Privacy Policy
How MultiTenant handles personal information — for the businesses that use the platform and for the customers who book through it.
Overview
This Privacy Policy describes how MultiTenant("we", "us") collects, uses, and protects personal information when you use our booking platform at multitenant.online and associated subdomains.
We process two distinct categories of personal information, and this policy covers both:
- Tenant information — the business that signs up to use the platform (owners, staff, billing contacts).
- End-customer information— the people who book appointments through a Tenant's booking page. For these records the Tenant is the data controller and we act as a processor on the Tenant's behalf.
What we collect
From Tenants: name, email, phone, business name, business address, services offered, working hours, branding assets (logo, cover image), and payment-method metadata (Razorpay Key ID and key fingerprints; full key secrets and webhook secrets are encrypted at rest with AES-256-GCM and never displayed in full).
From end-customers: name, phone, email, booking history, payment status, and any notes the customer or Tenant adds to a booking. Card / UPI / netbanking data is collected and processed by Razorpay directly — we never see full card numbers, CVVs, or UPI PINs.
Automatically: device and browser information, IP address, pages visited, and timestamps. We use this to operate the service, detect abuse, and improve performance.
How we use it
- To create and operate your account, your booking page, and your staff schedule.
- To send booking confirmations, reminders, cancellations, and review requests via the channel(s) you have enabled (WhatsApp, SMS, email).
- To process payments and refunds through your connected Razorpay account.
- To detect fraud, prevent abuse, and enforce the Terms of Service.
- To communicate service announcements, security alerts, and plan changes.
Data retention
We retain Tenant and end-customer data for as long as the Tenant account is active. On account deletion, we delete or anonymise Tenant data within 30 days, except where retention is required for tax, accounting, or regulatory reasons (typically 7–8 years for financial records). Encrypted Razorpay secrets are deleted immediately on disconnect.
Your rights
Depending on where you live, you may have the right to access, correct, port, or delete personal information we hold about you, and to object to or restrict certain processing. Tenants can do most of this themselves from Settings → User Profile and via the export tools. End-customers should contact the Tenant they booked with first; we will assist the Tenant in fulfilling verified requests.
To exercise data-subject rights, email support@multiitenant.online. We respond within 30 days.
Security
- Razorpay and WhatsApp secrets are encrypted at rest with AES-256-GCM (separate encryption keys, distinct rotation cadences).
- All traffic is HTTPS-only. HSTS is enabled.
- Webhook endpoints verify HMAC-SHA-256 signatures with constant-time comparison.
- Database access is limited to authenticated application services; no direct external access.
- Backups are encrypted in transit and at rest.
International transfers
We are based in India and primarily process data in the ap-south-1 region. Some of our subprocessors (Razorpay, Meta, Twilio, Resend) may process data in other regions under their own data-protection commitments. We enter Standard Contractual Clauses or equivalent safeguards where required.
Changes to this policy
We may update this policy from time to time. The "Effective date" at the top reflects the most recent revision. For material changes, we will give at least 14 days' notice by email and an in-product banner.
Contact
Privacy questions or complaints: support@multiitenant.online.
You can request data export or deletion from Settings → User Profile, or by emailing support@multiitenant.online.
Read the Terms of Service →