This Policy applies to Partners, Tenant Administrators, Tenant Users, and Hotspot Guests who interact with the Platform. Role-specific data-handling obligations are additionally set out in the Partner Agreement, Tenant Administrator Agreement, Tenant User Agreement, and WiFi Guest Terms of Use.
We process personal data for: providing and billing the guest WiFi service; verifying identity as required under Department of Telecommunications ("DoT")/Telecom Regulatory Authority of India ("TRAI") public WiFi norms; fraud prevention and network security; complying with legal obligations (including CERT-In directions on log retention and incident reporting); and, where you have given consent, sending service-related communications. Under the DPDP Act, our processing is grounded in your consent (captured at signup/OTP verification/checkbox acceptance) or as otherwise permitted by law (e.g., compliance with a legal obligation).
We share personal data with: the Venue/Tenant operating the specific hotspot you connect to (for their own service delivery and legal compliance); our payment gateway partner for processing transactions; law-enforcement or regulatory authorities pursuant to a lawful request; and infrastructure/SMS service providers strictly to deliver the Service (e.g., sending OTPs). We do not sell personal data to third parties for their independent marketing use.
Guest session logs are retained for the period required under applicable regulatory directions (currently a minimum 180-day window under CERT-In directions, and longer where a specific DoT/TRAI condition applies). Account data for Partners/Tenant Admins/Tenant Users is retained for the duration of the account relationship and thereafter as required for legal, tax, or dispute-resolution purposes.
Subject to the DPDP Act, 2023, you may have the right to: access a summary of personal data we hold about you; request correction or erasure (subject to our regulatory retention obligations under Clause 5); withdraw consent for processing that is consent-based (which may result in the Service being unavailable to you); and file a complaint with the Grievance Officer below, and thereafter with the Data Protection Board of India.
We apply reasonable technical and organisational safeguards — including encrypted transport (HTTPS), hashed password storage, and access controls scoped by role — consistent with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
The Platform uses session cookies necessary for login and, on the captive portal, device/session identifiers (MAC address, CSRF tokens) necessary to grant and secure WiFi access. We do not use these for cross-site advertising tracking.
The Platform is not directed at children. Where a minor uses guest WiFi under the WiFi Guest Terms of Use, this occurs only under the supervision and consent of a parent/guardian as described there.
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, you may contact our Grievance Officer at lhbsram@gmail.com or 9030716651 for any privacy-related query or complaint. We aim to acknowledge within 24 hours and resolve within 15 days.
We may update this Policy from time to time; the version and effective date above reflect the currently applicable Policy. Material changes will be highlighted on the Platform.