Privacy Policy
Effective Date: 08 August, 2025
This Privacy Policy describes how VacationBNA Pvt. Ltd, trading as "VacationBNA" ("Company", "we", "us", "our") collects, uses, shares, and protects your information when you use our website, the Customer App (for travellers booking villas, bungalows, and apartments), and the Host App (for owners/managers listing properties) (collectively, the "Services"). We operate primarily in India.
By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
1) Who we are & scope
Data Fiduciary (Controller): VacationBNA Pvt. Ltd, William industry estate office No. 19. 2nd floor SG Barve Marg, Above Sheetal Mithaiwala Kurla West, Mumbai, Maharashtra 400007, India.
Contact (privacy): vacationbna5@gmail.com | Phone: [8976203444]
Grievance Officer (India): [adnan], [8976203444], [
William industry estate office No. 19. 2nd floor SG Barve Marg, Above Sheetal Mithaiwala Kurla West, Mumbai, Maharashtra 400007].
This Policy covers personal data we process through our apps, website, APIs, and communications (email/SMS/phone/push). It does not cover third-party websites or services that are not controlled by us.
2) Key terms
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act):
- Data Principal = you, the individual to whom personal data relates.
- Data Fiduciary = us, the entity that decides the purposes and means of processing.
- Personal data = any data about an identifiable individual.
We also continue to follow applicable provisions under the IT Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), as updated or replaced.
3) What information we collect
A. From Customers (travellers)
- Identity & contact: name, mobile number, email.
- Booking data: search criteria, dates, guests, property booked, price, preferences, messages exchanged via our platform with Hosts (if messaging feature is available).
- Support interactions: messages and recorded calls with our customer support (we only record support calls; calls between travellers and Hosts happen off-platform and are not recorded by us).
- Note: We currently do not collect or store payment card details within our systems. If this changes (e.g., for memberships or deposits), we will update this Policy, provide notice, and use compliant payment gateways.
B. From Hosts (owners/managers)
- Identity & contact: name, mobile number, email.
- KYC for verification: Aadhaar and PAN details (and, if provided, images). We collect the minimum necessary for verification
- Property & listing: property address/location, amenities, photos/videos, pricing, house rules, availability, booking and payout preferences
- Support interactions: messages and recorded calls with our customer support (support calls only).
C. Data collected automatically (apps & website)
- Device & usage: IP address, device/browser identifiers, OS/app version, language, time zone, crash/log events, pages/screens viewed, referrers, campaign parameters (e.g., UTM).
- Cookie/SDK identifiers: Google Analytics 4 (GA4), Google Tag Manager, Hotjar, advertising pixels (Meta/LinkedIn/Google/Quora), and OneSignal push token.
- Current location (with permission): if you grant permission, we process your current (which may be precise) location to show nearby stays, maps, and improve search; you can disable this in your device settings.
- Communications metadata: OTP/SMS delivery status, email open/click signals.
D. Permissions we may request (mobile)
- Camera/Photos: to upload property images or profile pictures.
- Location (current/precise, if you allow): to enhance search and map features.
- Notifications: to receive booking updates and reminders via OneSignal or other 3rd party app.
- You can change app permissions in your device settings.
4) Why we process your data (Purposes) & lawful basis
We process personal data only as permitted by law:
- Provide and operate the Services (account creation, search, bookings, messaging, support) - contract/legitimate use.
- KYC & safety (verify Host identity and listing ownership; prevent fraud/abuse) - consent/legitimate use/legal requirement.
- Communications (booking confirmations, reminders, service messages) - contract/legitimate use.
- Product improvement & analytics (troubleshooting, app performance, usage analytics) - legitimate use/consent where required.
- Marketing & ads (optional) - with your consent, we may send marketing messages (email, push, and WhatsApp if enabled) and use advertising pixels to measure campaigns and show more relevant ads. You can opt out at any time.
- Legal compliance (respond to lawful requests, enforce Terms, record-keeping) - legal obligation.
- Future Host memberships (if introduced) - contract/consent, with prior notice.
Where required, we rely on your consent (e.g., for certain analytics/cookies, marketing, WhatsApp, or optional location). You can withdraw consent at any time; this will not affect prior processing but may limit some features.
5) Cookies & similar technologies
We use cookies, SDKs, pixels, and similar technologies on our website and apps to operate the Services, measure usage, improve UX, and run ads/retargeting. In particular:
- Google Tag Manager (GTM): a container to deploy and manage tags. GTM itself doesn't collect personal data beyond what is sent by the tags you configure.
- Google Analytics 4 (GA4): to measure traffic and usage trends.
- Hotjar: to understand user experience (e.g., heatmaps, session replays) and improve usability.
- Google Search Console: to monitor aggregated site performance and search queries (site owner tool; not a user tracker on pages).
- Google Maps Platform: to display interactive maps and location features. When maps load, Google may receive device/network information (e.g., IP address) and, if you allow location, your device's location for map functionality.
- Advertising pixels/SDKs: Meta Pixel (Facebook/Instagram), LinkedIn Insight Tag, Google Ads tag, and Quora Pixel to measure ad performance and (where enabled) build audiences for retargeting.
- Push notifications: OneSignal SDK to register your device/browser for notifications (if you opt in).
If in the future we enable WhatsApp Business messages, we will use a compliant WhatsApp messaging provider (see Annex B) and send messages only with your consent, with clear opt-out instructions in every message.
You can manage non-essential cookies/SDKs via your browser/device settings and ad platform preferences. Essential cookies/SDKs required for core functionality may not be disabled. If you prefer not to be measured for analytics/ads, you can also use built-in browser controls (e.g., tracking prevention) or industry opt-out tools. We will implement additional choices if laws or regulators require them.
6) Sharing & disclosure
We do not sell personal data. We share data only as necessary:
- Between booking participants: after a booking is confirmed, we share the traveller's contact number with the Host to coordinate the stay. We do not provide an in-app calling feature; calls occur directly via your own phone service.
- Service providers (processors): hosting/cloud infrastructure (Vercel, Hostinger), SMS/OTP, analytics/UX (Google Analytics 4, Hotjar), tag management (Google Tag Manager), search console (Google), Google Maps Platform, image storage/CDN, KYC/identity verification, support ticketing/call recording (for customer support only), push notifications (OneSignal), and advertising/attribution (Meta, LinkedIn, Google Ads, Quora). If enabled in future, a WhatsApp Business messaging provider will process your phone number and message metadata to deliver WhatsApp messages you opted into. We contractually require appropriate confidentiality, security, and data protection.
- Legal & compliance: to courts, law enforcement, regulators, or advisors when required by law or to protect our rights, users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
7) Cross-border transfers
Our primary operations are in India. However, some service providers (e.g., analytics or cloud hosting) may process data in other countries. Transfers will occur only in accordance with applicable Indian law (including any government-notified restrictions under the DPDP Act). We implement contractual and technical safeguards with providers handling personal data outside India.
8) Retention
We keep personal data only for as long as needed for the purposes described or as required by law, after which we securely delete or anonymise it. You can temporarily deactivate your account (profile becomes inactive but data is retained), or permanently delete your account (we delete your personal data, subject to legal retention requirements). See Annex A for indicative retention periods.
For permanent deletion requests, we aim to complete deletion within 30 days from verification of your request, except where we must retain limited data for legal, tax, fraud-prevention, or dispute purposes.
9) Security
We apply reasonable and appropriate technical and organisational measures, including: Encryption in transit (TLS) and at rest for sensitive data; Role-based access controls with least-privilege principles; Audit logs and periodic reviews of access to KYC data; Network and application security controls; secure software development practices; Vendor due diligence and contractual security obligations; Incident response playbooks and breach notification processes as required by law.
No system is 100% secure; if we detect or are notified of a breach affecting your data, we will act promptly and notify you and/or authorities as required.
10) Host identity verification (KYC)
We collect Aadhaar and PAN details from Hosts solely to verify identity and reduce fraud. We may collect and store numbers and images (e.g., photos/scans) as provided by you. We do not mask these values in storage. KYC data is encrypted and access-controlled, used only by authorised personnel or verification vendors. We do not use KYC data for marketing.
Retention: We retain KYC data until you permanently delete your account. If you temporarily deactivate your account, we continue to retain KYC data. Upon permanent deletion, we delete KYC data as part of account deletion (see Retention and Annex A), subject to any legal obligations to retain limited records.
11) Your choices & rights
Subject to law, you may:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Deactivate your account (temporary; data retained);
- Permanently delete your account (we delete your personal data, including KYC, subject to legal retention needs);
- Withdraw consent for optional processing (e.g., analytics, marketing, location);
- Portability (export basic account/booking data), where feasible;
- Grievance redressal via the Grievance Officer below.
How to submit a request: Use the in-app settings or contact vacationbna5@gmail.com with your registered email/phone. We may request additional information to verify your identity. We typically acknowledge within 48 hours and resolve within 30 days (or as required by law) with your registered email/phone. We may request additional information to verify your identity. We typically acknowledge within 48 hours and resolve within 30 days (or as required by law).
Withdrawing consent or requesting deletion may affect your ability to use some features or complete existing bookings. We may keep limited records to comply with law, enforce our agreements, or defend legal claims.
12) Children's privacy
Our Services are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided personal data, please contact us so we can delete it and take appropriate steps.
13) Updates to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you (e.g., in-app notice, email) and update the Effective Date above. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
14) Contact & Grievance Redressal
Privacy/Support
Email: vacationbna5@gmail.com
Grievance Officer (India)
Name: Adnan Shaikh
Email: skadnan40605@gmail.com
We aim to acknowledge complaints within 48 hours and resolve them within 30 days, unless a different period is prescribed by law.
15) India-only operations & future memberships
We currently focus on operations in India and do not offer services targeted to other countries. If we introduce Host memberships or cross-border services in the future, we will update this Policy and provide clear notice before launch, including any new data types (e.g., billing) and purposes.
Annex A - Indicative retention periods
Final periods may vary based on legal, tax, or dispute requirements.
| Data category | Typical retention |
|---|---|
| Customer account profile (name, phone, email) | While account is active + 12 months after closure |
| Booking records & communications | Booking date + 6 years (tax/accounting/defence) |
| Host profile & listing data | While account/listing is active + 24 months |
| Host KYC (Aadhaar/PAN) | Stored as provided (numbers and images), encrypted at rest; retained until you permanently delete your account. On permanent deletion, we delete KYC within 30 days, unless law requires longer retention. |
| Device/analytics logs (GA4/Hotjar) | 14–26 months (configurable); |
| Support tickets & complaints | Case closure + 24 months |
| Security/audit logs | 12–24 months (depending on system) |
Annex B - Service provider categories (current)
We will update this Annex if our vendor categories change. Specific provider names may be disclosed upon request or where legally required.
- Cloud hosting & CDN: Vercel, Hostinger (regions may include India and other countries).
- Analytics & user experience: Google Analytics 4, Hotjar, Google Search Console (site performance insights).
- Tag management: Google Tag Manager.
- Advertising & attribution: Meta Pixel, LinkedIn Insight Tag, Google Ads, Quora Pixel.
- Push notifications: OneSignal.
- Maps & geocoding: Google Maps Platform.
- Messaging (future): WhatsApp Business messaging provider - only if you opt in.
- SMS/OTP & email delivery: GupShup.
- Crash reporting & performance: Firebase.
- KYC/identity verification: [Internal process / Vendor if engaged later].
- Customer support & call recording: MyOperator for customer support calls only.
- Security & fraud prevention: Services used to detect abuse and secure accounts.
Annex C - Device permissions (summary)
Our mobile applications may request the following permissions, which you can grant or deny through your device settings:
| Permission | Purpose | Required? |
|---|---|---|
| Location | for nearby listings and maps; disable in device settings. | Optional |
| Camera/Photos | to upload listing images or profile photos | Optional |
| Notifications | optional, to receive booking updates and reminders | Optional |