STAYIN

Privacy Policy

Last updated: 2026-07-12

1. Data controller

The operator of the STAYIN platform is the controller for the processing described here, under Law n° 2008-12 of January 25, 2008 on the protection of personal data (Senegal) and the oversight of the Commission de protection des données personnelles (CDP). For any question, contact support@example.com.

2. Data we collect

We collect: your phone number and name; your listings and booking history; the messages you exchange on the platform, including a moderation copy of messages flagged for sharing personal contact details; payment metadata (never card numbers — the payment itself is processed by PayDunya); and, for hosts, a national ID card and selfie for verification purposes.

3. Purposes

This data is used to operate your account, process bookings and payments, prevent fraud, moderate the platform, and meet our legal obligations.

4. Retention

Identity documents (ID card and selfie) are deleted no later than 90 days after the verification decision, including the underlying files. Messages are retained for the life of the account; moderation copies are kept for as long as required for platform security.

5. Processors

We rely on the following providers: Supabase (data and database hosting), PayDunya (payment processing), Twilio (login SMS delivery), Vercel (web hosting), and Sentry (technical error tracking).

6. Your rights

Under Law n° 2008-12, you have a right to access, rectify, delete, and object regarding your personal data. To exercise these rights, contact support@example.com. You may also file a complaint with the CDP (cdp.sn).

7. Security

Data is encrypted in transit, database access is controlled row by row (row-level security), and no card data is stored on our servers.