Aangan
Legal · Aangan India

The fine print, as plainly as we could write it.

DRAFT — NOT YET LEGAL ADVICE. These documents are starter drafts. Before Aangan accepts a paying booking they must be reviewed by Indian counsel competent in the IT Act 2000, the Consumer Protection Act 2019, the DPDP Act 2023, the CGST Act, and Section 194-O of the Income Tax Act. Replace this banner with the reviewed version before launch.

This Privacy Notice explains what personal data Aangan collects, why, how we use it, and the rights you have under the Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Who is the Data Fiduciary?

Aangan India Private Limited, CIN [TO FILL], is the Data Fiduciary under the DPDP Act for personal data processed through the Aangan platform. Our Data Protection Officer can be reached at dpo@aangan.in.

2. What we collect

  • You give us: mobile number, name, email, profile photo (optional), payment instrument, preferences (veg/Jain/etc.), messages to hosts.
  • We collect when you use Aangan: booking history, listings viewed, device type, IP address, app crash reports.
  • Hosts give us: PAN, Aadhaar (last 4 digits only retained), bank account, property address, property photos.
  • We receive from partners: payment status from Razorpay, OTP delivery status from MSG91, KYC verification result from Karza / HyperVerge.

3. Why we use it

  • To operate the service — search, book, pay, message, refund.
  • To verify identity (KYC) where required by law or platform safety.
  • To compute and remit GST and TDS to the government.
  • To prevent fraud and respond to safety incidents.
  • To send transactional messages (booking confirmation, cancellation, refund). These are not marketing.
  • Marketing communications are sent only with separate express consent under DPDP and TRAI rules. You can withdraw consent at any time.

4. Lawful basis

We process personal data under (a) consent given at sign-up and at specific feature opt-ins; (b) "legitimate use" for performance of the booking contract (DPDP s.7(a)); and (c) compliance with the IT Act, GST and Income Tax law.

5. Sharing

We share only what is necessary:

  • Hosts see your first name, profile photo, dates and guest count, and any message you send them. They see your full contact details only after a confirmed booking.
  • Payment partners (Razorpay) receive the data needed to process payment and refund.
  • SMS / email providers (MSG91, AWS SES) receive your phone / email and the message body.
  • KYC partners (Karza, HyperVerge) receive host PAN and Aadhaar (masked) for verification.
  • Government authorities when compelled by lawful order; we publish an annual transparency note.

6. International transfers

Personal data is primarily processed in AWS ap-south-1 (Mumbai). We do not transfer your data outside India except where a sub-processor is unavoidably located abroad; in such cases we ensure DPDP-compliant safeguards.

7. Retention

  • Account and booking data: kept while your account is active and for up to 8 years after the last booking, as required by the Income Tax Act for transactional records.
  • Aadhaar full numbers: never stored — only the last 4 digits retained for matching during reverification.
  • Card numbers: never stored by Aangan — handled by Razorpay (PCI-DSS).
  • OTP codes: stored as a salted hash; deleted after 5 minutes (TTL) or on first use.
  • Marketing preferences: kept until you withdraw consent.

8. Your rights under DPDP

You have the right to:

  • Access a copy of your personal data we hold (request via privacy@aangan.in).
  • Correct or update inaccurate personal data.
  • Erase personal data we no longer need for a lawful purpose.
  • Nominate another person to exercise these rights in case of incapacity.
  • Withdraw consent for any processing relying on consent.
  • Grieve to our DPO (dpo@aangan.in). If unresolved within 30 days you may approach the Data Protection Board of India.

9. Children

Aangan is not for users under 18. We do not knowingly collect data from children. Under DPDP s.9 any processing of a child's data requires verifiable parental consent — if you believe we hold such data inadvertently please write to us and we will delete it.

10. Security

We use TLS 1.2+ in transit, AES-256 at rest, role-based access control on production data, MFA on all admin accounts, and store secrets in AWS Secrets Manager. We test backups quarterly. We will notify you and the Data Protection Board within 72 hours of any personal-data breach affecting you.

11. Cookies

See our Cookies notice for the small set of cookies we use and how to opt out.

Last updated: 2026-08-25.