Privacy Policy

StayRata — a product of Cyborian Tech Labs Pvt. Ltd.

Last updated: August 9, 2026

Final Draft for Legal Counsel Review

This Privacy Policy is prepared in alignment with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), notified 14 November 2025, and reflects current implementation practice among comparable B2B/B2C SaaS and travel-marketplace platforms as of the date of drafting. It is not itself legal advice.

Compliance under the DPDP Rules is being phased in three stages — Board establishment (13 November 2025), enforcement powers, penalties, and Consent Manager registration (13 November 2026), and full substantive compliance covering consent, notice, security safeguards, and data-principal rights (13 May 2027). Counsel should confirm which specific obligations are already binding as of the date this Policy is published, and revisit this Policy as each phase takes effect.

1. Introduction and Scope

Cyborian Tech Labs Pvt. Ltd. ("Company", "we", "us", "our") is the Data Fiduciary in respect of personal data processed through the StayRata mobile application(s) and web dashboard (the "Platform"). This Privacy Policy describes what personal data we collect from Travel Agents, Resort Partners, and their representatives ("you", "User"), why we collect it, how it is used and shared, and the rights available to you as a Data Principal under the DPDP Act.

This Policy applies to all Users of the Platform. It does not apply to end guests of a Resort Partner unless they interact directly with the Platform (for example, via a booking confirmation notification).

2. Personal Data We Collect

2.1 Identity and Contact Data

  • Full name, mobile number, email address, city, and state
  • Profile photograph (Travel Agents)

2.2 Verification and KYC Data

  • PAN and national ID details (Solo/Freelance Travel Agents)
  • GSTIN, company registration number, trade name, registered office address, and Authorized Representative details (Registered Travel Agencies)
  • Property ownership/authorization details, property address, Google Maps location, property type, room count, amenities, GSTIN, and PAN (Resort Partners)
  • Supporting documents requested for verification, where applicable

2.3 Financial and Transaction Data

  • Bank account details for Wallet-linked transactions, refunds, commission settlement, and payouts
  • StayRata Wallet balance, lock/unlock status, and transaction history
  • Booking value, commission records, and payment status

2.4 Trust and Reputation Data

  • Trust Score inputs including booking completion rate, cancellation rate, response time, and policy-compliance history
  • Ratings and reviews submitted by and about you following completed bookings

2.5 Usage and Device Data

  • Device identifiers, IP address, app usage logs, and crash/diagnostic reports
  • Location data, where enabled, for the purpose of Resort Partner/Travel Agent discovery

2.6 Communications Data

  • Booking confirmations and OTP messages sent via WhatsApp or SMS
  • Support, grievance, and fraud-review correspondence

3. Purpose of Processing

Consistent with the DPDP Rules' requirement that notice itemize the specific personal data collected against each specific purpose, we process personal data for the following purposes only:

  • Verifying the identity and eligibility of Travel Agents and Resort Partners, including Standard Verification, Business Wallet Activation, and Business Verification
  • Facilitating and confirming booking transactions between Travel Agents and Resort Partners
  • Operating the StayRata Wallet, including locking, unlocking, and, where applicable under the End User License Agreement, applying Wallet funds toward Reasonable Compensation following a Confirmed Fraud determination
  • Calculating and displaying Trust Scores, badges, and ratings
  • Fraud detection, investigation, and prevention, including maintaining records necessary to enforce blacklisting under the End User License Agreement
  • Sending booking confirmations, OTPs, and other service communications
  • Complying with legal, tax, and regulatory obligations
  • Improving Platform functionality, reliability, and user experience

We do not process personal data for any purpose beyond what is disclosed in this Policy or subsequently notified to you, consistent with the purpose-limitation principle under the DPDP Act.

4. Legal Basis and Consent

We process personal data on the basis of your consent — free, specific, informed, unconditional, and unambiguous, given through clear affirmative action at the point of collection, as required under Section 6 of the DPDP Act. Consent requests are presented in clear, itemized language, in English and, where offered, regional languages, independent of any bundled or pre-ticked mechanism.

You may withdraw consent at any time, with the same ease with which it was given, through the Platform or by writing to connect@cyborian.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may result in your inability to continue using features of the Platform that depend on that data.

Where processing is necessary for the performance of a contract with you (for example, processing a confirmed booking or settling a Wallet transaction) or to comply with a legal obligation, we may rely on the applicable legitimate-use grounds recognized under the DPDP Act in addition to, or instead of, consent, as permitted by law.

Consent Manager interoperability: the DPDP Rules establish a Consent Manager framework, with registration opening in the second implementation phase. As of the effective date of this Policy, the Platform's consent mechanism is a checkbox-based affirmative consent captured at registration; interoperability with a registered Consent Manager has not yet been built and should be assessed by engineering and counsel ahead of that framework becoming operative, so this Policy and the underlying consent flow do not require rebuilding at that stage.

5. Data Sharing and Disclosure

We share personal data only with the following categories of recipients, strictly for the purposes described in Section 3, and under contractual obligations requiring them to protect such data:

  • The relevant Resort Partner or Travel Agent counterparty, to the extent necessary to process and confirm a specific booking
  • Payment gateway and banking partners, for transaction, Wallet, and payout processing
  • Property Management System (PMS) or channel manager providers, where a Resort Partner has enabled such integration
  • Regulatory, tax, or government authorities, where required by law
  • Cloud hosting, analytics, and technical service providers, engaged as data processors under written data-processing terms

We do not sell personal data to any third party, and we do not share personal data for third-party marketing without your separate, specific consent.

6. Cross-Border Data Transfer

As of the effective date of this Policy, Platform infrastructure is provided by Cloudflare, Inc. (application hosting, edge network, and object storage for uploaded photographs) and Neon, Inc. (Postgres database hosting, currently located in the AWS ap-southeast-1 region, Singapore), accessed via Cloudflare Hyperdrive. Cloudflare's edge network is global by design and may process data outside India as part of ordinary request routing and content delivery.

Under Section 16 of the DPDP Act, cross-border transfer is permitted by default except to countries specifically restricted by the Central Government. [Counsel to confirm current restricted-country notifications, if any, as of the date of publication, and confirm whether the hosting arrangement described above requires any additional disclosure or safeguard.]

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy or as required by applicable law, including limitation periods under the Indian Contract Act, 1872 and applicable tax and financial record-keeping requirements.

Identity documents (PAN/national ID) of a blacklisted User are retained beyond standard retention periods solely to prevent re-registration in enforcement of the End User License Agreement's fraud provisions. [Retention schedule, by data category, to be finalized with counsel.]

Where your purpose for using the Platform ends or you withdraw consent, we will erase your personal data, or anonymize it in the case of Trust Score/ratings history retained for platform-integrity purposes, and will notify you at least 48 hours in advance of erasure unless retention is otherwise required by law, in accordance with the DPDP Rules.

8. Your Rights as a Data Principal

Under the DPDP Act, you have the right to:

  • Obtain a summary of the personal data we hold about you and the processing activities undertaken, including the identities of data processors with whom it has been shared
  • Request correction, completion, and updating of your personal data
  • Request erasure of your personal data, subject to legal retention requirements
  • Withdraw consent at any time
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
  • Register a grievance regarding the processing of your personal data, and seek redress

Requests may be submitted to connect@cyborian.com. We will respond within the timeframe prescribed under the DPDP Rules.

9. Grievance Redressal

Grievance Officer: [Name — to be confirmed by the Company]

Contact: connect@cyborian.com

We will acknowledge and address grievances within the timeframe prescribed under the DPDP Rules. If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India.

10. Security Safeguards

We implement technical and organizational safeguards proportionate to the sensitivity of the data we process. As of the effective date of this Policy, this includes:

  • Passwords are never stored in plain text — they are salted and hashed with PBKDF2-SHA256 (100,000 iterations) before storage.
  • All Platform traffic is encrypted in transit via TLS/HTTPS.
  • Data at rest (database records and uploaded photographs) is encrypted at rest by our infrastructure providers as a standard feature of their managed services.
  • KYC documents, Wallet data, and financial records are accessible only through authenticated, server-side application logic — there is no direct public access to the underlying database or storage bucket.

[Counsel/security team to confirm organizational safeguards not reflected above — access-control policy, employee data-handling training, incident-response procedures, and audit logging practices — for accurate and complete disclosure. Do not overstate measures not yet implemented.]

11. Data Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in accordance with the timelines and content requirements prescribed under the DPDP Rules, including a description of the breach, the categories of data affected, and the protective measures available to you.

12. Significant Data Fiduciary Status

As of the date of this Policy, the Company has not been designated a Significant Data Fiduciary under the DPDP Act. Counsel should monitor MeitY notifications and revisit this section, together with any additional obligations — including Data Protection Officer appointment, Data Protection Impact Assessments, and independent audits — should the Company's data volume or risk profile change or should such designation occur.

13. Children's Data

The Platform is intended for business use by Travel Agents and Resort Partners aged 18 and above and is not directed at children. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected such data, we will take steps to delete it, subject to verifiable parental/guardian consent requirements under the DPDP Act should any such processing become necessary.

14. Cookies and Similar Technologies

As of the effective date of this Policy, the Platform does not use cookies for advertising or third-party tracking. It uses browser local storage for limited functional purposes (for example, preventing accidental duplicate form submissions) and a service worker for offline availability and performance caching of the website.

This section will be updated if analytics, advertising, or other cookie-based technologies are introduced, including confirmation of whether a separate cookie-consent mechanism becomes required for the web dashboard at that time.

15. Changes to this Policy

We may update this Privacy Policy from time to time, including to reflect further phases of DPDP Rules implementation. Material changes will be notified through the Platform prior to taking effect.

16. Contact Us

For questions regarding this Privacy Policy, contact connect@cyborian.com.