1. Overview
Growth Story Company takes the security of HotelPilot.in and the data entrusted to it seriously. This Security Policy outlines the technical and organizational measures in place to protect Property and guest data.
2. Access Control
- Role-based access control (RBAC) ensures staff only access features and data relevant to their role.
- All user accounts are created exclusively by authorized administrators (superadmin or property owner) — there is no public self-registration on the platform.
- Multi-property data isolation is enforced at the database level, ensuring one Property cannot access another Property's data.
- Two-Factor Authentication (2FA) via TOTP (e.g. Google Authenticator) is available/enforced for sensitive accounts.
- Session timeout and rate limiting are enforced to reduce the risk of unauthorized or automated access.
3. Data Protection
- Row-Level Security (RLS) policies are applied across data tables, using security-definer database functions to enforce property-level and role-level data scoping.
- Data is encrypted in transit using industry-standard protocols (HTTPS/TLS).
- Sensitive operations (such as data wipe/reset) are restricted to the database level and are not exposed through the application interface, to prevent accidental or malicious data loss.
4. Audit & Monitoring
- Key actions within the Service (such as billing changes, cancellations, and administrative actions) are logged for audit and accountability purposes.
- Soft-delete with audit trails is used for financial records such as bills, rather than permanent deletion, to preserve audit continuity.
- The platform undergoes periodic security review, including database-level security audits, with identified issues remediated on a prioritized basis.
5. Input Validation & Application Security
- Input sanitization is applied to reduce risks such as injection attacks.
- Application code and infrastructure configuration are reviewed and updated on an ongoing basis as the platform evolves.
6. Incident Response
In the event of a suspected or confirmed security incident affecting Property or guest data, the Company will investigate promptly, take reasonable steps to contain and remediate the issue, and notify affected Properties in accordance with the Data Processing Agreement.
7. Property & Staff Responsibilities
- Properties are responsible for safeguarding login credentials issued to their staff and for promptly reporting any suspected unauthorized access.
- Properties should promptly deactivate access for staff who no longer require it (e.g. upon termination of employment), by contacting the Company or their administrator.
8. Reporting a Security Concern
If you discover a potential security vulnerability or have concerns about the security of the Service, please report it immediately to Consult@Growthstoryco.in or call 8007444464. We take all reports seriously and will investigate promptly.
9. Changes to this Policy
This Security Policy may be updated as our security practices evolve. Material changes will be communicated to Properties where appropriate.
Contact Us
Growth Story Company
Office No. 2, Second Floor, Opposite Zudio Clothing, Hatte Corner, Ganj Golai, Latur - 413512, Maharashtra, India
Email: Consult@Growthstoryco.in
Phone: 8007444464