Privacy Policy
Last updated: 27/08/2026
Book My Cabin ("we", "us") is operated by ThinkNovate LLP, India. We provide software that reading rooms, study cabins and coworking spaces ("branches") use to manage seats, students and payments, and that members of the public use to find and book a seat.
This policy explains what we collect, why, how long we keep it, and how you can have it removed. It applies to bookmycabin.in and to the console used by branch owners and their staff.
1. Who controls your data
Two different relationships exist, and the distinction matters for your rights:
- Branch owners and their staff. We are the data controller. You have an account with us.
- Students and visitors. The branch you join is the controller of your records; we process that data on their behalf as their service provider. Requests to correct or erase student records normally go to the branch first, though we will act on them directly where the branch cannot or will not.
2. What we collect
If you are a branch owner or staff member
- Name, email address, phone number, password (stored only as a bcrypt hash — never in readable form)
- Your branch's name, address, photographs, seat layout, pricing and opening details
- Payment settings you enter, including payment-gateway credentials, which are encrypted before storage
- Records of subscription payments you make to us
- Sign-in activity, including IP address and timestamps, and any two-factor settings you enable
If you are a student at a branch
- Name, phone number, and where the branch records it, address and photograph
- Which seat you hold, your fee, deposit, joining date and due dates
- Payments recorded against you, receipts issued, and deposits held or returned
- Attendance, where the branch uses that feature
- Aadhaar number, where the branch collects it — handled as described in section 3
If you simply visit the site
- Enquiries and contact messages you send, including the name and phone number you supply
- Booking and pre-booking details when you reserve a seat, and the payment reference from the gateway
- Standard server logs, including IP address, for security and abuse prevention
- An approximate location if you ask the site to show branches near you — used for that search and not stored against you
We do not sell personal data, and we do not use it for advertising or profiling.
3. Aadhaar numbers
Some branches record an Aadhaar number as proof of identity. Because it is among the most sensitive identifiers a person has, it is treated differently from everything else on this list:
- It is encrypted before it is written to the database and is never stored in readable form.
- It is never shown back in full — screens, exports and receipts display only the last four digits.
- The encrypted number is permanently deleted twelve months after it is recorded. The last four digits remain, so a branch can still recognise the record.
- It is excluded from our long-term archive by design. Copying it to a second location would put the most sensitive field we hold in more places, not fewer.
- We never share it with any third party, including payment providers.
If you would rather your Aadhaar number were not held at all, ask the branch — they can record a different form of identification.
4. Why we use your data
- To run the service — showing which seats are free, recording who holds one, issuing receipts.
- To take payments — passing the amount and a reference to the payment gateway and recording the result.
- To send reminders — fee reminders by WhatsApp or email, near your due date. Branches choose whether to enable these.
- To keep accounts — Indian law requires books of account to be retained for several years; see section 6.
- To keep the service secure — detecting repeated failed sign-ins, rate-limiting abuse, and keeping an audit trail of who changed financial records.
5. Who we share it with
We share only what each service needs to do its job, and only with these:
- Razorpay and Decentro — payment processing. They receive the amount, a reference, and the contact details needed to process and confirm a payment.
- Meta Platforms (WhatsApp Business Platform) — delivering WhatsApp messages. Meta receives the recipient's phone number and the message content. Only branches that connect a WhatsApp number use this.
- Resend — sending email such as receipts, password resets and reminders. Recipient address and message content.
- Google — only if you choose to sign in with a Google account, and only to verify that sign-in.
- OpenStreetMap (Nominatim) — converting a branch's written address into map coordinates. Only branch addresses are sent, never anything about a student.
- Oracle Cloud Infrastructure — hosting and encrypted backup storage. All data resides in Oracle's cloud.
We also disclose data where the law requires it, or to establish or defend a legal claim.
6. How long we keep it
Retention is enforced automatically, not left to memory:
- Payments, orders, bookings, deposits, expenses and vacating records — kept for three years in the live system, then moved to encrypted archive storage and retained for eight years in total. Financial records are never deleted before then: the Limited Liability Partnership Act requires eight years of books of account, and GST rules require six.
- Audit logs — twelve months live, then archived, six years in total. They record who changed a financial figure, so they have to outlive the figure itself.
- Aadhaar numbers — deleted after twelve months (section 3).
- Push notification subscriptions — removed after twelve months without use.
- Sign-in attempt records and payment webhook logs — 180 days.
- Attendance records — 90 days.
- Enquiries and contact messages — 30 days.
- Password reset links — 30 days, and each is single-use.
When an account is closed, we remove the personal records attached to it. Financial records required by law are retained for the periods above, and are kept for that purpose alone.
7. How we protect it
- All traffic is encrypted in transit using HTTPS.
- Passwords are stored as bcrypt hashes and cannot be recovered, only reset.
- Aadhaar numbers and payment-gateway credentials are encrypted at rest.
- Sessions expire after a period of inactivity, and can be signed out remotely from your own account.
- Two-factor authentication is available, and repeated failed attempts are throttled.
- Each branch's data is isolated: an owner can only reach records belonging to their own branches.
- Changes to financial records are recorded in an audit trail. Payments are voided rather than deleted, so the history stays intact.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.
8. Your rights
Under the Digital Personal Data Protection Act, 2023, you may:
- Ask what personal data we hold about you
- Ask us to correct anything inaccurate or incomplete
- Ask us to erase it, subject to the legal retention periods in section 6
- Withdraw consent for reminders and other optional messages
- Nominate someone to exercise these rights if you are unable to
- Complain to the Data Protection Board of India
To make a request, write to [CONTACT EMAIL]. We respond within 30 days. Students should normally ask their branch first, since the branch holds the record; we will act directly where that is not possible.
9. Cookies and similar technology
We use cookies only to keep you signed in and to keep your session secure. There are no advertising or third-party tracking cookies. Your browser may also store small amounts of data locally to remember display preferences. If you allow notifications, your browser gives us an address for your device so reminders can be delivered; you can revoke that at any time in your browser settings.
10. Children
The service is not directed at children under 18, and we do not knowingly collect their data without verifiable parental consent. Where a branch enrols a minor, the branch is responsible for obtaining that consent. If you believe we hold a child's data without it, contact us and we will remove it.
11. Changes to this policy
If we change this policy materially, we will update the date at the top and, where the change affects how we use data you have already given us, notify account holders directly.
12. Contact
Thinknovate LLP
4/117, Mullai street, Anuppanadi, Madurai, 625009
Email: teams@bookmycabin.in
Grievance Officer: Vigneshwar K G, reachable at the address above.
The Grievance Officer is named as required by the Digital Personal Data Protection Act, 2023, and by the Information Technology (Intermediary Guidelines) Rules.