# Privacy Policy

This Privacy Policy explains how StayBird Hospitality LLP ("StayBird", "we", "us") collects, uses, shares and protects your personal data when you use our website and book our hotels, serviced apartments, villas and event venues. We act as a Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and we also follow the Information Technology Act, 2000 and its rules where they apply.

## What data we collect

We collect only the data we need to take and manage your booking and to run our website.

- Identity and contact details: name, email address, mobile number and, at check-in, a government photo ID as required by law.
- Booking details: property, room type, dates, number of guests, special requests and stay history.
- Payment information: processed by our payment partner. We receive a payment confirmation and reference, not your full card or bank details.
- Technical and usage data: device type, browser, IP address, pages viewed and similar analytics, plus marketing source (UTM) information where present.
- Communications: messages you send us by form, email, chat or WhatsApp.

## How we use your data and our legal basis

We process your personal data on the basis of your consent and, where applicable, for the legitimate uses permitted by the DPDP Act. We use it to:

We limit processing to these stated purposes. If we need to use your data for a new purpose, we will tell you and, where required, ask for your consent.

- Create, confirm and manage your reservation and stay.
- Take payment and issue a GST invoice and receipt.
- Send booking confirmations, reminders and service messages.
- Respond to your enquiries and provide customer support.
- Improve our website, security and services.
- Send offers and marketing only where you have opted in. You can opt out at any time.

## Payments and where your data is stored

We store data on servers located in India and with reputable service providers.

Payments are processed by Razorpay, an RBI-authorised payment aggregator and a PCI DSS compliant processor. We do not collect, store or access your full card number, CVV, card PIN or UPI PIN. These are captured and processed directly by Razorpay. We retain only what we need to manage your booking, such as the transaction reference, amount, booking reference and the masked last four digits.

In line with the Reserve Bank of India’s data localisation requirement, payment system data is stored in India by our payment aggregator. If any other data is ever processed outside India, we will do so only as permitted by Indian law and with appropriate safeguards.

## Cookies and analytics

We use cookies and similar technologies to keep the site working, remember your preferences and understand how the site is used. You can manage non-essential cookies at any time using the "Cookie Preferences" link in our footer, and through your browser settings.

## Who we share data with

We do not sell your personal data. We share it only with parties that help us run our business, under contracts that require them to protect it:

- Our payment partner, to process payments and refunds.
- The specific property or venue where you have booked, to deliver your stay or event.
- Technology, hosting, analytics and communication providers that operate our website and messaging.
- Government, regulatory or law-enforcement bodies where we are legally required to share data.

## How long we keep your data

We keep personal data only for as long as needed for the purpose it was collected, or for as long as the law requires (for example, tax and accounting records). When data is no longer needed, we delete or anonymise it.

## How we protect your data

We follow reasonable security practices as required by the Information Technology Act, 2000 and its rules. These include access controls, encryption in transit and limiting who can see your data. No system is perfectly secure, but we work to protect your data and to act quickly if a problem occurs.

If a personal data breach occurs, we will notify affected individuals and the Data Protection Board of India as required by law, and take steps to limit any harm.

## Your rights

Under the DPDP Act, you have the right to:

To exercise any of these rights, contact our Grievance Officer using the details below.

- Access a summary of the personal data we hold about you and how we process it.
- Ask us to correct or update data that is inaccurate or incomplete.
- Ask us to erase your data where it is no longer needed and the law allows.
- Withdraw your consent at any time, as easily as you gave it.
- Nominate another person to exercise your rights if you are unable to.
- Raise a grievance with us and, if unsatisfied, with the Data Protection Board of India.

## Children’s data

Our services are intended for adults. We do not knowingly process the personal data of anyone under 18 without verifiable consent from a parent or lawful guardian, and we do not use children’s data for tracking or targeted advertising.

## Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top shows when it last changed. Significant changes will be highlighted on this page.

## About this page

Published by StayBird Hospitality. Facilities, capacities, policies and rates on this page come from StayBird's own property records and were last reviewed on 22 September 2026. Pune's civic services and ward boundaries are administered by the Pune Municipal Corporation, according to the corporation, and Maharashtra's state tourism body is the Maharashtra Tourism Development Corporation. Area profiles are linked below so any geographic claim here can be checked against a public source.

## References

- [Pune Municipal Corporation](https://www.pmc.gov.in/)
- [Maharashtra Tourism Development Corporation](https://www.maharashtratourism.gov.in/)

Last reviewed 24 June 2026.
