The DPDP Act is live. Fines reach ₹250 Cr, and every day matters.Run a free check
HOSPITALITY & TRAVEL

A guest gives you their data once. You use it eleven times.

Booking engine, OTA, property management system, POS, WiFi captive portal, loyalty programme, WhatsApp campaigns. A guest hands over their details once and the group processes them in a dozen places, most of which were never designed to ask permission.

Built for: Hotel groups, resorts, restaurant and QSR chains, travel operators, OTAs and loyalty programmes.

WHAT MAKES THIS SECTOR DIFFERENT

The pressure points, specifically

01

The guest record is fragmented by design

The same person exists in the PMS, the POS, the loyalty database and three campaign tools, often under different identifiers. A withdrawal that only reaches one of them is not a withdrawal, and a regulator will treat it as a failure rather than an integration problem.

02

Marketing is the whole commercial model

Offers, re-booking nudges, birthday campaigns and loyalty tiers are how the business grows, and every one of them needs a lawful basis you can produce on demand. Bought and inherited lists are the exposure nobody wants to look at.

03

Franchise and management contracts blur the roles

When the brand, the owner and the operator are three different companies, it is genuinely unclear who is the Data Fiduciary for the guest. That question has to be answered in writing before an incident forces the answer.

04

Collection happens at the least convenient moment

Check-in queues, a WiFi splash page, a QR code on a table. Consent has to be captured in seconds, in the guest's language, on their phone, without a member of staff explaining a privacy notice at the desk.

WHAT SAMMATI DOES

The parts that matter here

  • One guest identity across every property

    Consent is recorded against the data principal rather than the property or the channel, so a withdrawal captured at one hotel is visible to the loyalty programme and the campaign tool immediately, and the ledger shows when it took effect.

  • Capture in seconds, on the guest's phone

    A hosted consent page you can put behind a QR code at check-in, on a WiFi captive portal or in a booking confirmation, built to load fast on a mobile connection and available in twenty-two Indian languages.

  • Self-service preferences the guest actually finds

    An OTP-verified preference centre where a guest can turn marketing channels on and off themselves. It reduces the unsubscribe-by-complaint route, and every change lands in the same ledger as the original consent.

  • Bring an existing guest database into compliance

    Import the contacts you already hold, run a re-consent campaign against them, and get a defensible position on a legacy list rather than quietly continuing to mail it.

  • Cookie and web consent that matches the record

    A consent banner for the booking site and a scanner that tells you which trackers are actually firing, so the website story and the ledger story are the same story.

QUESTIONS WE GET ASKED

Hospitality and the DPDP Act

General information about the DPDP Act, 2023, not legal advice. For a position specific to your organisation, talk to us.

Where to start

Find out where you actually stand.

The free self-assessment takes a few minutes and gives you a written position on your own setup, not a generic checklist.