1. Who we are
Digilight PMS is a cloud-based hotel management software product and online service operated by Digilight India. This policy explains what personal data the product holds, why, who it is shared with, and what rights you have over it.
2. Who this policy is for
Two very different sets of people have data in Digilight PMS, and they are owed different things. The rest of this document depends on the distinction.
2.1 Hotel operators — our customers
The hotelier who signs up, and their owners, managers, front-desk and accounts staff. Digilight India decides how this data is used, so for it we are the Data Fiduciary under the Digital Personal Data Protection Act 2023 ("DPDP Act").
2.2 Hotel guests — our customers' customers
The people who stay at the hotel. Their data is entered into Digilight PMS by the hotel, for the hotel's own purposes. The hotel is the Data Fiduciary for it. Digilight India is the hotel's Data Processor and acts only on the hotel's instructions.
If you are a guest and you want your data corrected or erased, the hotel you stayed at is the party who decides — see §10. The terms governing our role are in the Data Processing Addendum.
3. What personal data we hold
The lists below reflect the personal data the product actually holds.
3.1 What a hotelier gives us
Name, email address, mobile number (the signup form asks for a WhatsApp mobile)
Hotel name and address; the owner's name, phone and email
The hotel's GSTIN, where it issues GST invoices
A password, stored only as a one-way bcrypt hash. We cannot read it, and we cannot recover it for you.
Your acceptance of these terms. When you tick the box at signup (Terms §1.1) we record which documents you accepted, the version of each, the moment you accepted, and the IP address and browser user-agent you accepted from.
We log that address for exactly one purpose: so that if you ever say you did not agree to something, the answer can be a time, a version and an origin rather than a tick in a box. It is not used for analytics, profiling or location. It is not shared. If a Digilight India employee sets your account up for you, the record says so and no IP is stored, because you did not click anything and inventing one would be manufacturing evidence.
3.2 Guest data a hotelier enters
Recorded by the hotel, about its guests, in the ordinary course of running the property:
- Name (required), email address, phone number
- Address, city, state, country, postcode, nationality
- Identity document type and number. The product accepts passport, driving licence, Aadhaar, voter ID and "other". It is stored as typed text.
- Vehicle number and purpose of visit
- Number of adults and children staying
- Free-text notes the hotel keeps against a guest, a booking or a stay
- Stay records: bookings, dates, rooms, folio charges and payments
Three things the product does not hold, which are worth stating because a reader will assume otherwise:
- No date of birth. No such field exists.
- No gender. No such field exists.
- No photographs, and no scans or images of identity documents. The only file upload in the product accepts a hotel logo and a favicon, nothing else. An identity document is captured as typed text and never as an image.
3.3 Guest communications
Where a hotel sends a guest a message through Digilight PMS, we store the recipient's phone number or email address, the subject, and the full text of the message that was sent.
3.4 Payment data — what we never see
Digilight India never receives, and never stores, your card, UPI or bank details. Subscription payments are handled by our payment gateway. Payment details are entered directly with the gateway; they do not pass through our servers.
This is verifiable rather than reassuring boilerplate: no card-number, CVV, expiry, UPI VPA or bank-account column exists anywhere in our database. What we store is the gateway's order reference, its payment reference, the amount, the status, and a method label.
We do store the raw notification payload the gateway sends us when a payment succeeds or fails, for reconciliation.
3.5 Data we generate
- Access and audit logs — who did what, and when, inside the product. These include the IP address and browser user-agent of the person who acted.
- Security logs of sensitive changes.
- Rate-limiting records, which briefly hold the IP address of anyone attempting to sign in or sign up. These are discarded about an hour later.
- Support-access records. Where a member of Digilight India's staff enters a customer's account to provide support, that session is time-limited, requires a written reason, and is logged. See the DPA.
- Subscription, invoice and payment records.
- Diagnostic and error logs.
4. Why we process it
| Purpose | Whose data | What we use |
|---|---|---|
| Providing the product to the hotel | Guests, hotel staff | §3.2, §3.3 |
| Creating and securing accounts | Hotel staff | §3.1 |
| Evidencing that you agreed to our terms | Hotel staff | §3.1 |
| Taking subscription payments and issuing invoices | Hotel staff, billing contact | §3.1, §3.4 |
| Detecting and preventing abuse, and investigating incidents | All | §3.5 |
| Meeting our legal and tax obligations | Hotel staff | §3.4 |
| Providing support when a hotel asks for it | All | §3.5 |
5. What we do not do
- We do not sell personal data.
- We do not use hotel, staff or guest data from the application for advertising, analytics or profiling — not ours, and not anyone else's. The application carries no analytics or advertising code of any kind.
- We do not use marketing-website analytics to identify you personally, and we do not sell or share what they collect. The marketing site does measure visits from the moment a page loads — Google Analytics 4, Microsoft Clarity, the Meta Pixel and Google Ads conversion tracking all run without asking first, and there is no cookie banner. We say so plainly rather than bury it: the Cookie Policy names every tool, every cookie, and every way to stop them.
- We do not connect marketing-website analytics to your account in the application. They are separate systems and we do not join them.
- We do not use guest data to train machine-learning models. No AI or LLM service is integrated into Digilight PMS.
6. Who we share data with
Every third party below was identified from the codebase and the deployment configuration. This list is complete.
| Sub-processor | What it does | Where it runs | Status |
|---|---|---|---|
| Vercel | Application hosting, scheduled jobs | Singapore (sin1) |
Live |
| Neon | Managed PostgreSQL database — this is where all the data in §3 lives | Singapore (AWS ap-southeast-1) |
Live |
| Resend | Sending transactional email (trial reminders, invoices) | To be confirmed | Integrated; not yet enabled |
| Razorpay | Subscription payment processing | India | Integrated; not yet enabled |
| OpenStreetMap Foundation | Map tiles, loaded by your browser, on one screen | To be confirmed | Live |
| Cloudflare | Map marker icons, loaded by your browser, on the same screen | Global | Live |
Overpass API (overpass-api.de) |
Looks up nearby hotels for the market-intelligence screen; called by our server, not your browser | To be confirmed | Live |
Marketing website only. The providers below never receive data from the
application, and are never joined to a hotel account. They see only visits to
digilightpms.com, and they run from the moment a page loads — there is no cookie
banner on the marketing site and nothing waits for a choice. The
Cookie Policy names every cookie each one sets and every way to stop them,
including a single setting that blocks all of them at once.
| Provider | What it does | Where it runs | Status |
|---|---|---|---|
| Google Analytics 4 | Counts visits, pages and CTA clicks on the marketing site | Global (Google) | Live |
| Google Tag Manager | Loader that holds and starts the tools below | Global (Google) | Live; sets no cookies of its own |
| Microsoft Clarity | Aggregated heatmaps and session replay of the marketing site | Global (Microsoft) | Live |
| Meta Pixel | Measures whether a Facebook or Instagram advert led to a signup | Global (Meta) | Live |
| Google Ads | Measures whether an advert led to a trial or enquiry | Global (Google) | Partly live — the linking component runs; no conversion is reported yet |
7. Where your data is stored
Your data is stored in Singapore. The application runs in Singapore and the database is hosted in Singapore (see the sub-processor table in §6). This means personal data — including guests' identity-document numbers — is processed outside India, which engages the cross-border transfer provisions of the DPDP Act. We disclose it here plainly rather than leaving you to find it.
Encryption in transit is enforced on every database connection. What is and is not encrypted at rest is set out honestly in the Security Policy.
8. How we protect it
Set out in full, including what we do not have, in the Security Policy.
9. How long we keep it
We keep personal data for as long as your hotel's account is open, and afterwards only for as long as we are required to keep it to meet our legal, tax and accounting obligations — for example, Indian tax law requires invoice records to be retained for several years, and those records survive a deletion request. Where we no longer need personal data for the purpose we collected it, and no law requires us to keep it, we delete it or irreversibly anonymise it.
If you are a guest and you want your data removed, contact the hotel you stayed at (see §10); the hotel decides what happens to its own guest records.
10. Your rights
Under the DPDP Act, a Data Principal has rights of access, correction, completion, erasure, grievance redressal, and nomination.
10.1 If you are a hotelier
To exercise any of these rights — access, correction, completion, erasure, grievance redressal or nomination — write to us at support@digilightpms.com. We will verify your request and act on it within the timeframes the DPDP Act requires.
10.2 If you are a guest
Contact the hotel you stayed at, not us. The hotel decides what happens to your record; we hold it on the hotel's behalf and act on the hotel's instruction. If you write to us directly, we will pass your request to the hotel and tell you that we have done so.
11. Grievance redressal
If you have a concern or complaint about how your personal data is handled, write to our grievance contact at support@digilightpms.com, and we will acknowledge it and respond. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India under the DPDP Act.
12. Cookies
This website sets analytics and advertising cookies from the moment a page loads. There is no cookie banner and nothing waits for a choice. The tools are Google Analytics 4, Google Tag Manager, Microsoft Clarity, the Meta Pixel and Google Ads conversion tracking.
You can stop all of them — blocking googletagmanager.com prevents every one at once,
your browser's own settings block or delete them individually, and each provider
publishes its own opt-out. None of it is needed to use this site.
The application is different. It sets two cookies, both strictly necessary for signing in, and carries no analytics or advertising code of any kind.
The complete detail — every cookie by name, every provider, how long each lasts, and every route to switch them off — is in the Cookie Policy.
13. Changes to this policy
Every change is recorded in the version history at the foot of this page. Where a change is material, we will notify hoteliers before it takes effect.
14. Contact us
- Business: Digilight India
- Product: Digilight PMS
- Website: www.digilightpms.com
- Support email: support@digilightpms.com
- WhatsApp: +91 95488 38588
- Support hours: Monday to Saturday, 10:00 AM – 6:00 PM IST
- Business address: Meerut, Uttar Pradesh, India
To exercise your privacy rights, see §10.