Privacy Policy
StayOne is software that PG and hostel operators in India use to run their buildings — beds, rent, complaints, staff and residents. This policy explains what the app stores, why, who can see it, and how to have it removed.
It covers the StayOne Android app (in.stayone.app), the web app at dev.stayone.app, and the servers behind them.
Two kinds of user, and it matters which you are. An operator (owner, manager or staff) signs up and enters data about their property and its residents. A resident is given an account by their operator. For resident data the operator is the controller and decides what is collected and how long it is kept; StayOne processes it on their instructions.
What is collected
| Data | Why |
|---|---|
| Name, mobile number, email | To create the account and sign in. The mobile number is the login. |
| A 6-digit PIN | Stored only as a bcrypt hash. It is never stored in a readable form and cannot be recovered, only reset. |
| Profile photo | Optional. Shown on the resident's own record and ID card. |
| Identity documents — Aadhaar, PAN, other ID proof, rental agreements, rent receipts | Uploaded by a resident or their operator, because Indian PG operators are expected to hold proof of who is living in the building. See the note below. |
| Date of birth, age, gender, blood group, occupation, permanent address, emergency contact | Resident record kept by the operator. Blood group and emergency contact exist for a medical emergency on the premises. |
| Bed, room and tenancy dates | To run occupancy and notice periods. |
| Rent charges, payments, receipts and dues | To bill rent and issue receipts. |
| Payment screenshots and reference numbers | Optional. When a resident pays by UPI they may attach the confirmation from their own banking app so the operator can check it against the money received. Visible to that resident and to the operator of their property, and to nobody else. |
| Name and mobile number sent through a property's public join link | Submitted by someone asking to move in, before any account exists. Held for the operator of that property to accept or decline; a declined request is deleted. |
| Complaints and service requests | To route and resolve maintenance. |
| Visitor entries, staff attendance and payroll | Operator-side records for the building. |
| Device language, theme and text-size preference | To render the app the way you left it. |
Identity documents
Aadhaar and PAN are sensitive. Three things are true of how StayOne handles them, and you should hold us to all three:
- They are visible only to the resident they belong to and to the operator of the property that resident lives in. No other operator on StayOne can see them.
- They are never used for advertising, profiling, scoring, or shared with any third party for those purposes.
- Uploading one is a choice made between a resident and their operator. StayOne does not require an Aadhaar to create an account, and the app works without one.
If you are an operator: collecting Aadhaar carries obligations under Indian law, including not storing the full number where you do not need it. Collect the minimum you actually require.
What is not collected
- No location or GPS. The app requests no location permission.
- No contacts, no call logs, no SMS, no microphone.
- No advertising identifier, no ad networks, no third-party analytics or trackers.
- No card numbers, and no payment gateway. Rent is paid the way it already was — cash at the desk, or UPI straight into the operator's own account. No money moves through StayOne, and residents never enter a card, a UPI PIN or a bank login anywhere in it.
One thing that is collected, so it is not mistaken for the above: an operator enters their own payout details — UPI ID, bank name, the last four digits of the account, and the QR their bank issued them — because that is how residents know where to send rent. Those are the operator's own details, entered by them, shown to their own residents. No resident's banking details are collected by anyone.
Notifications
If you allow notifications, your phone is issued a device token by Google and StayOne stores it so it knows where to send "rent due in 3 days" or "your complaint was resolved". It identifies the app on your device, not you personally, and it is deleted when you sign out or turn notifications off. Declining notifications leaves the rest of the app working.
Camera and photos
The app asks for camera and photo access only at the moment you attach an image — an ID proof, a profile photo, or a picture on a complaint. Declining leaves the rest of the app working; you simply cannot attach that image. Nothing is read from your gallery in the background.
Who can see your data
- You — a resident sees their own record, dues, receipts, documents and complaints.
- Your operator — the owner, manager and staff of the property you live in.
- StayOne staff — only where necessary to operate the service or to answer a support request you have raised.
Data is not sold, and it is not shared with advertisers, data brokers or analytics companies. Beyond that, it is disclosed only where the law requires it — and to the small number of suppliers below, who process it so the service can run at all.
Companies we rely on to run it
StayOne is not built on nothing. These are every outside company that can touch your data, what reaches them, and why. None of them is permitted to use it for their own purposes.
- DigitalOcean — hosts the servers and the database. All of it, at rest. India (Bengaluru).
- Google (Firebase Cloud Messaging) — delivers push notifications. Receives a device token that identifies your phone's app install, and the text of the notification itself (for example "Rent due in 3 days"). Not your documents or your ledger.
- Cloudflare (Turnstile) — the "are you human" check on the public joining and invitation pages. Receives your IP address and browser details, not what you typed.
- A language-model provider — only if your operator has switched on Ask. See the section below, which is the one worth reading closely.
Ask, and what leaves when you use it
Ask answers a question about your own property in plain words. It is off unless configured. When it is on, your question and the figures needed to answer it — which can include resident names, rent amounts, complaints and staff payroll — are sent to an outside language-model provider, which may be outside India. It can only read; it cannot change anything, and it can only reach data the person asking is already allowed to see.
If that is not acceptable for your property, ask your operator to leave Ask switched off, or to run it against a model hosted on their own hardware, which the software also supports. With Ask off, nothing about your property ever reaches a language-model provider.
Where it is stored
On servers operated by DigitalOcean, in their Bengaluru region. All traffic between the app and the server is encrypted in transit using HTTPS (TLS). PINs are never stored — only a bcrypt hash of them — so nobody at StayOne can read or recover your PIN. Session tokens expire and are re-issued on sign-in, and every account can be signed out everywhere at once.
Each property's data is scoped to that property in the database, so one operator's account cannot read another's. Actions that change money or a tenancy are written to an audit trail.
Data leaving India
Your records are stored in India. Two things can cross the border: a push notification, which goes through Google's network, and an Ask question, if your operator has switched Ask on and pointed it at a provider outside India. Nothing else leaves.
How long it is kept
Operational records — tenancies, rent, receipts — are kept while the operator's account is active, because an operator needs a history of what was billed and collected. When an operator closes their account, their property's data is deleted within 90 days, except where a record must be retained to meet a legal or tax obligation.
Your rights, and how to use them
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted.
- Residents: ask your operator first — they hold your record and can change or remove it directly in the app. If they do not respond, write to us at the address below and we will act on it.
- Operators: write to us and we will export or delete your account and the data under it.
Deleting your account removes your personal record and your documents. Financial entries already issued to another party — a receipt an operator has given a resident, for instance — may be retained in that party's books where the law requires.
Deleting your account and your data
You can ask us to delete your StayOne account and the personal data held under it at any time, and you do not have to give a reason.
- By email — write to [email protected] from the email address or phone number on the account, or from the account itself. We action it within 30 days and write back to confirm when it is done.
- What your operator can and cannot do — an owner or manager can end your tenancy and switch your login off from the app. That is not deletion, and we would rather say so plainly: your rent history and your identity documents stay in their records, because an operator is obliged to keep them after you leave. To have those erased, write to us.
When we action a deletion request we remove your personal record, your contact details, your identity documents, your photos, and your complaints. What may remain: financial entries already issued to another party — a receipt an operator has given a resident, for instance — where that party is required by Indian tax law to keep their own books. Those entries are kept by the operator, not used by StayOne for anything else, and are removed when their own retention period ends.
If you are a resident, your operator also holds your record and can remove it directly in the app. Ask them first; if they do not act, write to us and we will.
Children
StayOne is for adults running or living in shared accommodation. It is not directed at children under 13, and accounts are created by operators for their residents.
Changes
If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and signed-in users are told in the app.
Contact
Questions, corrections and deletion requests: [email protected]