1. Introduction
Welcome to Mana Binayak Boys Hostel ("we," "us," "our," or "Company"). We are committed to protecting your privacy and ensuring you have a positive experience on our website and services. This Privacy Policy explains what information we collect, how we use it, and what rights you have regarding your data.
By accessing and using our website at manabinayak-boys-hostel.vercel.app (the "Site"), submitting an enquiry form, contacting us via WhatsApp or phone, or booking accommodation with us, you agree to the terms outlined in this Privacy Policy.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Primary Uses
- Process Bookings: To handle your hostel reservation requests, confirm availability, and manage check-ins
- Communication: To respond to your enquiries, send confirmations, updates, or important notices
- Provide Services: To deliver the hostel services, meals, amenities, and support you expect
- Payment Processing: To process monthly payments and manage billing
3.2 Secondary Uses
- Service Improvement: To analyze usage patterns and enhance our website and services
- Security & Fraud Prevention: To prevent abuse, rate limiting violations, and unauthorized access
- Legal Compliance: To comply with applicable laws and regulations in Nepal and internationally
- Marketing (with consent): To share updates about new room types, special offers, or events (only if you opt-in)
Important: We will never sell, rent, or share your personal data with third parties for their marketing purposes without your explicit written consent.
4. Data Protection & Security
4.1 Security Measures
We implement comprehensive technical and organizational security measures to protect your data:
- Input Sanitization: All form inputs are sanitized to prevent cross-site scripting (XSS) attacks
- Rate Limiting: Automated protection against brute-force and spam attacks
- Content Security Policy (CSP): Strict CSP headers enforce that resources load only from trusted origins
- Encryption: Sensitive data is transmitted via HTTPS/TLS encryption
- Access Control: Only authorized personnel can access your data
- Regular Audits: We periodically review and update security protocols
4.2 Limitations
While we take security seriously, no method of online transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data to the best of our ability. You are responsible for maintaining the confidentiality of your login credentials if applicable.
5. Third-Party Services
5.1 Services We Use
To provide you with a better experience, we integrate with the following third-party platforms:
Google Maps
- Purpose: Display our hostel location and enable direction navigation
- Data Shared: Hostel address (20 Natole Rd, Lalitpur 44600, Nepal) and your request data
- Privacy Policy: Google Privacy Policy
WhatsApp & Telegram
- Purpose: Enable instant messaging for booking enquiries and customer support
- Data Shared: Phone number and message content
- Privacy Policy: WhatsApp Privacy Policy
Gmail & Email Services
- Purpose: Send booking confirmations and enquiry summaries
- Data Shared: Email address, name, booking details
- Privacy Policy: Google Privacy Policy
Facebook & TikTok
- Purpose: Social media presence and promotional content
- Data Shared: Only if you voluntarily visit our social pages
- Privacy Policies: Facebook | TikTok
5.2 Your Control
You can control which third-party services you interact with. For example, you can adjust privacy settings within Google, WhatsApp, and social media platforms directly.
6. Your Data Rights
6.1 Rights You Have
Depending on your location and applicable laws (including GDPR if you're in the EU), you have the following rights:
- Right to Access: You can request a copy of all personal data we hold about you
- Right to Rectification: You can request corrections to inaccurate information
- Right to Erasure: You can request deletion of your data (subject to legal retention requirements)
- Right to Data Portability: You can request your data in a portable format (e.g., CSV, JSON)
- Right to Withdraw Consent: If you've given consent to marketing communications, you can withdraw it anytime
- Right to Object: You can object to certain types of data processing
6.2 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
- Email: manabinayakboyshostel@gmail.com
- Phone: +977-9861888176
- Address: 20 Natole Rd, Lalitpur 44600, Nepal
We will respond to your request within 30 days of receipt. Some requests may require verification of your identity for security purposes.
7. Cookies & Local Storage
7.1 What We Use
Our website uses minimal cookies and local storage:
- Essential Cookies: Required for site navigation and security (e.g., session tokens)
- Local Storage: Rate-limiting data stored temporarily to prevent abuse (cleared after browser session)
- No Tracking Cookies: We do not use third-party tracking or advertising cookies
7.2 Managing Cookies
You can control cookies through your browser settings:
- Clear cookies after each session
- Disable cookies entirely (may affect site functionality)
- Use private/incognito browsing mode
8. Data Retention
8.1 How Long We Keep Your Data
- Booking Data: Retained for 12 months after checkout (for dispute resolution and accounting)
- Enquiry Records: Retained for 24 months
- Communication Logs: Retained for 12 months
- Session Data: Automatically deleted after browser session ends
- Legal Hold: Longer retention may be required for legal or regulatory compliance
8.2 Secure Deletion
When data is no longer needed, we securely delete or anonymize it. We do not retain data indefinitely unless required by law.
10. Policy Updates
10.1 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:
- Updating the "Last updated" date on this page
- Sending an email notification to your registered email address
- Posting a notice on our website
- Requesting explicit consent if required by law
10.2 Your Responsibility
It is your responsibility to review this policy periodically. Continued use of our website and services after changes constitute your acceptance of the updated policy.
10.3 Previous Versions
If you need access to a previous version of this Privacy Policy, please contact us at the email or phone address above.
Your privacy matters to us. We are committed to transparency and responsible data handling. If you believe your privacy rights have been violated, you have the right to lodge a complaint with your local data protection authority or regulatory body in Nepal.