LIV ASTA LIV ASTA Back to Livasta

Legal

Privacy Policy

How we collect, use, share, and protect your personal data.

Last updated: 4 September 2026

This Privacy Policy explains how LIV ASTA PRIVATE LIMITED ("Livasta", "we", "us") collects, uses, shares, and protects your personal data when you use Livasta. It is designed to align with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Rules, 2011.

Commitment to Data Security & Identity Privacy: For KYC and identity verification, we are collecting only masked documents for verification (such as masked Aadhaar with only the last 4 digits visible or redacted identification proofs). All personal, booking, and verification data is protected with encryption in transit and at rest.

1. Data we collect

  • Identity & contact: name, email, phone number, date of birth.
  • KYC & verification (Masked documents only): we are collecting only masked documents for verification (such as masked Aadhaar or officially valid documents where sensitive identification numbers are redacted or obscured) to verify guests and hosts. We do not solicit, require, or store unmasked government identification numbers.
  • Address & booking data: addresses, stay/booking history, messages with hosts/guests, reviews.
  • Payment metadata: transaction IDs, amounts, and status. We do NOT store your full card number, CVV, or UPI PIN — these are handled directly by Razorpay, a PCI-DSS compliant payment processor.
  • Device & usage data: IP address, device/browser information, and usage analytics (via cookies and similar technologies).
  • Location: approximate location for property maps and search (with your device's permission).

2. How we use your data

  • Create and manage your account.
  • Verify identity (KYC) and prevent fraud and abuse.
  • Process bookings, payments, payouts, and refunds.
  • Enable communication between guests and hosts.
  • Provide customer support and send service notifications.
  • Improve and secure the platform.
  • Comply with legal, tax, and regulatory obligations.

3. Legal basis

We process personal data based on your consent and on the necessity to perform our contract with you, and to comply with legal obligations, under the DPDP Act, 2023.

4. How we share data

We share personal data only as needed:

  • With hosts/guests: limited details required to fulfil a confirmed booking (e.g. name, booking dates, contact for coordination).
  • With Razorpay: to process payments and refunds.
  • With service providers: hosting, communications, analytics, and support vendors under confidentiality obligations.
  • With authorities: when required by law or to protect rights and safety.

We do not sell your personal data.

5. Payment data security

Card/UPI/net-banking details are entered within Razorpay's secure, PCI-DSS compliant environment. Livasta never sees or stores full card numbers or payment credentials.

6. Data retention

We retain personal data for as long as your account is active and as required to provide services, resolve disputes, and comply with legal obligations (e.g. KYC, tax, and financial record-keeping requirements). When no longer required, data is deleted or anonymised.

7. Your rights

Subject to the DPDP Act, you may:

  • access and obtain a summary of your personal data;
  • request correction or updating of inaccurate data;
  • request erasure of your data (subject to legal retention);
  • withdraw consent; and
  • raise a grievance with our Grievance Team.

To exercise these rights, contact us at privacy@livasta.com.

8. Security & data encryption

Your data is protected with encryption. We implement industry-standard technical, organizational, and operational safeguards to protect your personal information:

  • Encryption in transit: All data transmitted between your device and Livasta is protected with HTTPS/TLS encryption.
  • Encryption at rest: All user profiles, account records, and uploaded files are protected with encryption at rest within secure cloud environments.
  • Masked verification documents: We are collecting only masked documents for verification. All uploaded KYC files are kept in private, encrypted cloud storage with restricted access controls and time-limited, signed URLs available solely to authorized verification staff.
  • Access restrictions: Strict role-based permissions and access logging ensure only authorized personnel handle sensitive verification workflows.

While no electronic system is completely impenetrable, we continuously test and upgrade our security controls to protect your data.

9. Cookies & tracking

We use cookies and similar technologies for authentication, sessions, preferences, and analytics. You can control cookies through your browser settings; some features may not work without them.

10. Children

The platform is not intended for individuals under 18. We do not knowingly collect data from children.

11. Grievance / data protection contact

To raise a data-protection grievance, email privacy@livasta.com. We will acknowledge and address grievances within the timelines required by applicable law.

12. Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted here with a new "Last updated" date.

13. Contact

Email: privacy@livasta.com / support@livasta.com  ·  Phone: +91 89290 39102  |  Website: https://livasta.com