Skip to content

For Airbnbs, OYOs, and hotels

The way you collect guest IDs won't pass the new data law.

Safe Checkin is how properties take guest checkin data — with consent, locked storage, and deletion on a schedule.

  • Airbnbs
  • OYOs
  • Hotels
  • Homestays

What exactly is the problem?

These are the usual ways guest IDs are collected today. The new law treats all three as personal data sitting in the wrong place.

Does your hotel photocopy IDs at check-in?

Copies sit in a drawer. Anyone on shift can pick them up. There is no record of who looked.

Do you collect IDs on WhatsApp for your Airbnb?

Guest Aadhaar lives in a chat thread — on your phone, and on whoever else is in that group.

Do you click ID photos on your phone?

The gallery is not a register. If the phone is lost, every guest ID on it is lost with it.

What the law now asks

Under the DPDP Act, properties that collect guest IDs need these measures at minimum.

Consent and notice

A guest needs to clearly see what data is being collected and why, before they hand it over.

Secure storage

Guest personal data must be stored in a secure, authorised way — encrypted storage and a log of who accessed it. That means it cannot live in a phone gallery or an Excel sheet.

Retention policy

Guest data cannot be stored forever. It needs to be deleted after the time the law requires.

Be ready by

13 May 2027

From this date, the DPDP Act can penalise you for how guest IDs are collected and stored — including photocopies, WhatsApp chats, and your phone gallery.

Failing to keep personal data secure can attract penalties of up to ₹250 crore.

This is where Safe Checkin comes in

You create the booking. Guests upload from a link — no app for them. We handle consent, secure storage, and deletion after the retention period.

Get in touch

Leave your name and number. We'll WhatsApp you within a day.

We'll WhatsApp you on this number.