ValetSys
Features How It Works Pricing FAQ Contact Sign in Start Free

Privacy Policy

Myzow Solutions LLP · Effective 19-Aug-2026

On this page

  1. The two roles we play
  2. Data about venue guests
  3. Data about our customers
  4. Why we process it
  5. Anonymous Mode
  6. How long we keep it
  7. Who else touches it
  8. Where it is stored
  9. How it is protected
  10. Your rights
  11. Grievance redressal
  12. Children
  13. Cookies
  14. Changes

ValetSys is operated by Myzow Solutions LLP (LLPIN AAF-3140 ), registered at 501/A, B Wing, 6th Floor, Supreme Business Park, Hiranandani Gardens, Powai, Mumbai, Maharashtra 400076, India (“we”, “us”). This policy explains what personal data passes through ValetSys, on whose instructions, and what you can ask us to do about it.

It is written to meet the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

1. The two roles we play

This distinction decides who you address a request to, so it comes first.

Guest data — we are a Data Processor

When a hotel, restaurant or club uses ValetSys to park your car, that venue is the Data Fiduciary. It decides what to collect and why. We process guest data only on that venue's documented instructions, and we do not use it for our own purposes, sell it, or share it with other venues.

Customer account data — we are a Data Fiduciary

For the people who sign up for and administer a ValetSys workspace, we decide the purposes ourselves and are the Data Fiduciary.

2. Data about venue guests

When a venue checks your vehicle in, ValetSys may record:

  • Mobile number — so your digital ticket can be sent to you.
  • Vehicle registration number, and optionally make, model and colour.
  • Vehicle photographs — typically four angles at intake, recording the vehicle's condition when it was handed over.
  • Timestamps for check-in, retrieval request and handover.
  • Key tag number and parking location.
  • Handover verification events — whether the code matched, and any manager override.

We do not collect your name, address, email, payment details, government identifiers, or location. We do not track you between visits in a way that identifies you: our cross-venue statistics record vehicle registration numbers only, with no personal data attached, and they are never exposed to a venue other than the one you are at.

How your mobile number is stored

Your number is encrypted at rest using AES-256-GCM. Staff screens show only the last four digits. To let a valet find your ticket by searching, we also store a keyed one-way fingerprint of the number that cannot be reversed back into the number itself.

3. Data about our customers

For the venue staff and administrators who use ValetSys, we hold:

  • Name, mobile number, role, and the properties a person may access.
  • A one-way hash of the password — never the password.
  • The organisation's business name and its GSTIN or work email address, used to confirm the business is real.
  • Device identifiers for signed-in staff apps, so a lost phone can be revoked.
  • Audit records of privileged actions, and technical logs including IP address.
  • Billing records for paid subscriptions.

4. Why we process it

PurposeData usedBasis
Issue a digital ticket and deliver it to the guest Mobile number, vehicle details Consent given to the venue at check-in
Retrieve the right vehicle for the right person Handover code, last 4 digits of mobile Performance of the venue's service
Evidence the vehicle's condition at handover Photographs, timestamps Legitimate use — protecting both guest and venue in a damage dispute
Operate and secure the service Account data, audit and technical logs Our legitimate use as Data Fiduciary
Bill for paid subscriptions Organisation and billing data Contract, and Indian tax law

We do not use guest data for advertising, profiling or automated decisions that produce legal or similarly significant effects.

5. Anonymous Mode

A guest who prefers not to share a mobile number can ask for Anonymous Mode. The valet issues a pre-printed QR backup pass instead. In this mode no personal data about the guest is collected at all — only the vehicle, the key tag and the timestamps. The pass itself is what proves entitlement to the vehicle, so it should be kept safe.

6. How long we keep it

DataRetained for
Vehicle photographs 30 days on standard plans; up to 90 days where the venue subscribes to extended retention. Deleted automatically after that.
Photographs under an active legal hold Retained until the venue releases the hold, because they are evidence in a live dispute or claim.
Ticket records (encrypted mobile number, vehicle, timestamps) Kept while the venue's account is active, then deleted or returned on termination.
Aggregate vehicle statistics (no personal data) Retained indefinitely — these cannot identify a person.
Customer account and audit records For the life of the account, and afterwards only as long as tax, accounting or limitation periods require.
Guest ticket links Expire automatically, by default 24 hours after issue.

7. Who else touches it

We use a small number of sub-processors, each bound by contract to equivalent obligations:

  • Cloud hosting and object storage — servers and photograph storage.
  • WhatsApp Business and SMS providers — delivery of ticket links. Your mobile number is shared with them for that delivery only.
  • Number-plate recognition — a vehicle image is processed to read the registration number.
  • GSTIN verification — for customer businesses, not guests.

We also disclose data where the law compels it, and to professional advisers under a duty of confidence. We do not sell personal data, and we do not share it with advertisers.

A current, named list of sub-processors is available on request from support@valetsys.com.

8. Where it is stored

Personal data is stored on servers located in Asia Pacific (Mumbai), India . If we ever transfer personal data outside India, we will do so only to territories not restricted by the Central Government under section 16 of the DPDP Act, and under contractual safeguards.

9. How it is protected

  • Encryption in transit (TLS) and at rest for mobile numbers.
  • Passwords stored as one-way hashes.
  • Strict separation between venues — one venue's staff cannot query another's records; this is enforced in the database layer, not merely in the interface.
  • Role-based access, so a valet sees only what a valet needs.
  • Short-lived access tokens with rotating refresh credentials; reuse of a stolen credential revokes the whole session family.
  • Audit trails for privileged actions, including any access by our own staff.
  • Automatic deletion of photographs when their retention period ends.

If a personal data breach occurs, we will notify the Data Protection Board of India and affected persons as required by the DPDP Act, and we will inform the affected venue without undue delay.

10. Your rights

Under the DPDP Act you may ask for:

  • Access — a summary of the personal data being processed about you.
  • Correction of inaccurate or incomplete data, and completion or updating of it.
  • Erasure, unless retention is required for a legal purpose.
  • Withdrawal of consent, as easily as it was given.
  • Nomination of another person to exercise these rights if you die or become incapacitated.
  • Grievance redressal, described below.

If you are a guest at a venue, address your request to that venue first. They are the Data Fiduciary and hold the relationship with you. If you contact us directly, we will pass your request to the venue and support them in answering it — we are not permitted to act on their data without instruction.

If you hold a ValetSys account with us, contact us directly and we will respond within 30 days.

11. Grievance redressal

As required by section 13 of the DPDP Act and the IT Rules, our Grievance Officer is:

  • Name: Saif Ahmed
  • Email: saif.ahmed@valetsys.com
  • Phone: +91 98676 05577
  • Address: 501/A, B Wing, 6th Floor, Supreme Business Park, Hiranandani Gardens, Powai, Mumbai, Maharashtra 400076, India

We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.

12. Children

ValetSys is a business tool operated by venue staff and is not directed at children. We do not knowingly process the personal data of anyone under 18 as a guest, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child's data has reached us, tell the Grievance Officer and we will delete it.

13. Cookies

This website and the ValetSys dashboards use only strictly necessary cookies: a session cookie to keep you signed in, and a token that protects forms against cross-site request forgery. We use no advertising, analytics or third-party tracking cookies, so there is nothing here for you to consent to or opt out of.

14. Changes to this policy

We will post any change on this page and update the effective date. Where a change materially affects how personal data is handled, we will notify account holders by email or in the dashboard before it takes effect.

15. Contact

support@valetsys.com
Myzow Solutions LLP, 501/A, B Wing, 6th Floor, Supreme Business Park, Hiranandani Gardens, Powai, Mumbai, Maharashtra 400076, India

Back to home

ValetSys ValetSys is a product of Myzow Solutions LLP.
Copyright © 2026 Myzow Solutions LLP. All rights reserved.
About Us Contact Us Pricing Privacy Policy Terms of Service Cancellation & Refund Policy Shipping & Delivery Policy