Privacy Policy (Nandish Homes)

Last updated: 02 - 10 - 2025 

This Privacy Policy explains how Nandish Homes (“we”, “us”, “our”) collects, uses, shares, and protects your personal data when you visit our website, use our booking/WhatsApp flows, or stay at our properties.

We comply with applicable Indian laws, including the Digital Personal Data Protection Act, 2023 (DPDP Act), and other sectoral rules as applicable. If you access us via OTAs, their privacy policies also apply.

1) Who controls your data

  • Data Fiduciary/Controller: Nebula Enterprises

  • Contact/Grievance Officer: [email protected]

2) Data we collect

  • Identity & Contact: name, phone/WhatsApp, email, postal address, country, ID proofs (per law), emergency contact.

  • Booking & Stay: dates, guest count, preferences, payments, invoices, room/villa number, service requests, incident logs.

  • Payment: amount, method, status, transaction IDs. (Card/UPI details are processed by payment gateways; we do not store full card numbers.)

  • Communication: messages/emails/WhatsApp, call recordings (if support calls are recorded), feedback, reviews.

  • Device & Usage: IP address, browser type, device identifiers, pages viewed, cookies/SDK events, approximate location (if enabled).

  • CCTV (if installed at property): common-area footage for safety and security, retained for limited periods.

  • Third-party sources: OTAs/channel managers (e.g., RentalWise), payment gateways (Razorpay), analytics tools ([e.g., Google Analytics]), identity verification services (if used).

3) Why we use your data (Purposes)

  • Manage bookings, payments, check-in/ID verification, and property access.

  • Provide customer support, housekeeping/maintenance scheduling, and guest services.

  • Comply with legal requirements (taxation, local registrations/reporting, lawful requests).

  • Security, fraud prevention, and dispute handling.

  • Improve our website/services, run analytics, and measure performance.

  • Send transactional messages (confirmations, reminders, invoices).

  • With your consent where required: promotions, WhatsApp updates, and special offers (opt-out any time).

4) Lawful bases / Consent

  • Performance of a contract (to provide your stay/booking).

  • Compliance with law (KYC/ID, taxes, safety).

  • Legitimate interests (security, service improvement, limited direct marketing to existing customers).

  • Consent (promotional WhatsApp/SMS/email, cookies beyond strictly necessary). You can withdraw consent by contacting us or using available opt-out links.

5) Sharing your data

We may share limited data with:

  • Service providers/Processors: channel managers (e.g., RentalWise), payment gateways (e.g., Razorpay), KYC/ID tools, housekeeping/maintenance partners, IT/hosting, analytics, customer support tooling.

  • Regulators/Authorities when legally required.

  • OTAs where you originally booked.

  • Business transfers in case of merger, acquisition, or restructuring.

We do not sell your personal data.

6) International transfers

Some providers may process data outside India. We use reasonable safeguards (contractual protections, standard terms) to protect your data.

7) Retention

We keep data for as long as needed to fulfill the purposes above and comply with laws (e.g., tax/ID record-keeping). After that, we securely delete or anonymize it.

8) Your rights (DPDP & applicable laws)

Subject to law, you may request:

  • Access to your data,

  • Correction/Update,

  • Deletion (where legally permissible),

  • Grievance redressal.
    Contact: [Grievance Officer Email]. We aim to respond within [30] days.

9) Cookies & tracking

  • We use necessary cookies for core functionality.

  • With consent (where required), we use analytics/marketing cookies to understand usage and improve services.

  • Manage preferences via our cookie banner/browser settings. Blocking some cookies may impact site features.

10) WhatsApp, Calls & Messaging

By initiating a chat/call or providing your number, you consent to receive transactional updates. Promotional messages will be sent only with your consent and include an opt-out. Standard carrier/data charges apply.

11) CCTV at properties (if applicable)

CCTV may operate in common areas purely for safety and security. We don’t use it for guest profiling. Footage is stored for a limited time unless needed for an investigation/legal claim.

12) Children’s data

Our services are intended for adults (18+). We do not knowingly collect personal data from children without guardian consent.

13) Data security

We use administrative, technical, and physical safeguards (access controls, encryption in transit where feasible, least-privilege practices). However, no system is 100% secure—use the Services at your own risk and notify us immediately of any suspected compromise.

14) Third-party links

Our website may link to third-party sites/apps (OTAs, payment pages, maps). Their privacy practices are governed by their own policies.

15) Changes to this Policy

We may update this Policy periodically. Continued use indicates acceptance. Check the “Last updated” date.

whatsapp