Privacy Policy
StayOne is software that PG and hostel operators in India use to run their buildings — beds, rent, complaints, staff and residents. This policy explains what the app stores, why, who can see it, and how to have it removed.
Two kinds of user, and it matters which you are. An operator (owner, manager or staff) signs up and enters data about their property and its residents. A resident is given an account by their operator. For resident data the operator is the controller and decides what is collected and how long it is kept; StayOne processes it on their instructions.
What is collected
| Data | Why |
|---|---|
| Name, mobile number, email | To create the account and sign in. The mobile number is the login. |
| A 6-digit PIN | Stored only as a bcrypt hash. It is never stored in a readable form and cannot be recovered, only reset. |
| Profile photo | Optional. Shown on the resident's own record and ID card. |
| Identity documents — Aadhaar, PAN, other ID proof, rental agreements, rent receipts | Uploaded by a resident or their operator, because Indian PG operators are expected to hold proof of who is living in the building. See the note below. |
| Date of birth, age, gender, blood group, occupation, permanent address, emergency contact | Resident record kept by the operator. Blood group and emergency contact exist for a medical emergency on the premises. |
| Bed, room and tenancy dates | To run occupancy and notice periods. |
| Rent charges, payments, receipts and dues | To bill rent and issue receipts. |
| Complaints and service requests | To route and resolve maintenance. |
| Visitor entries, staff attendance and payroll | Operator-side records for the building. |
| Device language, theme and text-size preference | To render the app the way you left it. |
Identity documents
Aadhaar and PAN are sensitive. Three things are true of how StayOne handles them, and you should hold us to all three:
- They are visible only to the resident they belong to and to the operator of the property that resident lives in. No other operator on StayOne can see them.
- They are never used for advertising, profiling, scoring, or shared with any third party for those purposes.
- Uploading one is a choice made between a resident and their operator. StayOne does not require an Aadhaar to create an account, and the app works without one.
If you are an operator: collecting Aadhaar carries obligations under Indian law, including not storing the full number where you do not need it. Collect the minimum you actually require.
What is not collected
- No location or GPS. The app requests no location permission.
- No contacts, no call logs, no SMS, no microphone.
- No advertising identifier, no ad networks, no third-party analytics or trackers.
- No card numbers. Where online rent payment is enabled, the card or UPI details are entered with the payment gateway and never reach StayOne's servers.
Camera and photos
The app asks for camera and photo access only at the moment you attach an image — an ID proof, a profile photo, or a picture on a complaint. Declining leaves the rest of the app working; you simply cannot attach that image. Nothing is read from your gallery in the background.
Who can see your data
- You — a resident sees their own record, dues, receipts, documents and complaints.
- Your operator — the owner, manager and staff of the property you live in.
- StayOne staff — only where necessary to operate the service or to answer a support request you have raised.
Data is not sold. It is not shared with advertisers. It is disclosed to anyone else only where the law requires it.
Where it is stored
On servers operated by DigitalOcean. Traffic between the app and the server uses HTTPS. PINs are stored as bcrypt hashes; session tokens expire and are re-issued on sign-in.
How long it is kept
Operational records — tenancies, rent, receipts — are kept while the operator's account is active, because an operator needs a history of what was billed and collected. When an operator closes their account, their property's data is deleted within 90 days, except where a record must be retained to meet a legal or tax obligation.
Your rights, and how to use them
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted.
- Residents: ask your operator first — they hold your record and can change or remove it directly in the app. If they do not respond, write to us at the address below and we will act on it.
- Operators: write to us and we will export or delete your account and the data under it.
Deleting your account removes your personal record and your documents. Financial entries already issued to another party — a receipt an operator has given a resident, for instance — may be retained in that party's books where the law requires.
Children
StayOne is for adults running or living in shared accommodation. It is not directed at children under 13, and accounts are created by operators for their residents.
Changes
If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and signed-in users are told in the app.
Contact
Questions, corrections and deletion requests: [email protected]