Legal
Privacy Policy
Last updated: 25 July 2026
1. Who we are
Zyro ("we", "us", or "our") is a hospitality booking platform operated by Zyro Hospitality (registered in India). We connect travellers with hotels for short stays and with property owners for long-term rentals. This policy explains what data we collect, why, and your rights.
Contact: conect@zyroapp.in · +91 92625 92844 · India
2. Information we collect
- Account data: name, email, phone number, hashed password, role (guest / hotel partner / room owner).
- ID verification: government-issued ID (Aadhaar / Voter ID / Passport / Driving License) — uploaded once, reviewed by our admins, then encrypted at rest.
- Booking & rental data: dates, guest count, property choice, chat with the host, payment reference IDs from Razorpay.
- Property data (for partners): title, address, photos, amenities, price, electricity bill copy (rental owners).
- Device & usage: IP, browser type, pages viewed, service-worker cache status. Used only for security and reliability.
- Location: we ask for your city (not GPS) to show nearby stays. You can change it any time from the top bar.
3. How we use your data
- Deliver the booking / rental service (search, book, pay, chat, check-in, invoice, refund).
- Verify identity and prevent fraud (KYC compliance under Indian law).
- Send transactional messages: OTP, booking confirmation, payment receipt, cancellation refund status. We do not send marketing SMS/email without a separate opt-in.
- Improve the product — aggregated, non-identifying analytics only.
4. Who we share with
- Payment gateway: Razorpay Software Pvt. Ltd. handles card / UPI / wallet processing. We never see or store your full card number.
- Hotels & property owners: they see your name, booking dates, and in-app chat only. Your phone/email are hidden — communication happens through Zyro's chat.
- Government / law enforcement: only when compelled by a valid Indian legal order.
- Cloud infrastructure: Emergent object storage (files) and MongoDB Atlas (records), both in India-region servers.
We do not sell or rent your personal information to third parties. Ever.
5. Data retention
KYC documents are retained for 5 years after your last booking, as required under Indian hospitality & anti-money-laundering regulations. Booking records for 8 years for tax compliance. You may request deletion of chat and profile data at any time — booking / KYC records are anonymised where legally permitted.
6. Your rights
- Access — request a copy of the data we hold about you.
- Correction — update your profile from the app or contact support.
- Deletion — email conect@zyroapp.in; we respond within 30 days.
- Withdraw consent — you can disable OTP, chat, or delete your account.
- Grievance officer — Zyro Grievance Cell, India · conect@zyroapp.in · +91 92625 92844
7. Security
All traffic is TLS-encrypted. Passwords are hashed with bcrypt. OTPs are hashed and expire in 5 minutes with rate-limits. Payment signatures are verified with HMAC-SHA256. Sensitive documents are stored in access-controlled object storage.
8. Children
Zyro is not intended for anyone under 18. We do not knowingly collect data from minors.
9. Cookies & PWA
We use one httpOnly session cookie for authentication. Our service worker caches static assets for offline reliability — it does not track you. You can clear it from your browser at any time.
10. Changes to this policy
If we make material changes we will notify you in-app and via email 14 days before they take effect. Continued use of Zyro after the effective date means you accept the updated policy.
11. Contact
Zyro Hospitality
India
conect@zyroapp.in
+91 92625 92844
