We are committed to protecting your data with transparency, accountability, and compliance with Indian and international data protection laws.
BookMyLib (“we”, “us”, “our”, or the “Company”), operated by StudySpot India, a company incorporated under the laws of India with its registered office at New Delhi, India 110001, is committed to protecting the privacy, confidentiality, and integrity of Personal Data entrusted to us by every individual who interacts with our platform.
This Privacy Policy (“Policy”) describes in detail how we collect, process, use, disclose, store, retain, transfer, and safeguard your Personal Data when you access or use our website (bookmylib.com), mobile application (Android), application programming interfaces (APIs), owner/staff dashboards, or any related services, features, or functionalities (collectively, the “Service”). This Policy applies to all categories of users — including but not limited to students, library owners, staff members, leads, prospective users, and casual visitors — regardless of how they access the Service.
This summary is provided for convenience only. In the event of any conflict, the detailed provisions below shall prevail.
We collect and process Personal Data through multiple channels in order to deliver, maintain, improve, and secure the Service. The principle of data minimization (collecting only what is adequate, relevant, and limited to what is necessary) governs our practices. Below is an exhaustive breakdown of each category of data we process.
This is data you voluntarily furnish when creating an account, completing your profile, configuring your branch, or communicating with us.
When you access or use the Service, certain information is collected automatically by our servers, the Android application, and third-party analytics tools embedded in the Service.
We receive data from the following third-party sources, each subject to separate consent flows where applicable:
openid profile email.business.manage.contacts.readonly.gmail.send.Under Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the following categories of data processed by us are classified as SPDI and receive heightened protection measures:
In accordance with Rule 5(1) of the SPDI Rules, we collect SPDI only with your prior informed consent, which may be given electronically. You may withdraw consent at any time pursuant to Section 14 of this Policy.
For the avoidance of doubt, BookMyLib does not collect or process the following:
| Category | Data Elements | Purpose | Legal Basis (DPDPA / GDPR) |
|---|---|---|---|
| Identity & Contact | Name, email, phone, photo, DOB | Account creation, communication | Consent (S.6 DPDPA); Art.6(1)(b) GDPR |
| Financial / SPDI | Payment refs, UPI VPA, amounts | Payment processing, invoicing, tax compliance | Contract; Legal Obligation (S.7 DPDPA); Art.6(1)(c) GDPR |
| Attendance & WiFi | Check-in/out, SSID, BSSID, method, confidence | Attendance verification, anti-spoofing | Consent (S.6 DPDPA); Legitimate Interest Art.6(1)(f) GDPR |
| Technical / Device | IP, browser, OS, device model, FCM token | Security, fraud prevention, notifications | Legitimate Interest (S.7 DPDPA); Art.6(1)(f) GDPR |
| Google API Data | OAuth profile, GBP listings, Contacts, Gmail send | SSO, branch management, directory import, notifications | Consent (revocable at any time); Limited Use Policy |
| Booking / Subscription | Plan, seat, dates, status, renewals, locker | Service delivery, billing, analytics | Contract (S.7 DPDPA); Art.6(1)(b) GDPR |
| Communications | Support tickets, WhatsApp logs, announcements | Support, service updates, quality assurance | Contract; Consent (S.6 DPDPA); Art.6(1)(b) GDPR |
| KYC / Business (Owners) | Aadhaar (last 4), PAN, GSTIN, bank details | Identity verification, regulatory compliance | Legal Obligation (S.7 DPDPA); Art.6(1)(c) GDPR |
| Lead / Inquiry | Name, phone, email, inquiry subject | Lead follow-up, conversion | Consent (S.6 DPDPA); Legitimate Interest Art.6(1)(f) GDPR |
We process your Personal Data only for specified, explicit, and legitimate purposes as described below. In accordance with the purpose limitation principle under Section 5 of the DPDPA, 2023, we do not process your data for purposes incompatible with those for which it was originally collected, unless we obtain your separate consent or are required to do so by law.
Where we rely on “legitimate interest” (under GDPR Art. 6(1)(f) or DPDPA S.7) as a legal basis for processing, we conduct a balancing test to ensure our interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interest at any time by contacting our Grievance Officer (Section 17).
We do not sell, rent, lease, trade, or otherwise commercially share your Personal Data with any third party for their own marketing purposes. We disclose Personal Data only in the following strictly limited circumstances, and only to the minimum extent necessary for the stated purpose:
We engage carefully vetted third-party service providers who process Personal Data on our behalf, subject to contractual data protection obligations equivalent to or stricter than those in this Policy. These providers fall into the following categories:
Data shared with each provider is limited to the minimum necessary for the stated purpose. All data in transit is encrypted using TLS 1.2+, and data at rest is encrypted using industry-standard encryption. A complete list of sub-processors is available upon request by contacting our Grievance Officer.
Each sub-processor is bound by a Data Processing Agreement (DPA) or equivalent contractual terms that restrict their use of your data solely to providing the contracted service and require them to implement appropriate security measures.
When you register, book, or subscribe at a library branch, the authorised owners and staff of that specific branch may access the following data, limited to their own tenant scope:
Library partners cannotaccess: (i) your data at any other library; (ii) your password or authentication credentials; (iii) your device/IP information; (iv) your Google API data; or (v) raw WiFi BSSID values (they see only the match result: match/no-match).
We may disclose your Personal Data without your prior consent if required or permitted under applicable law, including but not limited to:
Where legally permissible, we will notify you of such disclosures and provide you with a copy of the request received.
In the event of a merger, acquisition, reorganisation, asset sale, joint venture, or insolvency/bankruptcy proceeding involving BookMyLib, your Personal Data may be transferred to the successor entity or acquiring party as part of the transaction assets. In such event:
We may share anonymised, aggregated, and de-identified data (from which no individual can be reasonably identified) with partners, researchers, or for public reporting. For example: “Average study session duration across all libraries is 4.2 hours.” Such data is not Personal Data under DPDPA or GDPR.
We implement and maintain comprehensive technical and organisational measures designed to protect your Personal Data against unauthorised access, alteration, disclosure, destruction, or accidental loss. These measures are proportionate to the nature, scope, and sensitivity of the data processed, in accordance with Rule 8 of the SPDI Rules, 2011 (which mandates “reasonable security practices and procedures”) and the security obligations under Section 8(4) of the DPDPA, 2023.
android:allowBackup is set to false to prevent unencrypted backup extraction.libraryId). Role-based middleware enforces access boundaries between admin, owner, staff, and student roles. Cross-tenant data access is architecturally impossible.In the event of a confirmed Personal Data breach (unauthorised access, disclosure, alteration, or destruction of Personal Data):
Disclaimer: While we implement industry-standard safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. In the event of a breach despite our safeguards, we will act promptly as described above.
As a Data Principal under the DPDPA, 2023, and potentially as a data subject under the GDPR (if you are located in the EEA), you are entitled to the following rights. We are committed to facilitating the exercise of these rights in a transparent, accessible, and timely manner.
If you are located in the European Economic Area, you additionally enjoy the following rights under the General Data Protection Regulation:
To exercise any of the above rights, please follow this procedure:
Upon a valid data portability request, we will provide your Personal Data in one of the following machine-readable formats at your choice: JSON (JavaScript Object Notation) or CSV (Comma-Separated Values). The export will include your profile data, booking history, attendance records, and payment transaction records. The export will be delivered via a secure, time-limited download link sent to your registered email address.
BookMyLib uses a minimal, carefully curated set of cookies and client-side storage technologies that are strictly necessary for the operation, security, and functionality of the Service. We do not use third-party advertising cookies, cross-site tracking pixels, web beacons, fingerprinting scripts, or any technology designed to track your browsing activity across unrelated websites.
Our cookies fall into two categories under the ePrivacy Directive framework and Indian regulatory guidance:
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| session_token | Essential | User authentication & session | Session / 30 days |
| csrf_token | Essential | CSRF protection | Session |
| theme | Functional | Light/dark mode preference | 1 year |
| branch_pref | Functional | Last-selected branch | 90 days |
During payment checkout, Razorpay and Cashfree may set their own cookies within their secure iframes to manage the payment session, detect fraud, and comply with PCI-DSS requirements. These cookies are governed by Razorpay’s Cookie Policy and Cashfree’s Privacy Policy respectively. BookMyLib does not have access to or control over these third-party cookies.
In addition to cookies, the Service may use browser localStorage and IndexedDB to cache non-sensitive UI state (e.g., sidebar collapse state, recently viewed pages) for performance optimisation. This data remains entirely on your device and is never transmitted to our servers. Clearing your browser data will remove all locally stored information.
You may configure your browser to refuse cookies, delete existing cookies, or alert you before a cookie is set. Note that disabling essential cookies (session_token, csrf_token) will prevent you from logging in to the Service. Instructions for managing cookies are available in your browser’s help documentation.
We retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The specific retention periods are determined based on: (i) the nature and sensitivity of the data; (ii) the purposes of processing; (iii) legal, regulatory, and contractual obligations; and (iv) our legitimate business interests (e.g., dispute resolution and fraud prevention).
| Data Category | Retention Period | Reason |
|---|---|---|
| Active account data | Duration of account + 3 years | Service continuity, audit |
| Financial records | 8 years from transaction | Indian Income Tax Act, GST |
| Attendance logs | 3 years | Dispute resolution, analytics |
| Support tickets | 2 years after resolution | Quality assurance |
| Server/access logs | 90 days | Security monitoring |
| Deleted account data | Anonymized within 90 days | DPDPA compliance |
| Google API tokens | Revoked on disconnect | Consent withdrawal |
| WhatsApp message logs | 1 year | Delivery confirmation |
Notwithstanding the above retention periods, we may retain specific data for longer periods if required by a legal hold, pending litigation, regulatory investigation, or court order. Affected users will be notified of such holds where legally permissible.
BookMyLib is headquartered in India and primarily serves Indian users. However, due to our use of globally distributed cloud infrastructure, your Personal Data may be processed in jurisdictions outside India. We ensure that all cross-border transfers comply with applicable data protection laws and are subject to appropriate safeguards.
Your data may be processed across multiple geographic regions depending on the service. Our key infrastructure commitments:
For transfers of Personal Data outside India, we rely on the following safeguards, as applicable:
You may request information about the specific safeguards applied to the transfer of your data outside India by contacting our Grievance Officer (Section 17). If you object to your data being transferred internationally, you may request account deletion; however, this will result in inability to use the Service as our core infrastructure requires cross-border data processing.
BookMyLib operates as a multi-tenant Software-as-a-Service (SaaS) platform where multiple independent libraries share the same underlying infrastructure while maintaining strict data isolation. This section explains how your data is partitioned, who can access what, and the legal relationships between BookMyLib and library operators.
Each library’s data is logically isolated at the database level through tenant-scoped queries. Every database operation is filtered by a unique libraryId identifier, ensuring that:
| Data Category | Owner | Staff | Student | Admin |
|---|---|---|---|---|
| Student profiles (own library) | ✅ | ✅ | Own only | ✅ |
| Booking & subscription records | ✅ | ✅ | Own only | ✅ |
| Attendance logs | ✅ | ✅ | Own only | ✅ |
| Payment records & financial reports | ✅ | ❌ | Own receipts | ✅ |
| Integration settings (Google, WhatsApp) | ✅ | ❌ | ❌ | ✅ |
| WiFi BSSID configuration | ✅ | ❌ | ❌ | ✅ |
| Staff management | ✅ | ❌ | ❌ | ✅ |
| Other library’s data | ❌ | ❌ | ❌ | ❌ |
Under the DPDPA, 2023, the data processing relationship in the BookMyLib ecosystem is structured as follows:
This dual role (Processor for tenant data; Fiduciary for platform data) is clearly delineated in our system architecture and reflected in our Data Processing Agreement with library owners.
ACCESS_FINE_LOCATION permission is an Android operating system requirement for reading WiFi network information — it does not mean we track your physical location.Starting with Android 8.1 (Oreo) and reinforced in Android 10+, Google’s Android operating system classifies WiFi network information (SSID and BSSID) as location-derived data because WiFi access point identifiers can theoretically be used to approximate physical location (via WiFi positioning databases). As a result, the ACCESS_FINE_LOCATION permission is required by the OS to read WiFi connection details. This is an immutable Android platform requirement, not a BookMyLib design choice.
What we do with this permission: Read the SSID and BSSID of your currently connected WiFi network. What we do NOT do: Call LocationManager.getLastKnownLocation(), FusedLocationProviderClient, or any GPS/cellular/Bluetooth location API.
WifiManager.getConnectionInfo() to read the current SSID and BSSID. This is a local, on-device operation.Attempting to spoof WiFi credentials (creating a fake WiFi network with a matching SSID, or using MAC address spoofing tools to fake a BSSID) to fraudulently record attendance without being physically present at the library constitutes a violation of our Terms of Service (Section 11) and may result in:
WiFi auto-attendance is entirely optional. You may opt out at any time using any of the following methods:
Revoking the Location permission will only disable WiFi auto-attendance. All other features of the app (bookings, payments, notifications, QR attendance) will continue to work normally.
The BookMyLib Android application is a Capacitor-based WebView application that loads the Service within a secure Android container. The following data practices and permissions are specific to the mobile application:
| Permission | Purpose | When Requested | Revocable? |
|---|---|---|---|
| INTERNET | Core network access for all Service functionality | Always (auto-granted) | No (required) |
| CAMERA | QR code scanning for attendance check-in | First QR scan attempt | Yes |
| ACCESS_FINE_LOCATION | Reading WiFi SSID/BSSID for auto-attendance (see Section 10.2) | First WiFi check-in | Yes |
| ACCESS_WIFI_STATE | Reading WiFi connection status and network info | Always (auto-granted) | No (normal) |
| POST_NOTIFICATIONS | Displaying push notifications (booking, payment, expiry alerts) | Android 13+ on first launch | Yes |
| RECEIVE_BOOT_COMPLETED | Re-registering FCM token after device restart | Always (auto-granted) | No (normal) |
You can revoke any runtime permission at any time through: Android Settings → Apps → BookMyLib → Permissions. Revoking a permission disables only the specific feature that requires it; all other features continue to function normally. The app does not request permissions that are not directly required for a user-facing feature.
android:allowBackup=false prevents extraction of application data through ADB backup.We may release updates to the mobile application through the Google Play Store to address security vulnerabilities, fix bugs, or add features. You are strongly encouraged to keep the app updated. Critical security updates may require a minimum app version; older versions may be blocked from accessing the Service after a reasonable deprecation period.
BookMyLib is committed to protecting the privacy and safety of children. Under the DPDPA, 2023, a “child” is defined as any individual below the age of 18 years. The following provisions apply to the processing of children’s Personal Data:
If we discover that we have collected Personal Data from a child without proper parental consent, we will:
BookMyLib employs certain automated processing systems as part of the Service. In accordance with transparency obligations under GDPR Article 22 and the principles of the DPDPA, 2023, we disclose the following automated decision-making and profiling activities:
None of the above automated processes produce legal effects or significantly affect individual users’ rights. Specifically:
You may contest any automated decision by contacting the library staff directly (for attendance and subscription issues) or by emailing our support team at studyspotindia@gmail.com. We will review the automated decision manually and provide a reasoned response within 48 hours.
In compliance with Section 6 of the DPDPA, 2023 (which requires “free, specific, informed, unconditional and unambiguous” consent) and GDPR Article 7 (where applicable), we implement granular consent management throughout the Service.
You may withdraw consent for any optional processing activity at any time through the following methods. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal (DPDPA Section 6(4); GDPR Article 7(3)).
Withdrawing consent for essential processing (core account consent) will result in inability to use the Service and may require account deletion. Withdrawing consent for optional features (WiFi attendance, Google integrations, push notifications, WhatsApp) will disable only the specific feature; all other Service functionality remains unaffected.
We maintain timestamped records of consent given and withdrawn, including: the consent mechanism (checkbox, OAuth, device permission), the specific scope of consent, the date and time of consent, and the version of the Privacy Policy accepted. These records are retained for the duration of the account plus 3 years for compliance and audit purposes.
The Service integrates with or links to third-party services in the following categories. Each operates independently and is governed by its own privacy policy. We encourage you to review their policies before using these integrations:
A complete list of third-party service providers, along with links to their respective privacy policies, is available upon request by contacting our Grievance Officer (see Section 17).
BookMyLib is not responsible for the privacy practices, terms of service, or data processing activities of these third-party services. Any data you provide directly to these services (e.g., payment details entered in Razorpay’s iframe) is governed solely by their privacy policies. We do not control and are not liable for their data handling practices.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. We categorise changes as follows:
If you disagree with a material change, you may delete your account before the effective date of the change without any penalty or additional fees. Your data will be handled in accordance with the version of the Policy that was in effect at the time of your deletion request.
Previous versions of this Privacy Policy are available upon request by emailing studyspotindia@gmail.com with the subject “Privacy Policy Version Request”.
For questions, concerns, complaints, or data rights requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:
Grievance Officer
Designated under Section 5(2) of the Information Technology Act, 2000 (read with Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021) and Section 8(10) of the Digital Personal Data Protection Act, 2023
Organisation: StudySpot India (operating as BookMyLib)
Email: studyspotindia@gmail.com
Address: New Delhi, India 110001
Response & Resolution Timeline: