Updated 10 October 2026
Privacy
This says what we collect, why, who else sees it and how to make us delete it. It is written to be read rather than to be defensible.
What we collect
- When you book
- Your name, email, mobile number, the dates and room, any request you type, and a GSTIN if you give one. The name has to match the photo ID you show at check-in, which is a legal requirement for hotels in India rather than our idea.
- When you pay online
- Nothing. The payment gateway hosts the checkout and tells us only whether it succeeded, the amount, and a reference. No card number, UPI ID, CVV or PIN ever reaches our server.
- When you message or call us
- What you wrote or, on a call, the number, the time, how long it lasted and any note the agent made. Calls may be recorded for training, and you are told so at the start of the call.
- When you use the site
- One cookie to keep you signed in, and whether you opened a marketing email. No advertising trackers, no third-party analytics, no fingerprinting.
Why we hold it
- To give you the room — the property needs your name, your dates and a way to reach you on the day.
- Because the law says so — GST invoices and the accounting behind them must be kept for seven years after the financial year they belong to.
- To answer you — your booking history is what makes a support conversation useful rather than an interrogation.
- To market to you, only if you let us — and you can switch that off per channel at any time without affecting your booking.
Who else sees it
The property you booked sees what it needs to check you in: your name, dates, room, party size and any request. It does not get your payment details or your history at other properties.
Our service providers see only what their job needs — the mail provider sees the email, the SMS provider the number and the message, the telephony provider the call, the payment gateway the transaction. Each is bound by its own contract.
We do not sell your data, and we do not share it for anyone else’s advertising. We hand it to a government authority only on a lawful order, and we will tell you unless the order forbids it.
AI and your data
The support assistant reads the stay catalogue and, if you are signed in, your own bookings — so it can answer about your stay rather than guessing. It cannot cancel, change or charge anything by itself; it proposes, and you or a member of staff confirms.
By default it runs on our own server with no external API call at all. When the hosted model is switched on, your message and the relevant booking details are sent to the model provider to generate the reply, and are not used to train anything.
How long we keep it
| What | How long | Why |
|---|---|---|
| Invoices and accounting records | 7 years after the financial year | Required by Indian tax law |
| Booking records | 7 years | Tied to the invoices |
| Support conversations | 3 years | So a repeat problem is not re-explained |
| Call logs and recordings | 12 months | Training and dispute resolution |
| Marketing records | Until you unsubscribe, then 1 year | Proof that you had opted in |
| Sign-in sessions | 30 days | So you are not asked constantly |
What you can ask for
- A copy of everything we hold on you — email us and you get it within 30 days.
- A correction — most of it you can fix yourself in your profile.
- Deletion — closing your account erases your name, email, phone and address. Invoices and the accounting behind them stay, because the law requires them, but they stop being linked to a usable account.
- To be left alone — turn off every marketing channel in your profile, or use the unsubscribe link in any message. Booking confirmations and invoices still come; those are not marketing.
How it is protected
Everything travels over TLS. Passwords are stored as scrypt hashes, never as text, and nobody here can read yours. Session cookies are signed, HTTP-only and same-site. Staff accounts are scoped — someone at the front desk of one property cannot see another property’s guests.
If there is ever a breach affecting you, we will tell you and CERT-In within 72 hours of knowing about it, and we will say plainly what went wrong.
Children
The site is not for under-18s to use on their own. Children stay as part of a booking made by an adult, and we hold nothing about them beyond how many and roughly how old, which the property needs for beds.
Changes
If this policy changes in a way that matters, we email everyone with an account before it takes effect. Smaller corrections get a new date at the top.
Questions about this? Email stay@ecrworlds.com, call +91 44 4712 3456, or write to ECRworlds Hospitality Pvt Ltd, 4 Beach Road, Thiruvanmiyur, Chennai 600041, Tamil Nadu.