Skip to main content
BookMyLib
DiscoverAboutFor OwnersContact
BookMyLib

Empowering reading rooms and study spaces with modern booking operations, seamless payment systems, and elevated user experience.

Product & Search

  • Discover Libraries
  • For Library Owners
  • About Us
  • Contact Support

Legal & Policies

  • Terms of Service
  • Privacy Policy
  • Refund Policy Form
  • Refund Guidelines
  • Cancellation Policy

Stay Updated

Subscribe to our newsletter for features updates, growth tips, and news.

support@bookmylib.com
StudySpot India, New Delhi
DPIIT Recognised StartupISO CertifiedMSME Registered

DPIIT-recognised startup (Department for Promotion of Industry and Internal Trade, Government of India) under the Startup India initiative. ISO 9001:2015 & MSME Registered.

Secured Payments via

StudySpot India Pvt. Ltd. • Brand: BookMyLib • Version 1.2.1

© 2026 BookMyLib. All rights reserved.

256-bit SSL Encrypted · PCI-DSS Compliant

Legal DocumentLast updated: July 6, 2025Version 3.0

Privacy Policy

We are committed to protecting your data with transparency, accountability, and compliance with Indian and international data protection laws.

DPDPA 2023
Digital Personal Data Protection Act
GDPR Ready
EU General Data Protection Regulation
IT Act 2000
Information Technology Act & SPDI Rules
Google API Policy
Limited Use Requirements Compliant
17 comprehensive sections
Grievance officer designated
AES-256 encryption
On this page
Grievance Officer
1. Information We Collect2. How We Use Information3. Disclosure of Information4. Data Security5. Your Data Rights6. Cookies & Tracking7. Data Retention8. International Transfers9. Multi-Tenant Data Access10. WiFi & Location Data11. Mobile Application12. Children's Privacy13. Automated Decisions14. Consent Management15. Third-Party Services16. Policy Changes17. Contact & Grievance Officer

BookMyLib (“we”, “us”, “our”, or the “Company”), operated by StudySpot India, a company incorporated under the laws of India with its registered office at New Delhi, India 110001, is committed to protecting the privacy, confidentiality, and integrity of Personal Data entrusted to us by every individual who interacts with our platform.

This Privacy Policy (“Policy”) describes in detail how we collect, process, use, disclose, store, retain, transfer, and safeguard your Personal Data when you access or use our website (bookmylib.com), mobile application (Android), application programming interfaces (APIs), owner/staff dashboards, or any related services, features, or functionalities (collectively, the “Service”). This Policy applies to all categories of users — including but not limited to students, library owners, staff members, leads, prospective users, and casual visitors — regardless of how they access the Service.

Regulatory Framework & Compliance:This Policy is drafted in compliance with and shall be interpreted in accordance with: (i) the Digital Personal Data Protection Act, 2023(“DPDPA”) and rules framed thereunder; (ii) the Information Technology Act, 2000(“IT Act”) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”); (iii) the General Data Protection Regulation(EU) 2016/679 (“GDPR”), to the extent applicable to users located in the European Economic Area; and (iv) Google API Services User Data Policy, including the Limited Use requirements, for all data obtained through Google APIs.
Key Definitions
  • “Personal Data” means any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDPA, 2023.
  • “Data Fiduciary” means any person who, alone or in conjunction with others, determines the purpose and means of processing Personal Data (library owners, in our context).
  • “Data Processor” means any person who processes Personal Data on behalf of a Data Fiduciary (BookMyLib, in its role as technology platform).
  • “Data Principal” means the individual to whom the Personal Data relates (you, the user).
  • “Sensitive Personal Data or Information” (“SPDI”) means data relating to passwords, financial information, health data, biometric data, and other categories specified under Rule 3 of the SPDI Rules.
  • “Processing” includes collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure, or destruction of Personal Data.
Quick Summary (Plain Language Overview)

This summary is provided for convenience only. In the event of any conflict, the detailed provisions below shall prevail.

  • We collect only what is necessary and proportionate to provide bookings, subscriptions, attendance, payments, communications, and support.
  • Payment card/UPI details are processed by PCI-DSS Level 1 compliant third parties (Razorpay, Cashfree). We never store full card numbers, CVV, or PIN data on our servers.
  • WiFi auto-attendance reads your connected network name (SSID) and router identifier (BSSID) only — we do not collect, store, or transmit your GPS coordinates, cellular tower data, or real-time geolocation.
  • Library owners and their authorised staff can see your booking, attendance, and payment data only for their own branch(es) — never for other libraries.
  • You have the right to access, correct, port, and delete your Personal Data at any time by emailing our Grievance Officer (response within 24 hours; resolution within 30 days).
  • We comply with the DPDPA 2023, IT Act 2000 & SPDI Rules 2011, and the Google API Services User Data Policy (including Limited Use requirements).
  • We do not sell, rent, lease, or trade your Personal Data to any third party for marketing, advertising, or profiling purposes.
  • Data breach notification: Affected users and the Data Protection Board of India will be notified within 72 hours of a confirmed breach.

1. Information We Collect

We collect and process Personal Data through multiple channels in order to deliver, maintain, improve, and secure the Service. The principle of data minimization (collecting only what is adequate, relevant, and limited to what is necessary) governs our practices. Below is an exhaustive breakdown of each category of data we process.

1.1 Information You Provide Directly

This is data you voluntarily furnish when creating an account, completing your profile, configuring your branch, or communicating with us.

  • Account Registration Data: Full legal name, email address, mobile phone number (with country code), role selection (student, owner, or staff), and password. If you register via Google OAuth, we receive your Google Account ID, primary email, display name, and profile picture in lieu of a password.
  • Profile & Demographic Data: Profile photograph (stored on Cloudinary CDN), date of birth, gender, educational institution name, course or program of study, year of study, emergency contact name, emergency contact phone number, and any optional biographical details you choose to share.
  • KYC / Identity Verification (Owners & Business Entities): Aadhaar number (we display only the last 4 digits; the full number is transmitted to our verification partner and not retained in our database in plaintext), Permanent Account Number (PAN), Goods and Services Tax Identification Number (GSTIN), trade license or business registration certificate, bank account details for settlement, and authorised signatory information.
  • Branch Configuration Data (Owners/Staff): Branch trade name, complete postal address (including PIN code), Google Maps coordinates (for map display, not for user tracking), operating hours and holiday schedules, listed amenities (AC, power backup, Wi-Fi, drinking water, etc.), WiFi credentials (SSID network name, WiFi password for student use, and optionally BSSID router MAC address for anti-spoofing), UPI Virtual Payment Addresses (VPAs), seat/desk layout configurations, locker inventory and numbering, branch photos and cover images, house rules and prohibited items, and custom plan/pricing structures.
  • Financial & Payment Data You Enter: UPI ID / VPA for receiving payments (owners), preferred payment method selections, billing address (where required by payment gateway).
  • Lead & Inquiry Data:If you submit an inquiry form on a library’s public landing page, we collect your name, phone number, email, and the nature of your inquiry. This data is shared with the respective library owner for follow-up.
  • Support & Communication Data: Full text and attachments of support tickets, in-app chat messages, email correspondence, and any feedback or reviews submitted through the Service. Metadata includes timestamps, resolution status, and assigned support agent (if any).

1.2 Information Collected Automatically

When you access or use the Service, certain information is collected automatically by our servers, the Android application, and third-party analytics tools embedded in the Service.

  • Device & Technical Data: Internet Protocol (IP) address (used for security, rate limiting, and approximate geo-location at the city level), browser type, version, and rendering engine, operating system name and version, device manufacturer, model name, and unique device identifier (Android ID for push notifications), screen resolution and pixel density, preferred language and locale settings, time zone offset from UTC, HTTP referrer URL (the page that linked you to us), and the sequence of pages, buttons, and actions you interact with during each session (clickstream data).
  • WiFi Network Identifiers (Attendance Feature):When the WiFi auto-attendance feature is active and you are connected to a WiFi network, our Android application reads: (a) the SSID (Service Set Identifier — the human-readable network name, e.g., “LibraryWiFi_5G”); and (b) the BSSID (Basic Service Set Identifier — the MAC address of the access point, e.g., “A4:CF:12:B3:5E:01”). This data is transmitted to our server for matching against the branch’s registered credentials and is notused for any purpose other than attendance verification. See Section 10 for comprehensive details.
  • Attendance & Session Records: Check-in timestamp (UTC and local time), check-out timestamp, attendance method (QR code scan, WiFi auto-detection, or manual entry by staff), confidence level indicator (HIGH when both SSID and BSSID match; NORMAL when only SSID matches), total session duration, associated branch ID, allocated seat/desk number, and the staff member who performed manual check-in/out (if applicable).
  • Push Notification Tokens:Firebase Cloud Messaging (FCM) registration tokens — unique identifiers assigned to your device by Google’s Firebase service that enable us to deliver push notifications. These tokens are device-specific and do not contain personal information.
  • Application Performance Data: Crash reports, error logs, API response times, and page load metrics collected for the purpose of maintaining and improving Service reliability. This data is aggregated and does not identify individual users.

1.3 Information Received from Third Parties

We receive data from the following third-party sources, each subject to separate consent flows where applicable:

  • Google OAuth 2.0 (Sign-In): When you choose to sign in with Google, we receive your Google Account unique identifier, primary email address, full display name, profile picture URL, and email verification status. We do not receive your Google password. Scope: openid profile email.
  • Google Business Profile API: For library owners who connect their Google Business Profile, we access storefront/business names, verified business addresses, phone numbers, business categories, website URLs, regular and special operating hours, Google Maps place IDs, customer reviews (text, rating, reviewer display name, timestamp), review replies, and performance metrics (search impressions, direction requests, phone call clicks). Scope: business.manage.
  • Google People/Contacts API:For library owners who choose to import student directories, we access contact names, email addresses, and phone numbers from the owner’s Google Contacts. Data is imported in a one-time read operation and cached locally in the library’s tenant database. We do not continuously sync or monitor your contacts. Scope: contacts.readonly.
  • Gmail API (Restricted Scope — Send-Only): For library owners who connect Gmail for outbound notifications, we access only the ability to send emails from the connected Gmail address (booking confirmations, payment receipts, expiry reminders, announcements). We do notread, scan, index, or cache inbox messages, drafts, labels, or attachments. This is a restricted scope subject to Google’s enhanced verification requirements. Scope: gmail.send.
  • Payment Gateway Webhooks (Razorpay / Cashfree): Upon completion or failure of a payment transaction, the payment gateway transmits to our server: transaction reference ID, payment status (captured, failed, refunded), payment amount, payment method category (UPI, card, netbanking), partial card details (last 4 digits only, card network), UPI reference number, settlement batch ID, timestamp, and failure/error reason codes. We do not receive or store full card numbers, CVV, expiry dates, or PINs at any point.
  • WhatsApp Delivery Receipts: For libraries on the Pro plan with WhatsApp enabled, we receive message delivery status updates (sent, delivered, read, failed) and connection state changes. We do not access or store the content of incoming messages from students.

1.4 Sensitive Personal Data or Information (SPDI)

Under Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the following categories of data processed by us are classified as SPDI and receive heightened protection measures:

  • Financial Information: UPI Virtual Payment Addresses (VPAs), bank account details for settlement (owners), transaction reference IDs, and payment amounts. Card numbers and CVVs are handled exclusively by PCI-DSS Level 1 compliant payment processors (Razorpay, Cashfree) and nevertransit through or reside on BookMyLib’s infrastructure.
  • Passwords & Authentication Credentials: User passwords are hashed using the bcrypt adaptive hashing algorithm with a minimum cost factor of 12 before storage. The original plaintext password is discarded immediately after hashing and is never logged, cached, or transmitted in cleartext after the initial TLS-encrypted submission. OAuth tokens from Google are stored encrypted and automatically invalidated upon disconnect.
  • WiFi Access Point Identifiers (BSSID): Although BSSID (MAC address) data is not classified as biometric data, it can function as a quasi-unique identifier for physical locations. We treat BSSID data with enhanced confidentiality, restrict access to authorised backend processes only, and do not share it with any third party beyond the specific library owner who configured it.

In accordance with Rule 5(1) of the SPDI Rules, we collect SPDI only with your prior informed consent, which may be given electronically. You may withdraw consent at any time pursuant to Section 14 of this Policy.

1.5 Data We Do NOT Collect

For the avoidance of doubt, BookMyLib does not collect or process the following:

  • GPS coordinates, latitude/longitude, or real-time geolocation tracking data
  • Biometric data (fingerprints, facial recognition templates, retina scans, voiceprints)
  • Health or medical records
  • Racial or ethnic origin, political opinions, religious beliefs, or trade union membership
  • Sexual orientation or sex life data
  • Criminal conviction or offence data
  • Social media activity, browsing history outside the Service, or cross-app tracking data
  • Contents of your Gmail inbox, sent items, drafts, or attachments (Gmail API is send-only)

1.6 Summary Table — Data Categories, Purpose & Legal Basis

CategoryData ElementsPurposeLegal Basis (DPDPA / GDPR)
Identity & ContactName, email, phone, photo, DOBAccount creation, communicationConsent (S.6 DPDPA); Art.6(1)(b) GDPR
Financial / SPDIPayment refs, UPI VPA, amountsPayment processing, invoicing, tax complianceContract; Legal Obligation (S.7 DPDPA); Art.6(1)(c) GDPR
Attendance & WiFiCheck-in/out, SSID, BSSID, method, confidenceAttendance verification, anti-spoofingConsent (S.6 DPDPA); Legitimate Interest Art.6(1)(f) GDPR
Technical / DeviceIP, browser, OS, device model, FCM tokenSecurity, fraud prevention, notificationsLegitimate Interest (S.7 DPDPA); Art.6(1)(f) GDPR
Google API DataOAuth profile, GBP listings, Contacts, Gmail sendSSO, branch management, directory import, notificationsConsent (revocable at any time); Limited Use Policy
Booking / SubscriptionPlan, seat, dates, status, renewals, lockerService delivery, billing, analyticsContract (S.7 DPDPA); Art.6(1)(b) GDPR
CommunicationsSupport tickets, WhatsApp logs, announcementsSupport, service updates, quality assuranceContract; Consent (S.6 DPDPA); Art.6(1)(b) GDPR
KYC / Business (Owners)Aadhaar (last 4), PAN, GSTIN, bank detailsIdentity verification, regulatory complianceLegal Obligation (S.7 DPDPA); Art.6(1)(c) GDPR
Lead / InquiryName, phone, email, inquiry subjectLead follow-up, conversionConsent (S.6 DPDPA); Legitimate Interest Art.6(1)(f) GDPR

2. How We Use Your Information

We process your Personal Data only for specified, explicit, and legitimate purposes as described below. In accordance with the purpose limitation principle under Section 5 of the DPDPA, 2023, we do not process your data for purposes incompatible with those for which it was originally collected, unless we obtain your separate consent or are required to do so by law.

2.1 Core Service Delivery

  • Account Lifecycle Management: Create, authenticate, and maintain your account throughout its lifecycle; verify identity through email/phone OTP or Google OAuth 2.0 protocol; enforce role-based access control (student, owner, staff, superadmin); manage profile updates and preferences; handle account deactivation, suspension, and permanent deletion workflows.
  • Booking & Subscription Processing: Process and confirm seat bookings; manage the full subscription lifecycle (activation, renewal, upgrade, downgrade, pause, cancellation, and expiry); allocate and release seats, desks, and lockers; enforce capacity limits; calculate pro-rata charges for mid-cycle changes; generate booking confirmation receipts.
  • Attendance Recording & Verification: Record check-in/check-out events via QR code scan, WiFi auto-detection, or manual entry by staff; verify WiFi attendance credentials against branch-registered SSID/BSSID; calculate session duration; enforce check-in grace periods; generate daily, weekly, and monthly attendance reports.

2.2 Financial Processing & Compliance

  • Payment Initiation & Verification: Initiate UPI, credit card, debit card, and net banking transactions via Razorpay and Cashfree APIs; verify payment capture status via webhooks; record offline cash payments entered by authorised staff; calculate outstanding dues and overdue amounts; generate itemised invoices, payment receipts, and financial summaries for library owners.
  • Tax Compliance: Maintain financial records as required under the Indian Income Tax Act, 1961 (Section 44AA); retain transaction records for GST audit purposes under the Central Goods and Services Tax Act, 2017; generate reports to assist library owners with their GST return filing (BookMyLib itself does not file GST returns on behalf of library owners).
  • Settlement & Reconciliation: Facilitate settlement of collected payments to library owners through payment gateway settlement cycles; provide reconciliation reports mapping transactions to settlements.

2.3 Communications & Notifications

  • Transactional Communications: Send booking confirmations, payment receipts, subscription expiry reminders (7-day and 1-day advance), plan renewal confirmations, seat allocation notifications, and locker assignment details via email, push notification (FCM), and/or WhatsApp (where enabled on Pro plan).
  • Operational Communications: Deliver branch announcements, schedule changes, maintenance notices, holiday closures, and system alerts initiated by library owners or BookMyLib.
  • Support Communications: Process and respond to support tickets, in-app chat messages, and email inquiries; maintain communication history for quality assurance and training purposes.

2.4 Analytics, Product Improvement & Research

  • Aggregated Usage Analytics: Analyse anonymised and aggregated usage patterns to: measure seat utilisation rates across branches and time periods; identify peak demand hours and seasonal trends; optimise platform performance and page load times; prioritise feature development based on usage data.
  • Individual-Level Data: Individual-level data (your specific browsing patterns, attendance history, or payment records) is never sold, licensed, or shared with any third party for marketing, advertising, profiling, or any commercial purpose unrelated to the Service.

2.5 Security, Fraud Prevention & Legal Compliance

  • Anti-Fraud Measures: Detect and prevent WiFi SSID/BSSID spoofing for false attendance; identify QR code sharing or duplication; flag multiple concurrent sessions from the same account; detect payment fraud patterns (rapid successive transactions, inconsistent amounts, high-volume chargebacks).
  • Security Operations: Monitor for brute-force login attempts, credential stuffing, SQL injection, cross-site scripting (XSS), and other OWASP Top 10 attack vectors; maintain rate limiting across API endpoints; perform periodic security audits and vulnerability assessments.
  • Legal & Regulatory Obligations: Comply with lawful requests from Indian law enforcement and regulatory authorities under Section 69 of the IT Act, 2000; respond to court orders, subpoenas, and government directives; maintain records required under the Prevention of Money Laundering Act, 2002 (where applicable); fulfil data subject access requests under DPDPA and GDPR.

2.6 Legitimate Interest Assessment

Where we rely on “legitimate interest” (under GDPR Art. 6(1)(f) or DPDPA S.7) as a legal basis for processing, we conduct a balancing test to ensure our interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interest at any time by contacting our Grievance Officer (Section 17).

Google API Limited Use Disclosure: Data obtained through Google APIs (OAuth sign-in, Business Profile, Contacts, Gmail send) is used exclusivelyto provide the specific integration features you have explicitly authorised. Specifically: (i) Google OAuth data is used solely for authentication; (ii) Google Business Profile data is used solely for branch management on the owner dashboard; (iii) Google Contacts data is used solely for one-time directory import; (iv) Gmail API (send scope) is used solely to send transactional emails from the owner’s address. This data is never used for advertising, user profiling, behavioural targeting, creditworthiness assessment, or any purpose beyond the stated Service functionality. Our use complies with the Google API Services User Data Policy, including the Limited Use requirements.

3. Disclosure of Your Information

We do not sell, rent, lease, trade, or otherwise commercially share your Personal Data with any third party for their own marketing purposes. We disclose Personal Data only in the following strictly limited circumstances, and only to the minimum extent necessary for the stated purpose:

3.1 Service Providers & Sub-Processors

We engage carefully vetted third-party service providers who process Personal Data on our behalf, subject to contractual data protection obligations equivalent to or stricter than those in this Policy. These providers fall into the following categories:

  • Application Hosting & Delivery: Our application is served via a globally distributed, SOC 2 Type II and GDPR compliant hosting provider.
  • Database Services: Application data is stored with a SOC 2 Type II certified managed database provider. All data is encrypted at rest and in transit.
  • Media Storage: User-uploaded images are stored with an ISO 27001 and SOC 2 Type II certified provider. No personally identifiable information is stored in image metadata.
  • Payment Processing: Payments are handled by PCI-DSS Level 1 certified gateways operating within Indian jurisdiction. We do not store full card numbers, CVV, or PINs on our systems.
  • Authentication & Communication: We use industry-leading authentication and communication APIs with ISO 27001 and SOC 2 certifications.
  • Push Notifications: Mobile notifications are delivered through a certified push notification service.
  • Business Messaging: For libraries on the Pro plan, automated WhatsApp messages are delivered through a secure messaging provider.

Data shared with each provider is limited to the minimum necessary for the stated purpose. All data in transit is encrypted using TLS 1.2+, and data at rest is encrypted using industry-standard encryption. A complete list of sub-processors is available upon request by contacting our Grievance Officer.

Each sub-processor is bound by a Data Processing Agreement (DPA) or equivalent contractual terms that restrict their use of your data solely to providing the contracted service and require them to implement appropriate security measures.

3.2 Library Partners (Tenant-Scoped Access)

When you register, book, or subscribe at a library branch, the authorised owners and staff of that specific branch may access the following data, limited to their own tenant scope:

  • Your name, phone number, email address, and profile photograph
  • Booking details (seat, dates, plan, status) and subscription history
  • Attendance logs (check-in/out times, method, session duration)
  • Seat and locker allocations
  • Payment status (paid, partially paid, overdue), amounts, and receipt references
  • Outstanding dues and account balance

Library partners cannotaccess: (i) your data at any other library; (ii) your password or authentication credentials; (iii) your device/IP information; (iv) your Google API data; or (v) raw WiFi BSSID values (they see only the match result: match/no-match).

3.3 Legal & Regulatory Authorities

We may disclose your Personal Data without your prior consent if required or permitted under applicable law, including but not limited to:

  • Compliance with a court order, judicial decree, or lawful governmental request under Section 69 of the IT Act, 2000
  • Response to a valid subpoena, warrant, or statutory inquiry from a competent authority
  • Protection of the rights, property, or personal safety of BookMyLib, its users, or the public
  • Investigation or prevention of suspected fraud, security incidents, or violations of our Terms of Service
  • Reporting to the Computer Emergency Response Team (CERT-In) under the IT Act as required for cybersecurity incidents

Where legally permissible, we will notify you of such disclosures and provide you with a copy of the request received.

3.4 Business Transfers & Corporate Events

In the event of a merger, acquisition, reorganisation, asset sale, joint venture, or insolvency/bankruptcy proceeding involving BookMyLib, your Personal Data may be transferred to the successor entity or acquiring party as part of the transaction assets. In such event:

  • You will be notified via email and prominent in-app notice at least 30 days before the transfer takes effect
  • The successor entity will be bound by the terms of this Policy for a minimum transition period of 12 months
  • You will have the opportunity to delete your account and data before the transfer is completed

3.5 Anonymised & Aggregated Data

We may share anonymised, aggregated, and de-identified data (from which no individual can be reasonably identified) with partners, researchers, or for public reporting. For example: “Average study session duration across all libraries is 4.2 hours.” Such data is not Personal Data under DPDPA or GDPR.

Google API Services User Data Policy Compliance: BookMyLib’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Userequirements. Specifically: (a) we do not allow humans to read Google user data unless required for security, legal compliance, or with your explicit consent; (b) we do not use Google data for serving advertisements; (c) we do not transfer Google data to third parties except as necessary to provide the Service, for legal reasons, or with your consent; (d) our internal access to Google data is restricted to specific roles with audited access logs.

4. Data Security

We implement and maintain comprehensive technical and organisational measures designed to protect your Personal Data against unauthorised access, alteration, disclosure, destruction, or accidental loss. These measures are proportionate to the nature, scope, and sensitivity of the data processed, in accordance with Rule 8 of the SPDI Rules, 2011 (which mandates “reasonable security practices and procedures”) and the security obligations under Section 8(4) of the DPDPA, 2023.

4.1 Technical Safeguards

  • Encryption in Transit (TLS): All client-server communications are encrypted using Transport Layer Security (TLS) 1.2 or 1.3 with forward secrecy. HTTPS is enforced across all endpoints; cleartext HTTP connections are automatically redirected. HTTP Strict Transport Security (HSTS) headers are applied with a minimum max-age of 31,536,000 seconds (1 year).
  • Encryption at Rest (AES-256): All data stored in Neon PostgreSQL is encrypted at rest using AES-256 encryption with provider-managed keys. Automated backup snapshots are similarly encrypted. Cloudinary images are stored with encryption enabled by default.
  • Password Security (Bcrypt): User passwords are hashed using the bcrypt adaptive hashing algorithm with a minimum cost factor of 12 (approximately 2^12 iterations). The plaintext password is discarded from server memory immediately after hashing. Passwords are never logged, cached, stored in plaintext, or transmitted in cleartext after the initial TLS-protected submission.
  • Session & Token Management: Authentication sessions use HttpOnly, Secure, SameSite=Lax cookies to prevent XSS and CSRF attacks. CSRF tokens are validated on all state-changing operations. JWT (JSON Web Token) sessions have configurable expiration periods. OAuth refresh tokens are stored encrypted and are immediately revoked upon user-initiated disconnect.
  • Rate Limiting & DDoS Protection:API endpoints are protected by progressive rate limiting to prevent brute-force password guessing, credential stuffing, and denial-of-service attacks. Vercel’s edge network provides additional DDoS mitigation at the infrastructure level.
  • Input Validation & Output Encoding: All user inputs are validated and sanitised on both client and server sides. Database queries use parameterised statements (via Prisma ORM) to prevent SQL injection. Output is encoded to prevent cross-site scripting (XSS) attacks.
  • Android Application Hardening: The Android APK/AAB undergoes R8 code shrinking and obfuscation; WebView debugging is disabled in release builds; the network security configuration enforces HTTPS-only connections (cleartext traffic is blocked); android:allowBackup is set to false to prevent unencrypted backup extraction.
  • Role-Based Access Control (RBAC): Strict multi-tenant data isolation using tenant-scoped database queries (every query is filtered by libraryId). Role-based middleware enforces access boundaries between admin, owner, staff, and student roles. Cross-tenant data access is architecturally impossible.
  • Content Security Policy (CSP): HTTP response headers include Content-Security-Policy directives restricting script sources, frame ancestors, and object embeddings to prevent code injection and clickjacking attacks.

4.2 Organisational Measures

  • Access Control: Access to production databases and infrastructure is restricted to authorised personnel on a need-to-know basis. All production access is authenticated via multi-factor authentication (MFA) and logged with immutable audit trails.
  • Code Review & Deployment: All code changes undergo mandatory peer review before merging. Deployments are automated through CI/CD pipelines with pre-deployment security scans.
  • Incident Response Plan: A documented security incident response procedure covers detection, containment, eradication, recovery, and post-incident review. The plan is tested periodically through tabletop exercises.
  • Vendor Due Diligence: Third-party sub-processors are evaluated for security posture, compliance certifications (SOC 2, ISO 27001, PCI-DSS), and data protection practices before onboarding and reviewed annually thereafter.
  • Employee Training: All team members with access to Personal Data receive periodic training on data protection obligations, phishing awareness, and secure coding practices.

4.3 Data Breach Response

In the event of a confirmed Personal Data breach (unauthorised access, disclosure, alteration, or destruction of Personal Data):

  • Internal Response (0–24 hours): The incident response team is activated to contain the breach, assess the scope and severity, preserve evidence, and begin remediation.
  • Regulatory Notification (within 72 hours): The Data Protection Board of India (DPBI) and/or CERT-In will be notified within 72 hours of confirmation, as required by Section 8(6) of the DPDPA, 2023 and CERT-In Directions dated 28 April 2022.
  • User Notification (within 72 hours): Affected users will be notified via email and in-app notice describing the nature of the breach, data categories affected, likely consequences, and remedial measures taken or recommended.
  • Post-Incident Review (within 30 days): A root cause analysis is conducted and documented. Technical and procedural improvements are implemented to prevent recurrence.

Disclaimer: While we implement industry-standard safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. In the event of a breach despite our safeguards, we will act promptly as described above.

5. Your Data Rights

As a Data Principal under the DPDPA, 2023, and potentially as a data subject under the GDPR (if you are located in the EEA), you are entitled to the following rights. We are committed to facilitating the exercise of these rights in a transparent, accessible, and timely manner.

5.1 Rights under the Digital Personal Data Protection Act, 2023

  • Right to Access (Section 11(1)): You have the right to obtain from us a summary of the Personal Data we hold about you, the processing activities performed on it, the categories of third parties with whom it has been shared, and any other information prescribed by the Central Government.
  • Right to Correction & Completion (Section 11(2)): You have the right to request correction of inaccurate Personal Data and completion of incomplete Personal Data relating to you.
  • Right to Erasure (Section 12(3)):You have the right to request the erasure of your Personal Data that is no longer necessary for the purpose for which it was collected, subject to mandatory retention obligations (see Section 7). Upon a valid erasure request, we will also direct our sub-processors to delete your data from their systems. Detailed steps and instructions are available on our dedicated Account Deletion Page.
  • Right to Grievance Redressal (Section 11(3)): You have the right to lodge a grievance with our Grievance Officer and receive a resolution within the prescribed timeframe. If dissatisfied with our response, you may escalate your complaint to the Data Protection Board of India (DPBI) established under Section 18 of the DPDPA.
  • Right to Nominate (Section 14): You have the right to nominate another individual who may exercise your data rights in the event of your death or incapacity, subject to identity verification of the nominee.

5.2 Additional Rights under GDPR (for EEA Users)

If you are located in the European Economic Area, you additionally enjoy the following rights under the General Data Protection Regulation:

  • Right to Restrict Processing (Art. 18): Request restriction of processing where you contest the accuracy of data, the processing is unlawful, or we no longer need the data but you require it for legal claims.
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
  • Right to Data Portability (Art. 20): Receive your Personal Data in a structured, commonly used, and machine-readable format (JSON or CSV) and transmit it to another controller without hindrance.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw your consent to processing at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
  • Right to Lodge a Complaint with a Supervisory Authority (Art. 77): Lodge a complaint with a supervisory authority in your EU/EEA member state of habitual residence, place of work, or place of the alleged infringement.

5.3 How to Exercise Your Rights

To exercise any of the above rights, please follow this procedure:

  1. Submit a Request: Email our Grievance Officer at studyspotindia@gmail.comwith the subject line “Data Rights Request — [Type of Right]” (e.g., “Data Rights Request — Access”).
  2. Identity Verification: For security purposes, we will verify your identity before processing your request. Verification may involve confirming your registered email address, providing a government-issued photo ID (Aadhaar card, PAN card, or passport), or answering security questions linked to your account.
  3. Acknowledgment (within 24 hours): We will acknowledge receipt of your request within 24 hours (excluding weekends and Indian public holidays).
  4. Processing & Resolution (within 30 calendar days): Your request will be processed and resolved within 30 calendar days of receipt. If the request is complex or voluminous, we may extend this period by an additional 30 days, with prior written notice explaining the reason for the extension.
  5. Fees: The first request per calendar quarter is processed free of charge. For subsequent or manifestly excessive/repetitive requests, we may charge a reasonable administrative fee (not exceeding ₹500 per request) or refuse the request, providing reasons for refusal.

5.4 Portability Format

Upon a valid data portability request, we will provide your Personal Data in one of the following machine-readable formats at your choice: JSON (JavaScript Object Notation) or CSV (Comma-Separated Values). The export will include your profile data, booking history, attendance records, and payment transaction records. The export will be delivered via a secure, time-limited download link sent to your registered email address.

6. Cookies & Tracking Technologies

BookMyLib uses a minimal, carefully curated set of cookies and client-side storage technologies that are strictly necessary for the operation, security, and functionality of the Service. We do not use third-party advertising cookies, cross-site tracking pixels, web beacons, fingerprinting scripts, or any technology designed to track your browsing activity across unrelated websites.

6.1 Cookie Classification

Our cookies fall into two categories under the ePrivacy Directive framework and Indian regulatory guidance:

  • Strictly Necessary / Essential Cookies: These cookies are required for the Service to function and cannot be disabled without breaking core features. They enable authentication, session management, and CSRF protection. Under most data protection frameworks, these do not require separate consent as they are essential for providing the service you have requested.
  • Functional / Preference Cookies: These cookies store your preferences (e.g., theme, last-selected branch) to improve your user experience. They are set only after you interact with the relevant feature.

6.2 Cookie Inventory

CookieTypePurposeDuration
session_tokenEssentialUser authentication & sessionSession / 30 days
csrf_tokenEssentialCSRF protectionSession
themeFunctionalLight/dark mode preference1 year
branch_prefFunctionalLast-selected branch90 days

6.3 Third-Party Cookies

During payment checkout, Razorpay and Cashfree may set their own cookies within their secure iframes to manage the payment session, detect fraud, and comply with PCI-DSS requirements. These cookies are governed by Razorpay’s Cookie Policy and Cashfree’s Privacy Policy respectively. BookMyLib does not have access to or control over these third-party cookies.

6.4 Local Storage & IndexedDB

In addition to cookies, the Service may use browser localStorage and IndexedDB to cache non-sensitive UI state (e.g., sidebar collapse state, recently viewed pages) for performance optimisation. This data remains entirely on your device and is never transmitted to our servers. Clearing your browser data will remove all locally stored information.

6.5 Managing Cookies

You may configure your browser to refuse cookies, delete existing cookies, or alert you before a cookie is set. Note that disabling essential cookies (session_token, csrf_token) will prevent you from logging in to the Service. Instructions for managing cookies are available in your browser’s help documentation.

7. Data Retention

We retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The specific retention periods are determined based on: (i) the nature and sensitivity of the data; (ii) the purposes of processing; (iii) legal, regulatory, and contractual obligations; and (iv) our legitimate business interests (e.g., dispute resolution and fraud prevention).

7.1 Retention Schedule

Data CategoryRetention PeriodReason
Active account dataDuration of account + 3 yearsService continuity, audit
Financial records8 years from transactionIndian Income Tax Act, GST
Attendance logs3 yearsDispute resolution, analytics
Support tickets2 years after resolutionQuality assurance
Server/access logs90 daysSecurity monitoring
Deleted account dataAnonymized within 90 daysDPDPA compliance
Google API tokensRevoked on disconnectConsent withdrawal
WhatsApp message logs1 yearDelivery confirmation

7.2 Deletion & Anonymisation Procedures

  • Scheduled Deletion: Automated data lifecycle processes identify and queue data that has exceeded its retention period for deletion during monthly maintenance windows.
  • Irreversible Anonymisation: Where complete deletion is not feasible (e.g., aggregated analytics), data is irreversibly anonymised using techniques that prevent re-identification, including key deletion, data masking, generalisation, and pseudonymisation followed by key destruction.
  • Sub-Processor Cascading: When data is deleted from our primary database, we issue deletion requests to relevant sub-processors (Cloudinary for images, Neon for database records) within the same maintenance window.
  • Backup Retention:Encrypted database backups are retained for a maximum of 30 days beyond the data’s active retention period for disaster recovery purposes, after which they are overwritten.

7.3 Legal Hold

Notwithstanding the above retention periods, we may retain specific data for longer periods if required by a legal hold, pending litigation, regulatory investigation, or court order. Affected users will be notified of such holds where legally permissible.

8. International Data Transfers

BookMyLib is headquartered in India and primarily serves Indian users. However, due to our use of globally distributed cloud infrastructure, your Personal Data may be processed in jurisdictions outside India. We ensure that all cross-border transfers comply with applicable data protection laws and are subject to appropriate safeguards.

8.1 Infrastructure Locations

Your data may be processed across multiple geographic regions depending on the service. Our key infrastructure commitments:

  • Database: Hosted with a SOC 2 Type II certified provider. All data is encrypted at rest and in transit (TLS 1.2+).
  • Application Hosting: Served via a globally distributed network with SOC 2 Type II and GDPR compliance.
  • Media Storage: Images are stored with an ISO 27001 and SOC 2 Type II certified provider across multiple regions.
  • Google Services:Authentication and communication APIs are processed on Google’s infrastructure, which maintains ISO 27001, SOC 2, and FedRAMP certifications.
  • Payments: All payment processing infrastructure is located in India, ensuring that financial transaction data does not leave Indian jurisdiction.

8.2 Transfer Safeguards

For transfers of Personal Data outside India, we rely on the following safeguards, as applicable:

  • DPDPA Section 16: Transfers to jurisdictions notified by the Central Government as providing adequate data protection, or under conditions prescribed by the Central Government.
  • Standard Contractual Clauses (SCCs): Where transfers are made to jurisdictions without an adequacy determination, we enter into Standard Contractual Clauses (as adopted by the European Commission, Decision 2021/914) with the data importer.
  • Contractual Safeguards: All sub-processors are bound by Data Processing Agreements (DPAs) that include data protection obligations equivalent to those in this Policy, including obligations regarding confidentiality, security measures, breach notification, and data return/deletion upon termination.
  • Encryption: All data in transit between India and international servers is encrypted using TLS 1.2 or higher, and data at rest is encrypted using AES-256.

8.3 Your Rights Regarding Transfers

You may request information about the specific safeguards applied to the transfer of your data outside India by contacting our Grievance Officer (Section 17). If you object to your data being transferred internationally, you may request account deletion; however, this will result in inability to use the Service as our core infrastructure requires cross-border data processing.

9. Multi-Tenant Data Access & Roles

BookMyLib operates as a multi-tenant Software-as-a-Service (SaaS) platform where multiple independent libraries share the same underlying infrastructure while maintaining strict data isolation. This section explains how your data is partitioned, who can access what, and the legal relationships between BookMyLib and library operators.

9.1 Architectural Data Isolation

Each library’s data is logically isolated at the database level through tenant-scoped queries. Every database operation is filtered by a unique libraryId identifier, ensuring that:

  • No library owner or staff member can access, view, or modify data belonging to any other library
  • No student can access data belonging to other students (even within the same library, except for publicly displayed profile names)
  • API endpoints enforce tenant isolation at the middleware layer before any database query is executed
  • Cross-tenant data leakage is prevented by architectural design, not merely by application-level access controls

9.2 Role-Based Visibility Matrix

Data CategoryOwnerStaffStudentAdmin
Student profiles (own library)✅✅Own only✅
Booking & subscription records✅✅Own only✅
Attendance logs✅✅Own only✅
Payment records & financial reports✅❌Own receipts✅
Integration settings (Google, WhatsApp)✅❌❌✅
WiFi BSSID configuration✅❌❌✅
Staff management✅❌❌✅
Other library’s data❌❌❌❌

9.3 Data Processing Relationship (DPDPA Framework)

Under the DPDPA, 2023, the data processing relationship in the BookMyLib ecosystem is structured as follows:

  • Library Owners = Data Fiduciaries (Section 2(i)): Library owners determine the purpose and means of processing student Personal Data at their establishments. They are responsible for obtaining lawful consent from students, maintaining consent records, responding to data rights requests from their students, and complying with all Data Fiduciary obligations under the DPDPA.
  • BookMyLib = Data Processor (Section 2(h)): BookMyLib processes student Personal Data on behalf of library owners (Data Fiduciaries) strictly in accordance with the terms of service and data processing instructions provided. BookMyLib does not independently determine the purpose of processing student data beyond what is necessary to operate the platform.
  • BookMyLib = Data Fiduciary (for its own purposes):For data collected for BookMyLib’s own purposes (e.g., account registration, platform analytics, security), BookMyLib acts as an independent Data Fiduciary and is directly responsible for compliance with all DPDPA obligations.

This dual role (Processor for tenant data; Fiduciary for platform data) is clearly delineated in our system architecture and reflected in our Data Processing Agreement with library owners.

10. WiFi & Location Data

Critical Disclosure:BookMyLib’s WiFi auto-attendance feature reads your connected WiFi network name (SSID) and router hardware identifier (BSSID) only. We do not collect, store, process, or transmit your GPS coordinates, cellular tower data, Bluetooth beacon data, or any form of real-time geolocation or movement tracking. The Android ACCESS_FINE_LOCATION permission is an Android operating system requirement for reading WiFi network information — it does not mean we track your physical location.

10.1 Data Collected

  • SSID (Service Set Identifier):The human-readable name of the WiFi network your device is connected to (e.g., “LibraryWiFi_5G”). This is compared against the branch’s registered WiFi name.
  • BSSID (Basic Service Set Identifier):The MAC address of the WiFi access point (e.g., “A4:CF:12:B3:5E:01”). When enabled by the library owner, this provides an additional layer of anti-spoofing verification by confirming the physical hardware identity of the access point. Library owners may configure BSSID validation as mandatory or optional.
  • Connection Status: Whether your device is currently connected to a WiFi network (boolean check). If not connected, no WiFi data is read.

10.2 Why Android Requires Location Permission

Starting with Android 8.1 (Oreo) and reinforced in Android 10+, Google’s Android operating system classifies WiFi network information (SSID and BSSID) as location-derived data because WiFi access point identifiers can theoretically be used to approximate physical location (via WiFi positioning databases). As a result, the ACCESS_FINE_LOCATION permission is required by the OS to read WiFi connection details. This is an immutable Android platform requirement, not a BookMyLib design choice.

What we do with this permission: Read the SSID and BSSID of your currently connected WiFi network. What we do NOT do: Call LocationManager.getLastKnownLocation(), FusedLocationProviderClient, or any GPS/cellular/Bluetooth location API.

10.3 How WiFi Auto-Attendance Works (Technical Flow)

  1. Configuration (Owner): The library owner enters the branch WiFi SSID (and optionally BSSID) in the branch settings dashboard. If BSSID is configured as mandatory, students must match both SSID and BSSID for a successful check-in.
  2. Detection (Student Device): When the student opens the BookMyLib app (or the app is in the foreground) while connected to a WiFi network, the Android application calls WifiManager.getConnectionInfo() to read the current SSID and BSSID. This is a local, on-device operation.
  3. Transmission: The detected SSID and BSSID are sent to our server via a TLS-encrypted HTTPS request as part of the attendance check-in API call.
  4. Server-Side Matching:The server compares the submitted SSID/BSSID against the branch’s registered credentials. The confidence level is determined as: HIGH (both SSID and BSSID match), NORMAL (SSID matches, BSSID not configured or not required), or REJECTED (SSID does not match, or BSSID mismatch when BSSID is mandatory).
  5. Recording:If matched, a check-in record is created with the timestamp, method (“wifi”), confidence level, and associated branch/seat. If not matched, no check-in is recorded and the student is not notified (to prevent information leakage about the expected credentials).

10.4 Anti-Spoofing Protections

Attempting to spoof WiFi credentials (creating a fake WiFi network with a matching SSID, or using MAC address spoofing tools to fake a BSSID) to fraudulently record attendance without being physically present at the library constitutes a violation of our Terms of Service (Section 11) and may result in:

  • Immediate suspension or permanent termination of your account
  • Invalidation of all attendance records associated with spoofed check-ins
  • Notification to the library owner of the spoofing attempt
  • Potential legal action under applicable Indian laws, including the Information Technology Act, 2000 (Sections 43, 66)

10.5 Opting Out of WiFi Attendance

WiFi auto-attendance is entirely optional. You may opt out at any time using any of the following methods:

  • Revoke the Location permission for the BookMyLib app: Android Settings → Apps → BookMyLib → Permissions → Location → Deny
  • Use alternative check-in methods: QR code scanning or manual check-in by staff
  • Request your library owner to disable WiFi attendance for your specific account
  • Simply do not connect to the library’s WiFi network

Revoking the Location permission will only disable WiFi auto-attendance. All other features of the app (bookings, payments, notifications, QR attendance) will continue to work normally.

11. Mobile Application

The BookMyLib Android application is a Capacitor-based WebView application that loads the Service within a secure Android container. The following data practices and permissions are specific to the mobile application:

11.1 Permission Inventory

PermissionPurposeWhen RequestedRevocable?
INTERNETCore network access for all Service functionalityAlways (auto-granted)No (required)
CAMERAQR code scanning for attendance check-inFirst QR scan attemptYes
ACCESS_FINE_LOCATIONReading WiFi SSID/BSSID for auto-attendance (see Section 10.2)First WiFi check-inYes
ACCESS_WIFI_STATEReading WiFi connection status and network infoAlways (auto-granted)No (normal)
POST_NOTIFICATIONSDisplaying push notifications (booking, payment, expiry alerts)Android 13+ on first launchYes
RECEIVE_BOOT_COMPLETEDRe-registering FCM token after device restartAlways (auto-granted)No (normal)

11.2 Permission Management

You can revoke any runtime permission at any time through: Android Settings → Apps → BookMyLib → Permissions. Revoking a permission disables only the specific feature that requires it; all other features continue to function normally. The app does not request permissions that are not directly required for a user-facing feature.

11.3 App Security Measures

  • R8 Code Shrinking & Obfuscation: The release build applies R8 optimisation, shrinking, and obfuscation to protect application logic.
  • HTTPS-Only: The Android network security configuration blocks all cleartext (non-HTTPS) traffic. No data leaves the app unencrypted.
  • No Backup Extraction: android:allowBackup=false prevents extraction of application data through ADB backup.
  • WebView Debugging Disabled: WebView developer tools are disabled in production builds.
  • No Third-Party SDKs: The app does not include any third-party analytics, advertising, or tracking SDKs beyond Firebase Cloud Messaging (for push notifications).

11.4 App Updates

We may release updates to the mobile application through the Google Play Store to address security vulnerabilities, fix bugs, or add features. You are strongly encouraged to keep the app updated. Critical security updates may require a minimum app version; older versions may be blocked from accessing the Service after a reasonable deprecation period.

12. Children's Privacy

BookMyLib is committed to protecting the privacy and safety of children. Under the DPDPA, 2023, a “child” is defined as any individual below the age of 18 years. The following provisions apply to the processing of children’s Personal Data:

12.1 Consent Requirements

  • Verifiable Parental Consent (Section 9 DPDPA):Before collecting any Personal Data from a child, we require verifiable consent from the child’s parent or legal guardian. Consent may be provided via: (a) parent/guardian’s email verification; (b) parent/guardian’s phone number verification via OTP; or (c) written consent provided to the library owner at the time of registration.
  • Library Owner Responsibility: Library owners who register minor students are responsible for obtaining, documenting, and retaining proof of parental/guardian consent. BookMyLib provides tools in the owner dashboard to record consent status.

12.2 Data Minimisation for Minors

  • We collect only the minimum Personal Data necessary to provide the Service to the child (name, contact, booking/attendance data).
  • We do not engage in behavioural profiling, targeted advertising, or automated decision-making with legal effects on children.
  • We do nottrack, monitor, or analyse children’s detailed behavioural patterns beyond what is necessary for attendance and subscription management.

12.3 Parental/Guardian Rights

  • Parents/guardians may exercise all data rights (access, correction, deletion) on behalf of the child at any time by contacting our Grievance Officer.
  • Parents/guardians may request a complete export of the child’s data in machine-readable format.
  • Parents/guardians may withdraw consent for the child’s use of the Service, resulting in account deactivation and data deletion (subject to legal retention obligations).

12.4 Discovery & Remediation

If we discover that we have collected Personal Data from a child without proper parental consent, we will:

  1. Immediately restrict processing of the child’s data to storage only
  2. Attempt to contact the parent/guardian to obtain retroactive consent
  3. If consent is not obtained within 72 hours, permanently delete all of the child’s Personal Data from our systems and direct sub-processors to do the same

13. Automated Decision-Making & Profiling

BookMyLib employs certain automated processing systems as part of the Service. In accordance with transparency obligations under GDPR Article 22 and the principles of the DPDPA, 2023, we disclose the following automated decision-making and profiling activities:

13.1 Automated Processing Activities

  • WiFi Attendance Matching (Section 10.3):Automated server-side comparison of your device’s reported SSID/BSSID against the branch’s registered WiFi credentials. Produces a confidence score (HIGH/NORMAL) and a binary accept/reject result. Logic: deterministic string comparison, not machine learning.
  • Subscription Lifecycle Automation: Automated date-based calculations for subscription expiry, grace period enforcement, status transitions (active → expiring → expired), and renewal reminder scheduling. Logic: calendar arithmetic based on subscription start date and plan duration.
  • Payment Due & Overdue Detection: Automated identification of partially paid or overdue subscription amounts by comparing total plan cost against recorded payments. Triggers automated payment reminder notifications. Logic: arithmetic comparison of payment records against plan pricing.
  • Fraud Detection Signals:Automated monitoring for: (a) rapid successive WiFi check-ins from different branches (possible spoofing); (b) multiple concurrent active sessions (possible credential sharing); (c) high-frequency chargeback patterns. Logic: rule-based thresholds, not machine learning profiling.
  • Demand & Utilisation Analytics: Aggregated seat occupancy calculations and trend analysis using anonymised data. This does not produce decisions affecting individual users.

13.2 Impact Assessment

None of the above automated processes produce legal effects or significantly affect individual users’ rights. Specifically:

  • No automated decision results in denial of service, credit assessment, or discrimination
  • All automated decisions are reviewable by a human operator upon request
  • Subscription status changes and payment calculations can be overridden by library staff or BookMyLib support
  • WiFi attendance rejections do not prevent you from checking in via alternative methods (QR code, manual)

13.3 Your Right to Contest

You may contest any automated decision by contacting the library staff directly (for attendance and subscription issues) or by emailing our support team at studyspotindia@gmail.com. We will review the automated decision manually and provide a reasoned response within 48 hours.

14. Consent Management

In compliance with Section 6 of the DPDPA, 2023 (which requires “free, specific, informed, unconditional and unambiguous” consent) and GDPR Article 7 (where applicable), we implement granular consent management throughout the Service.

14.1 How Consent Is Obtained

  • Account Registration (Core Consent):Upon signing up, you provide affirmative consent (checkbox acknowledgment or button click) to this Privacy Policy and our Terms of Service. This consent covers the processing activities described as “Contract” or “Consent” in the legal basis column of Section 1.6. You cannot create an account without providing this core consent.
  • Google API Integrations (Granular OAuth Consent):Each Google API scope (sign-in, Business Profile, Contacts, Gmail send) requires a separate OAuth consent flow managed by Google’s consent screen. You select which scopes to authorise and can revoke individual scopes at any time. We do not bundle Google scopes or require unnecessary permissions.
  • WiFi Auto-Attendance (Device Permission Consent):Requires explicit runtime permission grant for Location access on your Android device. The Android OS presents a system-level permission dialog explaining what data the app will access. You must affirmatively tap “Allow” or “While using the app”.
  • Push Notifications (Device Permission Consent): On Android 13+ (API 33+), requires explicit runtime permission grant via a system-level dialog. On earlier Android versions, push notifications are enabled by default but can be disabled in system settings.
  • WhatsApp Notifications (Implicit via Library Subscription): For libraries on the Pro plan with WhatsApp enabled, students who subscribe to that library may receive transactional WhatsApp messages (booking confirmations, payment reminders). Students may opt out by notifying the library owner.

14.2 Withdrawing Consent

You may withdraw consent for any optional processing activity at any time through the following methods. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal (DPDPA Section 6(4); GDPR Article 7(3)).

  • Google API Integrations: Settings → Integrations → Disconnect. OAuth tokens are immediately revoked with Google and deleted from our database.
  • WiFi Auto-Attendance: Android Settings → Apps → BookMyLib → Permissions → Location → Deny. Takes effect immediately; WiFi data is no longer read.
  • Push Notifications: Android Settings → Apps → BookMyLib → Notifications → Disable. Or within the app: Settings → Notifications.
  • WhatsApp Notifications: Contact your library owner or email us to opt out. The library can disable WhatsApp for your account specifically.
  • Account Deletion (Complete Consent Withdrawal):Email studyspotindia@gmail.com with subject “Account Deletion Request”. Your account will be deactivated within 24 hours and all Personal Data will be anonymised within 90 calendar days, subject to mandatory legal retention periods (Section 7).

14.3 Consequences of Consent Withdrawal

Withdrawing consent for essential processing (core account consent) will result in inability to use the Service and may require account deletion. Withdrawing consent for optional features (WiFi attendance, Google integrations, push notifications, WhatsApp) will disable only the specific feature; all other Service functionality remains unaffected.

14.4 Consent Records

We maintain timestamped records of consent given and withdrawn, including: the consent mechanism (checkbox, OAuth, device permission), the specific scope of consent, the date and time of consent, and the version of the Privacy Policy accepted. These records are retained for the duration of the account plus 3 years for compliance and audit purposes.

15. Third-Party Services & Links

The Service integrates with or links to third-party services in the following categories. Each operates independently and is governed by its own privacy policy. We encourage you to review their policies before using these integrations:

  • Payment Gateways: PCI-DSS Level 1 certified payment processors for handling transactions via UPI, cards, and netbanking.
  • Authentication & Identity: Industry-standard OAuth providers for secure sign-in and identity verification.
  • Business Messaging: WhatsApp Business API for automated notifications (Pro plan only).
  • Push Notifications: Certified push notification services for delivering mobile alerts.
  • Media Services: Image hosting and optimisation providers for user-uploaded content.
  • Hosting & Infrastructure: SOC 2 Type II certified application hosting and database providers.

A complete list of third-party service providers, along with links to their respective privacy policies, is available upon request by contacting our Grievance Officer (see Section 17).

BookMyLib is not responsible for the privacy practices, terms of service, or data processing activities of these third-party services. Any data you provide directly to these services (e.g., payment details entered in Razorpay’s iframe) is governed solely by their privacy policies. We do not control and are not liable for their data handling practices.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. We categorise changes as follows:

16.1 Material Changes

  • Definition: Changes that expand the categories of data collected, introduce new data sharing with third parties, reduce your rights, change the legal basis for processing, or alter data retention periods.
  • Notification: At least 30 days’ advance notice via email to your registered address and a prominent in-app notification/banner.
  • Consent: Where material changes require renewed consent under DPDPA or GDPR, we will obtain your affirmative consent before the changes take effect. Continued use of the Service after the notification period constitutes acceptance only where renewed consent is not legally required.

16.2 Non-Material Changes

  • Definition: Minor wording clarifications, formatting improvements, updates to contact information, or changes that do not affect the substance of your rights or our obligations.
  • Notification:The “Last updated” date at the top of this page will be updated. No separate notification is required.

16.3 Your Right to Terminate

If you disagree with a material change, you may delete your account before the effective date of the change without any penalty or additional fees. Your data will be handled in accordance with the version of the Policy that was in effect at the time of your deletion request.

16.4 Version History

Previous versions of this Privacy Policy are available upon request by emailing studyspotindia@gmail.com with the subject “Privacy Policy Version Request”.

17. Contact & Grievance Officer

For questions, concerns, complaints, or data rights requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:

Grievance Officer

Designated under Section 5(2) of the Information Technology Act, 2000 (read with Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021) and Section 8(10) of the Digital Personal Data Protection Act, 2023

Organisation: StudySpot India (operating as BookMyLib)

Email: studyspotindia@gmail.com

Address: New Delhi, India 110001

Response & Resolution Timeline:

  • Acknowledgment: Within 24 hours of receipt (excluding weekends and Indian public holidays)
  • General Inquiries: Substantive response within 48 hours
  • Data Rights Requests: Processed within 30 calendar days (extendable by 30 days for complex requests)
  • Grievance Resolution: Within 30 calendar days, in accordance with Rule 3(11) of the IT Intermediary Guidelines
  • Escalation:If dissatisfied with our response, you may: (a) escalate to the Data Protection Board of India (DPBI)established under Section 18 of the DPDPA, 2023; or (b) for EEA users, lodge a complaint with your local Data Protection Supervisory Authority
Legal Notices: All formal legal notices, regulatory communications, and litigation-related correspondence should be sent to our registered office address via registered post or courier with acknowledgment due. Electronic legal notices may be sent to studyspotindia@gmail.com and will be acknowledged within 24 hours.
BookMyLib Privacy Policy
Version 3.0 · Effective July 6, 2025 · Governed by Indian law
Terms of ServiceRefund PolicyBack to top