Privacy Policy
Bhukkad ("Bhukkad", "we", "us") provides hostel, PG, and mess management software used by property Owners/Managers ("Owner") and their residents ("Student"), and a separate coupon marketplace for local shops ("Merchant"). This policy explains what data we collect, why, and how it's handled.
1. Who enters your data
For Students: your Owner enters or uploads your roster details (or you complete onboarding yourself via a link the Owner shares). Bhukkad does not independently recruit or advertise to residents — every Student account exists because the Owner running that property added it.
2. What we collect
- Roster data: name, phone, email, room number, guardian name/phone/email, college/institution name.
- Identity verification (KYC) data, where an Owner chooses to record it: ID type (Aadhaar / PAN / Voter ID / Passport / other), ID number, and optionally a photo of the ID. This exists because several Indian states legally require PG/hostel operators to keep police-verification records of residents — Bhukkad is a record-keeping tool for that, not a verification service.
- Attendance & access data: meal check-ins, gate entry/exit timestamps, outpass and leave requests, visitor logs.
- Financial data: fee/rent amounts, due dates, and payments the Owner manually records after receiving money outside the app (Bhukkad does not process payments itself at this time).
- Account data: email/phone used to sign in, authentication tokens, device platform (Android/web).
- Merchant data (separate role): business name, category, location, coupons published — unrelated to hostel data and never linked to it.
We do not collect location tracking, contacts, camera roll, or any data beyond what's listed above, and we do not run advertising trackers or sell data to data brokers.
3. Why we process it
- To operate the core service: attendance, billing reconciliation, leave/outpass approval, complaints, security/gate logs, and the features the Owner has enabled.
- To let an Owner maintain legally-required records (e.g. police verification) for their own property.
- To bill the Owner for use of the platform (per-active-resident pricing) — this uses roster counts only, never individual Student financial or identity data.
4. Who can see your data
Data is scoped strictly to the specific hostel/PG you belong to. Only that property's Owner and the Managers/Guards they've explicitly granted access to can see it — enforced both in the app and at the database level (Firestore security rules), so one hostel's data is never reachable from another hostel or organization's account, even by another Owner. Bhukkad's own team does not browse customer data as a matter of course; access is limited to what's needed to fix a reported issue.
We do not sell, rent, or share your data with third parties for marketing. We do not share Student data with Merchants, or vice versa — those are separate, unrelated parts of the app.
5. Where data lives
Data is stored on Google Firebase (Firestore) and the app is hosted on Vercel, both operating India-accessible infrastructure. ID photos, where recorded, are stored as a compressed image directly on the record (not a separate file-hosting service).
6. How long we keep it
Data is kept for as long as your Owner keeps you on their active roster. If your Owner removes you from a re-uploaded roster, your account and associated attendance/leave/complaint/feedback history are permanently deleted. You or your Owner can request full deletion at any time by contacting us below.
7. Your rights
Under India's Digital Personal Data Protection Act, 2023, you have the right to access, correct, or request erasure of your personal data, and to withdraw consent where processing depends on it. To exercise any of these, contact your Owner directly (they control your roster record) or email us at the address below and we'll assist.
8. Children's data
Some hostel/PG residents may be minors. Where that's the case, the Owner (as the institution/property responsible for that resident) is responsible for obtaining any consent required from a parent or guardian before that resident's data is entered into Bhukkad.
9. Security
Access is gated by per-hostel authentication and server-side authorization rules (Firestore security rules) — not just app-side checks. Check-in credentials use rotating time-based codes rather than static QR images. That said, no system is perfectly secure; if you believe your data has been exposed, contact us immediately.
10. Changes to this policy
We may update this policy as the product changes. Material changes will be reflected here with an updated date above.
11. Grievance officer & contact
For any privacy question, correction request, or complaint:
Email: contact@bhukkad.site
Grievance Officer: [Name — to be filled in]
Registered address: [Address — to be filled in]