Legal

Privacy Policy

Last updated: August 2026

RapidSync ("RapidSync," "we," "us") provides a multi-tenant channel manager and direct booking platform for independent hotels and hotel groups. This policy explains what information we collect, how we use it, and the choices available to hotel staff, platform administrators, and hotel guests who interact with RapidSync.

Who this applies to

Information we collect

Hotel staff accounts

Staff and admin accounts are created by invitation only — a hotel admin or a RapidSync platform admin sends an invitation to a work email address, and the invited person sets a password to activate the account. We do not have a public self-service sign-up form for staff accounts. We store the account's name, email address, hashed password, assigned role, and the hotel(s) the account can access.

Guest bookings

When a guest completes a reservation through a hotel's Booking Engine, we collect the information needed to fulfil that booking: name, contact details, stay dates, room selection, and payment information. Payments are processed by our payment partner, Razorpay — RapidSync does not store full card numbers.

Booking notifications (WhatsApp)

If a guest opts in during checkout, we send booking confirmations over WhatsApp using Meta's WhatsApp Business Platform, in addition to email. This uses the phone number provided at booking and is strictly one-way: we do not read, store, or reply to messages a guest sends back to that WhatsApp number. We keep a delivery-status log (sent, delivered, read, or failed) so we can tell a guest's hotel whether a notice reached them — this log does not contain message content.

Operational and audit data

We keep audit logs of account activity and changes to inventory, rates, and reservations, and error/diagnostic logs to keep the platform reliable and secure. Each hotel's data is isolated from every other hotel on the platform.

How we use information

How we share information

We share the minimum data necessary with: OTA channel partners a hotel has connected (to keep availability and rates in sync), Razorpay (to process guest payments), and infrastructure providers (Amazon Web Services) who host the platform. We do not sell personal data to third parties.

Security

Payment-related credentials are encrypted at rest. Access to hotel data is scoped per account and per hotel. All administrative and booking traffic is served over HTTPS.

Email and unsubscribe

RapidSync's account emails (invitations, password resets, booking notices) are transactional and tied to an action you or your hotel took — they are not a marketing list you need to opt out of. If you believe you received an email in error, or want an account and its associated data removed, contact us using the details below.

Deleting your data

To request deletion of your data — a staff account, a guest's booking record, or WhatsApp opt-in and notification history — email hello@rapidsync.in with "Data Deletion Request" in the subject line and identify the account, hotel, or booking reference the request covers. We will acknowledge the request and confirm once the data has been deleted, except where we are required to retain records (for example, completed-booking financial records) to meet legal or accounting obligations, in which case we will tell you what is retained and why.

Cookies

This marketing site does not use analytics or tracking cookies. The Extranet and Booking Engine applications use session tokens strictly to keep you signed in.

Contact us

Questions about this policy, or requests to access or remove your data, can be sent to hello@rapidsync.in.

We may update this policy as the platform evolves. Material changes will be reflected by updating the date above.