[EFFECTIVE DATE], [DPO NAME/EMAIL], [confirm region], [SMS / WhatsApp / push provider(s)], [confirm], [Identity/KYC provider(s)].
Operated by HASU AURORA PRIVATE LIMITED
Effective date: [EFFECTIVE DATE] · Last updated: 18 August 2026
This Privacy Policy explains how HASU AURORA PRIVATE LIMITED ("HASU AURORA", "8055 Stays", "we", "us", "our") collects, uses, discloses, retains, and protects your personal data when you use the 8055 Stays hospitality marketplace, including:
For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), HASU AURORA PRIVATE LIMITED is the Data Fiduciary that determines the purposes and means of processing your personal data, and you are a Data Principal. Where the EU/UK GDPR applies to a particular processing activity, we act as the data controller for that activity (except where we act as a processor on a Host's behalf — see Section 12).
Contact details
| Registered office | C/O H.N. Murthy, 351, Marasandra, Bettahalsur, Bangalore North, Bengaluru – 562157, Karnataka, India |
| CIN | U56101KA2025PTC201692 |
| Privacy / data-protection contact | support@hasuaurora.com |
| Grievance Officer (DPDP & IT Rules) | Sukshith GM, support@hasuaurora.com |
| Data Protection Officer (if appointed) | [DPO NAME/EMAIL] |
The Platform serves three groups of people, and our role differs by relationship:
Marketplace relationship. 8055 Stays is an online marketplace that connects Guests with Hosts. For a booking, a Host and a Guest exchange certain personal data with each other through the Platform. In relation to the data a Host collects and uses for its own hotel/stay operations (for example, its own guest register or in-property records), the Host is an independent Data Fiduciary / controller and its own privacy notice also applies. We are the Data Fiduciary for the Platform itself.
We collect the categories below. Not every category applies to every person; what we collect depends on whether you are a Guest, Host, or visitor and which features you use.
| Category | Examples | Who |
|---|---|---|
| Account & identity | Name, email address, phone number, password (stored only as a secure hash), language, currency, time zone, profile photo. | Guests, Hosts |
| Authentication data | OTP verification status, social-login identifiers (e.g., Google/Apple), MFA settings, passkeys/credentials, security questions, session and device records. | Guests, Hosts |
| Guest profile & preferences | Saved travellers (which may include other people's names and details you enter), saved addresses, accessibility needs, notification preferences. | Guests |
| Booking & travel data | Search terms, dates, destinations, guest counts, wishlists, quotes, reservations, itineraries, special requests, arrival times. | Guests |
| Identity / check-in documents (planned) | Where a stay legally requires guest registration, identity/registration details provided at or before check-in. Note: the current system stores only minimal verification status, not document images — see Section 4. | Guests |
| Host onboarding & KYC | Business type, registration/tax details, and verification status. To minimise data, the system currently stores only the last four digits of the tax identifier plus KYC/banking status flags — not full tax IDs or uploaded ID-document images. | Hosts / partners |
| Payment data (planned) | Billing details and the payment status of transactions. When online payments go live, full card numbers, UPI credentials, and bank credentials will be entered directly with our payment providers (Razorpay / Cashfree); we will not store full card numbers. See Section 6. | Guests, Hosts |
| Content you create | Messages and attachments in Guest–Host messaging, ratings, reviews (including review images), private feedback, support tickets, dispute and safety reports. | Guests, Hosts |
| Listings & property data | Property descriptions, photos, amenities, pricing, availability, house rules, and property location. | Hosts |
| Communications | Emails, in-app messages, SMS/WhatsApp/push interactions, and support correspondence with us. | Everyone |
| Category | Examples | Notes |
|---|---|---|
| Device & technical data | Device type, operating system, app version, browser type, and IP address. | Used for security, fraud prevention, and to operate the service. |
| Location data | Approximate location derived from IP address; precise device location only when you grant permission for map search / "nearby stays" or when a Host uses location for operations. | Precise location is optional and permission-gated on mobile — see your device's permission settings. |
| Usage & analytics data | Named product events (e.g., "search performed", "booking confirmed") and a stable internal user ID, collected through PostHog only after you opt in. | Analytics is off by default. See Section 7 and the Cookie & Tracking Policy. |
| Diagnostic data | Crash and error signals via Cloudflare Workers observability and PostHog exception capture, limited to an allowlisted error class and a generic message — original messages, stack traces, and attached context are not sent. | Used to keep the apps stable. |
| Authentication network data | IP address and user-agent recorded with each login session for security. | Held in the authentication store. |
We do not buy personal data to build advertising profiles.
Some of the data above is more sensitive and receives additional protection:
precise /
approximate visibility control that rounds public coordinates when set to
approximate), and a Guest's device location only when granted for map/nearby
search (see your device's permission settings).We collect these only where necessary for a specific purpose, restrict internal access, and retain them only as long as needed (see Data Retention Policy). We do not use these categories for analytics or marketing. If you provide any accessibility or similar sensitive information (for example, an accessibility requirement), we use it only to fulfil your request.
Under the DPDP Act, we process personal data on the basis of your consent or for a legitimate use permitted by the Act (such as a purpose for which you voluntarily provided data, or compliance with law). Where the GDPR applies, the corresponding lawful basis is shown in brackets.
| Purpose | Examples | Basis (DPDP / GDPR) |
|---|---|---|
| Provide the service | Create and secure your account; search, quote, book, pay, check in, message, review, and manage trips or listings. | Performance of contract / voluntary provision for that purpose (contract) |
| Payments & payouts | Process guest payments and host payouts through Razorpay/Cashfree; handle refunds. | Contract / legal obligation |
| Identity & KYC verification | Verify Hosts and, where legally required, Guest check-in identity. | Legal obligation / consent |
| Safety, security & fraud prevention | Authenticate logins, detect and prevent fraud and abuse, protect users and the Platform, handle safety escalations. | Legitimate use / legitimate interests / legal obligation |
| Customer support | Respond to tickets, disputes, and grievances. | Contract / legitimate interests |
| Service communications | Booking confirmations, receipts, reminders, security alerts, and other transactional messages via email/SMS/WhatsApp/push. | Contract / legitimate interests |
| Product analytics & improvement | Understand feature usage through PostHog to improve the Platform. | Consent (opt-in) |
| Marketing communications | Optional promotional messages and offers. | Consent (opt-in); you can withdraw anytime |
| Legal & compliance | Tax invoicing, accounting, responding to lawful requests, enforcing our terms. | Legal obligation / legitimate interests |
You can withdraw consent at any time for consent-based processing (see Section 10). Withdrawing consent does not affect processing already carried out, and some features may stop working if the data they rely on is withdrawn.
When online payments go live, they will be processed by our payment providers Razorpay and Cashfree, supporting methods such as UPI, cards, and net banking. Your payment-method details (card number, UPI PIN, bank credentials) will be collected and processed by the payment provider under their own privacy policies and PCI-DSS obligations. We will receive the outcome of the transaction (success/failure, method type, a reference, and risk signals) but will not store full card numbers or UPI/bank credentials. Host payout bank details will be collected to make payouts and handled as sensitive financial data.
Product analytics on the Platform uses PostHog, and it is opt-in only, off by default: no analytics events are persisted while your consent is pending or denied. When you first use an app you see a consent card; you can change your choice at any time through Analytics settings.
When you opt in, we capture only explicitly named product events and safe exception reports. We deliberately do not use session replay, heatmaps, automatic click/pageview capture, or performance capture. We respect Do Not Track, strip URL query strings and fragments before events leave your device, and identify you in analytics only by a stable internal user ID — never by your name, email, message content, payment data, or identity documents.
For full details of cookies, SDK identifiers, and how to control them, see the Cookie & Tracking Policy.
Today, the Platform does not use AI/ML to process your personal data, and decisions such as listing moderation are made by trained people, not automated systems. We may introduce AI-assisted features in future (for example, search or recommendations). If and when we do, we will describe exactly what they are, what data they use, and the human oversight that applies in our AI Usage Policy, and we will not make solely automated decisions that produce legal or similarly significant effects about you without a lawful basis and, where required, human review.
We share personal data only as described here. We do not sell your personal data.
Between Guests and Hosts, for a booking. To complete and run a stay, we share the data each side needs (for example, a Guest's name and booking details with the Host; the Host/property contact and directions with the Guest). Messaging content is shared with the person you message.
Partner workspaces. Hosts operate within their own workspace; booking data is routed to the workspace that owns the listing.
Service providers / processors (subprocessors). We use vetted providers who process data on our instructions under contract:
| Provider | Role | Function | Region |
|---|---|---|---|
| Neon | Database (PostgreSQL + PostGIS) | Authoritative business data | Singapore (AWS ap-southeast-1) |
| Cloudflare | Workers, D1, R2, Images, Queues, Durable Objects, Email | Web/app delivery, authentication store, media storage, background delivery, real-time, transactional email | Global edge |
| Railway (Fly.io as portable alternative) | Hosting | Go API and worker hosting | Near Singapore |
| Upstash / managed Redis | Cache & rate-limiting | Ephemeral caching, rate limiting | [confirm region] |
| PostHog | Analytics | Consent-gated product analytics & exception capture | United States (us.i.posthog.com) |
| Sign-in (OAuth) & Maps Platform | Optional social login; web map search/display | Global (US-based) | |
| Apple | Sign in with Apple | Optional social login on iOS | Global (US-based) |
| Slack | Ops alerting | Internal dead-letter/operational alerts (not user-facing) | US |
| Razorpay (planned) | Payments | Guest payments, host payouts | India |
| Cashfree (planned) | Payments | Guest payments, host payouts | India |
| [SMS / WhatsApp / push provider(s)] (planned) | Communications | Opted-in and transactional messaging | [confirm] |
| [Identity/KYC provider(s)] (if used) | Verification | Host/guest identity verification | [confirm] |
Legal, safety, and compliance. We may disclose data to comply with law, respond to valid legal requests, enforce our terms, prevent fraud, or protect the rights, safety, and property of users, the public, or HASU AURORA.
Business transfers. If we are involved in a merger, acquisition, or asset sale, data may be transferred subject to this Policy and applicable law.
With your consent / at your direction. Any other sharing you ask for or agree to.
As a Data Principal you have the right to:
The DPDP Compliance Addendum explains how to exercise each right and our timelines.
Access, rectification, erasure, restriction, portability, objection, and the right not to be subject to certain automated decision-making, plus the right to lodge a complaint with a supervisory authority.
Guests can use Account → Privacy / Data & Rights on Web, iOS, or Android to request an encrypted export, deactivate their account, or schedule permanent deletion. Sensitive actions require recent authentication. Deletion has a 30-day cancellation period and may be blocked by an active reservation, dispute, safety case, legal hold, finance obligation, export, or product responsibility. Email support@hasuaurora.com for correction, nomination, appeals, or any request the self-service controls cannot resolve.
HASU AURORA PRIVATE LIMITED is incorporated in India, but the Platform's data is processed and stored outside India by our infrastructure providers:
Where we transfer personal data across borders, we do so in accordance with the DPDP Act and any country-transfer restrictions notified by the Central Government of India, and — where the GDPR applies — under an appropriate transfer mechanism (such as Standard Contractual Clauses). We contractually require all subprocessors to protect your data to a standard consistent with this Policy. If you require data localisation for a specific engagement, contact support@hasuaurora.com.
For some processing, a Host determines the purposes and means and we act on the Host's behalf (as a Data Processor / processor) — for example, a Host's own operational records about its guests within the Host tools. In those cases, the Host's privacy notice governs, and you should contact the Host to exercise your rights over that data. We will assist Hosts in meeting their obligations.
We protect personal data with technical and organisational measures including:
encryption in transit; access controls tied to identity, workspace, role, and
resource ownership (authorisation is enforced centrally by our Go API);
tenant isolation via workspace_id on every tenant-owned record; audited and
time-limited support access/impersonation; encrypted OAuth tokens and hashed
passwords in the authentication store; redaction of personal data from
background-job (outbox) payloads; and a strict rule that logs, analytics, and
diagnostics must not contain payment credentials, identity documents, access
tokens, or unnecessary personal data. No system is perfectly secure; we
maintain incident-response procedures and will notify you and the Data
Protection Board of India of a personal-data breach as required by law.
We keep personal data only as long as necessary for the purposes described here or as required by law (for example, tax and accounting records). Full periods by data category are in the Data Retention Policy. When data is no longer needed, we delete or irreversibly anonymise it.
The Platform is intended for users 18 years or older and is not directed at children. Consistent with the DPDP Act, we do not knowingly process the personal data of a child (a person under 18) without verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. A Guest may include a minor as part of a travel party (for example, in a saved-traveller entry or booking); that information is provided and controlled by the booking adult. If you believe a child has provided us personal data without the required consent, contact support@hasuaurora.com and we will act promptly.
If you have a concern or complaint about how we handle your personal data, contact our Grievance Officer:
We will acknowledge and resolve grievances within the timelines required by the DPDP Act and the Information Technology Act rules. If you are not satisfied, you may escalate to the Data Protection Board of India (see the DPDP addendum).
We may update this Policy to reflect changes to the Platform or the law. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice (for example, in-app or by email). Your continued use after an update means you accept the revised Policy, except where consent is separately required.
Questions about this Policy or your data: support@hasuaurora.com, or write to us at C/O H.N. Murthy, 351, Marasandra, Bettahalsur, Bangalore North, Bengaluru – 562157, Karnataka, India.