Privacy Notice
Standalone notice (DPDP Act, 2023 · Rule 3) · Version 2026-09-05-v1 · Last updated: 5 September 2026
Tathastu Farms ("we", "our", or "us"), operating the website and booking services at tathastufarm.com and our resort at Behind Silwar Hill, Hazaribagh, Jharkhand 825303, is the Data Fiduciaryfor digital personal data we decide the purpose and means of processing. This notice is independent of our Terms & Conditions. It applies to digital personal data of Data Principals in India in connection with our hospitality services.
1. Personal data we collect (itemised)
- Identity & contact: full name, email address, mobile number, optional profile avatar URL.
- Account / auth: authentication identifiers (including phone OTP via MSG91, Google account email/name/avatar when you choose Google sign-in), session tokens.
- Stay booking: room type/name, check-in/out dates, guest count, extra-bed count, special requests text, booking/payment status identifiers.
- Payments: payment provider order/payment identifiers (we do not store full card numbers; Razorpay processes card/UPI data as our payment processor).
- Food orders: order items, room number, customer name for delivery, payment and POS sync identifiers.
- Enquiries: name, email, phone, subject, message, and (for events) event type, guest count, date/time window.
- Optional profile CRM: birthday, anniversary (only if you choose to provide them).
- Government ID at check-in: collected offline / at the property as required by applicable law — not uploaded through this website today.
2. Purposes and goods/services
- Room reservation & stay: create and manage bookings, allocate rooms, communicate confirmations, provide hospitality services.
- Payments: collect and confirm payment for stays and food orders.
- In-room dining: take and fulfil food orders via our kitchen / POS partner.
- Account access: authenticate you (OTP or Google) and show your bookings / orders.
- Enquiries & events: respond to contact and banquet/hall enquiries.
- Legal / regulatory guest records: where applicable law requires guest registers or disclosures to authorities (certain legitimate use under Section 7 — see counsel).
- Optional personalisation:birthday/anniversary only with your specific consent — not used for children's tracking or targeted advertising.
Lawful basis under the DPDP Act is consent (Section 6) and/or a listed certain legitimate use (Section 7)only. We do not rely on GDPR "legitimate interest".
3. Recipients / processors
We do not sell personal data. We share data only as needed with processors/service providers under contract, including: payment gateway (Razorpay), SMS OTP (MSG91), property management (CheckinCloud), food POS (Petpooja), authentication/storage (Supabase / Google OAuth where used), and internal staff alerting (Telegram). Categories of recipients are disclosed so you can exercise access rights under Section 11.
4. Cross-border transfer
Some processors may process data on systems outside India. Under Section 16 and Rule 15, transfers are permitted unless restricted by the Central Government (negative-list model). We do not rely on GDPR SCCs or adequacy decisions as the legal basis. Localisation may be required for categories notified in future.
5. Retention & erasure
We keep personal data only as long as needed for the specified purpose, a legal obligation (for example tax or guest-register rules), or the minimum logging period required under Rule 6 / Rule 8(3). When the purpose is served and no legal hold applies, we erase or anonymise data and instruct processors where we can. See our retention schedule in internal ops docs.
6. Security
We apply reasonable security safeguards under Section 8(5) and Rule 6 (access control, integrity-protected sessions, monitoring/logging, backups). No safeguard is perfect; we maintain a breach response process under Rule 7.
7. Children (under 18)
Under the DPDP Act a child is a person under 18 years. Our online booking is intended for adults. The booker must be 18 or older. Do not create an account for a child. Verifiable parental/guardian consent is required before we knowingly process a child's personal data as Data Principal. We do not engage in tracking or targeted advertising directed at children.
8. Your rights (Data Principal)
- Right to access a summary of your personal data and processing activities (Section 11).
- Right to correction, completion, updating, and erasure (Section 12).
- Right to withdraw consent as easily as it was given (Section 6) — see link below.
- Right of grievance redressal (response within a reasonable period not exceeding 90 days).
- Right to nominate another individual in case of death or incapacity (Section 14).
This notice does not create rights the Act does not grant (for example a freestanding right to data portability or objection to automated decision-making).
9. Grievance redressal & Data Protection Board
Grievance contact: Privacy / Grievance Officer (interim: Resort Management) — email tathaastufarm@gmail.com, phone +91 62001 12103. We aim to respond within 90 days (Rule 14(3)).
You may also complain to the Data Protection Board of India. Use the Board's official website / app when published by the Government of India (monitor MeitY / Board announcements for the live portal URL).
10. Changes
When we change purposes or this notice in a material way, we will update this page and the notice version, and seek fresh consent where required.