verified_user Digital Personal Data Protection (DPDP) Act 2023 Compliant

Privacy Policy

ApnaRooms ("we", "us", "our") is dedicated to safeguarding your privacy and personal data in strict compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.

Effective Date: August 1, 2026 Last Updated: August 13, 2026 Jurisdiction: Phagwara / Jalandhar, Punjab, India

1 Who We Are (Data Fiduciary Identity)

Under the DPDP Act 2023, ApnaRooms acts as the Data Fiduciary responsible for determining the purpose and means of processing personal data collected from students, tenants, and visitors near Lovely Professional University (LPU), Phagwara, Punjab.

Platform Name: ApnaRooms (apnarooms.in)

Owner / Data Fiduciary: Ankit Kumar

Primary Address: Phagwara, Punjab 144411, India

Privacy Desk Email: privacy@apnarooms.in

2 What Personal Data We Collect

We collect only the essential personal data required to deliver secure PG accommodation, facilitate roommate matching, comply with Punjab Police verification laws, and issue invoices:

  • Identity Data: Full name, primary mobile number, email address, date of birth, gender, emergency contact details.
  • Identity Proof & Verification Documents (KYC): Aadhaar number & document scan, Passport number & scan (for international residents), Voter ID, PAN card.
  • Academic Data: LPU Roll Number / Registration ID, student ID card copy, program/department details.
  • Location Data: Permanent home address, state, pin code, current PG room assignment in Phagwara/Jalandhar.
  • Financial & Payment Data: Offline payment receipts, bank transfer reference numbers, Razorpay payment transaction IDs, invoice billing history (Note: We NEVER store credit/debit card numbers or bank account PINs).
  • Technical & Usage Data: IP address, device type, browser session cookies, login timestamps, PWA installation status.
  • Communications & Maintenance Logs: Support messages, complaint ticket history, maintenance service requests, visitor log entries.
  • Media Files: User profile avatars, uploaded identity cards, room inspection photos.

3 Why We Collect Data (Purpose Limitation)

In adherence to the principle of purpose limitation under Section 4 of the DPDP Act 2023, data is collected exclusively for specific, lawful purposes:

  • Facilitating PG room availability, advance token booking, and occupancy management.
  • Fulfilling statutory compliance under the Punjab Police Tenant Verification framework.
  • Generating monthly rent and electricity bill invoices with downloadable digital receipts.
  • Enabling roommate request matching and mutual roommate consent workflows.
  • Managing property maintenance complaints and assigning service workers.
  • Authenticating account access via email/password and Firebase Google OAuth.

5 Your Data Rights under DPDP Act Sections 11–15

As a Data Principal under Indian law, you hold statutory rights regarding your personal information:

visibility Right to Access (Sec 11)

Request a summary of personal data being processed and identities of data fiduciaries with whom data has been shared.

edit_note Right to Correction (Sec 12)

Request correction, updating, or completion of inaccurate or misleading personal details in your tenant profile.

delete_forever Right to Erasure (Sec 13)

Request account deletion and data purging upon completion of tenancy and settlement of zero balance dues.

gavel Right to Grievance Redressal (Sec 14)

Lodge a complaint with our Grievance Officer and escalate to the Data Protection Board of India (DPBI) if unsatisfied.

person_add Right to Nominate (Sec 15)

Nominate another individual to exercise your data rights in the event of death or incapacity.

6 How to Exercise Your Rights

To exercise any of your data rights or withdraw consent, write to us from your registered email address:

Email: privacy@apnarooms.in
Subject: DPDP Data Rights Request - [Your Name]

We will verify your identity and process your request within 7 business days free of charge.

7 Data Retention Schedule

Data Category Retention Period Purging Trigger
Tenant Profile & Contact Details Duration of active account + 12 months Account closure or erasure request
Police Verification & KYC Files Active tenancy + 12 months Statutory requirement expiry
Financial Receipts & Invoices 3 to 7 years Tax audit & accounting requirement
Server Access Logs & IP Records 180 days CERT-In 2022 cyber compliance rules

8 Third-Party Data Processors

We do NOT sell or rent your personal data to advertising agencies or third-party marketers. Data is processed only by essential infrastructure providers:

  • Firebase Auth (Google LLC): Identity management for Google OAuth login.
  • Razorpay Software Pvt. Ltd.: Payment processing gateway (when online payments are chosen).
  • Cloudflare Inc.: Content Delivery Network (CDN), SSL encryption, web application firewall (WAF).
  • cPanel Shared Hosting (India): Secure web application & database hosting server located in India.

9 Cross-Border Data Transfer Disclosures

Your core user profile, database records, and KYC document files reside on servers located within India.

Where third-party authentication services (Firebase Auth / Google LLC) involve servers in the United States, processing occurs under strict Standard Contractual Clauses (SCCs) and robust encryption safeguards in compliance with Section 16 of the DPDP Act 2023.

10 Cookies & Browser Local Storage Policy

We use functional, non-intrusive cookies and browser local storage tokens solely to:

  • Maintain your authenticated login session token securely.
  • Save your visual UI theme preferences (Dark Mode / Light Mode).
  • Power offline features and service worker caching for our Progressive Web Application (PWA).

11 Children's Data Policy (Section 9 Compliance)

ApnaRooms is designed for university students, working professionals, and PG residents who are at least 18 years of age.

If an individual under 18 years registers (e.g., first-year college student), processing of personal data requires verifiable consent from a parent or lawful legal guardian.

12 Technical & Organizational Security Safeguards

We protect your personal data through multi-layered security measures:

  • 256-bit TLS/SSL encryption for all data in transit.
  • Strong password hashing using bcrypt with configurable work factors.
  • Restricted server directory permissions for KYC document uploads.
  • Role-based access control (RBAC) ensuring service workers only view assigned complaint tasks.
  • Automatic admin portal session timeouts and 404 security cloaking.

13 Mandatory Grievance Officer Details (DPDP Act Sec 14)

In accordance with the DPDP Act 2023, ApnaRooms has appointed a dedicated Grievance Officer:

badge Ankit Kumar

Designation: Grievance Officer & Data Fiduciary Representative

Email: grievance@apnarooms.in / privacy@apnarooms.in

Address: Phagwara, Punjab 144411, India

Response SLA: Ticket acknowledgment within 24 hours; complete resolution within 7 business days.

14 Changes to This Policy & Contact Information

We may update this Privacy Policy to reflect changes in legal regulations or platform operational enhancements. Significant policy changes will be published on this page with an updated Effective Date.

Have a Privacy Grievance?

Submit a formal data request or complaint to our Grievance Desk.

gavel Go to Grievance Desk