Technopark Phase III, Trivandrum, Kerala

Jazzy Hotels and Resorts Pvt. Ltd.

Requester Integration Use Case • DigiLocker & API Setu

Pioneering ContactlessHospitality with TrustGate.

Demonstrating a live Requester implementation applying DigiLocker and API Setu for effortless, consent-driven guest verification and seamless hospitality.

API Setu
Requester Gateway
DigiLocker
Citizen Consent Auth
DPDP Ready
Zero Data Retention
Live Demo
Requester Sandbox
Explore
Requester Use Case

The Problem. The Solution.

India's hospitality sector processes millions of manual check-ins each year. TrustGate demonstrates how a Requester application applying DigiLocker and API Setu eliminates friction while meeting the strictest DPDP compliance standards.

The Old Way

Current industry standard

Paper ID Photocopies

Physical document copies collected at reception, stored in unsecured filing systems — creating compliance risk under DPDP Act 2023.

Long Front-Desk Queues

Manual ID verification takes 8–12 minutes per guest. Peak arrival times cause lobby congestion and degrade the guest experience.

Data Privacy Risks

Photocopied Aadhaar and PAN data stored locally without consent logs, data-retention limits, or audit trails — exposing hotels to regulatory liability.

No Audit Trail

No timestamped consent records, no cryptographic verification — making disputes impossible to resolve and compliance audits painful.

The TrustGate Way

Requester Flow at Jazzy Hotels

Applying DigiLocker Document Verification

API Setu Requester

Direct integration with API Setu OAuth 2.0 to fetch and verify cryptographically signed government credentials at source — zero physical contact, 100% authentic.

Instant Biometric & Photo Match

Sub-10ms Match

ArcFace biometric matching at sub-10ms with liveness detection, verifying live guests against verified photos retrieved via DigiLocker API integration.

Ephemeral Digital NFC Keys

Zero Plastic

AES-256 encrypted room key pushed to guest's mobile device instantly. Keys are time-bound, geofenced, and invalidated on checkout automatically.

Immutable Consent Audit Logs

DPDP Compliant

Every verification step captures a timestamped, hashed consent record. Full audit trail available for regulatory review — no document retention required.

< 45 sec
Full Check-in Time
vs. 10+ minutes
100%
Consent Logged
Immutable audit trail
0 docs
Physically Stored
Zero-retention policy
₹0
Compliance Liability
DPDP Act aligned
Requester Architecture & Compliance

Architecture & DPDP Compliance

Designed as a Requester consumer application interfacing with the DigiLocker and API Setu open ecosystem. Every integration endpoint is architected for data minimisation, citizen privacy, and zero data retention.

01

Data Minimisation via API Setu

Applying Scoped OAuth 2.0 Integration

TrustGate integrates API Setu to request only the exact verification parameters required for guest check-in — guest name, verified photo, and document identifier. Scoped OAuth tokens guarantee that raw document files, address lines, and extraneous personal attributes are never requested or stored.

API Setu IntegrationScoped OAuth 2.0 TokensField-Level Filtering
02

Zero-Retention Policy

No Sensitive Data on Local Servers

No Aadhaar XMLs, PAN images, or facial biometric vectors are permanently stored on hotel infrastructure. All sensitive payloads are processed in-memory during the verification session and immediately purged. Only a non-reversible verification hash is retained for the audit log.

In-Memory ProcessingSession-Scoped PayloadsAuto-Purge on Completion
03

Consent-Driven Architecture

Applying DigiLocker Consent Handshake

Explicit, purpose-bound user consent is captured through the official DigiLocker consent interface before any identity verification call is executed. Consent is timestamped, hashed, and logged to an immutable audit record — fully aligned with DPDP Act 2023 mandates.

DigiLocker Consent FlowAPI Setu HandshakeImmutable Audit Logs

Requester Application Specification

Applicant Entity

Jazzy Hotels and Resorts Pvt. Ltd.

Ecosystem Role

API Setu Requester (Consumer)

Permitted Documents

Driving Licence, Aadhaar, Voter ID, Passport

Storage Duration

0 seconds (In-Memory Only)

Regulatory Alignment

DPDP Act 2023Compliant Architecture
MeitY Requester GuidelinesAligned
API Setu Requester ProtocolArchitecture Aligned
IT Act 2000 S.43ACovered

DigiLocker & API Setu Requester Data Flow

Citizen ConsentAPI Setu GatewayDigiLocker AuthIn-Memory VerificationImmediate Purge

No raw documents, XML copies, or biometric vectors persist beyond the active verification session.

Interactive Integration Demo

The TrustGate Integration Flow

Experience the live reference flow demonstrating how DigiLocker and API Setu are integrated into real-world guest check-in. Click any step to inspect the API handshake, data handling, and privacy controls.

Step 1 of 4

Pre-Arrival Liveness & Selfie Capture

Before arriving at the property, the guest opens the TrustGate pre-arrival link, performs a liveness-verified selfie capture, and authorizes identity validation. The facial vector is processed in-memory against the authentic photo retrieved via DigiLocker API integration and immediately purged — reducing check-in arrival to under 10 seconds.

All Steps

9:41
TrustGate
Pre-Arrival

Jazzy Hotels & Resorts

Pre-Arrival Selfie

Look straight into the camera. Keep your face centred within the oval guide.

LIVENESS CHECK ACTIVE