Policies

Security Policy

How we protect booking data and payments, stated as what we actually do rather than what sounds reassuring.

Last updated: 31 August 2026

Our approach

We are a family-run farm resort, not a bank, and we do not pretend to run a bank’s security programme. What we do instead is hold as little personal data as the business needs, encrypt the sensitive parts of it, and keep card payments entirely out of our own systems. Everything below is implemented today.

Payments

Card, UPI and wallet details are entered into Razorpay’s checkout and go to Razorpay, a PCI-DSS compliant payment provider. They never pass through our website or our database, and we never see or store a card number. What we keep is the payment reference and the amount, which is what a refund and our accounts require.

Encryption

  • The whole site is served over HTTPS; there is no unencrypted route to it.
  • Guest phone numbers, address and free-text booking notes are encrypted at rest with AES-256-GCM, using a key held separately from the database. A copy of the database alone does not reveal them.
  • Revealing a guest phone number in the staff dashboard is a deliberate action, and it is written to an audit log.

Access control

  • Guest accounts can read and change only their own profile and their own bookings. This is enforced by row-level security in the database itself, not merely by the app — so it holds even if a bug in the front end asks for something it should not.
  • Anything privileged — creating a booking, taking a payment, issuing a refund — runs inside server-side functions. The browser only ever holds a public key that cannot perform those operations.
  • Staff dashboard accounts support two-factor authentication (TOTP), are permission-scoped by role, and lock out after repeated failed sign-ins.
  • Sensitive actions in the dashboard are recorded in an audit log.

Holding less in the first place

The most reliable protection for data is not to have it. We ask for a name, a phone number, an email address and anything you choose to tell us about your stay — and not for identity documents, dates of birth or card details. What we keep, and for how long, is set out in our Privacy Policy.

What you can do

  • Use a password for this site that you have not reused anywhere else.
  • Sign out on a shared or public computer.
  • Treat any message asking you to “confirm” a booking by sending card details or an OTP as fraudulent — we will never ask for those. If in doubt, hang up and call us on the number on this page.
  • Check that your browser shows arnavharmonyfarm.in before entering anything.

If something goes wrong

If a breach occurs that affects your personal data, we will investigate it, do what is needed to contain it, and tell the guests affected — along with the relevant authority where the law requires it — without undue delay. We would rather tell you about a problem than have you find out elsewhere.

Reporting a vulnerability

Found a security problem? Please report it to us privately, and see our Responsible Disclosure page for what is in scope and what to expect from us.


Contact us

Arnav Harmony Farm
At Bharje, Pali, sudhagad, 410205, Maharashtra
Phone: +91 8483032662 / +91 8483092662
Email: r9harmonyfarm@gmail.com

All policies