StayOne

Privacy Policy

Last updated 13 September 2026

StayOne is software that PG and hostel operators in India use to run their buildings — beds, rent, complaints, staff and residents. This policy explains what the app stores, why, who can see it, and how to have it removed.

Two kinds of user, and it matters which you are. An operator (owner, manager or staff) signs up and enters data about their property and its residents. A resident is given an account by their operator. For resident data the operator is the controller and decides what is collected and how long it is kept; StayOne processes it on their instructions.

What is collected

DataWhy
Name, mobile number, emailTo create the account and sign in. The mobile number is the login.
A 6-digit PINStored only as a bcrypt hash. It is never stored in a readable form and cannot be recovered, only reset.
Profile photoOptional. Shown on the resident's own record and ID card.
Identity documents — Aadhaar, PAN, other ID proof, rental agreements, rent receiptsUploaded by a resident or their operator, because Indian PG operators are expected to hold proof of who is living in the building. See the note below.
Date of birth, age, gender, blood group, occupation, permanent address, emergency contactResident record kept by the operator. Blood group and emergency contact exist for a medical emergency on the premises.
Bed, room and tenancy datesTo run occupancy and notice periods.
Rent charges, payments, receipts and duesTo bill rent and issue receipts.
Complaints and service requestsTo route and resolve maintenance.
Visitor entries, staff attendance and payrollOperator-side records for the building.
Device language, theme and text-size preferenceTo render the app the way you left it.

Identity documents

Aadhaar and PAN are sensitive. Three things are true of how StayOne handles them, and you should hold us to all three:

If you are an operator: collecting Aadhaar carries obligations under Indian law, including not storing the full number where you do not need it. Collect the minimum you actually require.

What is not collected

Camera and photos

The app asks for camera and photo access only at the moment you attach an image — an ID proof, a profile photo, or a picture on a complaint. Declining leaves the rest of the app working; you simply cannot attach that image. Nothing is read from your gallery in the background.

Who can see your data

Data is not sold. It is not shared with advertisers. It is disclosed to anyone else only where the law requires it.

Where it is stored

On servers operated by DigitalOcean. Traffic between the app and the server uses HTTPS. PINs are stored as bcrypt hashes; session tokens expire and are re-issued on sign-in.

How long it is kept

Operational records — tenancies, rent, receipts — are kept while the operator's account is active, because an operator needs a history of what was billed and collected. When an operator closes their account, their property's data is deleted within 90 days, except where a record must be retained to meet a legal or tax obligation.

Your rights, and how to use them

You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted.

Deleting your account removes your personal record and your documents. Financial entries already issued to another party — a receipt an operator has given a resident, for instance — may be retained in that party's books where the law requires.

Children

StayOne is for adults running or living in shared accommodation. It is not directed at children under 13, and accounts are created by operators for their residents.

Changes

If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and signed-in users are told in the app.

Contact

Questions, corrections and deletion requests: [email protected]