Legal
Privacy notice
Written by GoStay for the GoStay platform.
Who we are
GoStay operates this platform and is the controller of the personal data described here.
What we collect
- Account data: mobile number, name, email address if you provide one.
- Booking data: stay dates, guest count, guest name and phone for the property.
- Payment data: amount, status and gateway reference. We never store card numbers or UPI credentials.
- Provider data: business details and verification documents you upload.
- Support data: the cases and messages you send us.
Why we use it
To create your account, take and confirm bookings, pay providers, verify providers, handle complaints and safety cases, prevent fraud and meet legal obligations.
Who can see it
- You, for your own records.
- The provider hosting you, limited to the details needed to host your stay.
- GoStay staff handling verification, support or safety cases.
- Our payment gateway, for processing payments.
- Institutional partners only ever receive aggregated, non-personal figures.
Retention
Booking and payment records are kept as long as required for accounting and dispute resolution. Verification documents are kept for the life of the provider account and a reasonable period afterwards. Support cases are kept so patterns of harm can be detected.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete your account. Raise a case through Support and we will respond.
Security
Access is controlled by row-level security so each account can only reach its own records. Prices, bookings and payment verification run on our servers, never in your browser.
Changes
We will update this page when our processing changes and note the change on the platform.
