Built for India's data protection law: how DigiGo handles guest ID at check-in
How DigiGo collects, verifies, protects and deletes guest identity data at hotel check-in, in line with India's data protection law and the Aadhaar Act.

When a guest hands over an Aadhaar, a passport or a driving licence at check-in, they are trusting the hotel with some of the most sensitive information they have. The hotel, in turn, is trusting its software. This article explains in plain terms how DigiGo handles that identity data at every step, and how each step lines up with India's data protection law, the Digital Personal Data Protection Act, 2023, and with the Aadhaar Act.
The principles behind every DigiGo flow
- A clear purpose. Identity data is collected to check a guest in and to meet the hotel's legal reporting duties.
- The guest's approval. When documents are shared digitally, the guest approves the request first.
- Official verification. Documents are verified through government channels, not photocopies.
- Only what is needed. Aadhaar numbers are masked, and nothing beyond what check-in requires is kept.
- Restricted access. Only the hotel a guest stays with can see their documents, and every access is recorded.
- A defined lifespan. Documents are deleted once they are no longer needed.
Collected for check-in, and nothing else
DigiGo collects identity details for two reasons: to check a guest in, and to help the hotel meet its legal duty to keep a guest register and report foreign nationals to the authorities. Guest identity data is never sold and never used for advertising.
When a guest shares documents from their own phone, they see a consent screen first and choose whether to go ahead. With DigiLocker, nothing is fetched until the guest approves. With the Aadhaar app, the guest approves sharing on UIDAI's own screen. We walk through the DigiLocker journey step by step in this guide.
Verified through official government channels
A photocopy proves very little. DigiGo verifies documents at the source instead. An Aadhaar is checked through UIDAI's Secure QR code, whose digital signature confirms the details were issued by UIDAI and have not been altered. This is the offline verification method recognised under the Aadhaar Act. Documents from DigiLocker arrive signed by the authority that issued them. Either way, the hotel knows the identity in front of it is genuine.
Aadhaar numbers are never stored in full
The Aadhaar Act places strict limits on how Aadhaar numbers are handled. DigiGo keeps only the last four digits, in the same masked form UIDAI uses on its own masked Aadhaar. The full number is not kept in our records, in the documents we generate for the hotel, or in the details we pass to the hotel's own systems. The scanned code itself is read once and then discarded.
Only the hotel a guest stays with can see their documents
A guest's documents are visible only to staff at the property where that guest has checked in. When a returning guest presents their DigiGo code at a new hotel, staff also need the guest's name, which confirms the guest is actually at the desk. Every time a document is opened or downloaded, DigiGo keeps a record of who accessed it and when, so any access can be accounted for.
Kept only as long as it is needed
India's data protection law asks for two things that pull in opposite directions: personal data should not be kept once its purpose is served, and records must still be held for a minimum period so they are available if the authorities need them. DigiGo meets both. A guest's identity documents are kept for one year from their last check-in, then permanently deleted, together with the document photo and any scanned copies.
A guest who returns within the year does not need to verify again. When documents are deleted and we have the guest's email address, we let them know, so they can complete their KYC again before their next stay.
Government reporting, done accurately
Hotels must report every foreign guest to the Bureau of Immigration through Form C, and some states require a police guest register as well. DigiGo prepares these filings from the details already verified at check-in, and a member of hotel staff reviews each one before it is submitted. What reaches the authorities is complete and accurate, and the hotel stays in control of every filing. See how it works in our Form C guide.
Protected at every step
Guest data is encrypted in transit and at rest, and access is restricted by role and by property. We review our flows against India's data protection requirements as they come into force, and update them as the rules evolve.
Questions about your data
Guests and hotel partners can write to contact@digigo.club with any question about how their data is handled, or to ask for it to be deleted.




