Privacy notice
Carion Labs · last reviewed 19 September 2026 · questions to carionlabs@gmail.com
Carion is property-management software for hostels, hotels, guest houses and homestays. Two kinds of people give us data: hosts (the properties that use Carion and their staff) and guests (people who stay at those properties). This notice covers both. It is written for India’s Digital Personal Data Protection Act, 2023 and follows the same principles for everyone else.
Who is responsible for what
- For host account data (your name, email, business details, billing), Carion Labs is the data fiduciary.
- For guest data, the property you stay at is the data fiduciary: it decides what to collect and why, within the law. Carion Labs processes that data on the property’s instructions, as its data processor. Each property is separate — one property never sees another property’s guests.
What is collected, and why
- Guests: name, phone, email, nationality, address and a government ID, because Indian hospitality rules require a guest register and, for foreign nationals, a Form C filing with the Foreigners Regional Registration Office. For Aadhaar we read the card’s QR code and keep only the outcome of UIDAI’s signature check and the last four digits — never the full number and never a copy of the card. For a passport, driving licence or voter ID the number and, at check-in, a scan are kept. Also your booking dates, room or bed, charges and payments, and anything you order or request through the guest portal.
- Hosts and staff: name, email, role, what you do in the app (an activity log per property), and billing details for the Carion subscription.
- Not collected: card numbers (Razorpay handles them), precise location, advertising identifiers.
Where it is kept and how it is protected
Data lives in a managed PostgreSQL database in Mumbai, India (Supabase, AWS ap-south-1). ID scans are stored in a private bucket with time-limited access links. Everything is encrypted in transit and at rest. Access inside a property is controlled by roles the owner sets; the Carion team only sees a property’s data when invited onto its team for support. An encrypted backup is taken every night and kept for 35 days outside the primary database.
Who else receives data
Only providers needed to deliver a function, each for that function alone:
- Resend — transactional email (booking confirmation, portal link, team invites).
- Razorpay — online payments; they receive amount, reference and contact for the receipt.
- Vercel — hosts the application (Singapore); it stores no data of its own.
- Aiosell / Beds24 — the property’s channel manager, for availability and rates out and OTA bookings in.
- Groq and Google Gemini (paid tier, no training on inputs) — the Cari assistant, which only sees the question asked and the operational figures needed to answer it, and passport text extraction for Form C.
- Telegram — operational alerts to a chat the property links itself.
Nothing is sold, shared with advertisers, or used to train AI models.
How long it is kept
- Guest ID scans (passport, driving licence, voter ID) are deleted automatically after the property’s retention period (90 days after check-out unless the property sets otherwise). No Aadhaar image is ever stored. The register entry — name, document type and number (masked for Aadhaar) — is kept as the law requires.
- Bookings, folios and payments are kept for accounting and tax purposes.
- A guest’s credential wallet (saved identity details for faster check-in) is kept until the guest deletes it, and is released to a property only with the guest’s consent for that stay.
- Host accounts and their property data are deleted on request at the end of a contract.
Your rights
You can ask what we hold about you, have it corrected, have it erased where the law does not require us to keep it, and withdraw consent you gave (for example for your credential wallet). Guests should contact the property they stayed at first, since it is the fiduciary for their stay; either way, write to carionlabs@gmail.com and we will respond within 30 days. If you are not satisfied you may complain to the Data Protection Board of India.
Cookies
Carion sets one session cookie to keep you signed in (HTTP-only, secure, 7-day idle expiry) and remembers per-device preferences such as your active property. There is no advertising or cross-site tracking.
Changes
When what we collect, where it goes or how long we keep it changes, this page changes in the same release and the review date above moves.