Privacy Policy
Corporate Worldwide Stay (CWS) values your trust and is committed to protecting your personal information. This Privacy Policy explains how we collect, use and safeguard your data when you use our website, services and payment systems.
1. General
Corporate Worldwide Stay LLP ("Corporate Worldwide Stay LLP", "we", "our" or "us") recognises the importance of protecting personal details and information, and provides this Privacy Policy with respect to the access and use of www.corporate-stay.com and Corporate Worldwide Stay LLP (the "Sites") as owned and operated by us and/or our affiliates, and the payment facilitation services including bill payment services provided by us (the "Services"). The term Sites also includes all pages that are sub-domains of, associated with or within each Site, and all devices, applications, features, technologies, functionalities and other services that Corporate Worldwide Stay LLP operates or offers through such Sites.
For the purpose of this Privacy Policy, the user of Services may be merchants, sellers, billers, customers, buyers, consumers, or any other person using the Services or accessing the Sites ("User", "you" or "your"). This Privacy Policy will help you understand our policies and procedures regarding the collection, handling and use of any information which, directly or in combination with other information, is capable of identifying the User ("Personal Information").
By using our Services through the Sites, you signify your assent to this Privacy Policy and consent to the processing of your Personal Information. If you do not agree with this Privacy Policy, do not in any manner use our Services or download, install or use the mobile application.
Our website address is https://corporate-stay.com.
2. Information collection
We collect information about you which is essential to operate our business and to enable us to deliver and improve our Services. We may obtain the following information about you and the device from which you avail the Services:
- Profiling information. For providing the Services we require certain information for registration, such as your name, physical and postal addresses, telephone and fax numbers, and certain information about your personal identity such as gender, marital status and age. We also collect and store the usernames, passwords, email addresses and other security-related information that you use on our Sites in relation to our Services.
- Service usage and transactional information. To enable you to make payments using our Services, we may, upon your consent, store financial information such as your bank account details, credit or debit card details, or other payment instrument details required for a successful transaction. For certain Services, including our bill payment service, we require your bill payment account information such as account number, payment history and account history with us. We also store transaction details such as amount spent, merchant name, transaction ID, and the date and time of your e-commerce transactions, and we may store information relating to your income and lifestyle levels. All information stored by us is held in accordance with our PCI DSS certification.
- Navigational and log information. We collect information about your navigation of our Services — for example the URLs of websites from which you reach our Site and from which you request downloads, pages visited or downloaded on our Site, and websites or merchant pages you visit using our Services. We may also collect your domain name, web request, IP address, mobile application version, operating system, browser type, browser language, location, the date and time of the request, the products you buy, the referring site, and the time you spend on the site.
- Correspondence information. We collect the content of, and information about, correspondence between you and any other person using our Services — including email, blog, chat room and discussion board communications, instant messages, expert forum communications, facsimile mail and mailing-list membership.
- Cookies. A cookie is a small portion of data sent to the web browser of the device from which the Site is accessed. If your browser settings permit, cookies may be sent to your browser to record information about your online preferences and allow us to cater to your interests. You can set your browser to notify you when you are sent a cookie, giving you the chance to decide whether to accept it. If you accept a cookie, you thereby agree to our use of the information collected by us using that cookie.
- Stored information. We may collect any data or information created by you or by a third party which you wish to store on our servers — usernames, image files, documents and similar — or which may be required to display information to you through our Services.
- One Time Password (OTP). An OTP is a one-time password provided by your issuing bank in order to carry out second-factor authentication of your debit or credit card. If you opt for our one-tap feature, you understand that we will be able to retrieve the OTP from the message received on your mobile, and populate and submit it on the issuer's page for second-factor authentication.
3. Purpose and use of information
We understand the importance of your Personal Information and ensure that it is used for the intended purpose. By accepting the terms of use, you agree that we may collect and store your Personal Information, in accordance with applicable law, for as long as you subscribe to or use our Services, subject to the limitations set out in this Privacy Policy.
- We require profiling information — identity details, contact details, usernames and passwords — in order to manage our relationship with you and provide the Services.
- We collect and store service usage and transactional information so you can view details of transactions made using our Services, to provide uninterrupted and satisfactory Services, to administer our relationship with you, to comply with statutory or regulatory requirements, and to monitor your use of the Services for compliance with our user rules.
- To improve our Services we constantly update our business and marketing strategies, for which we require navigational and log information to determine and analyse the merchants, markets, technology, operating systems, browsers, devices and locations from which our Services are used most and least. Such analysis helps us provide a wider range of Services, develop updates for particular operating systems and application versions, offer other products or programmes that may interest you, and alert you to software compatibility issues.
- We require correspondence information so we can learn from the content of your communications, deduce your feedback, analyse it, endeavour to improve, ask for further feedback and reply.
- The data collected by cookies helps us track, analyse and understand user trends, so that we can identify problems such as slow response times and improve your experience of our Services, web design, features and functionality.
- We access data or information stored by a third party where this is required to provide uninterrupted and satisfactory Services, or where you have consented to it.
- To enable quicker transactions and relieve you of the need to key in a six-digit OTP, we have developed technology that automatically retrieves the OTP and enters it in the relevant field on the transaction page.
- Combinations of the information described in this Privacy Policy — physical address, device information and email address, coupled with information that is not Personal Information such as typing speed, maximum screen area usage and other patterns — help us detect and protect users and ourselves against errors, fraud and other criminal activity.
We collect and use some of your information in aggregated form to compile statistical and demographic profiles for our business and marketing activities and to customise our Services to you. We may disclose such information provided it is in an aggregated form that cannot be used or interpreted so as to identify you. The consolidated Personal Information of all users collected by us is the property of Corporate Worldwide Stay LLP, and we may use it, in whole or in part, at our sole discretion and without compensation to you, for any legitimate purpose.
4. Disclosure of information
We do not disclose or share your Personal Information with any third party unless it is essential in order to provide you the Services, or for the purposes set out below in accordance with this Privacy Policy.
- Information security is critical to us, and we will not share your Personal Information with third parties except, and only to the extent necessary, with parties such as our merchants, acquiring banks and credit card processors in order to deliver payment processing services to you.
- We do not disclose or distribute your Personal Information to a third party, or use it for commercial or marketing purposes, unless we receive your express consent. However, Corporate Worldwide Stay LLP may, itself or through third parties, send you emails, SMS or other communications, send payment reminders, advertise its services, promote new products and activities, or request your feedback.
- You acknowledge and agree that, in the interests of improving personalisation and service efficiency, we may under controlled and secure circumstances share your Personal Information with our affiliates or associates. Where we do, we will either disclose it in a non-aggregated form that cannot be used to identify you, or share it to deliver the Services you have asked for, to maintain and enhance the Services, to ensure their functionality and security, and to prevent and investigate fraud and other misuse.
- If, through some functionality of our Services, you receive Personal Information about another user, you agree to keep it confidential and use it only in connection with the Services, without disclosing it to another user or third party.
- To ensure that all our users comply with the user rules, we may monitor your Personal Information to the extent required to determine compliance and identify instances of non-compliance.
- We may disclose Personal Information pursuant to applicable laws, a directive or order of a government entity, statutory authority, judicial or regulatory authority, or to law enforcement agencies in any official investigation, including cyber incidents and the prosecution and punishment of offences. We may transfer your Personal Information or other information collected, stored or processed by us to any other entity or organisation located in India or outside India, only where necessary to provide the Services to you. We will co-operate with the appropriate law enforcement authorities in investigating claims of illegal activity.
- We will only disclose your Personal Information in accordance with this Privacy Policy. If we wish to use it for any other purpose, we will obtain your prior written consent.
- If you decline to submit Personal Information to us, we will unfortunately not be in a position to provide the Services to you.
- If all or some of the business, stock or assets of Corporate Worldwide Stay LLP are acquired by or merged with another business entity, we will share all or some of your information with that entity in order to continue providing the Services. You will receive notice of such an event and the new entity will inform you of any changes to the practices in this Privacy Policy. If the new entity wishes to make additional use of your information, you may decline at that time.
- Corporate Worldwide Stay LLP does not control the acts of its users. All users should be aware that when they disclose Personal Information such as their name or email address to third parties, that information may be collected and used by others to send unsolicited email. If you encounter any person improperly collecting or using information about users, please contact us at finance@corporate-stay.com.
5. Security of Personal Information
- We work to protect the security of your Personal Information during transmission by using appropriate software which encrypts the information you input. That encrypted information is stored on secure systems. We limit the number of employees involved in the management of the data centre who have physical access to those computers, and we use advanced security technology to prevent unauthorised access.
- We have implemented information security practices and standards, and maintain documented information security programmes and policies containing managerial, technical, operational and physical security measures compliant with Indian law, in order to protect the Personal Information provided to us from unauthorised access, use, modification, damage, disclosure or impairment. We hold ISO 27001 certification. We may from time to time use reasonable additional or alternative procedures to ensure the security and confidentiality of your Personal Information.
- No data transmission over the internet is fully secure, so we cannot ensure or warrant the security of any information you submit to us. We do not guarantee the security of any Personal Information that you transmit or share on the Site, and you do so at your own risk.
- If a security breach comes to our knowledge, we may take all steps required to protect against misuse of Personal Information, and may attempt to notify you electronically so that you can take appropriate protective steps.
Any information you provide when using our Services in an open, public environment or forum — including any blog, chat room, community, classifieds or discussion board — will not be considered confidential, will not be considered Personal Information, and is not subject to protection under this Privacy Policy. Because such environments are accessible by third parties, it is possible that third parties may collect or use that information for their own purposes. Please be careful when deciding to share Personal Information in public environments. We are not liable to you or any third party for damages arising from your disclosure of Personal Information in a public environment.
6. Changes to the Privacy Policy
Corporate Worldwide Stay LLP reserves the right to change, modify, add to or remove portions of this Privacy Policy at any time and for any reason. Where changes are made, we will update this page. Users should review this page periodically for the latest information on our privacy practices. Once posted, changes are effective immediately unless stated otherwise. Continued access to or use of the Services constitutes your acceptance of the changes and of the amended Privacy Policy. If you do not agree with the changes, please do not continue to use the Services or submit Personal Information to us.
7. Changes to your information
- If you would like to view the information we have collected from you, or you want to correct your information or details, please send us your request via the contact page on www.corporate-stay.com.
- You may at any time, while availing the Services or otherwise, withdraw consent previously given to Corporate Worldwide Stay LLP for collecting, receiving, possessing, storing, dealing with or handling your Personal Information, by sending us your request via the contact page on www.corporate-stay.com. In that case we will unfortunately not be in a position to provide the Services to you; however, we will be able to retain such Personal Information for the period required by applicable law.
8. Contacting us
If you have any questions, queries, concerns or feedback about this Privacy Policy or our privacy-related practices, please contact us via the contact page on www.corporate-stay.com.
If you have a grievance relating to the collecting, receiving, possessing, storing, dealing with or handling of Personal Information provided by you, you may contact our Grievance Officer at the address below.
The Grievance OfficerCorporate Worldwide Stay LLP
A-904/5/6, Kailas Business Park, Hiranandani Link Road
Vikhroli (West), Mumbai – 400079, India
