1. Who this policy applies to
This Privacy Policy applies when you use the PGYatra mobile application, pgyatra.com, public tenant joining or complaint forms, customer support and any related service that links to this policy (together, the “Service”). In this policy, “PGYatra”, “we”, “us” and “our” refer to the operator of the PGYatra Service.
By using the Service, you acknowledge the practices described here. If you provide another person's information to PGYatra, you are responsible for giving any required notice and obtaining any permission required by applicable law.
2. Our role and the PG owner's role
PGYatra serves two different privacy roles depending on the information involved:
- Owner account and service data: PGYatra decides why and how account, subscription, support, security and product-usage information is processed so we can operate the Service.
- Tenant and property records: the PG owner or operator generally decides what tenant data is entered and why it is used. PGYatra stores and processes that data to provide the features requested by the owner.
PG owners are responsible for their own notices, permissions, record accuracy, access decisions and lawful handling of tenant data. Tenants should normally direct a request about a record maintained by their PG to that PG owner first. We will support the owner where reasonably required.
3. Information we collect
The information collected depends on how you use the Service and may include:
- Account information: name, email address, phone number, login and verification information, account preferences and profile details.
- Property information: PG name, address or city, rooms, floors, beds, occupancy, facilities and related operational settings.
- Tenant and joining information: name, phone number, email address, home address, joining date, assigned room or bed, agreed rent and other information entered by the owner or submitted through a joining form.
- Rent records: monthly amount, due or payment status, payment date, partial amounts, mode recorded by the owner and notes. These are management records; PGYatra does not process the tenant's rent payment.
- Operations data: complaints, urgency and status updates, expense records, vendor or staff contacts, notices, imports, exports and property analytics derived from those records.
- Subscription information: plan, trial status, renewal and cancellation status, invoices, payment outcome and limited transaction references supplied by the payment processor.
- Support information: messages, attachments, bug reports and any other information you choose to provide when contacting us.
- Technical and usage information: device and operating-system type, app version, IP address, timestamps, diagnostic logs, crash information, security events and interactions needed to maintain and improve the Service.
4. Where information comes from
We receive information directly from account holders, from PG owners and authorised team members using the app, from tenants or prospective tenants using public forms, automatically from devices and service infrastructure, and from providers supporting authentication, payments, notifications, hosting and customer support.
5. Why we use information
We process information for lawful purposes connected with providing and protecting the Service, including to:
- create and secure accounts, verify users and remember preferences;
- organise properties, tenants, rooms, beds, rent records, complaints, contacts and expenses;
- receive joining and complaint submissions and deliver them to the relevant PG owner;
- generate dashboards, operational insights and requested Excel exports of tenant, rent and expense records;
- manage trials, subscriptions, invoices, renewals and cancellations;
- send essential account, security, billing and service communications;
- provide support, diagnose problems, monitor performance and improve usability;
- detect spam, fraud, misuse, unauthorised access and other security risks; and
- comply with legal duties, respond to lawful requests and establish or defend legal claims.
Depending on the context and applicable law, processing may be based on your consent, your request for the Service, performance of a contract, compliance with law, or another permitted legitimate use. Where processing depends on consent, you may withdraw it for future processing, although this may prevent the affected feature from working.
6. Public joining and complaint forms
A PG owner may share a public link to a joining or complaint form. Information submitted through that form is made available to the owner associated with the link. Submitters should verify that the form belongs to the intended PG and provide only information relevant to the request. PGYatra may apply technical safeguards such as rate limits and security logging to prevent abuse.
7. Notifications, email and WhatsApp
We may send transactional emails and, with device permission, push notifications about verification, password resets, subscriptions, joining requests, complaints, security and material service updates. You can manage optional push notifications through your device settings, but some essential service messages cannot be disabled while an account remains active.
When an owner chooses a WhatsApp reminder or notice, PGYatra prepares the message and opens WhatsApp on the owner's device. The owner reviews and sends the message from their own WhatsApp account. PGYatra does not independently send that WhatsApp message or control WhatsApp's processing of it.
8. Subscription payments and tenant rent
PGYatra subscription payments are processed by Razorpay. Razorpay receives payment details under its own terms and privacy policy. PGYatra does not store full card, UPI or bank credentials, but we may receive a transaction reference, payment status, amount and billing details necessary for account administration, reconciliation and legal records.
PGYatra is not a rent payment gateway. We do not collect a tenant's UPI ID for paying rent and do not receive, hold, settle or transfer rent between a tenant and an owner. Any payment mode shown in a rent record is information recorded by the owner for operational tracking.
9. When we share information
We do not sell personal information. We may disclose only the information reasonably necessary in these circumstances:
- To the relevant PG account: joining forms, complaints and other tenant submissions are shared with the owner and authorised users of the PG selected by the submitter.
- To service providers: companies supporting cloud hosting, databases, authentication, email, push notifications, diagnostics, payment processing and customer support process information for us under appropriate instructions or agreements.
- For legal and safety reasons: we may respond to valid legal process or disclose information where reasonably necessary to protect users, the public, our rights or the security and integrity of the Service.
- For a business change: information may be transferred as part of a merger, financing, acquisition, reorganisation or sale of assets, subject to appropriate confidentiality and applicable law.
- With your direction: we may share information when you request an export, initiate an integration or otherwise clearly direct us to do so.
10. Third-party services
The Service may link to or open services such as Razorpay, WhatsApp, Google Play and the Apple App Store. Those companies operate under their own terms and privacy notices. PGYatra is not responsible for how an independent third party handles information after you leave our Service or choose to interact with it.
11. International processing
Some service providers may process or store information outside your state or country. Where this occurs, we take steps intended to ensure the transfer and processing are permitted under applicable law and subject to appropriate protections. Government restrictions on transfers, where applicable, will continue to apply.
12. Data retention
We retain information only for as long as reasonably needed for the purposes described in this policy. Retention depends on the type of record, whether the account is active, the owner's instructions, security and backup requirements, dispute resolution, and tax, accounting or other legal obligations.
If a subscription ends, account data may be retained for a reasonable period to support read-only access or reactivation, as described in the product at that time. When information is no longer required, we take steps to delete or de-identify it, subject to lawful retention needs and normal backup cycles.
13. Account, PG and record deletion
Owners can update many records in the app and may use available controls to delete an individual PG or their account. Deleting an account is intended to remove the data associated with it, subject to information we must retain for legal, fraud-prevention, security, billing or dispute purposes. Before deleting information, export any records you are required to keep. Deletion may be irreversible.
14. Security
We use reasonable administrative, technical and organisational safeguards designed to protect information, including account authentication, access controls intended to separate each owner's data, service monitoring and protections used by our infrastructure providers. Users should protect their devices and credentials, choose a strong password, restrict team access and notify us promptly of suspected unauthorised use.
No internet service can guarantee absolute security. You use the Service with this limitation in mind.
15. Security incidents
If we become aware of a personal-data breach, we will investigate, take reasonable containment and remediation steps, and make notifications to affected people or authorities where required by applicable law. Owners must promptly inform us if an incident involving their account may affect data stored in PGYatra.
16. Your privacy choices and rights
Subject to applicable law and appropriate identity verification, you may ask for access to information about you, correction of inaccurate information, deletion, withdrawal of consent where consent applies, or help with a privacy grievance. You may also nominate another person to exercise applicable rights in the event of death or incapacity where the law provides that right.
Account holders can make many corrections directly in the app. To submit another request, email support@pgyatra.com from the address linked to your account and describe the request. We may ask for information needed to verify your identity and locate the relevant records. We will respond within the period required by applicable law.
17. Requests from tenants
If your information was entered by a PG owner or submitted to that owner's public form, the owner generally controls the operational record. Contact the relevant owner first to request access, correction or deletion. If you cannot reach the owner, contact us with the PG name and enough information to identify the record; we will assess the request and, where appropriate, coordinate with the owner.
18. Children and minors
PGYatra accounts are intended for adults authorised to operate a PG or accommodation business. The Service is not designed for children to create owner accounts. If an owner manages information about a minor tenant, the owner is responsible for obtaining verifiable parental or guardian consent and meeting any other legal requirements that apply. Contact us if you believe a child's information was provided improperly.
19. Website storage and tracking
The website may use browser storage and similar essential technologies to remember choices such as light or dark appearance and to support security and basic functionality. We do not use this information to process tenant rent. If we introduce non-essential analytics or advertising technologies, we will update our disclosures and provide choices where required.
20. Automated decision-making
PGYatra's dashboards and insights summarise records entered into the Service. They do not make legally binding decisions about tenants. Owners remain responsible for reviewing records and making fair, lawful accommodation and business decisions.
21. Changes to this policy
We may update this policy when the Service, our providers or legal requirements change. We will post the revised version here and update the effective date. If a change materially affects how we use information, we will provide additional notice through the Service or by email where appropriate.
22. Grievances and contact
For a privacy question, rights request or grievance, email our privacy contact at support@pgyatra.com with the subject “Privacy Request”. Please include your name, account email or phone number, the PG concerned (if relevant), and a clear description of the issue. We will acknowledge and address the request in accordance with applicable law. If you remain dissatisfied, you may use any further remedy available under applicable data-protection law.