ORAJIC
Services How it works Products Book a free consultation
Legal

Privacy Policy

Orajic Hotel Management System (HMS) · Last updated: 3 July 2026

1. Who we are

Orajic AI Solutions & Automations ("Orajic", "we", "us") builds and operates the Orajic Hotel Management System ("HMS"), software that hotels in India use to manage check-ins, bookings, billing and guest records. We are based in Solapur, Maharashtra, India.

This policy explains what personal data flows through HMS, why, how long we keep it, who it's shared with, and your rights under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

How the roles work. When a hotel uses HMS to record its guests, the hotel is the Data Fiduciary — it decides what to collect and is responsible for having a lawful basis. Orajic acts as the Data Processor, handling that data only on the hotel's instructions and to run the service. For a hotel's own account (owner and staff logins, subscription billing), Orajic is the Data Fiduciary. This policy covers both.

2. What personal data we collect

Guest data (collected by hotels through HMS):

  • Name, phone number, WhatsApp number, address, nationality, date of birth, gender
  • Government ID type and ID / Aadhaar number, stored in full for mandatory guest-registration compliance
  • Photographs of the guest's ID card (front and back), a face photo, and a signature
  • Booking and stay details (room, dates, charges, companions travelling with the guest)

Hotel account data (owner and staff):

  • Names, email addresses, phone numbers, role, and login credentials (passwords are stored only as secure one-way hashes — never in plain text)
  • Activity and audit logs of actions taken in the app

Payment data: Hotel subscription billing and any guest advance payments are handled by our payment processor, Razorpay. Card / UPI / bank details are entered on Razorpay's secure systems — Orajic does not see or store full card numbers. We store only a payment reference, status, and the subscription identifiers needed to run billing.

Technical data: IP address, browser/device information, and error/diagnostic logs generated while using HMS.

3. Why we collect it (purpose)

  • Legal compliance — Indian law requires hotels to record guest identity (including Aadhaar/ID) and to report guest details to police (e.g. Form C for foreign nationals and state guest-registration rules). HMS exists to help hotels meet these obligations.
  • Running the hotel — creating bookings, managing check-in/check-out, rooms, billing and invoices.
  • Billing — operating your monthly subscription and processing payments via Razorpay.
  • Support, security and improvement — assisting hotels, preventing fraud and abuse, keeping the service reliable and secure.

We do not sell personal data, and we do not use guest ID data for advertising.

4. How long we keep it, and where

Where: Guest and account records are stored in our MongoDB database, and ID images, photos and signatures are stored in private, access-controlled object storage. Both run on our servers located in India. Images are never public — they're served only through short-lived, signed links to authorised users.

How long: We keep guest records for as long as the hotel's account is active and it needs them to meet operational, tax and legal-retention duties (guest-registration records often must be retained under law). When a hotel closes its account, we delete or return its data within 90 days, unless a longer period is required by law.

5. Who we share it with

We share personal data only with service providers that help us run HMS, and only as needed:

ProviderWhat they processWhy
Google (Gemini Vision API)The ID/Aadhaar card image at check-inTo read the text off the card automatically (OCR) so staff don't retype it. The image is transmitted to Google for this extraction.
RazorpayPayment and subscription detailsTo process subscription auto-pay and any guest advance payments
ResendEmail address + message contentTo send transactional emails (welcome, account, receipts)
SentryDiagnostic/error dataTo detect and fix crashes and errors
CloudflareNetwork/traffic metadataContent delivery, DNS and basic protection

We also disclose data to the hotel that collected it, and to law-enforcement or government authorities where required by law (e.g. police guest-registration / Form C, or a lawful request). We do not currently share guest data with online travel agencies; if we add OTA channel-manager sync in future, we'll update this policy before that goes live.

Because OCR uses Google's API, the ID image is processed on Google's international infrastructure. All other guest data is stored in India.

6. Your rights under the DPDP Act

As a Data Principal (the person the data is about) you may:

  • Access a summary of your personal data and how it's processed
  • Correct, complete or update inaccurate data
  • Erase data that's no longer needed (subject to legal-retention rules)
  • Nominate someone to exercise your rights if you're unable to
  • Withdraw consent where processing is based on consent
  • Raise a grievance and get a response

Guests should first contact the hotel that recorded their data (the Data Fiduciary). For data Orajic controls, or if a hotel is unresponsive, contact our Grievance Officer:

Grievance Officer: Raj — [email protected]
We aim to respond within 30 days. If you're not satisfied, you may complain to the Data Protection Board of India.

7. Data breach notification

If a personal-data breach occurs, we will act promptly to contain and investigate it, and we will notify the Data Protection Board of India and affected users/hotels without undue delay, in the manner and timelines required by the DPDP Act. Hotels are responsible for onward notification to their guests where applicable, and we will support them with the information they need.

8. Security

We protect data with encryption in transit (HTTPS/TLS), strict per-hotel data isolation, role-based access, hashed passwords, and private storage with signed, expiring links for images. No system is perfectly secure, but we work to keep risk low.

9. Children

HMS is used by hotels to serve adult guests. We do not knowingly collect data directly from children; where a minor travels with a guest, they are recorded by the hotel as an accompanying guest under the responsible adult.

10. Changes and contact

We may update this policy; material changes will be posted here with a new "last updated" date. Questions or requests: [email protected].

ORAJIC

AI automation, intelligent assistants, and custom software for businesses ready to grow.

Explore

Services How it works Products Contact

Products

Orajic HMS AI WhatsApp Assistant

Legal

Privacy Policy Terms of Service

Get in touch

+91 97655 33400 [email protected] WhatsApp
© ORAJIC. All rights reserved. Intelligence that grows your business.