MarudharResort
Privacy

A plain-English summary of what we collect, why, and what you can ask us to do with it.

◆ Draft

This is a working draft of our privacy notice while the final document is being prepared with legal counsel. The substance below reflects how we currently handle guest information. The finalised, lawyer-reviewed version will replace this page before public launch.

01

Who we are

This privacy notice is for Marudhar Resort, a hospitality property located on NH-27, Panchdelva, near Gosunda Dam, Chittorgarh, Rajasthan 312001. Proprietor: Shiv Singh Medtiya.

When you book a stay, dine, or hold an event with us, we receive and hold some of your personal information. This page explains what, why, and how to ask us about it.

02

What we collect

We collect only what we need to run the booking, deliver the stay, and meet our legal obligations.

  • Identification details you provide at booking: name, mobile, email, and (for the lead guest) address.
  • Stay details: dates, room type, guest count, dietary or accessibility notes.
  • Government-issued ID at check-in, as required by Indian law. Foreign nationals additionally provide passport, visa, and Form C details to the FRRO.
  • Payment instrument details, handled by our payment processor (Razorpay). We do not store full card numbers ourselves.
  • Communications you send us by phone, email, WhatsApp, or this website.
  • Basic site analytics (pages viewed, device type) to improve the website. No cross-site tracking.
03

Why we use it

  • To confirm your booking and send check-in instructions.
  • To deliver services during your stay (room allocation, dining, special requests).
  • To raise GST-compliant invoices, as required by law.
  • To respond to enquiries and resolve issues you raise with us.
  • To meet legal record-keeping requirements (financial records: 7 years; guest registers: as required by the state).
  • To send occasional, opt-in updates about offers. You can unsubscribe at any time.
04

Who else sees it

We share your data only where the stay needs it, or where the law requires us to.

  • Razorpay (payment processing).
  • Gupshup and Resend (sending you booking confirmations and updates).
  • Tax authorities, when GST invoicing or audits require.
  • Local law-enforcement and the FRRO when legally required.
  • Our hosting and storage providers (Vercel, Supabase, Cloudflare R2), which process data on our behalf under standard contracts.

We do not sell your personal data, and we do not share it with advertisers.

05

How long we keep it

  • Booking and folio records: retained for 7 years after the stay, as required for tax and audit purposes.
  • ID document images: retained for the period required by Indian law, then deleted.
  • Marketing contact data: retained until you withdraw consent.
  • Website analytics: aggregated, retained for up to 13 months.
06

Your rights

Under the Digital Personal Data Protection Act, 2023 you can ask us to:

  • Tell you what personal data we hold about you.
  • Correct any information that is wrong.
  • Delete information that is no longer required (this does not apply to records we must keep by law).
  • Withdraw consent for marketing communications.
  • Nominate someone to exercise these rights on your behalf in the event of your death or incapacity.

To make any of these requests, write to marudharresort09@gmail.com with the subject line “Privacy request”. We will respond within 30 days.

07

How we keep it safe

  • Data in transit is protected with TLS.
  • Data at rest is held in encrypted databases and storage buckets.
  • Access is restricted to the resort staff who need it for their work, and to our hosting providers under contract.
  • Payment card data is handled by Razorpay; we never see or store the full card number.
  • Our team and contractors are bound by confidentiality.
08

Cookies and analytics

The website uses a small number of cookies to keep the site working (for example, remembering you are signed in to your folio). We may also use privacy-friendly analytics to count visits and understand which pages people use. We do not use advertising cookies and we do not allow third parties to track you across other sites from here.

09

Children

The website is not directed at children under 18. Children may of course stay with us as guests, but bookings must be made by an adult. If you believe a child has provided us with information directly, please contact us and we will delete it.

10

Changes to this notice

We may update this notice from time to time as the resort and the law evolve. Significant changes will be flagged on this page with a new “last updated” date. Current version dated 23 May 2026.

11

Contact us

For anything privacy-related:

You can also reach us through the contact form.