Privacy Policy
This policy explains what personal data otli collects, why we process it, who we share it with, how long we keep it, and the rights you hold under India's Digital Personal Data Protection Act, 2023.
1. Who We Are
1.1ScaleToPeak Consulting, a partnership firm (“Otli”, “we”, “us”), operates the Otli platform (the “Platform”), which connects verified home Hosts with Guests who book curated home-cooked dining experiences (“Tables”).
1.2Otli acts as the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) for personal data processed on the Platform. This Policy explains what we collect, why we process it, with whom we share it, how long we keep it, and the rights you hold.
1.3This Policy applies to Guests, Hosts, and visitors to our website and app. It forms part of the Otli Terms of Service and should be read together with the Master Host Service Agreement and Otli Cancellation & Refund Policy.
2. Personal Data We Collect
2.1Account and identity data.We collect your name, phone number, email, date of birth, and profile details when you sign up. For identity verification and safety, we collect government-ID details, a liveness-check video or image, and a face-match result through our verification partner. Hosts additionally provide PAN, GST status (GSTIN or a non-registration declaration), and bank account details verified by penny-drop.
2.2Listing and booking data.We collect Host listing content, menus, venue photos, seat and price details, and the Host’s address; and Guest booking details, attendance records, and cancellation data.
2.3Dietary and allergy disclosures.We collect dietary restrictions and allergies that a Guest chooses to share at booking. We use these only to pass them to the Host for the specific booked Event.
2.4Payment data.Payments are processed through our payment gateway. The gateway collects payment instrument details; we receive transaction confirmations, amounts, and settlement data, but not full card numbers or sensitive payment credentials.
2.5Communications and reviews.We collect messages sent through the Platform, reviews and ratings, reports, and grievance records.
2.6Event media.We collect photos and videos connected to Tables under the media consent framework in the Guest Terms and the media licence in the Master Host Service Agreement.
2.7Device and usage data.We collect device identifiers, IP address, app version, log data, and information via cookies or similar technologies to run, secure, and improve the Platform.
2.8Internal quality signals.We generate internal records about account activity on the Platform, such as booking behaviour, cancellations, reports, and compliance with our policies. We use these records to protect safety and integrity and to operate our Trust & Safety mechanisms.
3. Why We Process Your Data and Legal Basis
3.1We process personal data for the purposes below, based on your consent under Section 6 of the DPDP Act or for legitimate uses under Section 7, including data you voluntarily provide for specified purposes:
- To verify identity and prevent fraud (including KYC, liveness checks, face match, penny-drop bank verification).
- To create and operate accounts, Listings, Bookings, payouts, and loyalty Points.
- To pass booking details, including dietary and allergy disclosures, to the Host for the booked Event.
- To share a Host’s venue address with a Guest only after a confirmed Booking.
- To process payments, refunds, and statutory deductions and collections such as TDS under Section 194-O of the Income-tax Act and TCS under Section 52 of the CGST Act, where applicable.
- To run safety, trust, and enforcement processes under the Trust & Safety Policy, including suspension and strike systems described in our contracts.
- To handle grievances, respond to legal requests, and comply with tax and other regulatory obligations.
- To improve and secure the Platform, perform analytics, and, where you consent, to market Otli services, offers, and content.
3.2We provide itemised notice at or before the point of collection, in English, stating the personal data collected, the purpose of processing, how to exercise your rights, and how to complain to the Data Protection Board of India in accordance with the DPDP Act.
4. Consent and Withdrawal
4.1Where processing rests on consent, your consent is free, specific, informed, unconditional, and unambiguous, given by clear affirmative action (such as ticking a box or proceeding after an explained notice) for the stated purpose only.
4.2You may withdraw consent at any time, as easily as you gave it, through account settings or by contacting the Grievance Officer. Withdrawal does not affect processing already carried out while consent was in force, and we may need to limit or cease services that depend on the withdrawn consent (for example, identity-verified Bookings).
4.3Where supported, you may give, manage, review, and withdraw consent through a registered Consent Manager under the DPDP Act.
5. How We Share Personal Data
5.1With Hosts (Data Processors).A Host receives Guest booking details only through the Platform and only for the booked Event: name, seat count, and dietary or allergy disclosures. Hosts must not retain, export, market to, or otherwise use Guest data outside the Platform, and must delete or cease accessing Guest data after the Event, as required by the Master Host Service Agreement and Trust & Safety Policy.
5.2With Guests.A Guest receives the Host’s first name, listing content, and, only after a confirmed Booking, the venue address. We never display a Host’s exact address publicly in search or marketing; address details are shared only inside confirmed bookings.
5.3With Service Providers (Data Processors).We engage third-party service providers under contract to process data on our behalf, including:
- Identity-verification providers (e.g., KYC and liveness services).
- e-sign and document providers.
- Payment gateway providers.
- Cloud hosting, communications, and analytics vendors
- marketing and advertising partners (for example, Meta, Google, and other ad or social platforms) to run campaigns, measure performance and build permitted audiences in line with your settings and applicable law..
These providers act as Data Processors, must follow our instructions, implement appropriate security safeguards, and may not use your data for their own independent purposes.
5.4With authorities.We disclose data where law requires, including tax reporting connected to TDS/TCS and lawful requests from law-enforcement or regulatory authorities, including referrals under our Tier-I Trust & Safety enforcement mechanisms.
We do not sell personal data.
6. Your Rights
6.1Under the DPDP Act you may exercise the following rights with respect to your personal data:
- Access. Request a summary of your personal data held by us, the categories of processing activities, and the types of Data Fiduciaries and Processors with whom it has been shared.
- Correction. Ask us to correct inaccurate data, complete incomplete data, and update your data.
- Erasure. Ask us to erase personal data that is no longer necessary for the stated purpose, subject to legal retention requirements.
- Grievance. Use our grievance process described in Section 12, and, if unsatisfied, complain to the Data Protection Board of India.
- Nomination. If you wish to nominate another individual to exercise your DPDP rights in the event of your death or incapacity, you may send a written request to the Grievance Officer at grievance@otli.in with your full details, the nominee’s full details and any supporting proof. We will record and honour verified nominations in accordance with the DPDP Act and applicable rules.
6.2When exercising rights, you must not impersonate another person or suppress material information. We may need to verify your identity before responding to a rights request and may decline requests where permitted by law (for example, where disclosure would infringe another person’s rights or conflict with statutory obligations). We respond within timelines prescribed by applicable DPDP Rules.
7. Retention and Deletion
7.1We retain personal data only for as long as the stated purpose requires or law demands, and then erase it or irreversibly de-identify it. We also instruct our Data Processors to erase or de-identify data they hold on our behalf.
7.2Indicative retention patterns, subject to legal requirements and business needs, include:
- Account and profile data: for the life of the account and a limited period thereafter for audit and enforcement.
- KYC and verification records: for a period required by financial and platform-safety regulations and our fraud-prevention obligations.
- Transaction and tax records (including TDS/TCS data): for periods prescribed by tax and company-law record-keeping requirements.
- Grievance and enforcement records: for the time necessary to manage disputes and enforce platform rules.
- Event media: for the term of the media licence plus any agreed tail period under our contracts.
7.3Hosts must delete or cease accessing Guest data after the Event. This obligation binds Hosts under the Master Host Service Agreement and is reinforced by our interface design, which limits access to Guest contact details to the period reasonably necessary to host the Event and then removes or restricts that access within a reasonable time thereafter.
8. Security and Breach Notification
8.1We implement reasonable security safeguards to prevent personal-data breaches, including technical and organisational measures such as encryption in transit, access controls, logging, and separation of address details by design.
8.2If a personal-data breach occurs, we will notify the Data Protection Board of India and affected Data Principals in the form and within the timelines prescribed by the DPDP Rules and other applicable law.
9. Children
9.1The Platform serves adults only. Users must be 18 years or older to hold an account or attend Tables. We do not knowingly process children’s data, undertake tracking or behavioural monitoring of children, or direct advertising at children.
9.2If we become aware that we have inadvertently collected children’s personal data, we will delete such data and take steps to prevent recurrence.
10. Cross-Border Transfers
10.1We store personal data in India by default. If we transfer personal data outside India, we do so only in accordance with the DPDP Act and DPDP Rules, and never to a country or territory that the Central Government has restricted for such transfers. We will ensure that any cross-border transfers are subject to appropriate legal mechanisms and safeguards.
11. Cookies and Similar Technologies
11.1We use cookies and similar technologies to support sign-in, maintain session security, remember preferences, and perform analytics to improve the Platform.
11.2You may manage cookies through your browser or device settings. Where consent applies for non-essential cookies (such as certain analytics or marketing cookies), we will ask for your consent before setting them.
12. Grievance Officer and the Data Protection Board
12.1We have appointed a Grievance Officer to handle privacy and data-protection concerns:
- Grievance Officer: Arjun Dubey, Compliance Lead.
- Email: grievance@otli.in
We acknowledge privacy-related grievances within 48 hours of receipt and provide a resolution or formal status update within 15 business days, consistent with our obligations under the Consumer Protection (E-Commerce) Rules, 2020 and applicable IT and DPDP Rules.
12.2If our response does not satisfy you, you may lodge a complaint with the Data Protection Board of India in accordance with the DPDP Act.
13. Changes to This Policy
13.1We may update this Privacy Policy from time to time. When we make material changes, we will notify Users via the Platform (for example, in-app notice or email) and publish the effective date.
13.2Continued use of the Platform after the effective date of an updated Policy signifies acceptance of the changes. Where law requires fresh consent for new purposes or changes, we will seek such consent before proceeding.