1. Who we are
Bedwise ("we", "our", "us") is a paying-guest (PG) hostel management service operated by INFOPRIME EXPORTS AND IMPORTS LLP. We provide owner and tenant apps to record rent, manage rooms, log meals, and handle complaints inside a single PG.
Under India's Digital Personal Data Protection Act, 2023 (DPDP), we are the Data Fiduciary for the personal data described below.
2. What we collect
2.1 Account & identity
- Phone number — required for sign-in.
- 4-digit PIN — stored as a bcrypt hash, never in plain text.
- Full name — required.
- Email — optional, used only if you provide it.
- Profile photo — optional.
- Preferred language — English by default.
2.2 Device & technical
- Device ID — for session persistence so you stay signed in.
- Firebase Cloud Messaging (FCM) token — to deliver push notifications.
- IP address & user-agent — captured in server logs for security and abuse prevention.
- Crash & error reports — anonymised stack traces sent to Sentry to help us fix bugs.
2.3 PG operations (tenants only)
- Emergency contact name and phone.
- Permanent address.
- Purpose (e.g., "Working Professional", "Student") and company or college.
- KYC documents — Aadhaar, photo ID, signed rent agreements. Files are stored encrypted in Supabase Storage and access is limited to the PG owner and you.
- Joining date, rent amount, deposit — your rental terms with the PG.
2.4 Financial records
- Payments — amount, date, mode (cash, UPI, bank transfer). Bedwise does NOT process payments; we only record what your PG owner enters.
- Payment proof photos — when uploaded by an owner.
- Subscription billing (owners only) — what plan you're on, when it expires.
2.5 User-generated content
- Messages — chat between you and other PG members. May include text, photos, and voice recordings.
- Complaints — text descriptions and optional photos.
- Announcements (owners only) — broadcast messages to tenants.
- Activity log — record of significant actions (you joined, a payment was recorded, etc.).
2.6 What we do NOT collect
- Precise GPS location. We never request or use location data.
- Health, biometric, or political opinion data.
- Contacts list, SMS messages, call logs — even though we ask for your phone number, we do not read messages or calls.
- Browsing history outside the app.
3. Why we collect it
We use your data only to operate the Bedwise service:
- Sign you in and keep you signed in.
- Show you your rent, payment history, meals, and complaints.
- Let you and your PG owner / tenants communicate.
- Send push notifications (rent reminders, replies to your messages).
- Help PG owners maintain accounting and compliance records.
- Diagnose crashes and improve the app.
We do not sell your data, use it for advertising, build advertising profiles, or share it with data brokers.
4. Who can see what
- Inside your PG — the PG owner (and any co-owners they've added) can see your name, phone, KYC documents, payment history, complaints you've filed, and messages you've sent in PG threads. Other tenants in the same PG can only see your name in shared message threads.
- Bedwise staff — only the small set of engineers needed to operate the service, and only when investigating a specific support ticket or incident.
- Third parties — none, except as listed in section 5.
- Law enforcement — only on a valid legal order.
5. Service providers
We use the following third-party services to run Bedwise. Each handles a slice of your data only for the specific purpose listed.
- Supabase (database + file storage) — stores all the data above. Hosted in the AWS ap-south-1 (Mumbai) region.
- Hostinger (server hosting) — runs the Bedwise app servers.
- Firebase Cloud Messaging (Google) — delivers push notifications. Receives only the FCM token and notification payload, never your raw account data.
- Sentry (error reporting) — receives anonymised crash stack traces and app version. No PII is sent.
6. How long we keep it
- Account data (name, phone, PIN, KYC documents): until you delete your account. KYC documents are also deleted when your tenancy ends, if the PG owner removes them.
- Financial records (payments, expenses, rent agreements): retained for 8 years from the financial year they relate to, in line with Indian income-tax record-keeping requirements. After you delete your account, these records are kept but your name is replaced with "Deleted user" so the records cannot identify you personally.
- Messages and complaints: kept as long as the PG they belong to is active. Your personal name is anonymised on deletion.
- Server logs & crash reports: 90 days.
7. Your rights (DPDP)
Under India's DPDP Act, 2023, you have the right to:
- Access the data we hold about you (export your account from Settings → Account).
- Correct inaccurate data (edit Settings → Account).
- Erase your account — go to Delete your account, or in the app: Settings → Danger Zone → Delete my account.
- Withdraw consent for processing — equivalent to deletion, since the app cannot function without the processing covered here.
- Nominate another person to exercise your rights on your behalf in the event of death or incapacity.
- Grievance redressal — write to us at the address in section 10 first; if unresolved within 30 days, escalate to the Data Protection Board of India.
8. Security
All connections to Bedwise use TLS (HTTPS). PINs are stored as bcrypt hashes, never in plain text. Supabase rows are protected by row-level-security policies that prevent users from reading data outside their own PG. KYC files are stored in private buckets and served only to authorised users via short-lived signed URLs.
9. Children
Bedwise is intended for adults aged 18 and over (PG owners and adult tenants). We do not knowingly collect data from anyone under 18. If we learn we have collected such data, we will delete it.
10. Contact us
For privacy questions, deletion requests that cannot be done self-service, or grievances:
Data Fiduciary contact
Bedwise — INFOPRIME EXPORTS AND IMPORTS LLP
Email: privacy@bedwise.in
Registered office: 37-103, Blijapalem, Addanki, Andhra Pradesh – 523201, India
11. Changes to this policy
We may update this policy as the app evolves. When changes are material, we will notify you in-app and update the "Last updated" date above. Continued use of Bedwise after the change means you accept the updated policy.