LEGAL
HostelDost Privacy Policy
Last updated: 3 August 2026
HostelDost is an owner-facing hostel-management application. This policy is the privacy notice for the HostelDost app and website. It explains what personal data is handled, why it is handled, how to exercise choices and rights, and how to contact us.
Our role and contact
HostelDost is operated and published by Funnelkit LTD (“Funnelkit”, “we”, “us” or “our”). Our HostelDost contact address is Balaji Nagar, Warangal, Telangana 506002, India. For privacy requests or grievances, email support@hosteldost.in.
A hostel owner decides why and how resident data is collected for that hostel. The owner is therefore responsible for giving residents an appropriate notice, obtaining consent or relying on another lawful basis where required, and responding to resident requests. Funnelkit processes resident data to provide HostelDost and acts independently for its own account-security, fraud-prevention, legal-compliance and service-operation purposes.
Data we handle
- Owner account and hostel data: name, hostel name, address, registered mobile number, language and security preferences.
- Owner-verification data: identity, address, property-owner contact and the documents requested in the in-app verification flow, including a current selfie. Aadhaar should be masked where possible and no document should be uploaded unless the owner is authorised to provide it.
- Resident data entered by the hostel: name, Aadhaar number, contact details, emergency-contact name and number, gender, date of birth, profession, room and bed allocation, joining/vacating information, fees, deposits, notes and status.
- Payment records: amount, date, payment method, billing period and a note entered by the owner. HostelDost currently records payments only; it does not process card payments or store card or bank-account credentials.
- Security, diagnostic and audit data: sign-in and record-change events, timestamps, device/app identifiers, device model, crash/performance diagnostics and app interaction events needed to operate and secure the service. We do not collect fingerprint or face templates; the app records only the result/timestamp of a device biometric check.
The current HostelDost app does not collect resident profile photographs or resident identity-document images. Do not put identity images in a note or another text field. If an earlier app version accepted resident images for your account, contact support@hosteldost.in to request their deletion.
Purposes and consent
We handle data to create and secure accounts; provide hostel, resident, room, vacancy and payment-record features; prevent fraud and misuse; investigate security incidents; meet applicable legal obligations; and improve reliability. Owner-verification data is used only to assess account ownership and reduce impersonation/fraud. It is not used for advertising, credit decisions or behavioural profiling.
When consent is the basis for processing, the app presents the Privacy Policy and Terms before account creation. Consent is recorded with the account. You may withdraw consent or request deletion through the app or the form below; withdrawal does not affect processing already carried out and may prevent us from continuing features that need the relevant data. We may retain limited data where required or permitted by law for security, fraud prevention, accounting or legal claims.
Owner verification is a HostelDost security control. It is not a statement that every requested document is required by a particular Indian statute. Before collecting a document, owners must ensure it is necessary for their purpose and that they are authorised to provide it.
Service providers and security
HostelDost uses Google Firebase and Google Cloud services, including Firebase Authentication, Cloud Firestore, Cloud Storage, Firebase App Check, Firebase Analytics, Crashlytics and Performance Monitoring. These providers process data to operate, secure and support HostelDost. We do not sell personal data and do not use advertising SDKs.
Owner-verification documents and the owner selfie are reduced on the device to remove image metadata, then placed in a short-lived private quarantine area for validation and malware scanning. Clean files move to a private review vault; the mobile app receives no public download URL. This workflow is for owner verification only; it is not used for resident photographs or resident identity-document images. Firebase Authentication, Hosting, Play services, diagnostics and service metadata may be processed through Google’s wider infrastructure under Google’s applicable terms and data-processing documentation.
We use encrypted connections, restricted Firestore and Storage rules, server-side authorisation, App Check/Play Integrity, audit logging and device-security controls. No system can guarantee absolute security. Protect your device and do not upload information you are not authorised to handle.
Sharing and disclosures
We share data with service providers only as needed to operate HostelDost, with a hostel owner and authorised staff according to the owner’s permissions, when required by applicable law or valid legal process, or to protect the rights, safety and security of HostelDost, users or others. We do not sell personal data or share it for targeted advertising.
Retention, deletion and your choices
When an owner marks a resident as vacated, HostelDost schedules removal or redaction of that resident’s personal details, including emergency-contact details, within 90 days. The current app does not collect resident profile photographs or resident identity-document images. Owner-verification images are deleted if rejected or if scanning fails, and are deleted from the private review vault after the configured 30-day verification-review period. Encrypted temporary owner-verification upload stages on the device expire after seven days.
Payment and audit records may be retained only for accounting, security, fraud prevention, dispute handling or other applicable legal obligations. We remove or redact personal details when they are no longer required for those purposes. Deleted Cloud Storage files may remain recoverable only within the configured provider soft-delete window.
Owners can request account deletion in the app or through our account deletion request form. We verify the request against the registered mobile number and provide a seven-day cancellation window. After that window, each request is reviewed against the applicable retention requirements before deletion is approved; it is not deleted automatically. If you have lost access to your registered phone or number, use the separate account-recovery support form; it starts only a reviewed support contact and does not change an account automatically. You may also request access, correction or a grievance review at support@hosteldost.in. Residents and emergency contacts should first contact the hostel owner that entered their record.
Children and international processing
HostelDost is a business-management tool and is not directed to children. Owners must not use it to collect or upload a child’s data unless they have authority and a lawful basis to do so. Google Firebase may process information in locations where Google or its service providers operate; its applicable terms govern those transfers.
Website cookies and browser storage
The HostelDost website does not use advertising cookies or website analytics cookies. We use essential browser storage only to remember that you dismissed the website privacy notice. You can clear this preference at any time in your browser settings.
Changes to this policy
We may update this policy when the app or applicable legal requirements change. The latest version will be available at this URL.
Contact
Funnelkit LTD, operator of HostelDost
Balaji Nagar, Warangal, Telangana 506002, India
support@hosteldost.in