Privacy Policy
Last updated: August 2026
Stayva ("we", "our", "us") provides property management software for PG owners, managers, and residents. This policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it — in compliance with the Digital Personal Data Protection (DPDP) Act 2023, the Information Technology Act 2000, and the SPDI Rules 2011. It applies to our web application, Android and iOS apps, and related services.
1. Who Is Responsible for Your Data
Stayva acts in two distinct roles under the DPDP Act 2023, and your point of contact depends on which applies to you:
For PG owners & staff
Stayva is the Data Fiduciary for your account data. We decide how and why it is processed, and you can exercise your rights directly with us.
For residents / tenants
Your PG owner is the Data Fiduciary who collects your data during onboarding. Stayva is a Data Processor acting on their documented instructions. You may raise requests with your PG owner or directly with us — we will coordinate the response either way.
2. Data We Collect
We collect only what is needed to run the service — no more:
Resident Personal Data
- •Full name, mobile, email
- •Gender, permanent address
- •Identity proof (masked — last 4 digits only)
- •Scanned ID document (for KYC)
- •Emergency contact details
Financial Data
- •Rent amount and payment history
- •Security deposit records
- •Invoices and receipts
- •Payment transaction references (we never see full card or bank details — see Section 4)
Property & Usage Data
- •Property, room, and bed assignments
- •Occupancy history
- •Maintenance tickets and notes
Account & Device Data
- •Owner/staff name, email, password (stored only as a bcrypt hash)
- •Role and permissions
- •Login timestamps and access logs
- •Push notification token (mobile app)
- •Crash and error diagnostics
We do not collect your precise location, contacts, photos (beyond documents you choose to upload), or any data from other apps on your device.
3. Purpose & Legal Basis
Every processing purpose is tied to a lawful basis under the DPDP Act 2023. We do not use your data for any purpose not listed here, and we never sell personal data:
| Purpose | Legal Basis |
|---|---|
| Resident KYC verification & onboarding | Explicit consent at onboarding |
| Rent invoicing, receipts & payment tracking | Contract performance |
| Occupancy & property management | Legitimate use — service delivery |
| Account security, authentication & fraud prevention | Legal obligation & security |
| Maintenance and complaint management | Contract performance |
| Service emails (invoices, receipts, alerts) | Contract performance |
| Push notifications (rent reminders, updates) | Consent — via your device settings, revocable anytime |
| Error monitoring & service reliability | Legitimate use — service quality |
4. Who We Share Data With
We share personal data only with vetted service providers who process it under contract, solely to run Stayva. We never sell or rent personal data, and we never share it with advertisers or data brokers.
| Provider | Purpose | Data Involved |
|---|---|---|
| Razorpay | Payment processing (RBI-regulated) | Payment amount, transaction reference. Card/UPI/bank details go directly to Razorpay — Stayva never receives them. |
| Amazon Web Services (S3) | Encrypted storage of uploaded documents | KYC document scans, uploaded files |
| Email delivery provider (SMTP) | Sending invoices, receipts, and service alerts | Name, email address, invoice contents |
| Sentry | Crash and error monitoring | Technical diagnostics; scrubbed of personal identifiers where feasible |
| Google (Firebase Cloud Messaging) / Apple (APNs) | Push notification delivery on mobile | Anonymous device push token |
We may also disclose data where required by law — for example, to tax authorities, law enforcement acting under lawful process, or courts. We will notify affected users where the law permits us to do so.
5. How We Protect Your Data
- ✓All data in transit is encrypted using TLS 1.2+
- ✓Passwords are hashed using bcrypt — never stored or transmitted in plain text
- ✓Aadhaar numbers are masked before storage (last 4 digits only), consistent with the Aadhaar Act 2016 and UIDAI guidelines
- ✓Identity proof documents are stored in access-controlled, encrypted cloud storage (AWS S3), served only via short-lived signed URLs
- ✓API access is protected by JWT authentication, role-based access control, and rate limiting
- ✓Strict multi-tenant isolation: one PG owner can never access another owner's data
- ✓Access logs are maintained to detect and investigate unauthorised activity
6. Data Retention
We keep personal data only as long as the purpose it was collected for remains, or as the law requires — whichever is longer. When the period ends, data is deleted or irreversibly anonymised:
| Data Type | Retention Period |
|---|---|
| Active resident records | Duration of tenancy + 6 months |
| Financial records (invoices, payments) | 7 years (statutory requirement under tax law) |
| Identity proof documents | Duration of tenancy + 6 months, then deleted |
| Inactive account data | 2 years from last login, then deleted |
| Access & security logs | 90 days |
| Push notification tokens | Until you log out, uninstall the app, or disable notifications |
7. Your Rights (DPDP Act 2023)
Right to Access
Obtain a summary of the personal data we hold about you and how it is processed
Right to Correction
Have inaccurate, incomplete, or outdated data corrected or updated
Right to Erasure
Request deletion of your personal data once it is no longer required or consent is withdrawn
Right to Withdraw Consent
Withdraw consent at any time, as easily as it was given — without affecting prior lawful processing
Right to Grievance Redressal
Complain to our Grievance Officer, and escalate to the Data Protection Board of India if unsatisfied
Right to Nominate
Nominate a person to exercise your rights in the event of death or incapacity
To exercise any right, email privacy@stayva.in from your registered email address. We will verify your identity and respond within the timelines prescribed under the DPDP Act. Exercising your rights is free of charge.
8. Mobile App Permissions
The Stayva Android and iOS apps request only the permissions they need, and each can be revoked in your device settings at any time:
- •Notifications: To deliver rent reminders, payment confirmations, and service updates. Optional — the app works without it.
- •Storage / Files: Only when you choose to upload or download a document (e.g. a KYC scan or invoice PDF).
9. Children's Data
Stayva is intended for users aged 18 and above. We do not knowingly collect personal data of children as defined under the DPDP Act 2023, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child's data has been submitted to us without verifiable parental consent, contact us and we will delete it promptly.
10. Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected users in the form and manner prescribed under the DPDP Act 2023 and its rules, including the nature of the breach, the data involved, and the steps we are taking to contain it and prevent recurrence.
11. Where Your Data Is Stored
Your data is stored on secure cloud infrastructure. Where any transfer of personal data outside India occurs (for example, through a cloud or email provider), it is done only to territories not restricted by the Central Government under the DPDP Act 2023, and under contractual safeguards requiring the same level of protection described in this policy.
12. Changes to This Policy
We review this policy periodically and update it when our practices, features, or the law change. Material changes will be announced in-app or by email before they take effect, and the "Last updated" date above will always reflect the current version. Continued use of Stayva after an update constitutes acceptance of the revised policy, except where fresh consent is legally required — in which case we will ask for it explicitly.
13. Grievance Officer & Contact
As required under the IT Act 2000 and the DPDP Act 2023, we have appointed a Grievance Officer. For any privacy question, rights request, or complaint, contact:
Name: Grievance Officer, Stayva
Email: privacy@stayva.in
Response time: Acknowledgement within 72 hours; resolution within 30 days of receiving the complaint
If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India.
See also our Cookie Policy and Terms of Service.