Help

Frequently Asked Questions

Last updated: 23 July 2026

OurGate exists because two Indian laws pull hotels in different directions at once. This page explains, in plain language, what that means and how OurGate resolves it, for guests, for property owners, and precisely enough for anyone checking our legal position.

Why does a hotel even need to collect my ID?

It's a legal requirement, not a hotel preference. Indian police acts and state tourism regulations require every hotel/homestay to record a Guest Registration Card with an identity document for each guest, and to be able to produce that record to police or state authorities on request. Failing to keep or produce these records can expose the property to penalties under the Bharatiya Nyaya Sanhita (BNS), Sections 206 and 210 (omission to produce a document or give information to a public servant when legally bound to do so). For foreign nationals, the property must additionally file a C-Form with the local FRRO/police within 24 hours of arrival, under the Foreigners Act.

Doesn't India also have a data privacy law that says the opposite?

Yes. The Digital Personal Data Protection Act, 2023 (DPDPA) gives you rights over your personal data, including the right to request its erasure, and requires anyone holding your data to collect and retain only what's necessary. Read on its own, that looks like it conflicts with a police-act rule that says "retain guest ID records." It doesn't, in practice: the DPDPA itself recognizes that data held to meet another legal obligation is exempt from on-demand erasure until that obligation is satisfied (Section 8 and the Act's exemptions for compliance with law). OurGate is built to satisfy both laws at the same time, not to pick one over the other.

How does OurGate resolve the conflict?

By splitting the roles. Under the DPDPA, the hotel is the Data Fiduciary (the party legally obligated to collect your ID and able to answer to police or regulators for it). OurGate acts as the Data Processorand custodian: we hold the document securely on the hotel's behalf, for exactly as long as applicable Indian hospitality and police regulations require, and nothing longer. The hotel remains fully compliant with its retention duty because the record still exists and can still be produced, they just don't hold an unrestricted copy sitting in their own systems indefinitely.

For Guests

What information do you collect from me?

Your name, phone number, and a copy of the identity document you choose to upload (such as Aadhaar, passport, driving licence, or voter ID), the same information the hotel is legally required to record for every guest.

Who can see my document?

Only hotel staff with the specific permission to view guest documents, and only while your stay is active. Every time someone views your document, it's logged: who, when, and from where. Once you check out, hotel staff lose standing access; from that point, viewing your document again requires a specific, justified reason (such as a police or legal request) and is separately approved and logged.

How long do you keep my document?

For as long as applicable Indian hospitality and police regulations require the hotel to retain guest records, no longer. The exact duration depends on factors such as the property's state and whether you're an Indian or foreign national.

Can I get my document deleted?

Yes. You can request deletion at any time, through your verification link or by contacting us directly. Here's exactly what happens next:
  1. We log your request immediately, with a timestamp.
  2. We carry out due diligence, checking with the hotel you stayed at and, where relevant, confirming there is no active legal, police, or regulatory requirement still requiring your record to be retained.
  3. Once that check is complete, we delete your document and personal data from our systems and confirm to you, in writing, once it's done.
  4. If a legal retention requirement is still active, we'll tell you that plainly, along with why, rather than deleting your data while a hotel or authority may still be legally entitled to it.

Is this optional, or do I have to upload my ID?

It's a legal requirement for the hotel, not an OurGate preference. Indian law requires every guest's identity to be recorded before check-in. What OurGate changes is what happens to that document afterwards: it's held securely, access is restricted and logged, and you have a clear path to request its deletion.

For Hotels & Property Owners

Why can't my staff access guest documents whenever they want, like before?

Because standing, unrestricted access to guest ID copies is exactly the kind of data exposure the DPDPA is designed to reduce, and it's also your biggest liability if a device is lost, an employee turns over, or a breach occurs. OurGate takes custody of the documents instead, so your property meets its legal retention obligation without you having to secure, restrict, and audit access to sensitive ID copies yourselves.

If OurGate holds the data, am I still meeting my police/state retention obligation?

Yes. You remain the Data Fiduciary (the legally responsible party), and the record still exists and is retrievable for exactly the period your local regulations require. OurGate is your Data Processor, retaining the record on your behalf and producing it when you have a legitimate, documented need (such as a police request), rather than the record disappearing or your compliance duty being transferred away.

What if police or a court asks us for a guest's document after checkout?

Contact OurGate support with the request. Because this is a specific, legally justified need rather than routine access, we verify and grant a time-limited, logged unlock so you can retrieve exactly the document requested.

What's OurGate's role vs. ours, in one line?

You collect the document and remain accountable for the guest relationship and your regulatory obligations as Data Fiduciary; OurGate stores it securely, limits and logs who can view it, enforces the retention period, and handles deletion requests as Data Processor, so the compliance burden sits with us, not you.

What happens if a hotel doesn't comply

These aren't abstract rules. Both sides carry real, separately enforceable penalties, and a hotel can be exposed on both at once if guest records aren't handled correctly.

Penalties for not maintaining/producing guest records (police & state regulations)

Under the Bharatiya Nyaya Sanhita (BNS), Sections 206 and 210 (the successors to IPC Section 176), a property that omits to keep or produce guest records when legally bound to furnish them to a public servant (such as police during a verification drive or investigation) can face criminal liability, including fine and/or imprisonment. Separately, state police acts and lodging-house/tourism regulations carry their own administrative penalties, which can include fines, suspension of the property's registration or licence, and, in states where hotel operation requires police/tourism department clearance, non-renewal of that clearance. For foreign guests specifically, failing to file the C-Form within 24 hours under the Foreigners Act, 1946 (and the 2016 amendment to the Foreigners Order) can independently expose the property to imprisonment of up to five years and a fine under Section 14 of that Act, on top of any state-level penalty.

Official references: MHA Foreigners Division, Bureau of Immigration (C-Form/e-FRRO).

Has this actually been enforced against a hotel before?

Yes. In Vijukumar v. State of Kerala, the Kerala High Court examined police invoking the Foreigners Act against a lodging-house keeper for failing to comply with guest-registration requirements, confirming that non-compliance with these registration obligations is a live, prosecutable offence, not just a paperwork formality. Separately, the pre-independence Sarai Act, 1867, still in force in several states, is regularly cited by police to demand guest-register production, and licence suspensions over missing or incomplete guest records are a routine, ongoing enforcement reality for Indian hotels, independent of any DPDPA question.

Penalties for mishandling guest data (DPDPA)

Under the Digital Personal Data Protection Act, 2023, a Data Fiduciary that fails to implement reasonable security safeguards, or otherwise breaches its obligations under the Act, can be penalised up to ₹250 crore per instance under the Schedule referenced in Section 33 (the highest tier in the Act, reserved for failures like a data breach caused by inadequate security). Smaller penalties apply to other lapses, such as failing to notify the Data Protection Board of a breach or failing to fulfil a data principal's request (like an erasure request) without lawful justification. These penalties apply to the Data Fiduciary; in a direct guest-ID-collection setup, that's the hotel itself, not a vendor storing the data on their behalf.

Official reference: DPDP Act, 2023 (PDF, meity.gov.in), Section 33 and Schedule.

Can a hotel actually face both at once?

Yes, and this is exactly the trap a hotel falls into without a system like OurGate: keep guest ID copies indefinitely, unrestricted, on a shared office computer or drive to be safe on the retention side, and you've likely created a DPDPA exposure (excess retention, inadequate access control, no ability to action an erasure request). Delete or restrict access too aggressively to be safe on the DPDPA side, and you risk not being able to produce a record police ask for, exposing the property under BNS/state regulations instead. OurGate's custodian model exists specifically to avoid this trap: retaining exactly what the law requires, for exactly as long as required, with logged and restricted access throughout.

Is the DPDPA side just a theoretical risk right now?

Not for much longer. The DPDPA and its Rules are rolling out in phases: the Data Protection Board was established from 13 November 2025, the Board's enforcement powers and penalty mechanism activate from 13 November 2026, and full compliance obligations (consent, notice, data-principal rights, breach reporting, and the rest) become mandatory by 13 May 2027. The penalty structure, up to ₹250 crore per instance, is already written into the Act itself, not a future proposal; what's still ahead is the Board actively investigating and penalising breaches. That gives hotels a genuine window to get their guest-data handling in order before enforcement is fully live, rather than a reason to delay.

The legal basis, precisely

For anyone who needs the exact citations rather than the plain-language summary above:

  • Retention obligation: State police acts, state tourism/lodging-house regulations, and, for foreign nationals, the Foreigners Act, 1946 (C-Form filing within 24 hours of arrival). Non-production of required records to a public servant can attract liability under Bharatiya Nyaya Sanhita (BNS) Sections 206 and 210 (successors to IPC Section 176).
  • Data protection obligation: Digital Personal Data Protection Act, 2023, including the data principal's right to erasure, the data fiduciary's duty of purpose limitation and storage limitation, and the Act's recognition that retention required to comply with another law is not subject to on-demand erasure until that obligation lapses. Read the official Act (PDF, meity.gov.in).
  • How OurGate reconciles the two: by acting as Data Processor/custodian on the hotel's behalf, restricting standing access to the retention window required by law, and actioning deletion requests once no active legal retention requirement remains, as described above and in our Privacy Policy and Terms & Conditions.

Still have a question?

Contact us at urbanescape09@gmail.com or by phone at 9958780399. For formal data access, deletion, or grievance requests, the same contact also reaches our Grievance Officer under the DPDPA and applicable IT Rules.