Club Athiva
Operated byLOYALTICIAN
← Back to Club Athiva

Privacy Policy

Last updated: 20 August 2026

This Privacy Policy explains how Club Athiva ("the Programme"), operated by Chalet Hotels Limited and powered by Loyaltician CRM India Private Limited, collects, uses, and protects your personal data. It is prepared in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.

1. Who We Are (Data Fiduciary)

Chalet Hotels Limited is the Data Fiduciary — the entity that determines why and how your personal data is processed. Loyaltician CRM India Private Limited is the Data Processor — a technology and marketing company that processes data on behalf of Chalet Hotels Limited to operate the Member App and Programme platform. Data Protection Officer: Nikhil Durgale, Compliance Officer- Nikhil@loyaltician.com

2. What Personal Data We Collect

We collect only what is necessary to operate your Membership: • Identity: full name, title, date of birth. • Contact: mobile number (WhatsApp), email address. • Membership: card number, tier, validity, payment reference. • Usage: Voucher bookings, redemptions, transaction codes, feedback and ratings. • Technical: device type, app usage patterns (for performance only; no advertising profiling). • Consent: timestamp and version of your consent to this Privacy Policy. We do not collect payment card numbers, bank account details, Aadhaar, or PAN.

3. Purpose of Processing

We process your data for the following purposes, each requiring your explicit consent at app activation: • Membership management: creating your account, issuing Vouchers, processing bookings, generating invoices. • Service communications: booking confirmations, redemption codes, renewal reminders via WhatsApp and email. • Programme improvements: aggregate (non-identifiable) usage analysis to improve the Programme. • Legal compliance: retaining transaction records for 7 years as required under the GST Act, 2017. We do not use your data for advertising, sell it to third parties, or share it without your consent.

4. Who We Share Your Data With

Data is shared only with parties necessary to operate the Programme: • Participating hotel properties (for booking fulfilment and Member identification at the property). • Loyaltician CRM India Private Limited (platform operator, bound by a Master Services Agreement). • Supabase Inc. (cloud database and authentication — servers in AWS Mumbai, India). • WhatsApp / Meta Platforms (for OTP and transactional messages — your number is processed by Meta as a sub-processor). • Cashfree Payments (payment gateway for membership fee only — we do not store card details). All sub-processors are contractually bound by data protection obligations consistent with the DPDP Act.

5. How Long We Keep Your Data

• Active membership: retained for the duration of your Membership. • Post-expiry: identity and contact data retained for 2 years for renewal and support purposes. • Financial records (payments, invoices, transactions): retained for 7 years as required by the GST Act. • On deletion: identity and contact data is permanently anonymised. Financial records are retained but de-linked from your identity.

6. Your Rights Under the DPDP Act 2023

As a Data Principal, you have the following rights: • Right to information: request a summary of personal data we hold about you. • Right to correction: correct inaccurate data via Account → Profile in the Member App or by contacting the DPO. • Right to erasure: delete your account via Account → Privacy → Delete Account. Your identity is permanently anonymised; financial records are retained for legal compliance. • Right to withdraw consent: withdraw at any time. Withdrawal ends your Membership, as the data is necessary to operate it. It does not affect lawfulness of prior processing. • Right to nominate: register a nominee to exercise your rights in the event of incapacitation or death. Contact the DPO. • Right to grievance redressal: raise a complaint with the DPO. If unsatisfied, approach the Data Protection Board of India. Contact: nikhil@loyaltician.com . Requests acknowledged within 48 hours; resolved within 30 days.

7. Data Security

We apply the following safeguards: • Data stored in India (AWS Mumbai, ap-south-1) on Supabase — SOC 2 Type II certified infrastructure. • Encryption at rest (AES-256) and in transit (TLS 1.2+). • OTP-only authentication — no passwords stored. • Staff access is role-restricted; mobile numbers are masked by default; reveals are time-limited and logged. • OTP requests are rate-limited: maximum 5 sends per email per 15 minutes. • In the event of a data breach, the Programme will notify the Data Protection Board and affected Members within 72 hours of becoming aware.

8. Children's Data

The Programme is for adults aged 18 and above. We do not knowingly collect data from anyone under 18. If we discover a Member is under 18, their account will be suspended pending verification.

9. Cross-Border Data Transfers

Personal data is stored in India. Limited processing may occur outside India by sub-processors (e.g., Meta for WhatsApp OTPs) only where adequate data protection exists. We do not transfer data to countries not notified as adequate under the DPDP Act.

10. Changes to this Privacy Policy

We may update this Policy to reflect legal or operational changes. We will update the version number and effective date and notify you through the Member App. For material changes, fresh consent will be sought.

11. Contact

Data Protection Officer: [DPO Name : Nikhil Durgale Email: nikhil@loyaltician.com Response: 48-hour acknowledgement | 30-day resolution Escalation: Data Protection Board of India at www.dpb.gov.in (once operational) Version 1.2 Updated August 19, 2026