This Privacy Policy explains how SlotKaro Technologies Private Limited ("SlotKaro", "we", "us" or "our") handles personal data when customers, business partners, staff members and website visitors use our platform. It should be read with the applicable customer terms or partner terms. We process personal data under applicable Indian law, including the Information Technology Act, 2000 and applicable data-protection requirements.
| Category | Examples and purpose |
|---|---|
| Account and authentication | Name, mobile number, optional customer email and optional customer gender, account role, OTP issue/verification status, login/session records and security-attempt information used to create, verify and protect accounts. A Partner registration requires an owner/contact email that is verified before a new outlet can be registered. |
| Customer bookings | Selected business, services, staff member, date and time, dining party size where applicable, coupon, selected payment mode, booking and payment status, start OTP, cancellations, no-show status, ratings, reviews and private booking-chat/support messages. Website booking notes may also be stored when a customer chooses to provide them. |
| Partner and business profile | Owner/contact details, business name, type, address, area, map location, opening hours, weekly-off and slot settings, descriptions, services, prices, staff names/specialities, availability, GST information, and approval/subscription status. |
| Partner licences and certificates | Business registration, shop or trade licence, medical registration, AERB licence, bar licence and other category-specific supporting image or PDF files that a partner deliberately selects for upload. SlotKaro uses these files for restricted administrator review, approval, compliance, fraud prevention and support; they are not displayed publicly. |
| Photos and other content | Business, gallery and menu images that a partner deliberately selects or uploads; an optional customer profile photo; plus reviews, messages and other content submitted to the Platform. |
| Location | When permission is granted, the customer app may use the customer's current foreground location to show a current location or relevant nearby businesses. Partner coordinates are used when a partner places a business on the map. The apps do not request background-location permission or track customer movement in the background. Search text and coordinates may be sent to our API or a mapping/geocoding service to return relevant results. |
| Technical and security data | IP address, request date/time, browser or app information, requested pages/API routes, security events, error information and similar server-log data used to operate, troubleshoot and protect the Platform. |
| Push-notification and installation identifiers | When the SlotKaro customer app or SlotKaro Partner uses Firebase Cloud Messaging for transactional booking and service alerts, Firebase generates a per-installation Firebase Installation ID and an FCM token. SlotKaro associates the encrypted token with the signed-in customer or partner account only to address service notifications to that app installation. Firebase may also process app version and limited device/app metadata needed to provide and maintain the messaging service. |
| Payment and transaction records | For an online customer booking or partner subscription, order identifier, amount, currency, payment status/reference, and relevant booking or subscription/accounting records. Payment-instrument details entered on a payment provider's page are handled by that provider and are not intentionally stored by SlotKaro. |
| Partner wallet and earnings ledger | Read-only records of booking amounts, eligible online-payment credits, coupon or offer credits and cash-at-venue booking entries used for Partner reporting and reconciliation. The current ledger is not a cashout, payout, bank-transfer or withdrawal facility. |
For a clinic booking, the selected service or a note supplied through the website could reveal or imply health-related information. SlotKaro does not ask customers to upload medical records through the current apps; please do not include unnecessary medical or identity information in free-text fields.
We do not sell personal data. We will seek any consent required by law before using contact details for promotional marketing, and marketing consent can be withdrawn.
We use SMS one-time passwords to verify mobile numbers. A separate short booking-start OTP may be generated so a customer can confirm arrival with the selected business. OTPs must not be shared except for their intended booking or account-verification purpose. Authentication tokens and limited account cache may be stored on the device so the apps can keep a user signed in.
Transactional messages and alerts may be delayed or fail because delivery depends on networks, device settings and service providers. Private customer details are not intended to appear in public-facing notification text.
Third-party services process data under their own terms and privacy notices as well as any arrangements applicable to our use of their services. Their systems may operate in locations outside your state or country, subject to applicable law.
Before the hosted flow opens, a partner selects whether verification is as an Individual or as a Firm. CaseDocker then shows the checks, documents and fields applicable to that selection and the provider's available service. The hosted flow may ask for PAN, Aadhaar, bank-verification or other applicable business-verification information. That information is entered on and processed through CaseDocker's service. SlotKaro's integration records workflow identifiers, the hosted resume link, environment/mode, verification status, and minimal check-type and status information needed to display and administer progress. We do not expose provider credentials to either app.
SlotKaro may separately request a category-specific business document for manual review where required: a Shop & Establishment or Trade Licence for a Salon or Spa, a medical-registration document for a Clinic, an AERB licence for a Diagnostic Centre, or a Bar/Excise licence for a Dining outlet that declares alcohol service. These category-specific documents are separate from CaseDocker identity verification.
CaseDocker may retain information under its own policy and legal obligations. A partner should review the provider notice shown in the hosted flow before submitting identity or financial information. Provider verification does not, by itself, guarantee business approval on SlotKaro.
Each outlet uses one locked payment mode: Cash at Venue or Pay Online to SlotKaro. When an outlet uses Pay Online, SlotKaro uses Cashfree to create and complete the payment. To create and verify the order, we send Cashfree the minimum details needed for that transaction: an internal customer/order reference, booking amount and currency, customer name, mobile number, email if supplied, and a return URL. Cashfree handles payment-instrument entry. SlotKaro does not intentionally store full card, bank-account, or UPI authentication credentials entered on Cashfree's page.
SlotKaro retains the order identifier, amount, provider reference/status and the related booking record. Before marking a booking as paid, our server checks the payment status with Cashfree. Cash at Venue is settled directly at the business; SlotKaro does not process that cash payment.
If paid Partner subscriptions are enabled for a business category and the payment gateway is configured, a partner can also choose to pay through Cashfree. The same principles apply: Cashfree handles payment-instrument entry, while SlotKaro retains only the order, provider reference/status and the resulting subscription/accounting record.
Depending on the data and applicable law, we process personal data with consent, to provide a feature or service the user requested, to perform our agreements, to meet legal obligations, and for permitted security, fraud prevention, support and business-operation purposes. A user can withdraw consent where applicable, but some features may then stop working. Withdrawal does not invalidate processing already carried out lawfully.
We retain account and operational data while an account is active and for as long as reasonably needed for the purposes described above. Retention varies by category; we do not use one fixed period for every record.
Customers and partners can request deletion from inside their app or at slotkaro.com/delete-account.html. After identity verification, we delete or de-identify the active account and associated data that is no longer required. Data we must retain is restricted to the applicable legal, security, accounting or dispute purpose and is not used to keep the deleted account active.
We use reasonable technical and organizational measures appropriate to the service, including HTTPS in transit, access controls, role-based API checks, protected authentication-token storage in the apps, and security logging. No internet service or storage system can be guaranteed completely secure. Users must protect their devices and never share account OTPs, passwords, payment credentials or verification documents with anyone who contacts them unexpectedly.
Subject to applicable law, a user may ask for access to a summary of personal data, correction or updating, erasure, withdrawal of consent, and grievance redressal. We may verify identity through a registered contact channel before fulfilling a request. Use the account-deletion page above or contact the support address listed in Section 16. If a request cannot be completed in full because a record must be retained, we will explain the applicable reason where required.
Partner accounts are intended for adults authorized to operate the relevant business. Customer accounts are intended for persons legally able to use the service; a person under 18 should use the Platform only with the involvement and valid consent of a parent or legal guardian where required. Contact us if you believe a child's personal data was submitted without appropriate consent.
The website uses necessary session/security cookies and local storage for login, security and user preferences. The mobile apps store authentication tokens, limited account cache and preferences on the device. Clearing app data, uninstalling an app or deleting browser cookies signs out or removes local copies but does not submit an account-deletion request.
The Platform may open third-party hosted pages, maps, payment or verification services. Their privacy notices apply to information submitted directly to them. Check the destination before entering personal, identity or payment data.
For privacy questions, rights requests or grievances, contact:
We may ask for enough information to locate the account and verify the requester, but we will not ask for an OTP, password, full payment credential, API key or identity-document image in an ordinary email request.
We may update this Policy when products, providers or legal requirements change. The current version will remain posted at this URL with a revised "Last updated" date. Material changes will be communicated where required.