Privacy Policy

Secure Isolation

At CheckInLK, your data is your property. We have engineered our platform on the principles of Zero-Trust and Data Decoupling to ensure your personal identification remains private and ephemeral.

1. The 24-Hour Hot Buffer

Raw identification strings (NIC/Passport) are stored in an isolated, encrypted partition for a maximum of 24 hours. Our automated Purge Job executes every 60 minutes to identify and permanently destroy expired records from our database, ensuring no long-term persistence of sensitive raw strings.

2. Cryptographic Safeguards

All PII is secured at rest using AES-256-GCM encryption with unique 96-bit initialization vectors per record. For identity deduplication, we utilize SHA-256 one-way salted hashing, a mathematically irreversible process that recognizes your identity without storing the original number.

3. Authorized Sub-Processors

We partner with industry-leading providers to facilitate secure payments and communications. Your data may be processed by:

  • Stripe: For secure, PCI-compliant payment tokenization.
  • Dialog & Mobitel: For localized SMS notifications within Sri Lanka.
  • Resend / Zoho: For encrypted email delivery and account verification.
  • Telegram Bot API: For optional real-time booking alerts.
  • Didit: For decentralized identity verification logic.

4. PDPA & Legal Compliance

We strictly adhere to the Sri Lankan Personal Data Protection Act (PDPA) and the Hotel Keepers Act. We only collect the minimum information required for a legal guest registration and never share your data with third-party advertisers.

5. Financial Security

Payment processing is handled exclusively by Stripe. CheckInLK never sees or stores your credit card details. Our infrastructure only maintains a secure token provided by Stripe to manage your settlements.