GuestConnect ← Back

Privacy Policy

Version 1.0 · Effective 05 August 2026
This Privacy Policy explains how Guest Connect Networks ("Company", "we") collects, uses, discloses, and protects personal data across the GuestConnect platform, in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and rules made thereunder.

1. Who This Policy Covers

This Policy applies to Partners, Tenant Administrators, Tenant Users, and Hotspot Guests who interact with the Platform. Role-specific data-handling obligations are additionally set out in the Partner Agreement, Tenant Administrator Agreement, Tenant User Agreement, and WiFi Guest Terms of Use.

2. Personal Data We Collect

  • Account data (Partners/Tenant Admins/Tenant Users): name, email, phone number, business/company details, GSTIN where provided, and login credentials (stored as salted hashes, never in plain text).
  • Guest data (Hotspot Users): mobile number (for OTP verification or receipts), device MAC address, IP address, session timestamps, and approximate data usage — collected for connectivity, billing, and regulatory identification purposes described in the WiFi Guest Terms of Use.
  • Payment data: payments are processed by our PCI-DSS compliant, RBI-authorised payment gateway partner; we do not store full card numbers or bank credentials on our servers.
  • Technical data: IP address, browser/user-agent, and access logs generated automatically through normal use of the Platform.

3. Purpose & Legal Basis of Processing

We process personal data for: providing and billing the guest WiFi service; verifying identity as required under Department of Telecommunications ("DoT")/Telecom Regulatory Authority of India ("TRAI") public WiFi norms; fraud prevention and network security; complying with legal obligations (including CERT-In directions on log retention and incident reporting); and, where you have given consent, sending service-related communications. Under the DPDP Act, our processing is grounded in your consent (captured at signup/OTP verification/checkbox acceptance) or as otherwise permitted by law (e.g., compliance with a legal obligation).

4. How We Share Data

We share personal data with: the Venue/Tenant operating the specific hotspot you connect to (for their own service delivery and legal compliance); our payment gateway partner for processing transactions; law-enforcement or regulatory authorities pursuant to a lawful request; and infrastructure/SMS service providers strictly to deliver the Service (e.g., sending OTPs). We do not sell personal data to third parties for their independent marketing use.

5. Data Retention

Guest session logs are retained for the period required under applicable regulatory directions (currently a minimum 180-day window under CERT-In directions, and longer where a specific DoT/TRAI condition applies). Account data for Partners/Tenant Admins/Tenant Users is retained for the duration of the account relationship and thereafter as required for legal, tax, or dispute-resolution purposes.

6. Your Rights as a Data Principal

Subject to the DPDP Act, 2023, you may have the right to: access a summary of personal data we hold about you; request correction or erasure (subject to our regulatory retention obligations under Clause 5); withdraw consent for processing that is consent-based (which may result in the Service being unavailable to you); and file a complaint with the Grievance Officer below, and thereafter with the Data Protection Board of India.

7. Security Measures

We apply reasonable technical and organisational safeguards — including encrypted transport (HTTPS), hashed password storage, and access controls scoped by role — consistent with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Cookies & Similar Technologies

The Platform uses session cookies necessary for login and, on the captive portal, device/session identifiers (MAC address, CSRF tokens) necessary to grant and secure WiFi access. We do not use these for cross-site advertising tracking.

9. Children's Data

The Platform is not directed at children. Where a minor uses guest WiFi under the WiFi Guest Terms of Use, this occurs only under the supervision and consent of a parent/guardian as described there.

10. Grievance Officer

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, you may contact our Grievance Officer at lhbsram@gmail.com or 9030716651 for any privacy-related query or complaint. We aim to acknowledge within 24 hours and resolve within 15 days.

11. Changes to This Policy

We may update this Policy from time to time; the version and effective date above reflect the currently applicable Policy. Material changes will be highlighted on the Platform.

© 2026 Guest Connect Networks. All rights reserved.

Grievance / Support: lhbsram@gmail.com · 9030716651