How we collect, use and protect information on Atithi PMS.
This policy covers two kinds of data: account data belonging to hotels and their staff who use Atithi PMS, and guest data that hotels enter into the Service. For guest data, the hotel is the data controller and Atithi PMS acts as a data processor on the hotel's behalf.
We do not sell hotel or guest data. Data is shared only: with the hotel's own staff according to their role-based permissions; with third-party services the hotel explicitly enables (e.g. WhatsApp, Tally); and where required by law or a valid legal process.
Each hotel's data is isolated at the tenant level. Sensitive fields are encrypted at rest, access is governed by role-based permissions, and mutating actions on sensitive resources are recorded in an audit log that cannot be edited or deleted.
Account and guest data is retained for as long as the hotel's subscription is active, and afterwards only as long as needed to meet legal, tax and accounting record-keeping requirements.
Hotel staff can access or correct their account details from within the app. Requests relating to guest data should be directed to the hotel where the stay took place, as they control that data; hotels can contact us for assistance fulfilling such requests.
This marketing site and the Atithi PMS application use only the cookies/local storage required to keep you signed in and remember basic preferences — no third-party advertising trackers.
We may update this policy from time to time; material changes will be reflected by the "Last updated" date above.
Questions about this policy can be sent through the Contact link in the site footer.