Legal

Privacy Policy

Last updated: 25 September 2026. What we collect, why, where it goes, and how it is deleted.

TrackMyPG — A product of BuildsInfinity Technologies. · General inquiries: info@trackmypg.com

1. Who We Are

TrackMyPG (“we”, “our”, “us”) is a PG and hostel management platform operated by BuildsInfinity Technologies.. This Privacy Policy explains how we handle personal data across the TrackMyPG website, the PG Owner dashboard, the Tenant Portal, our mobile apps and our APIs.

TrackMyPG is offered to customers in India. We do not market or direct the Service to people in the European Economic Area or the United Kingdom, and we are not set up to take on the obligations that would come with doing so. If you need us to handle personal data under the EU or UK GDPR, please talk to us before signing up rather than assuming we can.

It should be read together with our Terms of Service, Cookie Policy and Refund Policy.

2. Two Very Different Kinds of Data

This distinction runs through the whole policy, so it comes first.

2.1 Customer data — you, the PG Owner

When you sign up for TrackMyPG, we decide what account information is needed to operate the Service and we are responsible for how it is handled. Under India's Digital Personal Data Protection Act, 2023 that is the role of a Data Fiduciary — the role other regimes call a controller. This policy governs that data.

2.2 Workspace data — the tenants, guests and staff you enter

The tenant, guest and staff records you create inside TrackMyPG are your business records. You decide who to record, what to collect about them and why. For that data you generally act as the Data Fiduciary — the role other regimes call a controller — and TrackMyPG acts as a Data Processor: we store and process it on your instructions, solely to provide the Service to you.

We do not decide what tenant data you collect, we do not use it for our own purposes, and we do not sell it. How these roles are formally characterised can depend on the applicable law and on the particular circumstances; whatever the label, the substance is the same — the records are yours, and we handle them for you.

You are responsible for having a lawful basis and the appropriate authority to enter that information and to send communications through TrackMyPG. See section 5 of the Terms of Service. If you are a tenant with a question about your own record, please contact your PG Owner first — the record belongs to them.

3. Information We Collect

3.1 PG Owner account information

  • Full name, business name, business type, email address and phone number
  • A password, stored only as a salted one-way hash — never in readable form
  • Optional profile photo
  • Two-factor authentication settings, where you enable them
  • Your record of accepting these policies at signup: that you accepted, when, and which version of the Terms and Privacy Policy applied at that moment

3.2 Property and operational data you enter

  • Property, room, bed and settings records
  • Tenant and guest records — which typically include name, contact details, address, an ID proof type and number, emergency contact details, stay dates and an optional photo
  • Invoices, rent and deposit records, notices, move-outs and support tickets
  • Staff members you invite, and the roles and permissions you assign them

3.3 Payment information

Subscription and rent payments are processed by Razorpay. Card numbers, UPI credentials and bank credentials are entered on Razorpay's systems and are never received or stored by TrackMyPG. We store the transaction outcome: amount, currency, status, Razorpay payment/order identifiers, and the invoice, subscription or platform service settlement it relates to. For UPI platform service, we also keep a history of the amounts accrued, settled and waived on your account.

3.4 Technical and security information

  • IP address, browser/app platform and time zone at signup and sign-in
  • A random device identifier generated in your browser or app, used for new-device verification and to detect one person creating many accounts
  • Signup attempt records — including failed and blocked attempts — kept for fraud and abuse investigation
  • Security and audit logs of significant account actions
  • Server-side application logs, which may contain IP addresses and request paths

3.5 Website analytics

Analytics scripts run on our public website only if you accept them on the cookie banner. Exactly which ones, and how to change your mind, is set out in the Cookie Policy.

4. Why We Use It

  • To create and operate your account and workspace, and to authenticate you
  • To deliver the features you use — invoicing, payment tracking, reminders, reports and document generation
  • To send transactional messages on your behalf to the tenants and guests in your workspace, by email, SMS and WhatsApp
  • To take subscription and platform service payments and issue receipts
  • To provide support and respond to your requests
  • To detect and investigate fraud, abuse and unauthorised access
  • To meet legal, tax and accounting obligations
  • To understand aggregate website usage — only with your analytics consent

We do not sell personal data, and we do not use the tenant records in your workspace to advertise to anyone.

4.1 The basis we rely on

Where data protection law requires us to identify a legal basis for each purpose, these are the ones we rely on:

PurposeBasis
Creating and operating your account, delivering the features you use, and taking paymentPerformance of our contract with you
Sending transactional messages to the tenants and guests in your workspacePerformance of our contract with you, acting on your instructions as your processor
Support and responding to your requestsPerformance of our contract with you
Detecting and investigating fraud, abuse and unauthorised access, and keeping security logsOur legitimate interest in keeping the Service and its customers secure
Tax, accounting and other statutory recordsCompliance with a legal obligation
Website analyticsYour consent, which you can withdraw at any time

For the tenant, guest and staff records you enter, the basis for collecting them is yours to determine and to hold — see section 2.2.

5. How We Share Information

We do not sell personal data. We may share personal data with trusted service providers that help us operate TrackMyPG — such as providers of hosting and infrastructure, payment processing, communications (email, SMS and WhatsApp), file storage, mapping, and website analytics.

These providers process information only as necessary to provide their services to us or to you, subject to appropriate contractual or legal obligations. Website analytics providers are used only in accordance with your cookie preferences — see our Cookie Policy.

If you would like to know which specific providers process data for your account, contact us at the address in section 13 and we will tell you.

We also operate RoomXplore, our property marketplace. If you choose to publish a listing, the property details you publish become publicly visible, and enquiries from prospective tenants flow into your TrackMyPG workspace. Nothing is published unless you choose to publish it.

Beyond these providers, we disclose personal data only where the law requires it, where it is necessary to establish or defend a legal claim or to protect safety, or as part of a merger or acquisition — in which case this policy continues to apply until you are told otherwise.

6. Security

The measures below are ones we have actually implemented. We do not hold any security certification (such as ISO 27001 or SOC 2) and do not claim one.

  • All traffic to TrackMyPG is served over HTTPS/TLS
  • Passwords are stored as salted bcrypt hashes and are never recoverable
  • Selected sensitive tenant, guest and contact fields are encrypted at rest at the application layer using AES-256-GCM, in addition to the storage encryption provided by our database and file-storage providers
  • Session tokens are HttpOnly cookies, and signing out or revoking sessions invalidates them server-side rather than only in the browser
  • Optional two-factor authentication, plus email OTP verification on new devices
  • Role and permission checks scoped to your properties on every request, so one customer's workspace is not reachable from another's
  • Rate limiting, request validation, and signature verification on payment webhooks
  • Security and audit logging of significant account events

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at info@trackmypg.com.

6.1 If there is a breach

If we become aware of a personal data breach affecting your account or your workspace, we will investigate it, take steps to contain it, and notify you without undue delay, with what we know about what happened, what data was involved, and what we are doing about it. Where a breach affects the tenant, guest or staff records you entered, you are the one who decides whether those individuals must be told — we will give you the information you need to make that decision and to meet your own notification duties. We will also make any report to a regulator that the law requires of us.

7. Retention and Deletion

We keep data for as long as your account is active and you need it to run your business, and afterwards only where we must — for example financial records retained to meet tax and accounting obligations.

Some records are deleted automatically on a fixed schedule:

  • Signup attempt records used for fraud and abuse investigation — deleted automatically 12 months after the attempt.
  • Security and audit logs of account events — deleted automatically after 90 days.
  • One-time passwords, password reset tokens and session refresh tokens — deleted automatically once they expire.
  • Financial and tax records — retained for as long as Indian tax and accounting law requires us to keep them, which is longer than the life of your account.

General server logs are kept only as long as we need them to operate and debug the Service; they are not on a fixed automatic schedule, and we do not use them to build any profile of you.

7.1 Deleting individual records

You can edit or remove tenant, guest, room and similar records from your workspace at any time, directly in the dashboard.

7.2 Deleting your whole account

PG Owners can request full account deletion from Settings → Account Deletion after signing in. The request must be confirmed with an OTP sent to your registered email address, is then reviewed by our administration team, and on approval account access is disabled and a controlled server-side erasure of your workspace begins. You are notified when it completes. Full details are on our account deletion page.

Because each request is reviewed by a person, we do not commit to a fixed number of days for completion. We process approved requests without undue delay.

7.3 What survives deletion

After erasure we may retain a minimal, non-content audit record of the deletion request and its completion, and records we are legally required to keep. The automatic schedules in section 7 continue to apply to anything they cover.

Deleted workspace content is removed from our active systems. It may persist for a limited period in our providers' encrypted backups until those backups expire or are overwritten on their normal cycle, and in records we are required by law to keep. Backups are never used to restore an individual deleted account — only to recover the platform from a failure.

8. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct data that is inaccurate or incomplete — most of it is editable in your account
  • Delete your account and workspace, through the process in section 7.2
  • Export your data — tenant, invoice and report exports are available in the dashboard, and we will help with anything the exports do not cover
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent, such as website analytics
  • Nominate someone to exercise these rights on your behalf if you die or become unable to exercise them yourself — a right given by India's Digital Personal Data Protection Act, 2023. Write to us and we will record your nomination.

To exercise any of these, email info@trackmypg.com from your registered address. We may need to verify your identity before acting.

If you are a tenant or guest: your record was created by a PG Owner who controls it. Please contact them first. If you cannot reach them, contact us and we will pass the request on to the relevant owner.

8.1 Automated decisions

We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you. We do run automated checks that score signup and login attempts for signs of fraud and abuse, but those checks raise the matter for a person to review — they do not by themselves refuse an account. We do not profile you for advertising.

8.2 Complaining to a regulator

Please raise concerns with us first, using section 13.1 — we would rather fix the problem. You also have the right to complain to a data protection authority. In India, that is the Data Protection Board of India, once it is constituted under the Digital Personal Data Protection Act, 2023; until then, complaints under the Information Technology Act, 2000 and the rules made under it may be raised with the appropriate authority. Complaining to us first does not take away that right.

9. Children

TrackMyPG accounts are for businesses and are not offered to anyone under 18. We do not knowingly create an account for a child, and if we learn that we have, we will close it.

Accommodation providers do sometimes house residents under 18, so a PG Owner may record a tenant or guest who is a child. That record is workspace data: the PG Owner decides to collect it and is responsible for having the consent the law requires. Under India's Digital Personal Data Protection Act, 2023 that means verifiable consent from a parent or lawful guardian before a child's personal data is processed.

We do not profile children, serve them advertising, or track their behaviour. We hold their records only to provide the Service to the PG Owner. TrackMyPG does not currently ask you to record whether a tenant is a minor or to evidence guardian consent, so if you accommodate residents under 18, you must obtain and keep that consent yourself before entering their details.

10. International Transfers

TrackMyPG is operated from India and serves customers primarily in India. Some of the service providers described in section 5 operate globally, so data may be processed outside your country of residence. Where that happens, we seek to use established providers that offer data protection terms in their standard agreements, and we share only what that provider needs to perform its function. We will comply with any restrictions on cross-border transfers that apply to us as the relevant provisions of Indian law are brought into force.

Your data is stored and processed principally in India. Because the Service is offered to customers in India, we do not undertake the transfer arrangements that EU or UK law would require for data coming from those regions, and we will not represent that such an arrangement is in place unless it has actually been signed. See section 1.

11. Changes to This Policy

We may update this policy. Each version carries an effective date — this one is 25 September 2026 — and the version in force when you signed up is recorded against your account.

For minor changes — clarifications, corrections, a new provider in the same category — we update this page and its effective date.

For material changes — a new purpose for your data, a new category of processing, or anything that meaningfully changes what we do with it — we will notify registered PG Owners by email before the change takes effect. Where the change depends on your consent, or where the law requires it, we will ask you to review and acknowledge the updated policy rather than treating continued use as agreement.

12. Applicable Law

We aim to handle personal data in line with the Indian Information Technology Act, 2000 and rules made under it, and the Digital Personal Data Protection Act, 2023 as its provisions are brought into force. Any dispute about this policy is governed by Indian law.

We do not hold ourselves out as complying with the EU or UK GDPR, and we have not appointed a representative in those regions. That is a statement about our obligations, not about your rights here: the rights in section 8 are offered to every user of TrackMyPG regardless of where they live.

13. Contact Us

Email: info@trackmypg.com

Operator: BuildsInfinity Technologies.

Address: Noida, Uttar Pradesh, India

Phone: +91 7970370554

13.1 Privacy and grievance requests

To exercise any of the rights in section 8, or to raise a complaint about how we have handled personal data, email info@trackmypg.com with “Privacy request” or “Grievance” in the subject line. Tell us what you are asking for and the email address or phone number on the account, so we can find the right record.

We acknowledge these requests and respond in accordance with applicable law. We may need to verify your identity first — we will not act on a request to export or erase an account from someone we cannot confirm is entitled to make it.

If you are a tenant, guest or staff member and your request concerns a record a PG Owner created about you, please contact that PG Owner first — the record is theirs and they can act on it directly. If you cannot reach them, write to us at the address above and we will pass the request on.

© 2026 TrackMyPG. All rights reserved.

Join 500+ PG owners using TrackMyPG

Ready to Simplify Your
PG Management?

All plans include a 7-day trial, activated with a one-time ₹1 payment via Razorpay. No auto-renewal. Set up your PG in under 5 minutes and see the difference.

✓ 7-day trial✓ ₹1 activation via Razorpay✓ No auto-renewal✓ 24/7 support