1. Introduction
This Privacy Policy explains how BOOKMYSET TECHNOLOGIES PRIVATE LIMITED, which operates the wenuru platform ("wenuru", "we", "us", or "our"), collects, uses, discloses, stores, retains and protects your personal data when you use our platform.
wenuru is an online marketplace that connects people who want to book creative spaces and creative services — photo studios, video studios, podcast studios, shoot locations, and freelance creative professionals — with the hosts, studio owners and freelancers who offer them, primarily across India.
This policy applies to:
- The website at wenuru.com and all of its subdomains
- The wenuru Android application distributed through Google Play
- The wenuru iOS application distributed through the Apple App Store
- The wenuru host and administrator consoles
- Our APIs, booking flows, in-platform messaging, emails, notifications and support channels
Together these are referred to as the "Platform". By creating an account or otherwise using the Platform, you acknowledge that you have read and understood this Privacy Policy. Where the law requires your consent, we will ask for it separately and you may withdraw it at any time as described in Section 14.
This policy should be read together with our Terms & Conditions, Cancellation Policy and Disclaimer.
2. Who we are and how to reach us
The wenuru platform is owned and operated by:
BOOKMYSET TECHNOLOGIES PRIVATE LIMITED A company incorporated under the Companies Act, 2013 Registered office: 4th Floor, Arcadia Grace, K No. 1177/205, Pattandur Agrahara, Whitefield, Bengaluru, Karnataka — 560066, India
"wenuru" is the brand and trading name under which BOOKMYSET TECHNOLOGIES PRIVATE LIMITED provides the Platform. In this policy, "wenuru", "we", "us" and "our" mean BOOKMYSET TECHNOLOGIES PRIVATE LIMITED.
For the purposes of the Digital Personal Data Protection Act, 2023, BOOKMYSET TECHNOLOGIES PRIVATE LIMITED is the Data Fiduciary in respect of the personal data described in this policy.
For any privacy question, request or complaint, write to support@wenuru.com with the subject line "Privacy Request". Grievance escalation details are in Section 17.
3. The roles people hold on wenuru
Different people share different data with us, so it helps to be precise about roles:
- Customer / Creator — a person who searches for, enquires about, books and pays for a space or a creative service.
- Host / Studio owner — a person or business that lists a space or service, sets availability and pricing, and receives payouts.
- Freelancer — an individual creative professional who lists services on the Platform.
- Manager / Crew — a team member a host adds to a listing to help operate it, with limited access to that listing's bookings and enquiries.
- Administrator — wenuru personnel who operate, moderate and support the Platform.
Where a section below applies only to a particular role, we say so.
4. Personal data we collect
4.1 Data you provide directly
Account and identity data
- Email address (required; this is your primary account identifier)
- Mobile phone number
- First name and last name
- Profile photograph, if you upload one
- The sign-in method you choose — a one-time password (OTP) sent to your email, Sign in with Google, or Sign in with Apple
- The unique identifier supplied by Google or Apple when you use social sign-in
- Your selected role on the Platform, and the listings you are a member of
- Where you request an email change, the new ("pending") email address until it is verified
Booking and enquiry data (Customers)
- The listing, service and pricing plan you select
- Booking date, start and end time, duration, timezone and preferred time slot
- Number of guests or crew attending
- Add-ons you select and the resulting price breakdown
- Booking status, payment status, reschedule history and cancellation records
- Enquiry messages you send to hosts about a listing
- Wishlist and saved listings
- Reviews you submit — rating, title, written review, photographs, the service reviewed and the display name shown with the review
Listing and business data (Hosts, Freelancers)
- Listing title, description, category, sub-category and what the space is suitable for
- Listing contact email and phone number
- Listing address, locality and map location, including latitude and longitude coordinates selected via Google Maps and Places
- Operating hours, availability rules, blocked dates and booking lead times
- Pricing plans, hourly and fixed rates, cleaning fees and add-ons
- Photographs, galleries, logos and other listing media
- GST registration number, where you supply one
- Team members you add to a listing, and their roles
Verification (KYC) data (Hosts, Freelancers)
- Identity and business verification documents you upload
- The document reference number you enter
- The verification status, the date it was reviewed, and any reason recorded if a request is rejected
Payout data (Hosts, Freelancers)
- Your chosen payout method — bank account or UPI
- Bank account holder name, bank account number, IFSC code and bank name; or your UPI ID
- The contact and fund-account identifiers created for you by our payments partner
- Payout records: amount, currency, method, reference, status and payment date
Payment data (Customers, Hosts)
- The order, payment and receipt identifiers generated by our payments partner
- Amount, currency (₹ INR), payment status, timestamp and, where a payment fails, the failure reason
- A snapshot of the amounts that made up the transaction, including platform commission and applicable GST
- Subscription plan and billing records, where you subscribe to a paid host plan
We do not collect or store your full card number, card expiry, CVV, UPI PIN, net-banking credentials or any other payment authentication credential. Those are captured directly by our payment gateway on its own systems. See Section 8.
Messages and attachments
- Messages you exchange with other users through in-platform chat, including message text, timestamps and read state
- Files and images you attach to messages
- Any report you file about a conversation or a message, including the reason and the details you give
Support and contact data
- Your name, email address, phone number, the audience and topic you select, and your message when you use our contact form or email support
- Whether you gave consent on the form
- Whether the request is an account-deletion request
- Notes our team records while resolving your request
4.2 Data we collect automatically
- Device and app data — device type and model, operating system and version, app version, browser type and version, language and screen characteristics
- Log and usage data — IP address, request identifiers, pages and screens viewed, listings viewed, searches and filters used, referring URLs, timestamps, and errors encountered
- Approximate location — derived from your IP address, and from the city or area you search in. We do not collect continuous background location. On mobile, precise device location is used only if you grant the permission and only while you are actively using a feature that needs it, such as finding spaces near you
- Cookies, local storage and similar technologies — see Section 6
- Analytics events — where analytics is enabled for the property, aggregated usage measurement through Google Analytics
- Security and integrity signals — sign-in attempts, OTP request and verification attempt counts, rate-limiting counters, and audit records of privileged administrative actions
4.3 Data we receive from third parties
- Google and Apple, when you use social sign-in: your email address, basic profile details you have permitted, and a stable account identifier. We do not receive your Google or Apple password. Where you use Apple's private-relay email, we receive and use the relay address
- Our payments partner: payment outcome, settlement and payout status, and limited instrument metadata such as the payment method used
- Hosts and customers: information a counterparty provides about a booking you are part of, for example a host recording an offline payment for your booking
- Public and open sources, such as map and place data used to resolve an address you enter
4.4 Data about other people
If you enter another person's details — for example a co-host, a crew member, or a colleague attending a shoot — you confirm that you are entitled to share those details with us for the purpose described.
5. Mobile application specifics
Our Android and iOS apps may request the following device permissions. Each is optional, each is requested in context, and each can be revoked at any time in your device settings without losing access to the rest of the app:
- Camera — to take a photograph for a listing, a review or a chat message
- Photos, media and files — to upload images you select for listings, reviews, verification documents or chat
- Location — to show spaces near you and to pre-fill a city; used only in the foreground
- Notifications — to send booking, message and payment updates
Revoking a permission may disable the specific feature that relies on it. The apps do not read your contacts, call logs or SMS messages.
Your use of the apps is also subject to the privacy practices of the store you downloaded them from. Google Play and the Apple App Store may process data about the download, installation, updates and crash reporting under their own policies, which we do not control.
6. Cookies and similar technologies
We use a small number of cookies and browser storage mechanisms:
- Strictly necessary — a session cookie (
sp_token) and equivalent browser storage that keep you signed in, protect the session, and let the host console hold your access token. The Platform cannot function without these - Preference — remembering choices such as recently used filters or dismissed prompts
- Analytics — where a measurement property is configured, Google Analytics cookies help us understand aggregate usage, which pages perform poorly and where journeys break. This is measurement, not advertising
We do not use cookies to build cross-site advertising profiles and we do not sell cookie data.
You can clear or block cookies through your browser settings, and reset the advertising identifier on your mobile device. Blocking strictly necessary cookies will sign you out and break booking flows.
7. How and why we use your personal data
| Purpose | Data used | Basis |
|---|---|---|
| Create and operate your account; authenticate you; send OTPs | Account, identity, device, security signals | Performance of our contract with you |
| Publish listings and show them in search | Listing, business, media, location data | Contract; host instruction |
| Take, confirm, reschedule and cancel bookings | Booking, account, listing data | Contract |
| Process payments, commission, GST and host payouts | Payment, payout, billing, GST data | Contract; legal obligation |
| Enable communication between customers and hosts | Messages, attachments, account data | Contract |
| Verify hosts and reduce fraud and impersonation | KYC documents, identity, security signals | Legitimate interest; legal obligation |
| Moderate content, listings and attachments | Listing media, chat attachments, message text | Legitimate interest in a safe marketplace |
| Provide customer support and resolve disputes | Support, booking, payment, message data | Contract; legitimate interest |
| Send transactional emails and notifications | Account, booking, payment data | Contract |
| Send marketing or product updates, where you have opted in | Account and usage data | Consent |
| Measure and improve the Platform | Usage, analytics, device data | Legitimate interest; consent where required |
| Enforce our Terms, protect our rights, and defend claims | Any relevant category | Legitimate interest; legal obligation |
| Comply with tax, accounting, anti-fraud and other legal duties | Booking, payment, payout, GST data | Legal obligation |
We do not use your personal data to make solely automated decisions that produce legal effects about you, other than the safety and integrity measures described in Section 8.
8. Automated processing, moderation and payment handling
Automated content moderation. To keep the marketplace safe and to protect both sides of a booking, images and files uploaded to in-platform chat are scanned automatically. This scanning uses a third-party image-analysis service to detect unsafe or explicit content, reads text visible in an image, and detects QR codes and barcodes. Where a file is flagged, it may be blocked from delivery and made available to our moderation team for review.
Automated contact masking. Messages sent through in-platform chat are automatically scanned for phone numbers, email addresses, UPI IDs, external links and requests to pay outside the Platform. Where detected, those fragments are masked in the delivered message. This protects users from off-platform fraud, keeps the booking record complete, and enforces Section 11 of our Terms & Conditions. It means message content is processed by automated systems before delivery.
Watermarking. Images uploaded to listings and galleries may be automatically watermarked with the wenuru mark before they are published.
Payments. Payments and payouts are processed by Razorpay, a payment aggregator authorised by the Reserve Bank of India. When you pay, your card, UPI or net-banking details are collected on Razorpay's systems, not ours. We receive only the order reference, payment reference, amount, status and limited instrument metadata. Razorpay processes that data as an independent controller under its own privacy policy, and card data is handled under PCI DSS requirements.
Administrative access. Our administrators may, for support and dispute resolution, access an account in a time-limited support session. Every such session is logged with the administrator's identity, the account accessed and the time, and those logs are retained as an audit record.
9. How we share your personal data
We do not sell your personal data. We share it only as set out below.
9.1 With other users of the Platform
- When you make a booking, the host and the listing's authorised team members receive your name, the booking details, the amount paid and the contact route needed to fulfil the booking. Hosts need this to let you into the space and to run the session
- When you list a space, your listing details, business contact information, verified status, ratings and public host profile become visible to prospective customers. Do not put anything in a listing that you do not want to be public
- When you send an enquiry or a message, the recipient receives it, subject to the masking described in Section 8
- When you post a review, your rating, review text, photographs and the display name attached to the review are published publicly on the listing
9.2 With service providers who process data on our behalf
| Provider | What they do | Data involved |
|---|---|---|
| Razorpay | Payment collection, settlement and host payouts | Payment, payout, billing and limited identity data |
| Amazon Web Services | Cloud hosting, database and file storage; automated image moderation | All hosted data, uploaded media, chat attachments |
| Maps and Places for addresses and map display; Google Sign-In; Analytics; web fonts | Location and address data, sign-in identifiers, usage data | |
| Apple | Sign in with Apple; app distribution | Sign-in identifiers, app install and crash data |
| Email delivery provider | Sending transactional email and OTPs over SMTP | Email address, name, message content |
These providers are bound to use the data only for the services they provide to us, to keep it confidential, and to protect it appropriately.
9.3 For legal and safety reasons
We may disclose personal data where we reasonably believe it is necessary to comply with a law, regulation, court order or valid request from a law-enforcement or government authority; to enforce our Terms; to detect, prevent or address fraud, security or technical issues; or to protect the rights, property or safety of wenuru, our users or the public.
9.4 In a corporate transaction
If wenuru is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction. We will require the recipient to honour this policy, and we will notify you of any material change in how your data is handled.
9.5 With your direction
We share data with anyone else only where you ask us to, or where you have given consent.
10. Storage location and international transfers
The Platform is operated primarily for users in India and our infrastructure is hosted with cloud providers in one or more regions. Some of our service providers — including cloud hosting, image analysis, mapping, analytics and email delivery — may process personal data on servers outside India.
Where personal data is transferred outside India, we do so only for the purposes described in this policy, only with providers bound by contractual confidentiality and security obligations, and in accordance with applicable Indian law, including any restriction the Central Government may notify on transfers to specific countries.
11. Data security
We take the security of your data seriously and apply administrative, technical and physical safeguards, including:
- Encryption of data in transit using TLS/HTTPS
- Password-less authentication using short-lived, rate-limited one-time passwords, and signed JSON Web Tokens with expiry for sessions
- Hashed and time-boxed OTPs with attempt limits to resist brute force
- Role-based access control, with least-privilege permissions for host teams and administrators
- Audit logging of privileged actions, permission changes and support sessions
- Security headers, request rate limiting, CORS restrictions and input validation on every API endpoint
- Access to production data restricted to authorised personnel on a need-to-know basis
- Separation of payment credentials, which never reach our systems
No method of transmission or storage is completely secure. You are responsible for keeping access to your email account and device secure, since access to your email allows sign-in via OTP. Tell us immediately at support@wenuru.com if you suspect unauthorised use of your account.
If a personal data breach occurs that is likely to affect you, we will notify you and the relevant authority as required by law, and describe what happened and what you can do.
12. How long we keep your data
We keep personal data only as long as necessary for the purposes described, and then delete or anonymise it. Indicative periods:
| Category | Retention |
|---|---|
| Account and profile data | While your account is active, and up to 30 days after deletion completes |
| Booking, invoice, commission and payout records | Up to 8 years from the end of the relevant financial year, to meet tax, GST and accounting obligations |
| Payment and transaction records | Up to 8 years, as required by financial and audit rules |
| Host KYC and verification documents | While the host relationship is active, and up to 8 years thereafter where retention is required for compliance or dispute defence |
| In-platform messages and attachments | Up to 3 years from the last message in the conversation, or longer where linked to a dispute or an open report |
| Reviews and ratings | Retained after account deletion in de-identified form, because they form part of a host's public record |
| Support and contact submissions | Up to 3 years from resolution |
| Server, access and audit logs | Typically 90 to 180 days, longer where needed for a security investigation |
| Analytics data | Per the retention configured in the analytics property, typically up to 14 months |
| Marketing consent and opt-out records | For as long as needed to honour your preference |
Where we are required to keep a record, we restrict it so that it is used only for that legal purpose and not for ongoing service delivery.
13. Account deletion
You can ask us to delete your wenuru account and the personal data associated with it at any time, whether you signed up on the web, on Android or on iOS.
13.1 How to request deletion
From the website. Go to wenuru.com/contact, choose "Request account deletion" as your topic, confirm the email address registered to your account, and submit the form. The request is routed directly to our support team and flagged as a deletion request.
From the Android or iOS app. Open the app, go to your profile or account settings, and choose the account-deletion or help option, which opens the same deletion request flow. You can also use the website route above from your mobile browser — no app is required to delete your account.
By email. Write to support@wenuru.com from your registered email address with the subject line "Account Deletion Request".
We may ask you to verify control of the registered email address before acting on the request. This is to prevent someone else from deleting your account.
13.2 What happens next
- We acknowledge your request, ordinarily within 72 hours.
- We verify that the request comes from the account holder.
- We tell you about anything that must be resolved first — an upcoming confirmed booking, a pending refund, an unsettled host payout, or an open dispute — and give you the option to proceed once it is closed.
- We complete deletion, ordinarily within 30 days of a verified request, and confirm by email.
13.3 What is deleted
- Your name, email address, phone number and profile photograph
- Your profile, saved preferences, wishlist and saved searches
- Your payout details, including bank account number, IFSC and UPI ID
- Your identity and business verification documents
- Your draft and unpublished content
- Your device sessions and access tokens, so you are signed out everywhere
- Your marketing preferences and mailing-list entries
Where full deletion is not immediately possible, we de-identify the record so that it can no longer be linked to you.
13.4 What is retained, and why
Some records cannot be deleted on request, because the law requires us to keep them or because deleting them would destroy someone else's record:
- Financial records — bookings, invoices, payments, commission, GST and payout entries are retained for the statutory period described in Section 12. Your name is retained on an invoice only to the extent the invoice legally requires
- Reviews you posted — the rating and review text remain published, but are detached from your account and shown without your name or photograph, because deleting them would misrepresent a host's history
- Messages in a shared conversation — messages you sent remain visible to the other participant as part of their own record, shown under a removed-user label
- Records under active dispute, investigation or legal hold — retained until the matter is closed
- Fraud, abuse and safety records — where an account was restricted for abuse, fraud, payment default or a safety incident, we keep the minimum record needed to prevent the same person from re-registering
- Backups — deletion propagates to encrypted backups on their normal rotation cycle, ordinarily within 90 days
13.5 Hosts and listings
If you are a host, deleting your account also unpublishes your listings. Before we can complete deletion we will ask you to complete or cancel any confirmed future bookings, so that customers who have already paid are not left without a space. Any pending payout owed to you will be settled to your registered payout account before the payout details are erased.
13.6 Deactivating instead of deleting
If you only want to pause, ask us to deactivate the account instead. A deactivated account is hidden and unusable but recoverable. Deletion is permanent and cannot be reversed — you will not be able to recover bookings, messages, reviews or host history, and re-registering with the same email creates a new, empty account.
14. Your rights and choices
Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you have the right to:
- Access — obtain a summary of the personal data we hold about you, how it is processed, and the categories of third parties it has been shared with
- Correction and completion — have inaccurate or misleading data corrected, and incomplete data completed. Most profile fields can be edited directly in your account settings
- Erasure — ask us to delete your personal data, as described in Section 13
- Withdraw consent — withdraw a consent you previously gave, with effect going forward. Withdrawing consent does not affect processing that relies on contract or legal obligation, and may limit features
- Opt out of marketing — unsubscribe from any marketing email using the link in that email, or by writing to us. You cannot opt out of transactional messages about your bookings, payments and account security
- Nominate — nominate another individual to exercise your rights on your behalf in the event of your death or incapacity
- Grievance redressal — raise a complaint with us and, if unresolved, escalate it as described in Section 17
To exercise a right, email support@wenuru.com from your registered email address. We respond within the timelines set by applicable law and ordinarily within 30 days. We may need to verify your identity first, and we may decline a request where the law permits — for example where it would compromise another person's rights, or where we are legally required to retain the data.
You are responsible for the accuracy of the information you give us, and for not making false or frivolous requests, including impersonating another person.
15. Children
The Platform is not intended for children under 18. We do not knowingly collect personal data from a child, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children.
Anyone under 18 may use the Platform only through a parent or legal guardian who holds the account, accepts the Terms & Conditions and takes responsibility for the activity. If you believe a child has provided us personal data, write to support@wenuru.com and we will delete it.
16. Third-party links and services
Listings, blog posts, messages and other content may link to third-party websites, applications, maps or payment pages. Those services have their own privacy policies and terms, and we do not control and are not responsible for their practices. Review their policies before providing personal data. See our Disclaimer.
17. Grievance officer and complaints
If you have a privacy concern, we want to resolve it. Write to:
Grievance Officer — wenuru BOOKMYSET TECHNOLOGIES PRIVATE LIMITED Email: support@wenuru.com Address: 4th Floor, Arcadia Grace, K No. 1177/205, Pattandur Agrahara, Whitefield, Bengaluru, Karnataka — 560066, India
Please include your registered email address, a description of the issue, and any reference numbers. We acknowledge complaints within 24 to 48 hours and aim to resolve them within 30 days, in line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is constituted and operational, or to any other competent authority.
18. Changes to this policy
We may update this Privacy Policy to reflect changes in our services, technology or the law. The "Last updated" date at the top of this page always shows the current version.
Where a change is material — for example a new purpose, a new category of recipient, or a change in retention — we will give notice by email, in-app notice or a prominent notice on the Platform before it takes effect, and where the law requires it we will seek fresh consent. Continued use of the Platform after a change takes effect means you accept the updated policy.
19. Contact us
For any question, request or concern about this policy or your personal data:
BOOKMYSET TECHNOLOGIES PRIVATE LIMITED Email: support@wenuru.com Contact form: wenuru.com/contact Registered office: 4th Floor, Arcadia Grace, K No. 1177/205, Pattandur Agrahara, Whitefield, Bengaluru, Karnataka — 560066, India