Privacy Policy

At FestBooking, your privacy is not just a legal obligation — it is a core value. This Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights as a Data Principal under Indian law.

📅 Effective Date: 1 June 2025 🔄 Last Updated: 16 June 2025 🏛️ Governed by Laws of India 📍 Jaipur, Rajasthan

Summary (Plain Language): We collect your name, contact details, location, payment info, and (for vendors) identity documents. We use this to run the FestBooking marketplace, process payments, and comply with Indian law. We do not sell your data. You can access, correct, or delete your data by contacting our Data Protection Officer. Read the full policy below for complete details.

1 Legal Framework

This Privacy Policy is prepared in compliance with the following Indian laws and regulations:

Law / RegulationRelevance
Digital Personal Data Protection Act, 2023 (DPDP Act)Primary data protection law in India — governs collection, processing, storage, and rights of Data Principals
Information Technology Act, 2000 — Sections 43A, 72, 72ALiability for data breaches, wrongful disclosure, compensation for privacy violations
IT (Reasonable Security Practices and Procedures and SPDI) Rules, 2011Mandatory security practices; rules for Sensitive Personal Data or Information
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021Intermediary obligations, grievance officer, user data transparency
Consumer Protection Act, 2019 & E-Commerce Rules, 2020Consumer data rights, transparency in data use, prohibition on deceptive practices
Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 & Aadhaar Authentication for Good Governance Rules, 2020Restrictions on Aadhaar storage and use — we do NOT authenticate via Aadhaar APIs
Prevention of Money Laundering Act, 2002 (PMLA) & RBI KYC Master DirectionsMandatory KYC collection and retention for vendor payouts
RBI Data Localisation Circular (2018)Payment data of Indian users must be stored exclusively in India
Indian Contract Act, 1872Consent as a valid contract element for data processing

2 Who We Are — Data Fiduciary

📋 Under the DPDP Act 2023, Section 2(i), the entity that determines the purpose and means of processing personal data is the Data Fiduciary. FestBooking Internet Private Limited is the Data Fiduciary for all personal data collected through festbooking.in.

🏢

FestBooking Internet Private Limited

Registered Office: 123, Business Hub, Vaishali Nagar, Jaipur, Rajasthan – 302021
CIN: [To be registered under Companies Act, 2013]
Email: privacy@festbooking.in  |  Website: www.festbooking.in

This Policy applies to all users of FestBooking — Customers (event bookers), Vendors (service providers), and visitors to our website. It covers data collected through our website (festbooking.in), vendor dashboard, customer portal, and any related mobile applications.

3 Personal Data We Collect

📋 DPDP Act 2023, Section 2(t): "Personal data" means any data about an individual who is identifiable by or in relation to such data.

3.1 Data Provided by Customers

CategorySpecific Data PointsWhen Collected
IdentityFull name, profile photoRegistration
ContactMobile number, email addressRegistration / Booking
LocationCity, GPS coordinates (with consent), event venue addressBooking / Search
Booking DetailsEvent type, date, number of guests, special requirementsBooking
PaymentUPI ID / masked card number / payment reference (NOT full card number or CVV)Payment
CommunicationsMessages sent to vendors through Platform chatChat / Support
ReviewsRating, written review, photos submitted with reviewPost-service
TechnicalIP address, browser type, device ID, OS, session logsAutomatic (all visits)

3.2 Data Provided by Vendors

CategorySpecific Data PointsWhen Collected
Identity (KYC)Full name, date of birth, Aadhaar number (masked / last 4 digits only), PAN number, photo of Aadhaar & PAN cardRegistration
BusinessBusiness name, GST number, years of operation, service description, portfolio photosRegistration
FinancialBank account number, IFSC code, UPI ID, TDS records, payout historyRegistration / Payouts
LocationService city, area, GPS location, travel coverage radiusRegistration
OperationalAvailability calendar, booked slots, pricing, cancellation recordsDashboard usage
TechnicalLogin time, IP address, device type, dashboard activity logsAutomatic

3.3 Automatically Collected Data

When you visit our website, we automatically collect:

  • IP address and approximate location derived from IP
  • Browser type, version, and language preference
  • Pages visited, time spent, click patterns, and referral source
  • Device type, operating system, and screen resolution
  • Cookie identifiers (see Section 8)

4 How We Use Your Data

PurposeData UsedLegal Basis
Creating and managing your accountName, email, mobile, password hashContract (consent)
Processing bookings and paymentsBooking details, payment data, locationContract
KYC verification of vendorsAadhaar, PAN, bank detailsLegal obligation (PMLA 2002, RBI KYC)
Payout to vendorsBank account, IFSC, UPI ID, TDS recordsContract + Legal obligation (Income Tax Act)
Showing relevant vendor listingsLocation, event type, search historyLegitimate interest / Consent
Customer support and dispute resolutionBooking data, chat logs, complaintsContract + Legitimate interest
Sending booking confirmations & updatesMobile, email, booking IDContract
Marketing & promotional communicationsEmail, mobile (with opt-in consent)Consent (withdrawable)
Fraud detection and securityIP, device ID, transaction patternsLegitimate interest + Legal obligation
Compliance with court orders / government directionsAny data as directedLegal obligation
Platform analytics and improvementAnonymised/aggregated usage dataLegitimate interest
Tax reporting (GST, TDS filing)Vendor financials, PANLegal obligation

⚠️ We do NOT sell, rent, or trade your personal data to any third party for their own marketing purposes. We do not use your data for automated profiling that produces legal or similarly significant effects without human review.

5 Legal Basis for Processing

📋 DPDP Act 2023, Section 4: Personal data may be processed only for a lawful purpose, for which the Data Principal has given consent, or for certain legitimate uses specified under Section 7.

We process your personal data on the following legal grounds:

  • Consent (Section 6, DPDP Act 2023): For account creation, marketing communications, location access, and cookie placement. You may withdraw consent at any time — withdrawal does not affect processing done before withdrawal.
  • Contractual necessity: Processing necessary to fulfil the booking service contract between us, or between Vendor and Customer.
  • Legal obligation (Section 7(b), DPDP Act 2023): KYC, TDS, GST compliance, responding to court orders, law enforcement requests.
  • Legitimate uses (Section 7, DPDP Act 2023): Fraud prevention, security monitoring, platform analytics (using aggregated/anonymised data).
  • Vital interest: In rare emergencies where processing is necessary to protect life.

Where we rely on consent, you will be presented a clear, specific, and informed consent notice before data collection. Consent is recorded with timestamp, version of notice, and the specific data category consented to.

6 Sensitive Personal Data or Information (SPDI)

📋 IT (SPDI) Rules, 2011, Rule 3: Sensitive Personal Data includes passwords, financial information, health data, sexual orientation, biometric data, and other categories. Higher protection standards apply.

The following categories of data collected by FestBooking qualify as SPDI under the IT Rules, 2011:

  • Financial information: Bank account numbers, IFSC codes, UPI IDs, payment card details (masked)
  • Biometric data: Photographs used in Aadhaar/PAN verification
  • Identity documents: Aadhaar number (stored as last 4 digits only after verification), PAN number
  • Location data: Precise GPS coordinates (only with explicit consent)

For SPDI, we implement additional safeguards:

  • Collection only with explicit prior written consent
  • Stored with AES-256 encryption at rest
  • Access restricted to authorised personnel on a need-to-know basis
  • Never transferred to third parties without explicit consent, except where required by law
  • Deleted upon account closure (subject to statutory retention requirements)

7 Aadhaar & KYC Data

📋 Aadhaar Act 2016, Section 29: No Aadhaar number shall be published, displayed, posted, or shared by any entity. Use of Aadhaar for authentication requires UIDAI authorisation under Section 8. Violation is punishable under Section 37 (imprisonment up to 3 years).

7.1 What We Collect and Why

For vendor KYC verification (mandatory under PMLA 2002 and RBI KYC Master Directions 2016), we collect a photograph of the Aadhaar card and PAN card. This is for offline visual identity verification only — we are NOT an Aadhaar Authentication Agency and do NOT use UIDAI's authentication API.

7.2 What We Do NOT Do With Aadhaar

  • We do NOT store the full 12-digit Aadhaar number in our database
  • We do NOT use Aadhaar for biometric authentication
  • We do NOT share Aadhaar images or numbers with any third party (except as required by law enforcement with valid court order)
  • We do NOT use Aadhaar for any purpose other than KYC verification of vendors

7.3 Masking and Storage

Upon verification of the Aadhaar card photo, we redact the first 8 digits and store only the last 4 digits (e.g., XXXX-XXXX-4321) as a reference. The original Aadhaar card photograph is encrypted and stored in a separately secured data store with restricted access.

📋 Your right: You may request deletion of your Aadhaar card photograph from our systems at any time after your vendor account is verified and active. Send a request to kyc@festbooking.in. Post-deletion, we retain only the last-4-digit reference and the verification outcome record.

8 Cookies & Tracking Technologies

📋 IT (SPDI) Rules 2011, Rule 5(7): Users must be informed about cookies and given the option to opt out where cookies are not strictly necessary.

8.1 Types of Cookies We Use

TypePurposeDurationCan be Disabled?
Strictly NecessaryLogin session, booking flow, CSRF protection, language preferenceSession / 30 daysNo — website won't function
FunctionalRemembering your city, search filters, previously viewed vendors90 daysYes
AnalyticsPage visits, click patterns, performance monitoring (anonymised)365 daysYes
MarketingRetargeting ads, personalised promotional offers (only with consent)180 daysYes — requires explicit opt-in

8.2 Local Storage

In addition to cookies, we use browser localStorage to maintain session data (e.g., booking in progress, selected vendors, location consent) within your browser session. This data is not transmitted to our servers unless you actively proceed with a booking.

8.3 Managing Cookies

You can manage cookie preferences at any time through your browser settings. Note that disabling strictly necessary cookies will prevent login and booking functionality. You may also use your browser's private/incognito mode to browse without persistent cookies.

9 Sharing & Disclosure of Personal Data

📋 DPDP Act 2023, Section 8(3): Data Fiduciaries must ensure that Data Processors they engage provide sufficient guarantees of data protection. IT (SPDI) Rules 2011, Rule 6: Sharing SPDI requires prior consent, except where required by law.

9.1 Sharing Within the Platform

When a Customer makes a booking, the following data is shared with the relevant Vendor:

  • Customer name and mobile number (for coordination only)
  • Event date, location, and service requirements
  • Booking confirmation ID

Vendors are contractually prohibited from using this data for any purpose other than delivering the booked service.

9.2 Third-Party Service Providers (Data Processors)

CategoryPurposeData Shared
Payment Gateway / AggregatorProcessing customer payments and vendor payoutsName, mobile, amount, order ID (PCI-DSS compliant processor)
SMS / OTP ProviderSending OTP, booking confirmationsMobile number, message content
Email Service ProviderTransactional and marketing emailsEmail address, name, booking details
Cloud Hosting ProviderData storage and computing (India region)All Platform data (stored within India)
Analytics ProviderAnonymised usage analyticsAnonymised IP, page views, session data only
CA / AuditorTax filing, TDS returnsVendor PAN, financial data (under legal obligation)

All Data Processors are bound by data processing agreements ensuring DPDP Act 2023 compliance.

9.3 Legal Disclosures

We may disclose personal data without your prior consent when required by:

  • A valid court order or judicial warrant under the Code of Criminal Procedure, 1973
  • A government direction under Section 69 of the IT Act, 2000 (national security / public order)
  • Tax authorities under the Income Tax Act, 1961 or GST laws
  • The Enforcement Directorate or Financial Intelligence Unit under PMLA, 2002
  • Any other competent authority under applicable Indian law

We will attempt to notify you of such disclosure to the extent permitted by law.

9.4 Cross-Border Data Transfers

⚠️ Data Localisation: All personal data of Indian users is stored and processed on servers located within India, in compliance with the RBI Data Localisation Circular (April 2018) and the DPDP Act 2023. We do not transfer personal data outside India without (a) your explicit consent, and (b) verification that the destination country provides adequate data protection as notified by the Central Government under Section 16 of the DPDP Act 2023.

10 Data Localisation

In compliance with the Reserve Bank of India's circular on "Storage of Payment System Data" (6 April 2018) and the DPDP Act 2023:

  • All payment data (UPI transaction IDs, payment references, bank account details) of Indian users is stored exclusively on servers located within India.
  • All personal data of Indian users processed through FestBooking is stored within the territory of India.
  • Our cloud hosting infrastructure is hosted on India-region data centres.
  • Any international system used for analytics or communication receives only anonymised or pseudonymised data with no personally identifiable information.

11 Data Retention

📋 DPDP Act 2023, Section 8(7): A Data Fiduciary shall not retain personal data beyond the period necessary for the specified purpose. IT (SPDI) Rules 2011, Rule 5(4): SPDI must not be retained longer than necessary.

Data CategoryRetention PeriodBasis
Customer account dataUntil account deletion + 3 yearsDispute resolution, legal claims
Booking records7 years from booking dateConsumer Protection Act 2019 / Tax audit
Payment / financial data8 yearsIncome Tax Act 1961 (Section 44AA) / GST law
Vendor KYC documents (Aadhaar / PAN photo)Until account closure + 5 yearsPMLA 2002, Rule 9 — 5 years post-account closure
Vendor PAN / bank account referenceUntil account closure + 8 yearsTDS records, Income Tax Act
Customer reviews and ratingsUntil vendor account deletionLegitimate interest
Server / security logs180 daysIT Rules 2021 (Intermediary Guidelines) Rule 3(1)(j)
Marketing consent recordsUntil consent is withdrawn + 3 yearsEvidence of lawful processing
Cookies (analytics)365 daysFunctional necessity

After the retention period expires, personal data is securely deleted or irreversibly anonymised. Anonymised/aggregated data may be retained indefinitely for statistical purposes.

12 Security Measures

📋 IT (SPDI) Rules 2011, Rule 8: Every body corporate handling SPDI must implement comprehensive documented information security programmes and policies, including IS/ISO/IEC 27001:2013 standard or equivalent.

We implement the following security safeguards to protect your personal data:

  • Encryption in transit: All data transmitted between your device and our servers uses TLS 1.2 / 1.3 (HTTPS). HTTP access is permanently redirected to HTTPS.
  • Encryption at rest: All databases and file storage containing personal/SPDI data use AES-256 encryption.
  • Access controls: Role-based access control (RBAC) — employees access only the minimum data necessary for their role. All admin access is logged.
  • Password security: User passwords are stored as salted bcrypt hashes (cost factor ≥ 12). Plain-text passwords are never stored.
  • Two-factor authentication: Available for all vendor and admin accounts (OTP-based).
  • Vulnerability management: Regular OWASP Top 10 security reviews, dependency audits, and penetration testing.
  • Data backup: Daily encrypted backups with geographically separate storage within India.
  • Employee training: All personnel handling personal data are trained on data protection obligations under DPDP Act 2023 and SPDI Rules 2011.
  • Vendor/processor audits: Third-party Data Processors are audited for security compliance annually.
  • Incident response plan: Documented procedure for detecting, containing, and reporting data breaches (see Section 16).

⚠️ Your responsibility: You are responsible for keeping your account credentials confidential. Do not share your password or OTP with anyone, including persons claiming to be FestBooking staff. We will NEVER ask for your password or full OTP over phone or email.

13 Children's Privacy

📋 DPDP Act 2023, Section 9: Processing of personal data of children (below 18 years) requires verifiable parental consent. Data Fiduciaries shall not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

FestBooking is intended for users who are 18 years of age or older. We do not knowingly collect personal data from individuals below 18 years of age without verifiable parental or guardian consent.

If you are a parent or guardian and you believe your child has provided personal data on our Platform without consent, please contact us immediately at privacy@festbooking.in. We will promptly delete such data upon verification.

We do not engage in behavioural tracking, targeted advertising, or profiling of any user below 18 years of age, in compliance with Section 9 of the DPDP Act 2023.

14 Your Rights as a Data Principal

📋 DPDP Act 2023, Chapter III (Sections 11–14): Data Principals (individuals whose data is processed) have enforceable rights against Data Fiduciaries.

📋

Right to Information (Sec 11)

Know what personal data we hold about you, how it is being processed, and who it has been shared with.

✏️

Right to Correction (Sec 12)

Request correction or updating of inaccurate, incomplete, or outdated personal data.

🗑️

Right to Erasure (Sec 12)

Request deletion of personal data that is no longer necessary, subject to legal retention obligations.

🔕

Right to Withdraw Consent (Sec 13)

Withdraw previously given consent for processing at any time. Withdrawal does not affect prior processing.

⚖️

Right to Grievance (Sec 13)

Lodge a complaint with our Grievance Officer if you believe your data rights have been violated.

🏛️

Right to Data Protection Board (Sec 14)

If unsatisfied with our response, escalate to the Data Protection Board of India established under the DPDP Act 2023.

👤

Right to Nominate (Sec 14)

Nominate another individual to exercise your data rights on your behalf in case of death or incapacity.

🚫

Right to Opt-Out of Marketing

Unsubscribe from promotional emails or SMS at any time via the unsubscribe link or by contacting us.

How to Exercise Your Rights

To exercise any of the above rights, submit a written request to our Data Protection Officer at dpo@festbooking.in or use the Privacy Settings in your account dashboard. We will respond within 30 days of receiving your request. We may verify your identity before processing the request. Requests are free of charge for up to 2 requests per year per user.

📍 Data Protection Board of India: If you remain unsatisfied after exhausting our internal process, you may file a complaint with the Data Protection Board of India at the web portal designated by the Ministry of Electronics and Information Technology (MeitY). The Board has the power to impose penalties and direct remediation under the DPDP Act 2023.

15 Grievance Redressal

📋 IT (Intermediary Guidelines) Rules 2021, Rule 4(2): Significant social media intermediaries and platforms must appoint a Grievance Officer, resident in India, to receive and acknowledge complaints within 24 hours and resolve within 15 days.

⚖️

Grievance Officer

Name: Mr. Rahul Sharma
Designation: Grievance Officer
Email: grievance@festbooking.in
Phone: +91 98765-43210
Hours: Mon–Sat, 10 AM – 6 PM IST
Response Time: Within 24 hours (acknowledgement); 15 days (resolution)

🔐

Data Protection Officer

Name: Ms. Priya Joshi
Designation: Data Protection Officer
Email: dpo@festbooking.in
Postal: FestBooking Internet Pvt. Ltd., 123 Business Hub, Vaishali Nagar, Jaipur – 302021
Scope: All DPDP Act 2023 and IT Rules 2011 related matters

16 Data Breach Notification

📋 DPDP Act 2023, Section 8(6): Upon becoming aware of a personal data breach, the Data Fiduciary must notify the Data Protection Board and affected Data Principals in the prescribed manner and within the prescribed time period.

In the event of a personal data breach that is likely to result in harm to Data Principals, FestBooking will:

  • Notify the Data Protection Board of India within the timeframe prescribed by the Board's rules (currently being notified under DPDP Act 2023).
  • Notify affected users via email and/or SMS to their registered contact details without undue delay.
  • The notification will include: nature of the breach, categories and approximate number of individuals affected, likely consequences, measures taken or proposed to address the breach, and contact information for more details.
  • Maintain a breach register documenting all incidents (including those not meeting the notification threshold) for internal accountability.

We also maintain cyber insurance in compliance with best practices for digital platforms.

17 Third-Party Links & Embedded Content

Our website may contain links to third-party websites (e.g., payment gateways, social media pages, government portals). Clicking such links takes you to a website governed by that third party's privacy policy, not ours.

We are not responsible for the privacy practices, content, or security of any third-party website. We recommend you review the privacy policy of any external site before providing personal data to it.

Embedded content from third parties (such as maps, social share buttons, or videos) may collect your IP address and set cookies independently. Such processing is governed by the respective third party's privacy policy.

18 Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes:

  • We will update the "Last Updated" date at the top of this Policy.
  • We will notify registered users via email to their registered address at least 14 days before the change takes effect.
  • For significant changes affecting your rights, we will seek fresh consent as required under the DPDP Act 2023.
  • Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.

Previous versions of this Policy are archived and available upon request from privacy@festbooking.in.

19 Contact Us & Data Protection Officer

For any privacy-related queries, requests, or complaints, you may contact us through any of the following channels:

📧

Privacy Team

General Privacy Queries: privacy@festbooking.in
Data Erasure / Access Requests: dpo@festbooking.in
KYC Document Deletion: kyc@festbooking.in
Grievances & Complaints: grievance@festbooking.in

🏢

Registered Office (Postal)

FestBooking Internet Private Limited
123, Business Hub, Vaishali Nagar
Jaipur, Rajasthan – 302021, India
Phone: +91 98765-43210 (Mon–Sat, 9 AM – 8 PM IST)

🏛️ Regulatory Escalation: If you are not satisfied with our response to your privacy complaint, you have the right to lodge a complaint with the Data Protection Board of India (once operational under DPDP Act 2023) at the portal to be designated by MeitY, or approach the competent civil courts at Jaipur, Rajasthan for relief under Section 43A of the IT Act, 2000.

Policy Version: 1.0  |  Effective: 1 June 2025  |  Last Updated: 16 June 2025  |  Governing Law: Laws of India  |  Jurisdiction: Jaipur, Rajasthan  |  Language: English (prevails over any translation)