Privacy Policy

Last updated: 3 July 2026 · Effective: 3 July 2026

This Privacy Policy explains how Timewheel Internet Private Limited (CIN: U62012OD2026PTC052654, GSTIN: 21AAMCT8270C1ZF) ("Book A Sloth", "we", "us", or "our"), a company incorporated in India under the Companies Act, 2013 with its registered office at Ground Floor, Holding No-55, Ward No-19, Natapada, Jajpur Road, Byasanagar, District Jajpur, Odisha – 755019, India, collects, uses, shares, and protects your personal data when you use the Book A Sloth platform, website, and related services (the "Platform").

We are committed to processing your personal data in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules), and, where it applies, the EU General Data Protection Regulation (GDPR). Under the DPDP Act we act as the Data Fiduciary that decides how and why your personal data is processed, and you are the Data Principal the data relates to.

We provide this Policy in English. If you would like it in any other language listed in the Eighth Schedule to the Constitution of India, please contact our Grievance Officer (Section 11).

By using the Platform you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Platform.

1. Who this Policy applies to

The Platform serves two main types of users, and we collect data from both:

  • Hosts (creators) — individuals or businesses who publish services, accept bookings, sell digital products, and receive payouts.
  • Guests — individuals who discover hosts, book appointments, buy products, and make payments. Guests may book either by creating an account or by verifying their email through a one-time password (OTP) without an account.

This Policy also applies to visitors who browse public host profiles without booking.

2. The personal data we collect

2.1 Data you provide directly

Account & profile data (Hosts and registered Guests): name, email address, role (host/guest), username, bio, tagline, profession, profile and cover images, and social media links.

Booking data (Guests): name, email address, phone number, the service booked, the scheduled date and time, and any notes you add to a booking. Guests booking without an account provide name, email, and phone at checkout.

Verification data: one-time passwords (OTPs) sent to your email for booking confirmation, login, or password reset. OTPs are short-lived and stored only until they expire.

Reviews: the rating, comment, and display name you submit after a completed booking.

Communications: messages, support requests, and feedback you send us.

2.2 Data we collect automatically

Usage and device data: when you use the Platform we may collect log data such as IP address, browser type, device information, pages visited, and timestamps.

Cookies and similar technologies: see Section 8.

2.3 Data from third parties

Payment data: when you pay, our payment processor Razorpay collects and processes your card, UPI, netbanking, or wallet details. We do not receive or store your full payment instrument details. We only receive a transaction reference (e.g. a Razorpay payment ID), the amount, and the payment status. See Section 6.

Google Calendar (Hosts only): if a host connects Google Calendar, we receive OAuth access and refresh tokens to read availability and create calendar events / meeting links on the host's behalf. We use these tokens only to provide the calendar and meeting-scheduling features.

Book A Sloth's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data for advertising, do not sell it, and do not transfer it to third parties except as necessary to provide the booking and scheduling features, to comply with applicable law, or as part of a merger or acquisition.

Image storage: images you upload (profile, cover, product, and service images) are stored and served through Supabase Storage.

2.4 Marketing & contact data

If you opt in, we maintain contact records (email, phone, name, contact type) to send campaigns and notifications. We track your email and WhatsApp opt-in/opt-out status and honour suppression requests.

We do not knowingly collect special-category data and ask that you do not submit it through the Platform.

3. How we use your data and our legal basis

PurposeExamplesLegal basis (DPDP / GDPR)
Provide the PlatformCreate accounts, publish services, process bookings, generate meeting linksPerformance of a contract; consent (DPDP)
Payments & payoutsProcess payments via Razorpay, settle host payouts, maintain financial recordsContract; legal obligation
Verification & securitySend OTPs, prevent fraud, secure accountsLegitimate interests; consent
CommunicationsBooking confirmations, reminders, reschedule notices, password resetsContract; consent
MarketingEmail/WhatsApp campaigns and offers (only if you opt in)Consent
Reviews & ratingsDisplay feedback on host profilesContract; legitimate interests
Legal & accountingTax, GST, double-entry financial records, dispute handlingLegal obligation
Improve the PlatformAnalytics, troubleshooting, feature developmentLegitimate interests; consent

We will not use your personal data for a materially different purpose without informing you and, where required, obtaining your consent.

4. How we share your data

We share personal data only as needed to run the Platform:

  • Between hosts and guests. When you book a service, the host receives your name, email, phone, scheduled time, and booking notes so they can deliver the service. Hosts must use this data only to fulfil the booking.
  • Service providers (processors) who act on our instructions: Razorpay (payments), Supabase (database, authentication, and file/image storage), Google (calendar and meeting links), our email/SMTP provider (transactional and campaign email), and, where enabled, WhatsApp/messaging providers (notifications and campaigns).
  • Legal and regulatory authorities when required by law, court order, or to protect our rights, users, or the public.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

We do not sell your personal data.

Some of our processors may store or process data outside India. Where personal data is transferred outside India, we do so subject to any requirements or restrictions the Central Government may specify under the DPDP Act and DPDP Rules, and, for EU data, using GDPR-compliant transfer mechanisms.

5. Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy:

  • Account and profile data — while your account is active and for a reasonable period afterwards.
  • Booking, payment, and financial records — retained as long as required to meet tax, accounting, and legal obligations under Indian law.
  • OTPs — deleted shortly after they expire.
  • Marketing contact data — until you withdraw consent or opt out.
  • Processing and security logs — retained for at least one year, as required by the DPDP Rules and to detect, investigate, and prevent unauthorised access.

When data is no longer needed, we delete or anonymise it.

6. Payments and PCI-DSS

All payments on the Platform are processed by Razorpay, a PCI-DSS compliant payment gateway. Your card, UPI, netbanking, and wallet details are entered directly with Razorpay and are governed by Razorpay's privacy policy. Book A Sloth does not collect, see, or store your full payment credentials. We retain only transaction metadata (payment ID, amount, status) needed to confirm bookings, issue payouts, and keep accurate financial records.

7. Your rights

7.1 Under the DPDP Act (all users in India)

As a Data Principal you have the right to: access a summary of the personal data we process about you and the processing activities; request correction, completion, or updating of inaccurate or incomplete data; request erasure of data that is no longer needed for the purpose it was collected; nominate another person to exercise your rights in the event of death or incapacity; and readily available means of grievance redressal (Section 11).

You may withdraw your consent at any time, and withdrawing it will be as easy as giving it; this does not affect processing carried out before withdrawal. Where a registered Consent Manager is available, you may also give, manage, review, and withdraw your consent through it.

If you are not satisfied with how we handle your request or grievance, you may make a complaint to the Data Protection Board of India.

7.2 Under the GDPR (users in the EU/EEA)

If you are in the EU/EEA, you also have the right to data portability, the right to object to or restrict processing, the right not to be subject to solely automated decisions with legal effects, and the right to lodge a complaint with your local supervisory authority.

7.3 How to exercise your rights

Contact us at [email protected] (or the Grievance Officer in Section 11). We will respond within the timeframes required by applicable law and, for grievances, within 90 days as required by the DPDP Rules. We may ask you to verify your identity before acting on a request.

8. Cookies and tracking

We use cookies and similar technologies to:

  • Keep you signed in — authentication tokens and session cookies are essential for the Platform to work.
  • Remember preferences — such as theme and settings.
  • Understand usage — basic analytics to improve performance and features.

Essential cookies are necessary for the Platform to function and cannot be switched off. You can control non-essential cookies through your browser settings; blocking some cookies may affect how the Platform works. Where required by law, we ask for your consent before placing non-essential cookies.

9. Data security

We use technical and organisational measures to protect your data, including encrypted connections (HTTPS), encryption or obfuscation of stored data where appropriate, access controls, row-level security on our database, restricted administrative access, monitoring and logging to detect unauthorised access, backups, contractual security obligations on our processors, and storing payment data only with our PCI-DSS compliant processor. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs, we will intimate each affected Data Principal without delay, and notify the Data Protection Board of India without delay and provide a detailed report within 72 hours of becoming aware of the breach, as required by the DPDP Act and DPDP Rules.

10. Children

The Platform is not intended for children under the age of 18. We do not knowingly process a child's personal data without verifiable consent from a parent or lawful guardian as required by the DPDP Act. We do not carry out tracking, behavioural monitoring, profiling, or targeted advertising directed at children. If you believe a child has provided us data, contact us and we will delete it.

11. Grievance Officer and contact

In accordance with the DPDP Act and applicable Indian law, you may contact our Grievance Officer for any concern about your personal data:

  • Grievance Officer: Shubham Narendra Datarkar
  • Email: [email protected]
  • Phone: +91 8637758344
  • Registered office: Ground Floor, Holding No-55, Ward No-19, Natapada, Jajpur Road, Byasanagar, District Jajpur, Odisha – 755019, India
  • Operations office: #6, 2nd Floor, Eureka Coworking, Mate Square, Nagpur, Maharashtra

We will acknowledge and address grievances within the time required by the DPDP Rules (currently 90 days). For GDPR matters, you may also contact us at the same email. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India or your local data protection authority.

12. Changes to this Policy

We may update this Policy from time to time. We will post the revised version with a new "Last updated" date and, for material changes, provide additional notice. Your continued use of the Platform after changes take effect means you accept the updated Policy.

Operated by Timewheel Internet Private Limited · CIN U62012OD2026PTC052654 · GSTIN 21AAMCT8270C1ZF