Privacy Policy
Effective 23 August 2026 ยท Autobot360 Technologies
1. Scope
This policy explains how Autobot360 Technologies ("Autobot360", "we") handles personal data processed through StayOS โ data belonging to PG/hostel owners who operate a workspace, and residents whose information owners collect through the platform. It is written to align with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
2. What we collect
- Owner account data: name, email, phone, and workspace/organization details provided at signup.
- Resident identity data: name, date of birth, gender, and government ID details (Aadhaar, PAN, driving licence, passport) collected either via OCR photo capture or, where you choose to use it, via DigiLocker's consent-based OAuth flow.
- Operational data: bed/room assignments, rent and deposit ledgers, maintenance tickets, visitor logs, and WhatsApp message metadata needed to run reminders and support flows.
- Payment data: handled by our payment processor (Razorpay); StayOS stores payment status and receipts, not card or bank credentials.
3. DigiLocker verification, specifically
When an owner or resident chooses to verify identity via DigiLocker, the verification happens entirely on DigiLocker's own government-operated domain. You log in and grant or deny consent there โ StayOS never sees your DigiLocker password or Aadhaar number directly. After you consent, DigiLocker shares only the data fields your consent authorized (typically your name, date of birth, and gender, plus any documents you explicitly choose to share) with StayOS via a secure server-to-server call. You can revoke this consent at any time from your DigiLocker account.
4. Why we process this data
To operate the core service (bed inventory, rent collection, KYC record-keeping, resident support), to detect fraud or duplicate tenancy records, to comply with legal record-keeping obligations property owners are subject to (e.g. police tenant-verification requirements in several Indian states), and to send the WhatsApp messages you configure (rent reminders, KYC requests, maintenance updates).
5. Who we share it with
- The property owner's own organization/staff, scoped by the role-based permissions they configure.
- Service providers acting on our behalf: Meta (WhatsApp Business Cloud API for messaging), Razorpay (payments), Didit and DigiLocker (identity verification), and our cloud database provider (Firebase).
- Law enforcement or regulators, only where legally required โ e.g. police tenant-verification submissions the owner explicitly generates.
We do not sell resident or owner personal data.
6. Retention
Operational and KYC records are retained for the duration of an active tenancy plus the period required by applicable record-keeping law after move-out. Owners can request deletion of a resident's record once no legal retention obligation applies. Account data is deleted within 90 days of workspace closure, except where retained for legal or dispute-resolution purposes.
7. Your rights
Residents and owners may request access to, correction of, or deletion of their personal data by contacting the property owner (data controller for resident records) or Autobot360 directly at hello@autobot360.com. We respond to verified requests within 30 days.
8. Security
Data is encrypted in transit (TLS) and access-controlled by role within each organization's workspace. Identity documents are stored with restricted access limited to authorized administrators of the relevant property.
9. Changes to this policy
We'll update the effective date above when this policy changes and, for material changes, notify active workspace owners by email.
10. Contact
Privacy questions or data requests: hello@autobot360.com.
This document is a general-purpose template and has not been reviewed by a lawyer for your specific jurisdiction or business structure. We recommend having it reviewed by counsel before relying on it for a live, paying customer base.