Privacy Policy
Last updated: 10 August 2026
This policy explains what PriceMyDay collects and how it is used. It is written to be
read, not skimmed past. We aim to comply with India's Digital Personal Data Protection
Act (DPDP) principles: collect what's needed, use it for the stated purpose, delete it
when done.
Two different roles, and the difference matters for who you ask. For a
business's own account we are the Data Fiduciary. For that business's customers —
the people who fill in a quote form — the business is the Data Fiduciary and we
are its Data Processor: we hold that data on their instructions, and requests about it
go to them first. Section 7 says what to do if that does not resolve it.
1. Data we hold for businesses (our direct users)
- Account details: name, email, password hash, optional phone/2FA secrets.
- Business content: wizards, prices, pages, media you upload, settings (including
GSTIN and UPI ID you choose to display).
- Billing records: edition, invoices, payment references from the payment gateway.
2. Data businesses collect through us (their customers)
- When a customer submits a quote they provide contact details (name, email, phone,
event date) and their selections. This data belongs to the business they contacted —
we process it on that business's behalf and never sell it or use it for advertising.
- Anonymous usage events (steps viewed, options picked) power the business's funnel
analytics; they contain a random session id, not the customer's identity.
- Marketing attribution (utm parameters, referring site) is stored with the lead so
the business knows which channel sent it.
3. Identity documents and payment proofs
Some businesses — a venue, a retreat, a homestay — have to hold a guest ID
against a confirmed booking. This is the most sensitive category on the platform, so it
is fenced more tightly than anything else:
- Off unless a business turns it on. Collection is disabled by default. Most
businesses on the platform never enable it and are never asked for a document.
- Only after a booking is confirmed. A customer still comparing quotes is
never asked for identification.
- The business writes the notice. What a customer reads when asked — why
it is needed, how long it is kept — is written by that business, because they are
the ones collecting it. The retention period in that notice is filled in from the
setting the deletion actually uses, so the two cannot disagree.
- It is deleted on a clock. Each business sets a period between 30 and 180
days (90 by default), counted from the event date. When it expires the scan is
erased automatically. The record of which document was checked survives —
the type, the last four characters, the name — because a business must be able
to show that it carried out a check. The document itself does not.
- The deadline is fixed when the document arrives. Shortening the setting
later cannot erase a document earlier than the person handing it over was told, and
the wording they were shown is stored alongside it.
- We never hold a full Aadhaar number. Where a number is typed in, only the
last four characters are stored. We do not read numbers out of the image.
- Looking is recorded. Every time someone at the business opens an identity
document it is written to that booking's activity log, so the owner can see who
looked and when.
- Not on a public link. Identity documents are deliberately kept out of the
media system that serves public pages; they are readable only by a signed-in member
of that business.
- Payment receipts a business uploads against a recorded payment are held with the
lead and erased with it.
Deleting a lead deletes its identity document and payment proofs with it.
4. Cookies
The admin uses strictly-necessary session cookies (sign-in, CSRF). Public quote pages
set no tracking cookies from us; a business may add its own Google Analytics or Meta
Pixel to its pages, which is disclosed as that business's tracking, not ours.
5. Where data lives & who touches it
- Hosting and storage run on cloud infrastructure located in or near India where
available; email is delivered through a transactional email provider; DNS and TLS by
Cloudflare. These processors receive only what's needed to do their job.
- Where a business enables WhatsApp updates, the customer's phone number and the
message fields go to Meta to deliver them. That only happens for businesses that
switch it on and customers who have not opted out.
- Where a business collects online payments from its customers, the payment gateway
receives what it needs to raise the payment link. Card and bank credentials are
entered on the gateway's own pages and never reach us.
- Operational logs and usage analytics carry an account identifier and request
details for diagnosing faults, not customer identities.
- Identity documents and payment proofs stay in our own storage. They are not sent
to any third party.
- We never sell personal data. We disclose it only if the law requires it.
6. Retention & your rights
- Businesses can export all their data (JSON) and can permanently erase individual
leads (GDPR/DPDP-style delete) from the admin — only the quote number and email remain
in the audit trail.
- Account deletion removes tenant data within 30 days, except minimal legal/accounting
records.
- Identity documents are erased on the schedule in section 3 whether or not
anyone asks, and a business can remove one at any time before that.
- Customers of a business should direct requests to that business first (it is the
data fiduciary for its leads); we help businesses fulfil them with the tools above.
7. Complaints and grievances
If you are a customer of a business that uses PriceMyDay, raise it with that business
first — they decide what is collected and why, and they can delete it. If they do
not resolve it, or if your complaint is about how we handle data, write to our
grievance contact at
[email protected]. Tell us what happened
and which business it concerns; we will acknowledge and respond.
If you are still not satisfied, the Digital Personal Data Protection Act, 2023 gives
you the right to complain to the Data Protection Board of India. Nothing here
requires you to come to us first before exercising that right.
Contact
Privacy questions and grievances:
[email protected].