Cookie Policy

What we store on your device, why, and how to control it

COOKIE POLICY

AtithiBhaarat — Hotel Partner Platform (Website & Mobile Application)

Effective Date: 10 June 2026 Last Updated: 10 August 2026 Version: 1.0


1. INTRODUCTION

This Cookie Policy explains how AtithiBhaarat DigiSolutions Private Limited ("AtithiBhaarat", "we", "us") uses cookies and similar tracking technologies on the website at https://atithibhaarat.com and within the AtithiBhaarat mobile and web applications (together, the "Platform").

It forms part of the AtithiBhaarat Privacy Policy and should be read alongside the Cache & Data Retention Policy.

By continuing to use the Platform after setting your preferences in the consent banner, you agree to the use of cookies in the categories you have permitted. Strictly necessary cookies operate without consent, as the Platform cannot function without them.


2. WHAT ARE COOKIES AND SIMILAR TECHNOLOGIES

2.1 Cookies are small text files placed on a device when a website is visited. They allow the site to recognise the device, remember preferences, and understand how the site is being used.

2.2 First-party cookies are set by AtithiBhaarat. Third-party cookies are set by another organisation whose service is embedded in our Platform.

2.3 Session cookies are erased when the browser is closed. Persistent cookies remain for a stated period or until deleted.

2.4 Similar technologies used by us include:

TechnologyWhat It IsWhere Used
Local storage and session storageBrowser-based key-value stores, larger and more durable than cookiesWeb application
Software development kits (SDKs)Embedded code libraries that record app usage and crashesMobile application
Mobile advertising identifiersDevice-level identifiers, being the Google Advertising ID on Android and the Identifier for Advertisers on iOSMobile application, only if you consent to marketing
Pixels and web beaconsTiny transparent images that record whether a page or email was openedWebsite; email communications
Server-side session identifiersAn opaque token linking a browser to an authenticated sessionWeb application

Throughout this Policy, the word "cookies" is used to refer to all of the above.


3. WHY WE USE COOKIES

We use cookies to:

  • keep a Hotel Partner securely signed in and prevent session hijacking;
  • protect against fraud, credential stuffing, bots and automated abuse;
  • remember language, property selection, dashboard layout and accessibility settings;
  • balance server load and route requests correctly;
  • measure which features are used, so that the Platform can be improved;
  • identify and diagnose errors and performance problems;
  • record and honour your cookie consent choices;
  • deliver marketing communications, only where you have separately opted in.

4. CATEGORIES OF COOKIES WE USE

Current state. At present the Platform runs no analytics, advertising or support-chat vendor, and sets no third-party cookie of any kind. The tables below list only what is genuinely active today. This Policy will be updated, and a fresh consent choice sought, before any analytics, marketing or support-widget tool is switched on.

4.1 Strictly Necessary Cookies — always active, consent not required

These are essential for the Platform to work. Without them, sign-in, security and core check-in functions fail. They cannot be switched off through our consent banner.

Cookie / ItemProviderPurposeTypeDuration
atithi_sessionAtithiBhaaratMaintains the authenticated session (Hotel Partner dashboard)First-party, HttpOnly, SecureSession
atithi_refreshAtithiBhaaratRenews the session without re-loginFirst-party, HttpOnly, Secure7 days
atithi_csrfAtithiBhaaratPrevents cross-site request forgeryFirst-partySession
atithi_consentAtithiBhaaratRecords the choice made in the consent bannerFirst-party12 months

4.2 Functional Cookies — consent required

These remember choices you make so the Platform behaves the way you expect.

Cookie / ItemProviderPurposeDuration
atithi_langAtithiBhaaratStores language preference12 months
atithi_propertyAtithiBhaaratRemembers the last property selected, for multi-property groups6 months
atithi_themeAtithiBhaaratStores display and accessibility preferences12 months

If declined: the Platform still works, but preferences reset on each visit.

4.3 Analytics, Performance and Marketing Cookies — not currently in use

We do not presently run any analytics, crash-reporting, advertising or marketing pixel on the Platform, and no such cookie or identifier is set. If this changes, this Policy will be updated in advance, the tables above will name the provider and duration, and fresh, specific consent will be sought through the consent banner before any such cookie is set. No marketing cookie is ever placed on any Traveller-facing screen, or in connection with any identity verification or check-in flow, irrespective of what is introduced here in future.


5. MOBILE APPLICATION — SDKs AND IDENTIFIERS

Mobile applications do not use browser cookies in the conventional sense. Instead, the AtithiBhaarat application uses:

ItemPurposeConsentDuration
Secure keystore tokenAuthenticationNecessaryUntil logout or expiry
Application-scoped installation identifierDistinguishes one installation from another for crash grouping and licensingNecessaryUntil the app is uninstalled
Push notification tokenDelivers service alerts, check-in notifications and security warningsNecessary for service alerts; separate opt-in for promotional notificationsUntil revoked
Crash and diagnostics SDKError and stability reportingConsent180 days
Analytics SDKAggregate feature usageConsent14 months
Advertising identifierCampaign measurementOpt-in onlyUntil reset by the device user

We do not use the device advertising identifier unless marketing consent has been given, and we do not link it to any Traveller record under any circumstance.


6. YOUR CHOICES AND HOW TO MANAGE COOKIES

6.1 Consent banner. On your first visit, a banner presents three choices, each as prominent as the others and reachable in a single click:

ChoiceEffect
AllowAll cookie categories in Section 4 are enabled, including any introduced in future once you have separately consented to that category
Limited AccessOnly Strictly Necessary and Functional cookies are enabled; Analytics, Performance and Marketing cookies (Section 4.3) remain off
Not AllowedOnly Strictly Necessary cookies are enabled, being the minimum required for the Platform to function; all other categories are declined

There is no dark pattern, pre-ticked box, or a "decline" option hidden behind additional clicks.

6.2 Changing your mind. Preferences may be revised at any time through:

  • the Cookie Settings link in the footer of every page of https://atithibhaarat.com;
  • the mobile application, at Settings — Privacy — Tracking Preferences.

Withdrawal takes effect immediately and non-essential cookies already set are deleted.

6.3 Browser controls.

  • Google Chrome: Settings — Privacy and security — Third-party cookies
  • Mozilla Firefox: Settings — Privacy & Security — Cookies and Site Data
  • Microsoft Edge: Settings — Cookies and site permissions
  • Safari: Settings — Privacy

6.4 Mobile device controls.

  • Android: Settings — Privacy — Ads — Delete advertising ID
  • iOS: Settings — Privacy & Security — Tracking

6.5 Do Not Track. Browser "Do Not Track" signals are not yet subject to a uniform standard. We honour the Global Privacy Control signal where our infrastructure detects it, and we treat it as a rejection of non-essential cookies.

6.6 Effect of blocking. Blocking strictly necessary cookies will prevent sign-in and will make the check-in module unusable. Blocking other categories will not prevent the Platform from working.


7. LEGAL BASIS

Strictly necessary cookies are used on the basis that they are essential to provide the service you have expressly requested. All other categories are used only on the basis of your prior, freely given, specific, informed and unambiguous consent under Section 6 of the Digital Personal Data Protection Act, 2023, which consent you may withdraw at any time with the same ease with which it was given.

Where a cookie collects personal data, that data is handled in accordance with the Privacy Policy.


8. THIRD-PARTY COOKIES AND CROSS-BORDER FLOWS

The Platform sets no third-party cookie today. Should a third-party service named in a future version of the tables above set a cookie and process the resulting data on infrastructure located outside India, that processing will be undertaken only under contractual safeguards and only in respect of countries not restricted by the Central Government under Section 16 of the DPDP Act.

Where third-party cookies are introduced, their use will additionally be governed by the privacy policy of the third party concerned. A current list of our material sub-processors is available on request by writing to info@atithibhaarat.com, and will be published at /subprocessors once finalised.


9. COOKIES AND TRAVELLER DATA — AN IMPORTANT ASSURANCE

Cookies and similar technologies on the Platform are used to operate and improve the Hotel Partner experience. They are not used to:

  • identify, profile, track or re-target an individual Traveller;
  • build a behavioural or commercial profile of any guest;
  • link check-in activity to any advertising network;
  • share any guest data with an analytics or marketing provider.

No cookie set by the Platform contains an Aadhaar number, any Government identity number, a facial template, or a guest register entry.


10. UPDATES TO THIS COOKIE POLICY

Cookies change as the Platform evolves. We review this Policy at least once every twelve months and update the tables above accordingly. Material changes will be notified through a refreshed consent banner requiring your choice afresh. The version number and revision date appear at the head of this Policy.


11. CONTACT AND GRIEVANCES

Data Protection Officer: Jayant Chaubey, info@atithibhaarat.com Grievance Officer: Jayant Chaubey, info@atithibhaarat.com, +91 77938 80880 Address: 101, Vishveshwariya Nagar, Gopalpura Bypass, Durgapura, Jaipur, Rajasthan – 302018

Grievances are acknowledged within twenty-four (24) to seventy-two (72) hours and disposed of within twenty (20) days. Unresolved complaints may be escalated to the Data Protection Board of India.


Governed by the laws of India. Courts at Jaipur, Rajasthan shall have exclusive jurisdiction, subject to the arbitration provisions of the Terms & Conditions.

Recognised by
DPIITiStart RajasthanYourStoryDPIITiStart RajasthanYourStoryDPIITiStart RajasthanYourStoryDPIITiStart RajasthanYourStoryDPIITiStart RajasthanYourStoryDPIITiStart RajasthanYourStory