotel is a B2B tool for hospitality operators. We do not knowingly collect personal data from individuals under 18 as account holders. If you believe a minor has created an account, please contact us and we will remove the record.
In line with Rule 3(11) of the IT Rules, 2011 and the DPDP Act 2023, our designated Grievance Officer is:
Rishabh Raj
J.RUUPSHILAA PRIVATE LIMITED
967/1, C.P. Mission Compound, Sipri Bazar, Jhansi, UP – 284003
Email: [email protected]
Phone: +91 88893 65318
We aim to acknowledge grievances within 48 hours and resolve them within 30 days.
We may update this Policy to reflect changes in law, product features or security practices. Material changes are notified by email to the account owner and posted here with a revised "Last updated" date. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.