1. Information We Collect
We collect only the minimum operational information required to maintain accurate occupancy, rent ledgers, and communication between PG owners/managers and their residents:
| Data Category | Examples | Purpose |
|---|---|---|
| Owner & Staff Account Data | Name, verified email address, role permissions, organization and property names. | Authentication, property setup, role-based access control, and operational alerts. |
| Tenant Profile & Stay Data | Full name, 10-digit Indian mobile number, floor/room/bed assignment, check-in/check-out dates, and emergency/ID reference notes recorded by the PG. | Occupancy tracking, tenant OTP sign-in, and linking residents to their statement. |
| Financial Ledger & Evidence | Rent terms, utility meter readings, charges, verified receipts, deposit movements, UPI reference numbers, and optional payment screenshot images. | Auditable accounting, payment verification, and checkout settlement between owner and tenant. |
| Device & Diagnostic Data | Push notification tokens (FCM/APNs) and crash diagnostics (Firebase Crashlytics). | Delivering in-app notices and diagnosing application stability issues. |
2. How Information is Used
- To compute prorated rent, shared electricity allocations, running balances, and checkout statements in India Standard Time (`Asia/Kolkata`).
- To authenticate users via email verification or mobile OTP (`Fast2SMS` / `Meta WhatsApp Cloud API`).
- To deliver opt-in due-day rent reminders and property announcements.
- To maintain an immutable audit trail of financial and occupancy actions within each property.
3. Property Isolation & Technical Security
All records are stored in PostgreSQL (Supabase) protected by strict Row-Level Security (RLS) policies:
- Zero Cross-PG Exposure: Owners and delegated managers can query only the properties where they hold an active membership.
- Tenant-Scoped Access: Tenants signed in via verified phone OTP can read only their own stay, ledger charges, payment claims, and property notices.
- Private Evidence Storage: Payment screenshot images are stored in private, access-controlled buckets with size and retention limits — never on public URLs.
- Encrypted Off-Site Backups: Daily independent backups of database records and evidence files are encrypted (`AES-GCM` / authenticated encryption) before storage in Cloudflare R2.
4. Free-Tier Advertising Policy
Properties operating on the 3-Month Pilot or the Paid Property Plan experience zero advertisements. For properties that choose the continuing Free tier after the pilot:
- Modest banner ads (via Google AdMob) may appear only on non-transactional screens such as general dashboard or notice-list views.
- Ads are never placed over payment entry, identity details, checkout approval, or urgent notices.
- Zero Financial Data Targeting: Tenant rent amounts, overdue balances, identity notes, and payment records are never transmitted to any ad network for behavioral targeting.
5. Data Retention, Downgrades & Export
Downgrading from a Pilot or Paid plan to the Continuing Free tier never deletes or locks historical financial records, receipts, or checkout statements. Property owners can export their occupancy and ledger records to CSV at any time. Payment-evidence images are subject to published storage quotas and retention windows based on the property's active tier.
6. Your Rights & Grievance Officer Contact
Under applicable Indian data protection laws (including the Digital Personal Data Protection Act, 2023), users may request access to, correction of, or erasure of personal profile data not required to be retained by the property owner for statutory accounting or tenancy records.
For privacy inquiries, data export assistance, or grievance redressal, contact:
Email: support@pgmanagement.in