Legal

Privacy Policy

How J.RUUPSHILAA PRIVATE LIMITED, operator of Asyncotel, collects, uses and protects your data. Written to be readable — not to hide behind jargon.

Last updated · 16 August 2026

This Privacy Policy describes how J.RUUPSHILAA PRIVATE LIMITED (registered at 967/1, C.P. Mission Compound, Sipri Bazar, Jhansi, Uttar Pradesh – 284003; GSTIN 09AAGCJ5051K1ZF) handles personal and business data on our Asyncotel SaaS platform.

We comply with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDP Act). For data processing on behalf of your hotel (e.g. guest records), Asyncotel acts as a Data Processor and the hotel is the Data Fiduciary.

1. Information We Collect

Account information

Name, email, phone, organisation name, role, and login credentials (stored as salted hashes, never in plaintext).

Business information

Property name, address, GSTIN, PAN, room inventory, tariffs, and other operational data you configure in the platform.

Guest & transaction data

Bookings, check-ins, guest IDs (for GRC/Form-C compliance), invoice records, payment references and communication history — stored on your behalf as Data Processor.

Payment information

Card/UPI details are handled entirely by Razorpay (PCI-DSS certified). We store only the Razorpay payment/order IDs and masked references — not full card numbers or CVVs.

Technical & usage data

IP address, browser, device type, pages visited, feature usage and diagnostic logs — used for security, debugging and product improvement.

WhatsApp Business data

When a hotel connects its WhatsApp Business number, we store the message body, sender/recipient phone numbers, contact names (where provided by WhatsApp), delivery status and timestamps for each conversation. This data is used to power the hotel's operator inbox and AI assistant. Retained for the life of the hotel's account, subject to the deletion process on our Data Deletion page.

Google Business Profile data

When a hotel connects Google Business Profile through Google OAuth, we store the OAuth tokens needed to maintain that connection, the selected Google account and location identifiers, a cached copy of listing profile fields, and synced reviews/replies. This is separate from any Google Gemini / generative-AI processing used in other product features. See the dedicated section below.

2. How We Use Your Data

  • Provide, operate and maintain the Services under your subscription.
  • Process payments, raise GST-compliant invoices and manage billing cycles.
  • Authenticate users, prevent fraud, and investigate security incidents.
  • Send transactional email (receipts, trial expiry, security alerts) and operational notifications.
  • Improve the platform through aggregated, de-identified usage analytics.
  • Comply with Indian legal obligations (IT Act 2000, DPDP Act 2023, GST law).

We do not sell your data, and we do not share it with third parties for their own marketing.

3. Third Parties We Work With

To deliver the Services we rely on a small number of trusted sub-processors. Each is contractually bound to handle your data only on our instructions and to uphold appropriate security standards:

ProviderPurpose
RazorpayPayment gateway (PCI-DSS compliant)
Supabase / AWSDatabase, object storage (data hosted in Mumbai, India)
RailwayApplication hosting
Resend / PostmarkTransactional email (receipts, alerts)
PostHogProduct analytics (de-identified usage)
OTAs & channel managersOnly when you connect one (Booking.com, MMT, Agoda, distribution partners, etc.)
Meta / WhatsApp BusinessOnly when you connect a WhatsApp Business number — message delivery and webhook routing via Meta's Cloud API
Google (Gemini API)AI assistant for WhatsApp replies — guest message text sent per-turn, no training on your data. This is not the Google Business Profile connection.
Google OAuth / Google Business Profile APIsOnly when an authorised hotel user connects Google Business Profile — OAuth, listing profile, locations, reviews/replies, and (where the product calls them) Business Profile Performance APIs

We may also disclose data where required by law, a valid court order, or to protect the rights and safety of our users.

Google Business Profile and Google APIs

Asyncotel can connect a hotel's Google Business Profile when an authorised organisation user starts Google OAuth from the PMS. This integration is optional. It is not the same as Google Gemini / generative-AI features, which are a separate Google API used for assistant replies.

The OAuth scope requested is Google's business.manage scope. Based on the current implementation, Asyncotel may access:

  • • Google Business Profile account information (account resource name and display name) to discover listings the signed-in Google user can manage.
  • Business locations under those accounts, so the hotel can select the correct listing.
  • Business profile information such as name, address, website, phone, hours, categories and related listing fields (read and cache; authorised settings-admin users can also push selected fields back to Google via the profile-update API).
  • Reviews and review/reply content, including reviewer display name, photo URL, star rating, comment text, and existing public replies — so staff can monitor and respond from Asyncotel.
  • OAuth authorization and token information (access token, refresh token, expiry, granted scope) required to maintain the connection and refresh access.

The product also contains a client for Google's Business Profile Performance (insights) API. Those metrics are not currently fetched, stored, or shown in the live PMS UI. We do not claim daily performance time-series collection today. If that surface is enabled later, this policy will be updated.

Purpose. We use this data for hotel listing/profile management, review monitoring, review response management, profile synchronisation, and hotel operational/reputation intelligence. We do not sell Google Business Profile data and do not use it to train general-purpose AI models.

Storage. Asyncotel stores, per organisation: the connection row (Google account and location identifiers, listing title, connection status, last sync time), encrypted OAuth tokens, a cached JSON snapshot of the listing profile, and a local cache of synced reviews and replies. We store this so staff can work in the PMS without calling Google on every page load, and so replies can be posted back to the correct review.

Access. Only authenticated users in the same organisation can use the integration, and only according to Asyncotel role-based access control. Connecting, disconnecting, choosing a location, and pushing profile updates to Google are limited to hotel settings-admin roles. Front-desk operational roles may view connection status, read/sync the profile cache, list/sync reviews, and post review replies. Other organisations cannot read another organisation's Google connection or reviews.

Security. OAuth access and refresh tokens are sealed at rest with AES-256-GCM when the production encryption key is configured. Production refuses to store new tokens if that key is missing. Tokens are not written to application logs. Google passwords are never collected.

Retention. There is currently no separate automatic purge timer for Google Business Profile caches while the connection remains active. Connection tokens, profile cache and synced reviews are retained for the life of the connection (and otherwise follow the account retention rules in section 5). Google's Limited Use / data minimisation expectations may require a future retention improvement (for example, a maximum cache lifetime after disconnect or inactivity). That improvement is not claimed as implemented today.

Disconnect and deletion. An authorised settings-admin user can disconnect Google Business Profile in the PMS. Disconnect deletes the locally stored connection (including tokens and profile cache) and cascaded review/post rows for that organisation. Asyncotel also attempts to revoke the Google OAuth token at Google when disconnecting; if Google-side revoke cannot be completed, local credentials are still deleted. Additional deletion can be requested as described on our Data Deletion page.

4. Data Security

  • All traffic encrypted over TLS 1.2+; HSTS enabled on production domains.
  • Passwords stored using industry-standard one-way hashing (bcrypt/argon2 with salt).
  • Role-based access control within the platform; principle of least privilege for our engineers.
  • Daily encrypted database backups; 30-day retention.
  • Regular dependency security scanning; incident response protocol in place.

5. Data Retention

We retain your data for as long as your account is active. On cancellation, data is available in read-only export mode for 30 days. After that, it is purged from production within a further 60 days, subject to the following exceptions:

  • • Financial records (invoices, GST filings) — retained for 8 years as required by Indian tax law.
  • • Audit logs for security investigations — retained for up to 2 years.
  • • Anonymised aggregate statistics may be retained indefinitely.

6. Cookies & Tracking

We use strictly-necessary cookies for authentication (session tokens) and a small set of first-party analytics cookies via PostHog to understand product usage. We do not run third-party advertising trackers or sell cookie data.

7. Your Rights (DPDP Act 2023)

Right to access

Request a copy of the personal data we hold about you.

Right to correction

Update inaccurate or outdated information directly in-app, or by emailing us.

Right to erasure

Request deletion of your account and associated personal data after any statutory retention period. See our Data Deletion page for step-by-step instructions for hoteliers and for guests whose WhatsApp messages we hold.

Right to data portability

Export your data in machine-readable form at any time from the in-app export tools.

Right to grievance redressal

Raise a complaint to our Grievance Officer (details below) — we respond within 30 days as required by DPDP Act 2023.

8. Children's Data

Asyncotel is a B2B tool for hospitality operators. We do not knowingly collect personal data from individuals under 18 as account holders. If you believe a minor has created an account, please contact us and we will remove the record.

9. Grievance Officer

In line with Rule 3(11) of the IT Rules, 2011 and the DPDP Act 2023, our designated Grievance Officer is:

Rishabh Raj

J.RUUPSHILAA PRIVATE LIMITED

967/1, C.P. Mission Compound, Sipri Bazar, Jhansi, UP – 284003

Email: [email protected]

Phone: +91 88893 65318

We aim to acknowledge grievances within 48 hours and resolve them within 30 days.

10. Updates to this Policy

We may update this Policy to reflect changes in law, product features or security practices. Material changes are notified by email to the account owner and posted here with a revised "Last updated" date. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

Privacy or data request?

Write to our Grievance Officer — we reply within 48 hours.