Privacy policy
What HamaraPG collects, why it collects it, who else ever sees it, and what you can ask us to do about it.
Read this first. This is a plain-English summary of how the service actually operates, written by the people who build it and not by a lawyer. It is accurate about the software; it has not been reviewed by counsel, and it should be before launch. Where a fact about the company itself is missing you will see a marked slot rather than an invented answer.
Effective from [UNFILLED: date this policy takes effect]. This notice is published by Vedatricks Technologies Private Limited, the company that operates the HamaraPG software and the public PG listings on this site (“HamaraPG”, “we”).
Two different roles, and which one we are
India’s Digital Personal Data Protection Act, 2023 separates whoever decides why personal data is processed (the Data Fiduciary) from whoever processes it on their behalf (a Data Processor). HamaraPG is both, on different data, and the difference decides who you should ask for what.
- Your own account
- Your name, your phone number and email, and the record of your organisation and its plan. We decide why we hold these, so for this data we are the Data Fiduciary and this notice is our notice to you.
- Your residents, staff, landlords and vendors
- Everything a PG owner types into the product about other people — residents and their KYC, guardians and emergency contacts, staff attendance, landlord and vendor details. The owner is the Data Fiduciary for all of it and we are their Processor. We store it, we secure it, and we act on that owner’s instructions. If you are a resident and want your record changed or removed, ask the PG that entered it; if they need our help to do it, they can raise a ticket from inside the product.
- An enquiry left on a public listing
- We collect it and then hand it to the owner of that PG, who becomes responsible for it from that moment. This has its own section below, because it is the one place on this site where a stranger’s phone number changes hands.
Notice at collection: what we take, and the purpose it is taken for
Nothing here is collected in case it turns out to be useful later. Each item has one purpose, and that purpose is the only thing it is used for.
- Name, mobile number and email address — to create your account, to sign you in, and to send you what the product has to send you: an invoice, a receipt, a reminder, a portal invite. Signing in with a mobile number sends a one-time code to that number; signing in with an email sends one to that address.
- Your organisation’s operating records — properties, rooms, beds, bookings, invoices, payments, expenses, complaints, agreements and the rest. This is the product. It exists because you entered it, it is visible only inside your organisation, and we do not mine it.
- Resident and staff personal details — collected by the PG that engages them and held by us on their behalf. Which of your own team can see which parts of it is set by you: every module has separate view and manage permissions, and figures like what you pay a landlord are withheld individually rather than by hiding whole screens.
- Enquiries from the public listings — a name, a mobile number, and an optional message.
- A callback request from a PG owner — a name, a mobile number, the city the PG is in, and roughly how many beds it has. Left either on the “call me back” form or in the chat panel on this site, by somebody who does not have an account yet. It is taken for one purpose: so that we can ring that number about running their PG on HamaraPG. It stays with us. It is not sold, not passed to another PG owner, and not added to a marketing list.
- Payment records — what plan was bought, for how many beds, for what period, and whether it was paid. Card and UPI credentials never reach us. They are entered on the payment gateway’s own page; we receive an identifier and a status.
- Support tickets — what you wrote to us and the account it came from, so that we can answer it.
- Ordinary server logs — an IP address, a timestamp, a user agent, and what was requested. Kept for security and for diagnosing failures, which is the only thing they are read for.
When you enquire about a PG, your number goes to that PG
This is the most important sentence on the page for anyone who is not a customer. If you fill in the enquiry form on a public listing, your name, your mobile number and your message are recorded as an enquiry against that one property and become visible to the owner of that PG — so that they can call you back, which is the entire purpose of the form and the reason the number is asked for.
We do not sell that number, publish it, pass it to other PGs, or use it to market anything to you. The owner who receives it is responsible for what they do with it from that point, and they are bound by the same law that protects you. If a PG contacts you after you have asked them not to, tell them directly, and tell us using the details at the end of this page.
Consent, and taking it back
Where we rely on your consent it is asked for a stated purpose, and it covers that purpose only. You can withdraw it as easily as you gave it: write to the grievance contact below and say so. Withdrawing consent stops further processing; it does not undo what was lawfully done while the consent stood, and it cannot erase records we are separately required to keep, such as the tax record of a payment you made.
Some processing does not run on consent at all, because it cannot. If you have bought a plan we need your contact details and your payment record in order to give you what you bought and to keep the books that go with it.
Who else sees any of it
We do not sell personal data and we do not share it for anybody’s advertising. It reaches a third party only where the product cannot work otherwise, and then only the part they need:
- Razorpay, our payment gateway, for taking payments and for UPI Autopay mandates where an owner chooses one.
- Google, if — and only if — you choose to sign in with your Google account. Not using that button means Google is not involved.
- An AI provider, for the optional in-product assistant, and only for an account that actually opens it. The assistant is a paid capability and it is off unless your plan includes it.
- Our email provider, to deliver the mail the product sends, and an SMS provider for one-time codes and reminders once SMS delivery is enabled.
- Our hosting provider, which stores the database the application runs on.
- A public authority, where the law actually requires it — not on a casual request.
Cookies and tracking on this site
These public pages — the home page, the blog, the listings, this one — load no advertising script, no third-party analytics and no social tracking pixel. There is no consent banner because there is nothing to consent to. Your browser may hold a first-party session cookie set by the framework the site runs on; it carries no profile and does not follow you to other sites.
Inside the product a first-party page-analytics tool can be switched on by us. When it is, it loads on owner screens only: never in the resident portal, never in the platform console, and never on the two URLs that carry a one-time link in the path — the agreement signing page and the portal join page — because handing either of those to a third party would be handing over a working credential.
How long we keep it
Your operating records stay until you or your organisation remove them. We do not delete a customer’s data on a timer, and we do not delete it when a subscription lapses or is cancelled: what changes is access, not the records. That is deliberate. An owner who has stopped paying still has residents in rooms, deposits they are holding, and filings to make against invoices this product issued.
A resident’s portal login is a different thing from their record. It ends in the same moment their last live booking closes; their record stays with the PG, in the PG’s account, exactly as it was.
Server logs are kept only as long as they are useful for security and diagnosis, and are not assembled into a profile of anyone.
Keeping it safe
Traffic runs over HTTPS. Passwords are stored hashed and are not recoverable, by us or by anyone. Access inside an organisation is scoped by role and by property. The platform-operator side sits behind a separate check that is re-read from the live account record on every single request rather than trusted from a token, and any support impersonation of an account is recorded.
We are not going to claim a certification we do not hold, or promise that a breach is impossible. If one happens and it affects you, we will tell you and the Data Protection Board as the Act requires.
Your rights under the DPDP Act
If you are a Data Principal whose data we hold as Fiduciary — in practice, a HamaraPG account holder, or somebody who left an enquiry — you may:
- Ask what we hold: a summary of your personal data, what we are doing with it, and who we have shared it with.
- Have it corrected or completed when it is wrong or out of date. Most of it you can edit yourself inside the product.
- Have it erased, unless the law requires us to keep it or we still need it for the purpose you gave it for.
- Nominate someone to exercise these rights for you if you die or become unable to exercise them yourself.
- Have your grievance addressed by us first, before you need to go anywhere else.
If your data sits inside a PG’s account rather than ours — you are a resident, or one of their staff — ask that PG. They are the Fiduciary. We will help them act on your request; we will not act on it behind their back.
The Act asks something of you in return: do not impersonate somebody else when making a request, and do not raise a grievance you know to be false. We will ask for enough to be satisfied that a request is genuinely yours before acting on it, because acting on a forged one would be the worse failure.
Grievances
Write to us first and we will take it seriously. If we cannot resolve it you may complain to the Data Protection Board of India.
- Grievance officer: [UNFILLED: name and designation of the grievance officer]
- Email: info@hamarapg.com
- Postal address: [UNFILLED: registered office address]
If you already have an account, the fastest route is the support dock inside the product. Otherwise our phone number, our email address and an enquiry form are on Contact.
Changes to this notice
When this changes materially we will move the effective date at the top and, where the change affects what we do with your data, tell account holders inside the product. Small corrections happen without an announcement.
Related: Terms of service · Refund and cancellation policy · Contact