All policies

Privacy · PG owners, landlords and authorised business partners

Partner KYC & listing verification

How BookPGnow verifies PG owners, landlords, authorised property managers and service partners before publication or settlement.
Effective / updated15 August 2026Version2.0

Operational policy, not a waiver of rights. Mandatory law and the specific terms displayed for a transaction prevail where they provide additional rights or obligations.

CanWe Technologies LLP · LLPIN ACY-4633J-68, Sector 3, Airoli, Navi Mumbai, Thane, Maharashtra 400708, India[email protected]

01

Whose identity is verified

This listing KYC flow verifies the PG owner, landlord, authorised property manager or service partner submitting the business or property. It does not request tenant information. Tenant KYC, where required for an active stay, is a separate resident workflow with its own purpose and consent.

  • The partner must use their own identity
  • An authorised manager must be able to show authority to act
  • A partner check is not presented as tenant verification
02

Consent-led DigiLocker use

When DigiLocker or MeriPehchaan is available, the partner is redirected to the official consent flow to share only the approved identity result. BookPGnow does not ask for or store the partner's DigiLocker password, OTP or access token, and does not retain a full Aadhaar number from this flow.

  • Consent is shown before redirection
  • Only purpose-limited, masked verification references are retained
  • A cancelled or failed consent returns the application to a safe review state
03

API Setu approval and data controls

Any API Setu or DigiLocker integration must remain disabled until the requester onboarding, approved purpose, consent screens, credentials, callback security and production approval are complete. BookPGnow records the consent transaction and purpose but never stores a user password, OTP or reusable provider token. Access is restricted to the minimum approved dataset and retention period.

  • Separate sandbox, testing and production credentials
  • Purpose and consent evidence linked to the verification case
  • Security incidents affecting API Setu data are escalated to API Setu within 24 hours and handled under applicable law
  • Provider responses and logs are masked before operational display
04

Property and business authority

Identity alone does not prove that a listing is genuine. BookPGnow may also review the complete address, map point, recent photos, ownership or management authority, business details, payout ownership and a field-visit record before publication or settlement activation.

  • Only publish photos and information you own or may lawfully use
  • Public listing data is separated from private KYC evidence
  • A verified badge is removed or suspended if material facts change
05

Review, retention and appeal

Applications can remain draft, pending review, approved, rejected or suspended. Access to KYC evidence is role-limited and retention follows the verification, fraud, dispute and legal purpose. A partner may request correction or deletion where applicable and may appeal a decision through the linked support case.

  • Review decisions and material changes are logged
  • Deletion can have documented legal or fraud-retention exceptions
  • Never send full identity documents, OTPs or credentials through chat
REF

Official references

Use the current official text for legal interpretation; BookPGnow summaries are practical guidance.

DigiLocker Requester onboarding - official portalDigiLocker APIs - API SetuDigiLocker data protection and consent compliance

Need help with a live case?

Keep the evidence connected to your signed-in support record.

Open support