NightBay
Back to nightbay.in

Privacy Policy

Version 2.0 · Updated 2026-06-10 · Sahasamstapaka Private Limited

1. Introduction

1.1. This Privacy Policy (“Policy”) describes how Sahasamstapaka Private Limited, operating under the brand name “Night Bay” (“Company”, “NightBay”, “we”, “our”, or “us”), collects, processes, stores, uses, shares, and protects personal data in connection with its parking marketplace platform, mobile application, website, and related services (“Platform”). 1.2. The Platform enables individuals and entities with spare overnight parking capacity, including apartment residents, Resident Welfare Associations (RWAs), schools, offices, and malls (“Hosts”), to list their available parking spots, and enables car owners seeking monthly parking (“Renters”) to search for, request, and book such spots. Hosts and Renters are together referred to as “Users”. 1.3. The Platform incorporates privacy-focused features including phone-number (OTP) based authentication, disclosure of a Renter’s contact details to a Host only upon a booking request, and disclosure of a Host’s contact details to a Renter only once the Host accepts a booking request. 1.4. By accessing or using the Platform, Users acknowledge that they have read, understood, and agreed to the terms of this Privacy Policy. 1.5. This Privacy Policy is intended to comply with applicable privacy and data protection laws, including the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”), the Information Technology Act, 2000 and rules made thereunder. As all current operations and Users are located within India, this Policy does not reference the GDPR, CCPA, or other foreign data protection frameworks. 1.6. We encourage you to read this Policy carefully and contact us at support@nightbay.in if you have any questions or concerns regarding your personal data.

2. Applicability of Policy

2.1. This Privacy Policy applies to all Users, visitors, and any other individuals accessing or using the Platform in any manner, whether as a Host, a Renter, or otherwise: account creation and sign-in via phone number and OTP; Host listing creation, including verification calls and, for larger listings, in-person site visits; Renter search, booking requests, and booking confirmations; payments, recurring monthly charges, and Host payouts; Host KYC (PAN and bank account details) for payout onboarding; customer support and grievance handling; and legal and regulatory compliance, including tax record-keeping. 2.2. This Privacy Policy applies to all personal data collected through the Platform, email communications, customer support channels, and other interactions with the Company. 2.3. Separate terms, including NightBay’s Terms & Conditions and the Booking Agreement, shall be read together with this Privacy Policy.

3. Types of data collected

• Phone number (primary identifier, used for OTP-based login) • Name • GPS/location data (used for the “Near me” search feature; Renters may grant or deny this permission) • Vehicle registration number (for booking confirmation and verification) • Locality/general address information (used for search and matching; not a precise home address) • For Hosts: PAN and bank account details, collected for payout onboarding via Razorpay Route linked accounts • For shared/RWA and vacant-plot listings specifically: a government ID document, collected during manual verification • A photograph of the parking spot at listing time • For listings of 5 or more spots at one location: records of the mandatory in-person site visit, including the visit date, the verifying NightBay staff member, and any photos taken during the visit for internal verification purposes • Payment transaction metadata (amounts, dates, status) is retained by NightBay. Card and UPI details are handled directly by Razorpay and are not stored by NightBay. • Bank account details and government ID documents (collected from certain Hosts, as described above) qualify as sensitive personal data requiring extra care under DPDP Act guidance and RBI-adjacent norms. • NightBay does not collect health, biometric, religious, or other similarly sensitive categories of data.

4. Purpose of data collection and legal basis

• authenticating Users via OTP; • matching Renters to nearby available and verified listings; • processing monthly recurring payments and automated split payouts to Hosts; • verifying listings before they go live, including phone/photo checks and, for larger listings, an in-person site visit; • generating GST-compliant tax invoices; • customer support and dispute resolution; and • legal and tax record-keeping. 4.2. In-person visit records collected for larger listings are used solely to confirm the accuracy and legitimacy of a listing before it is published and are not shared with Renters beyond the listing’s final public verification status. 4.3. Personal data is not currently used for marketing or advertising, is not sold or rented to third parties, and is not used for any purpose beyond those described in this Policy. Should NightBay in future wish to send renewal reminders or promotional messages, this will be treated as a separate, specific consent obtained independently of general account-signup consent, and this Policy will be updated accordingly. 4.4. We process personal data primarily based on consent (obtained explicitly at sign-up, and separately for location access) and contractual necessity (the Platform cannot function without phone verification, payment processing, or, for Hosts, payout details). Retention of invoices and financial records is additionally grounded in legal obligation, as GST law requires such records to be retained for 72 months. 4.5. There is no behavioral profiling, credit scoring, or automated approval/rejection of Users. The only algorithmic ranking on the Platform is the distance-based sorting used for “Near me” search, which is purely geographic and not based on user behavior history.

5. Methods of data collection

5.1. Personal data is collected directly from Users through in-app forms at sign-up, listing creation, and booking. 5.2. Location data is collected via device GPS, with an explicit permission prompt that Renters may deny without the app ceasing to function (though “Near me” search will not be available). 5.3. For listings of 5 or more spots at one location, personal data is additionally collected during an in-person site visit conducted by a NightBay team member. 5.4. Host payout KYC data is collected indirectly via Razorpay during the payout onboarding process.

6. Data sharing and third parties

• Razorpay — Payment processing and automated Host payouts (Route linked accounts) • MSG91 — SMS delivery for OTP verification • MongoDB Atlas — Cloud database storage • Emergent — The platform used to build and host the application infrastructure 6.2. Razorpay and MSG91 are RBI and TRAI-regulated entities respectively, each subject to their own compliance obligations for the data they handle on NightBay’s behalf. 6.3. When a Renter sends a booking request, the Renter’s name, phone number, and verification status are disclosed to the Host, to allow the Host to assess the request. The Host’s phone number is disclosed to the Renter only if and when the Host accepts the request. NightBay does not provide an in-app messaging service; further coordination between Host and Renter takes place directly between them by phone or other means outside the Platform, and NightBay is not a party to and does not record those communications. 6.4. NightBay does not sell or rent personal data to third parties and does not use personal data for any purpose beyond those described in this Policy. 6.5. The MongoDB Atlas cluster used to store NightBay’s data is located in the Mumbai, India region. Data storage currently stays within India, and NightBay does not transfer personal data outside India as part of its operations.

7. Data storage, retention and deletion

7.1. Personal data collected through the Platform is stored on NightBay’s own MongoDB Atlas cluster, located in the Mumbai, India region. Payment-specific data is additionally held by Razorpay in accordance with its own regulatory retention requirements, and OTP records are briefly held by MSG91 for delivery purposes. 7.2. Invoice, payment, and payout records are retained for 72 months (6 years) in anonymized form, in accordance with Section 36 of the CGST Act. Personal identifiers, including name, phone number, ID documents, and bank details are erased upon account deletion, except where deletion is deferred as described in Clause 7.3. 7.3. Users may delete their account through a self-serve flow, available both in-app and via public page. Account deletion anonymizes personal data while retaining anonymized financial records for the legally required period. Deletion (and the associated anonymization) is deferred, and personal data is retained, while any of the following applies: (a) the User has an active or live Booking, including one awaiting payment or within its notice period; (b) the User owes NightBay money on any Booking; (c) a refund is pending to the User; (d) an open dispute involves the User's account, whether raised by the User or against them; or (e) a Host payout to the User is unsettled, including during the 48 (forty-eight) hour payout hold applied after a Booking starts. Once none of these conditions apply, deletion proceeds as described above.

8. Encryption and security

8.1. All data in transit is protected using TLS, enforced at a minimum of TLS 1.2 on the MongoDB Atlas cluster; TLS 1.0 and 1.1 are rejected outright and this cannot be disabled. 8.2. Data at rest on the MongoDB Atlas production cluster is encrypted using AES-256, provider-managed keys, enabled by default across all Atlas tiers used by NightBay. 8.3. All client-server communication uses HTTPS/TLS. User authentication uses JWT (JSON Web Tokens), as regular User login is OTP-based rather than password-based.

9. User rights

i) access their personal data; ii) request correction of their personal data; iii) request deletion of their account and associated personal data, via the self-serve flow described in Clause 7.3; and iv) raise a grievance regarding the processing of their personal data, via the Grievance Officer named in Clause 15.2. 9.2. Account deletion (erasure) is available as a built, self-serve flow both in-app and via the web. Requests for access to a copy of one’s data, or for correction beyond what is available through in-app profile editing, are currently handled manually by the Grievance Officer. NightBay will endeavor to respond to such requests within a reasonable timeframe and in accordance with applicable law.

10. Children’s data & age restrictions

10.1. The Platform is intended for use only by individuals who are eighteen (18) years of age or older, consistent with its involvement in financial transactions and binding booking commitments. 10.2. The Company does not knowingly collect personal data from minors. If the Company becomes aware that personal data of a minor has been collected, it will take reasonable steps to delete such information.

11. Cookies and tracking technologies

11.1. The mobile app and the web app (app.nightbay.in) use token-based authentication — a JWT stored in secure device storage on mobile, and in localStorage on web — rather than cookies. 11.2. The marketing site does not currently use analytics or tracking cookies. Should NightBay introduce such tracking on the marketing site in future, this Policy will be updated, and cookie consent will be obtained where required by law before such tracking is enabled.

12. Data security measures

HTTPS everywhere, and JWT-based authentication; rate limiting on OTP requests (per phone number), with lockout after repeated failed attempts; admin login rate limiting and constant-time password comparison; webhook signature verification for payment confirmations, rejecting unsigned or forged webhook calls; and CORS restricted to explicit known origins (nightbay.in, app.nightbay.in). 12.2. NightBay has completed a third party-style security audit covering payment mock-endpoint gating, OTP leakage prevention, and webhook forgery protection. 12.3. The Company is in the process of formalizing a documented data breach response plan. In the interim, in the event of a suspected personal data breach, the Company shall take commercially reasonable steps to investigate, contain, and remediate the breach, and shall notify affected Users and, where legally required under the DPDP Act, the Data Protection Board of India, without undue delay and in accordance with applicable law.

13. Alternate dispute resolution

13.1. Negotiation: Any dispute, controversy, or claim arising out of or in connection with this Privacy Policy or the Company’s data processing activities shall first be attempted to be resolved amicably through good-faith negotiations between the concerned parties. 13.2. The party raising the dispute shall provide written notice specifying the nature of the dispute, following which the parties shall attempt resolution within thirty (30) calendar days from receipt of such notice. 13.3. Mediation: If the dispute is not resolved through negotiation, the parties shall attempt to resolve it through mediation with a mutually appointed mediator, within thirty (30) days of the negotiation period ending. The costs of mediation shall be shared equally, unless otherwise agreed in writing. 13.4. Arbitration: If the dispute remains unresolved following negotiation and mediation, it shall be referred to and finally resolved by arbitration under the Arbitration and Conciliation Act, 1996, as amended from time to time. The arbitration shall be conducted by a sole arbitrator mutually appointed by the parties. The seat and venue of arbitration shall be Bengaluru, Karnataka, and the language of arbitration shall be English. The arbitral award shall be final and binding on the parties. 13.5. Nothing in this Clause 13 shall prevent either party from seeking urgent interim or injunctive relief from a competent court at Bengaluru, Karnataka, where necessary to prevent irreparable harm, pending the outcome of negotiation, mediation, or arbitration.

14. Updates to Privacy Policy

14.1. The Company reserves the right to modify, amend, or update this Privacy Policy at any time to reflect changes in applicable law, Platform features, or security practices, including as NightBay expands to new cities such as Mumbai. 14.2. The Company will provide notice of any material change to this Policy via an in-app notice, consistent with the DPDP Act’s emphasis on informed consent, rather than a silent update to the policy page. 14.3. Continued access or use of the Platform after such notice shall constitute acceptance of the revised Privacy Policy. 14.4. This Policy will be reviewed at least annually, and immediately whenever a new data-handling practice, vendor, or jurisdiction is introduced.

15. Grievance Officer, Data Protection Officer and contact information

15.1. For any questions, concerns, complaints, or requests relating to this Privacy Policy or the processing of personal data, Users may contact the Company through the following channels: Sahasamstapaka Private Limited (NightBay) Registered Office: No. 11 (old No. 76), Diagonal Road, 3rd Block, Jayanagar, Ward No. 167 (Old No. 59), Bangalore, Karnataka — 560011 Email: support@nightbay.in Phone: 9741146164 15.2. For Privacy Concerns Contact: Name: Prathibha K P Designation: Grievance Officer Email: Prathibha.kp@nightbay.in 15.3. Data Protection Officer: Name: Abinaya Balas Designation: Data Protection Officer Email: abinaya@bsrlawfirm.in