Privacy Policy
1. Who We Are
HotelO is a cloud-based hotel-management software service owned and operated by Dwoing (“Dwoing”, “HotelO”, “we”, “us” or “our”). HotelO provides software for hospitality businesses to manage bookings, rooms, guests, payments, invoices, reports and related hotel operations.
This Privacy Policy explains how HotelO handles personal data relating to visitors, prospective customers, account holders, authorised users and other individuals whose information HotelO processes in connection with its services.
2. Important Distinction: HotelO Data and Hotel Guest Data
HotelO operates a business-to-business software service. This means there are two important categories of information.
HotelO account/service data: information about the hotel/business, its owners or administrators, authorised users, billing contacts and technical users that HotelO processes to establish and operate the customer relationship.
Hotel guest/customer data: personal data that a hotel customer enters into HotelO about its guests or customers. The hotel generally determines why that information is collected and how it is used. HotelO processes such information to provide the contracted CRM service and under the applicable Data Processing Agreement (DPA).
The hotel customer remains responsible for having the appropriate legal basis, notices and permissions required for its collection and use of guest/customer data.
3. Personal Data We May Collect
Depending on how you use HotelO, we may process the following categories:
- name, email address, phone number and business contact details;
- hotel/property name, address and business information;
- account username and role information;
- subscription, plan, invoice and payment-status information;
- payment-provider identifiers and transaction/subscription references;
- IP address, browser, device and operating-system information;
- login, session, security and audit information;
- support requests and communications;
- information submitted through forms or uploaded to the service; and
- hotel guest/customer information processed through the CRM on the hotel’s instructions.
We aim to collect information that is reasonably necessary for the relevant purpose and do not intentionally require unnecessary personal information.
4. Guest and Customer Information Entered by Hotels
A hotel customer may enter information about guests or customers, which may include names, contact details, booking and stay information, room information, billing records, operational notes and, where enabled by the product, identification or document information.
HotelO processes such information primarily to provide hosting, CRM, booking, operational, reporting, security and related services to the hotel. The hotel determines the purposes for which its guest/customer data is collected and is responsible for providing required notices and establishing an appropriate legal basis.
HotelO does not use hotel guest/customer data as a commercial data-broker product and does not sell such Customer Data as a standalone data asset.
5. Purposes for Processing
We may process personal data for purposes including:
- creating and administering HotelO accounts;
- authenticating users and maintaining secure sessions;
- providing CRM and hotel-management functionality;
- processing subscriptions, billing and payment-related records;
- providing customer support and responding to enquiries;
- sending service, security and account communications;
- maintaining backups, logs and operational records;
- detecting, preventing and investigating fraud, abuse and security incidents;
- monitoring service reliability and troubleshooting technical problems;
- improving functionality, security and performance;
- complying with applicable law, court orders and lawful requests;
- establishing, exercising or defending legal claims; and
- performing other purposes that are disclosed to you and permitted by applicable law.
6. Legal Basis and Consent
Depending on the circumstances and applicable law, HotelO may process personal data on the basis of consent, performance of a contract, compliance with a legal obligation, certain legally recognised legitimate/authorised uses, or another lawful basis available under applicable law.
Where consent is required, HotelO will seek it in an appropriate manner and will not make optional marketing consent a condition of receiving the core service.
India’s Digital Personal Data Protection Act, 2023 establishes a framework addressing notice, consent, obligations of data fiduciaries and rights of data principals. Its provisions have been notified with phased commencement. HotelO intends to operate its privacy processes consistently with applicable requirements as they become effective.
7. Account Registration
When you register, we may collect information such as your name, hotel/business name, email address, phone number, account credentials, role and other information needed to create and secure the account.
We use this information to create the account, authenticate access, communicate with you and provide the requested service.
8. Billing and Payment Information
HotelO may use third-party payment providers such as Razorpay to process subscriptions and payments. Depending on the integration, HotelO may receive payment status, transaction identifiers, subscription identifiers, invoice references and related information.
Where payment credentials are collected directly by a payment provider, those credentials are handled under that provider’s systems and policies. HotelO does not intentionally store complete card numbers or payment authentication credentials on its own application database.
9. Technical, Security and Log Information
We may collect IP addresses, browser and device information, timestamps, login events, session identifiers, error information and security/audit logs. These records help us authenticate users, protect accounts, investigate suspicious activity, troubleshoot problems and maintain reliable service.
Where legally required or reasonably necessary for security and compliance, technical records may be retained for an appropriate period.
10. Cookies and Similar Technologies
HotelO may use cookies or similar technologies that are necessary for authentication, session management, security, preferences and basic website functionality.
We may introduce analytics or other optional technologies where appropriate. If optional tracking is introduced, the relevant notice, consent mechanism or preference controls will be updated as required by applicable law.
11. Service Providers and Sub-Processors
HotelO may engage third-party service providers to support hosting, infrastructure, payment processing, email, security, monitoring, backups, customer support or other functions required to operate the service.
Where a provider processes personal data on HotelO’s behalf, HotelO will use appropriate contractual and organisational controls consistent with applicable law and the DPA.
12. Data Sharing and Disclosure
We may disclose personal data where reasonably necessary to:
- provide the HotelO service;
- process payments and subscriptions;
- operate hosting, infrastructure and security services;
- respond to support requests;
- comply with applicable legal obligations or lawful government requests;
- protect the rights, safety, security or property of HotelO, Dwoing, users or others;
- investigate fraud, abuse or security incidents; or
- establish, exercise or defend legal claims.
We do not sell personal data as a commercial data-broker product.
13. Hotel Customer as Data Fiduciary / Controller-Type Role
For guest/customer information entered into HotelO by a hotel, the hotel generally determines the purposes and means of collecting that information. The hotel is responsible for its own guest-facing privacy notice, lawful collection, accuracy, retention decisions and responses to guest/customer requests, subject to applicable law.
HotelO provides technical processing services to the hotel under the applicable DPA.
14. Data Processing Agreement
HotelO maintains a separate DPA for business customers where HotelO processes personal data on the customer’s behalf. The DPA addresses processing instructions, confidentiality, security, sub-processors, incident handling, assistance, retention and deletion/return arrangements.
The DPA should be read together with this Privacy Policy and the HotelO Terms & Conditions.
15. Security Measures
HotelO uses reasonable technical and organisational safeguards appropriate to the service and information processed. Depending on the system, these may include HTTPS/TLS, authentication controls, session management, role-based access, server-side authorisation, tenant isolation, database access controls, CSRF protections, backups, logging, monitoring, access restrictions and security updates.
Security is a shared responsibility. Customers must protect their passwords, devices, authorised users and uploaded information. No internet service can guarantee absolute security.
16. Data Breach and Security Incidents
If HotelO becomes aware of a personal-data security incident affecting information processed through its services, HotelO will investigate and take reasonable steps to contain, remediate and document the incident and make notifications required by applicable law and contractual obligations.
Where HotelO processes hotel guest/customer data on behalf of a hotel, HotelO will follow the applicable DPA and provide information reasonably necessary for the hotel to meet its own legal obligations.
17. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the service, maintain security, comply with legal/accounting obligations, resolve disputes, prevent fraud and enforce agreements.
After an account ends, information may be deleted, anonymised or securely disposed of when the applicable retention period ends. Backups may persist for a limited period before normal rotation and deletion processes remove them.
18. Your Privacy Rights
Subject to applicable law and the role HotelO is performing in relation to the data, individuals may have rights concerning their personal data, including rights to obtain information about processing, request correction or erasure, withdraw consent where consent is the basis, and raise grievances.
For guest/customer data controlled by a hotel, requests should normally be directed to the relevant hotel first because the hotel determines the purpose of that processing. HotelO will provide reasonable assistance where required under the applicable DPA or law.
19. How to Make a Privacy Request
For HotelO account/service data, contact:
Dwoing / HotelO
Email: hello@hotelo.in
Please provide enough information for us to identify the relevant account and understand the request. We may need to verify identity or authority before disclosing, correcting or deleting information.
20. Children’s Data
HotelO is a business service and is not intended to be used by children to create independent accounts. Hotels may nevertheless process information about guests or family members as part of hospitality operations. Customers are responsible for ensuring that any collection or processing of children’s personal data through HotelO is lawful and complies with applicable requirements.
HotelO will apply any child-data requirements that become applicable to its role and processing under Indian law.
21. International Processing and Transfers
HotelO may use infrastructure or service providers located in jurisdictions outside India where permitted and where appropriate safeguards or contractual arrangements are in place. Any transfer or processing outside India will be subject to applicable law, contractual commitments and restrictions that apply at the relevant time.
22. Data Accuracy
Customers are responsible for ensuring that information they enter into HotelO is accurate, relevant and appropriately updated. HotelO may provide tools to correct or update information but does not independently verify the accuracy of all Customer Data.
23. Account and Data Deletion
You may request closure of your HotelO account or deletion of eligible personal information by contacting HotelO. Deletion may be subject to contractual terms, legal retention requirements, security records, accounting requirements, dispute preservation and technically necessary backup retention.
For hotel guest/customer data, the hotel customer may initiate deletion or retention instructions in accordance with the DPA and applicable law.
24. Marketing Communications
HotelO may send necessary service communications, including security alerts, account notices, billing messages and operational announcements. Optional promotional communications will be handled separately where required, and you may opt out of marketing communications without affecting essential service messages.
25. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in the service, law, technology or processing practices. The revised version will show an updated date and, where appropriate, a version number. Where a material change requires additional notice or consent, we will take appropriate steps.
26. Relationship With Other Legal Documents
This Privacy Policy should be read together with the HotelO Terms & Conditions, Cancellation & Refund Policy and Data Processing Agreement. Where the DPA governs processing performed on behalf of a hotel customer, the DPA will control to the extent of a conflict concerning that processing.
27. Governing Framework
HotelO is operated in accordance with applicable Indian law and other laws that may apply to a particular processing activity. This Privacy Policy is intended to describe our practices clearly and is not a representation that every legal obligation applies identically to every Customer or every processing activity.
The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 are important parts of India’s current digital-data protection framework. Certain provisions have phased commencement, so our controls may be updated as the applicable provisions become operative.
28. Contact and Grievance
Dwoing / HotelO
Email: hello@hotelo.in
Website: hotelo.in
Application: app.hotelo.in
Privacy or data-protection concerns can be submitted through the email above. We will review and respond according to the nature of the request and applicable legal/contractual requirements.