
We use cookies for analytics & marketing. Essential analytics always run — you can decline marketing & ad cookies.
Last updated: 3 July 2026 · Effective: 3 July 2026
This Privacy Policy explains how Timewheel Internet Private Limited (CIN: U62012OD2026PTC052654, GSTIN: 21AAMCT8270C1ZF) ("Book A Sloth", "we", "us", or "our"), a company incorporated in India under the Companies Act, 2013 with its registered office at Ground Floor, Holding No-55, Ward No-19, Natapada, Jajpur Road, Byasanagar, District Jajpur, Odisha – 755019, India, collects, uses, shares, and protects your personal data when you use the Book A Sloth platform, website, and related services (the "Platform").
We are committed to processing your personal data in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules), and, where it applies, the EU General Data Protection Regulation (GDPR). Under the DPDP Act we act as the Data Fiduciary that decides how and why your personal data is processed, and you are the Data Principal the data relates to.
We provide this Policy in English. If you would like it in any other language listed in the Eighth Schedule to the Constitution of India, please contact our Grievance Officer (Section 11).
By using the Platform you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Platform.
The Platform serves two main types of users, and we collect data from both:
This Policy also applies to visitors who browse public host profiles without booking.
2.1 Data you provide directly
Account & profile data (Hosts and registered Guests): name, email address, role (host/guest), username, bio, tagline, profession, profile and cover images, and social media links.
Booking data (Guests): name, email address, phone number, the service booked, the scheduled date and time, and any notes you add to a booking. Guests booking without an account provide name, email, and phone at checkout.
Verification data: one-time passwords (OTPs) sent to your email for booking confirmation, login, or password reset. OTPs are short-lived and stored only until they expire.
Reviews: the rating, comment, and display name you submit after a completed booking.
Communications: messages, support requests, and feedback you send us.
2.2 Data we collect automatically
Usage and device data: when you use the Platform we may collect log data such as IP address, browser type, device information, pages visited, and timestamps.
Cookies and similar technologies: see Section 8.
2.3 Data from third parties
Payment data: when you pay, our payment processor Razorpay collects and processes your card, UPI, netbanking, or wallet details. We do not receive or store your full payment instrument details. We only receive a transaction reference (e.g. a Razorpay payment ID), the amount, and the payment status. See Section 6.
Google Calendar (Hosts only): if a host connects Google Calendar, we receive OAuth access and refresh tokens to read availability and create calendar events / meeting links on the host's behalf. We use these tokens only to provide the calendar and meeting-scheduling features.
Book A Sloth's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data for advertising, do not sell it, and do not transfer it to third parties except as necessary to provide the booking and scheduling features, to comply with applicable law, or as part of a merger or acquisition.
Image storage: images you upload (profile, cover, product, and service images) are stored and served through Supabase Storage.
2.4 Marketing & contact data
If you opt in, we maintain contact records (email, phone, name, contact type) to send campaigns and notifications. We track your email and WhatsApp opt-in/opt-out status and honour suppression requests.
We do not knowingly collect special-category data and ask that you do not submit it through the Platform.
| Purpose | Examples | Legal basis (DPDP / GDPR) |
|---|---|---|
| Provide the Platform | Create accounts, publish services, process bookings, generate meeting links | Performance of a contract; consent (DPDP) |
| Payments & payouts | Process payments via Razorpay, settle host payouts, maintain financial records | Contract; legal obligation |
| Verification & security | Send OTPs, prevent fraud, secure accounts | Legitimate interests; consent |
| Communications | Booking confirmations, reminders, reschedule notices, password resets | Contract; consent |
| Marketing | Email/WhatsApp campaigns and offers (only if you opt in) | Consent |
| Reviews & ratings | Display feedback on host profiles | Contract; legitimate interests |
| Legal & accounting | Tax, GST, double-entry financial records, dispute handling | Legal obligation |
| Improve the Platform | Analytics, troubleshooting, feature development | Legitimate interests; consent |
We will not use your personal data for a materially different purpose without informing you and, where required, obtaining your consent.
We share personal data only as needed to run the Platform:
We do not sell your personal data.
Some of our processors may store or process data outside India. Where personal data is transferred outside India, we do so subject to any requirements or restrictions the Central Government may specify under the DPDP Act and DPDP Rules, and, for EU data, using GDPR-compliant transfer mechanisms.
We keep personal data only for as long as necessary for the purposes described in this Policy:
When data is no longer needed, we delete or anonymise it.
All payments on the Platform are processed by Razorpay, a PCI-DSS compliant payment gateway. Your card, UPI, netbanking, and wallet details are entered directly with Razorpay and are governed by Razorpay's privacy policy. Book A Sloth does not collect, see, or store your full payment credentials. We retain only transaction metadata (payment ID, amount, status) needed to confirm bookings, issue payouts, and keep accurate financial records.
7.1 Under the DPDP Act (all users in India)
As a Data Principal you have the right to: access a summary of the personal data we process about you and the processing activities; request correction, completion, or updating of inaccurate or incomplete data; request erasure of data that is no longer needed for the purpose it was collected; nominate another person to exercise your rights in the event of death or incapacity; and readily available means of grievance redressal (Section 11).
You may withdraw your consent at any time, and withdrawing it will be as easy as giving it; this does not affect processing carried out before withdrawal. Where a registered Consent Manager is available, you may also give, manage, review, and withdraw your consent through it.
If you are not satisfied with how we handle your request or grievance, you may make a complaint to the Data Protection Board of India.
7.2 Under the GDPR (users in the EU/EEA)
If you are in the EU/EEA, you also have the right to data portability, the right to object to or restrict processing, the right not to be subject to solely automated decisions with legal effects, and the right to lodge a complaint with your local supervisory authority.
7.3 How to exercise your rights
Contact us at [email protected] (or the Grievance Officer in Section 11). We will respond within the timeframes required by applicable law and, for grievances, within 90 days as required by the DPDP Rules. We may ask you to verify your identity before acting on a request.
We use cookies and similar technologies to:
Essential cookies are necessary for the Platform to function and cannot be switched off. You can control non-essential cookies through your browser settings; blocking some cookies may affect how the Platform works. Where required by law, we ask for your consent before placing non-essential cookies.
We use technical and organisational measures to protect your data, including encrypted connections (HTTPS), encryption or obfuscation of stored data where appropriate, access controls, row-level security on our database, restricted administrative access, monitoring and logging to detect unauthorised access, backups, contractual security obligations on our processors, and storing payment data only with our PCI-DSS compliant processor. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs, we will intimate each affected Data Principal without delay, and notify the Data Protection Board of India without delay and provide a detailed report within 72 hours of becoming aware of the breach, as required by the DPDP Act and DPDP Rules.
The Platform is not intended for children under the age of 18. We do not knowingly process a child's personal data without verifiable consent from a parent or lawful guardian as required by the DPDP Act. We do not carry out tracking, behavioural monitoring, profiling, or targeted advertising directed at children. If you believe a child has provided us data, contact us and we will delete it.
In accordance with the DPDP Act and applicable Indian law, you may contact our Grievance Officer for any concern about your personal data:
We will acknowledge and address grievances within the time required by the DPDP Rules (currently 90 days). For GDPR matters, you may also contact us at the same email. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India or your local data protection authority.
We may update this Policy from time to time. We will post the revised version with a new "Last updated" date and, for material changes, provide additional notice. Your continued use of the Platform after changes take effect means you accept the updated Policy.
Operated by Timewheel Internet Private Limited · CIN U62012OD2026PTC052654 · GSTIN 21AAMCT8270C1ZF