StayNiska
Privacy Policy
Effective date: 1 July 2026
Information We Collect
Information you provide directly
- Account data — name, email address, password (stored hashed), and optional profile details when you register.
- Booking data — guest names, check-in / check-out dates, room preferences, and special requests you enter during checkout.
- Payment data — billing address and last-four digits of a card. Full card numbers are processed exclusively by our PCI-DSS-certified payment partners (Razorpay, ResAvenue). We do not store full card numbers.
- Communications — messages you send to customer support or our AI concierge.
Information collected automatically
- Device & log data — IP address, browser type, operating system, pages visited, and timestamps, collected for security and service reliability.
- Location data — approximate location (via IP geolocation) or precise location (via browser API) only when you grant permission to show nearby stays.
- Cookies & trackers — essential cookies are always active; analytics and marketing cookies require your explicit consent via our cookie banner. See our Cookie Policy.
How We Use Your Data
We process your personal data only for the following purposes:
- Booking fulfilment — to create, confirm, and manage your reservations and communicate them to the property.
- Account management — to maintain your profile, authentication, and trip history.
- Payments — to verify transactions, process refunds, and prevent fraud.
- Customer support & AI concierge — to answer your queries, assist trip planning, and resolve disputes.
- Service improvement — to analyse aggregate usage patterns, fix bugs, and improve search results.
- Marketing communications — only if you have opted in; you can unsubscribe at any time via the link in any email or through your account settings.
- Legal obligations — to comply with applicable law, respond to lawful government requests, and enforce our Terms of Use.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy:
- Account data — kept while your account is active, then deleted within 30 days of a verified erasure request.
- Booking records — retained for 7 years to comply with Indian GST and accounting regulations, after which they are anonymised or deleted.
- Log data — automatically purged after 90 days unless required for an active security investigation.
- Marketing consent records — retained until you withdraw consent, plus 3 years for compliance documentation.
Data Security
We implement appropriate technical and organisational measures to protect your personal data:
- All data is transmitted over HTTPS/TLS 1.2+ encryption.
- Passwords are hashed using industry-standard algorithms (bcrypt); we never store plaintext passwords.
- Access to production databases is restricted by role-based access control and audited.
- Payment data is handled exclusively by PCI-DSS certified partners.
- We conduct regular security assessments and promptly address identified vulnerabilities.
While we take reasonable steps to protect your data, no internet transmission is completely secure. Please notify us immediately at hello@niskagroup.com if you believe your account has been compromised.
Your Privacy Rights
Depending on your location, you have the following rights regarding your personal data:
India — Digital Personal Data Protection Act, 2023 (DPDP)
- Right to access — request a summary of the personal data we hold about you.
- Right to correction — ask us to correct inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data where we have no lawful basis for continued processing.
- Right to withdraw consent — withdraw any consent given for optional processing (e.g. marketing emails) at any time.
- Right to nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
EEA / UK visitors — GDPR rights
- Rights of access, rectification, erasure, restriction, and data portability apply where GDPR is applicable. You also have the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, email hello@niskagroup.com with the subject line "Privacy Request". We will respond within 30 days. For account deletion, you may also use the Delete account page directly.
International Data Transfers
NISKA INNOVATIONS LLC is incorporated in Wyoming, USA. Your personal data may be processed on servers located in the United States and, for Indian users, within India where we use Indian-region cloud infrastructure. We implement appropriate safeguards for any cross-border transfers in compliance with applicable law, including standard contractual clauses where required.
Children's Privacy
StayNiska is not directed at children under 18 years of age. We do not knowingly collect personal data from minors. If you believe a child has provided us with their personal data, please contact us at hello@niskagroup.com and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and by posting a notice on the StayNiska website at least 14 days before the changes take effect. The updated effective date will always appear at the top of this page. Continued use of StayNiska after the effective date constitutes acceptance of the revised policy.
How to Contact Us
For any privacy-related questions, data requests, or complaints, contact us at:
- Email: hello@niskagroup.com
- Post: NISKA INNOVATIONS LLC, 30 N Gould St, Sheridan, WY 82801, United States
- Website: niskagroup.com
Questions?
Email hello@niskagroup.com · NISKA INNOVATIONS LLC, 30 N Gould St, Sheridan, WY 82801, USA