Zittle← Back to home

Legal

Privacy Policy

Last updated: 21 August 2026

This Privacy Policy explains how Zittle (“Zittle,” “we,” “us,” or “our”), operating at hotels.zittle.in, collects, uses, stores, shares, and protects information when hotels and other hospitality businesses (“Client,” “you,” “your”) use our financial operating system and related services (the “Service”).

Zittle is built for businesses, not consumers. This policy is written with that in mind — most of the data we process belongs to your business, not to an individual end-user. Where we do process personal data (for example, of your staff, guests, or authorized signatories), the relevant sections below apply.

1. Who We Are

Zittle is an AI-powered financial operating system for the hospitality industry. We help hotels reconcile cash inflows across payment sources (OTAs, POS, cash, B2B), and — as our product expands — manage cash outflows, GST, and income tax filing. We are not an accounting software replacement; we integrate with your existing systems (such as Tally and Zoho Books) as an analytical and automation layer on top of them.

For any questions about this policy, contact: support@zittle.in

2. Information We Collect

2.1 Information you provide directly

  • Business and account details: legal entity name, GSTIN, PAN, property details, room count, billing contact
  • Login and authentication credentials
  • Documents you upload or share for reconciliation, GST, or tax purposes (invoices, statements, receipts)
  • Communications with our team (support requests, onboarding calls, emails)

2.2 Information we collect through integrations

With your authorization, Zittle connects to and pulls data from:

  • Bank accounts, via the RBI Account Aggregator ecosystem (e.g., FinVu, CAMS Finserv, OneMoney), through Zittle’s registration as a Financial Information User (FIU) under the Sahamati framework
  • OTAs: MakeMyTrip, Booking.com, Agoda, Goibibo, Cleartrip, Yatra, and other channel/booking sources you connect
  • POS and billing systems used at your property
  • PMS / channel manager platforms (e.g., Channex, eZee)
  • Accounting software you use (e.g., Tally, Zoho Books)
  • Email, where you authorize Zittle to read specific transactional or financial emails (e.g., settlement notices, OTA payout emails) for reconciliation purposes

We only pull data from the sources you explicitly connect and authorize. You can review and revoke these connections at any time.

2.3 Information collected automatically

  • Usage data (features accessed, login times, actions taken in the product)
  • Device and log data (IP address, browser type, timestamps) for security and diagnostics

2.4 Personal data of third parties

If financial or booking records we process contain personal data of your staff or guests (e.g., a guest name on an OTA settlement report), we process that data only as necessary to reconcile and report on your finances, and only on your instructions as the data controller for that information.

3. How We Use Information

We use the information we collect to:

  • Reconcile your revenue against actual cash received across all payment sources
  • Detect and flag discrepancies (e.g., missing or delayed settlements)
  • Prepare GST records, returns, and support ITR / income tax filing
  • Provide the managed accounting service layer currently offered alongside our software (including human review by our team or partner CAs, where applicable)
  • Improve and train the AI models and automation that power reconciliation and anomaly detection, using patterns observed across the operational data we process
  • Communicate with you about your account, service issues, and updates
  • Meet legal, tax, and regulatory obligations
  • Ensure security and prevent fraud or misuse of the Service

We do not use your financial data to build products for or share your data with your competitors, and we do not sell your data.

4. How We Share Information

We share information only in the following circumstances:

  • Service providers and sub-processors: cloud hosting, data processing, and infrastructure partners who process data on our behalf under confidentiality and data-processing obligations
  • Account Aggregator ecosystem participants: banks and AA entities (FinVu, CAMS Finserv, OneMoney, Sahamati and similar), strictly to retrieve the bank data you’ve consented to share
  • Chartered accountants / tax partners, where your engagement includes CA-delivered GST or ITR filing as part of our managed service
  • Your existing accounting software (Tally, Zoho Books), where you’ve connected these for two-way sync
  • Legal and regulatory authorities, where required by law, court order, or valid government request
  • Business transfers, in the event of a merger, acquisition, or sale of assets — you will be notified of any change in ownership or control of your data

We do not share your data with OTAs, or with any third party for their own marketing purposes.

5. Data Storage and Security

  • Financial data is encrypted in transit and at rest.
  • Access to client financial data is restricted to authorized personnel and systems on a need-to-know basis.
  • We maintain audit logs of access to sensitive financial and banking data.
  • Bank data accessed via the Account Aggregator framework is handled per RBI’s AA data-sharing and consent-management requirements, including purpose limitation and consent expiry.
  • No system is completely secure, and we cannot guarantee absolute security, but we are committed to promptly investigating and addressing any suspected breach.

6. Data Retention

We retain your data for as long as your account is active and as needed to provide the Service. After termination, we retain financial and transaction records for the period required under applicable Indian tax and accounting law (generally up to 8 years for GST/tax-related records, unless a longer period applies), after which data is securely deleted or anonymized, except where retention is required by law or for resolving disputes.

7. Your Rights and Choices

You may:

  • Access, correct, or request a copy of the data we hold about your business
  • Revoke any third-party data connection (bank via AA, OTA, email, POS) at any time
  • Request deletion of your data, subject to our legal retention obligations
  • Withdraw consent for AA-based bank data access at any time through the AA consent-management interface

To exercise these rights, contact support@zittle.in. We will respond within a reasonable timeframe as required under applicable law, including India’s Digital Personal Data Protection Act, 2023 (DPDP Act) where it applies to personal data we process.

8. Cross-Border Data Transfer

If any data is processed or stored outside India (e.g., via cloud infrastructure), we take reasonable steps to ensure it receives a comparable level of protection, consistent with applicable Indian law.

9. Children’s Data

The Service is intended for business use and is not directed at individuals under 18. We do not knowingly collect personal data from minors.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-product notice. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

11. Contact Us

Zittle Technologies Private Limited
4th Floor, Cave-6, D Square Co. Working Space,
100ft Road Madhapur, 500081, Kondapur,
Serilingampally, Rangareddy