Legal
Privacy Policy
Last updated: May 2026 · QuietSummit Private Limited
This Privacy Policy explains how QuietSummit Private Limited ("QuietSummit", "we", "us") collects, uses, stores, and protects your personal data when you use our platform at quietsummit.in. We are committed to protecting your privacy and complying with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian laws.
01Information We Collect
1.1 Information you provide directly:
- Account registration: Name, email address, phone number (WhatsApp-linked)
- Google Sign-In: Name, email address, and profile photo (if you choose to sign in with Google)
- Profile: Bio, travel preferences, emergency contact name and phone, health declaration
- KYC verification: Government-issued photo ID, selfie for identity verification
- Financial information: Bank account number, IFSC code, account holder name (collected from service providers for payouts only)
- Homestay registration: Property documents, property photos, address, coordinates
- Guide registration: Certifications, government license, address proof
- Booking details: Traveler names, check-in/check-out dates, group size
- Community content: Posts, replies, uploaded photos
1.2 Information collected automatically:
- Authentication tokens: Session tokens stored in cookies for maintaining your login state
- Device tokens: Push notification tokens (if you enable notifications)
- Usage data: Pages visited, features used, timestamps (server logs)
1.3 Information from third parties:
- Google: Name and email when you authenticate via Google Sign-In
- Razorpay: Payment confirmation status (we do not receive or store your card numbers, UPI PINs, or bank login credentials)
02How We Use Your Information
- Account management: Creating and maintaining your account, authenticating your identity
- Booking processing: Facilitating bookings between travelers and service providers
- Payment settlement: Processing payouts to guides, homestay owners, and journey creators
- KYC verification: Verifying your identity for Quiet Membership, guide, or homestay owner roles
- Communication: OTP verification (via WhatsApp/email), booking confirmations, platform notifications
- Safety & trust: Fraud prevention, dispute resolution, community moderation
- Platform improvement: Understanding usage patterns to improve features and user experience
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
04Data Security
- Bank account numbers and government ID numbers are AES-256 encrypted at rest.
- Passwords are hashed using BCrypt (irreversible).
- All traffic between your browser and our servers is encrypted via HTTPS/TLS.
- KYC documents are stored with private access controls and accessed only by authorized admin personnel.
- Our infrastructure is hosted on AWS India (Mumbai region) with industry-standard security controls.
- Access to production systems is restricted to authorized personnel only.
05Data Retention
| Data Type | Retention Period |
|---|---|
| Account data (name, email, phone) | Until account deletion |
| KYC documents (govt ID, selfie) | 90 days after verification, then permanently deleted |
| Financial records (transactions, settlements, invoices) | Retained permanently (legal/tax compliance) |
| Community posts and replies | Until account deletion |
| Uploaded photos (profile, property, journey) | Until account deletion |
| Server logs | 90 days |
| Authentication tokens | 7 days (auto-expire) |
06Your Rights
Under the DPDP Act and applicable law, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and personal data. Profile data, KYC documents, photos, and community posts are permanently deleted. Financial records are retained as required by law.
- Withdraw consent: You may withdraw consent for optional data processing (e.g., push notifications) at any time through your account settings.
- Grievance redressal: You may raise concerns about data handling by contacting us (see Section 10).
To exercise any of these rights, email support@quietsummit.in with your registered email address. We will respond within 30 days.
08Children's Privacy
The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from individuals under 18. If we become aware that we have collected data from a minor, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us immediately.
09Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 7 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
10Contact & Grievance Redressal
For any privacy-related questions, data requests, or grievances:
QuietSummit Private Limited
H No 72 BP City, Adityapuram, Morar, Gird
Gwalior — 474006, Madhya Pradesh, India
support@quietsummit.in
We will acknowledge your request within 48 hours and provide a resolution within 30 days.