Privacy Policy - StayJi

Effective: 2026-09-21 · Updated: 2026-09-21 · Version: 2026-09-21

StayJi is currently an experimental/personal project and is not incorporated or registered as a company, LLP or other business entity.

StayJi Support & Grievance Contact: +91 91796 77292 · hello.stayji@gmail.com

These Terms shall be governed by the laws of India. Subject to applicable law, courts having jurisdiction at Indore, Madhya Pradesh shall have jurisdiction over disputes arising out of or relating to these Terms. Mandatory statutory remedies are preserved.

1. Scope and accountability

This notice describes processing for the StayJi discovery and connection platform. The project status and support contact are displayed with this document. Owners independently handle information supplied to them for accommodation; they must use it lawfully and only for the requested purpose. StayJi remains responsible for its own processing and applicable duties, even when suppliers are used.

2. What we collect

Account and profile information includes names, email, phone/country code, account role, profile details, consent versions/timestamps, verification flags, login/security history and authentication credentials stored using the existing password-hashing mechanism. Google sign-in uses the Google identity response to authenticate and obtain account information such as verified email, name and profile image; it does not give StayJi access to your Gmail mailbox. Do not assume every Google identifier is retained: retention follows the account implementation.

Owners submit property descriptions, locality, private address, coordinates or Maps links, media, rent/deposit, vacancy, sharing details, amenities and authorization declarations. Interaction records include enquiries, callbacks, visits, messages, reports, reviews, favourites, comparisons, recently viewed properties, saved searches, notifications, lead/conversion records and support communications.

Security and technical records can include IP address, device/browser information, timestamps, error logs, consent metadata and necessary browser storage. If you request location assistance, browser permission controls device coordinates; approximate distance/geocoding outputs may also be processed. A map link may transmit a location to an external mapping service when opened.

Where you use existing move-in/reward or payment-review features, uploaded proofs, joining information, UPI/bank payout details and administrative payment records may be processed. A proof upload is not a payment gateway or escrow. Do not upload card security codes, passwords, OTPs or unrelated identity documents.

3. Purposes and lawful use

We use necessary information to authenticate accounts, operate profiles and listings, return search results, facilitate enquiries and communications, manage owner inventory, keep histories and notifications, review reports, prevent fraud, maintain security, support users, administer disclosed fees/rewards and comply with legal obligations. Each use must have an applicable legal basis and remain proportionate to its purpose.

Optional marketing requires a lawful basis and any consent required by law; accepting platform terms is not blanket consent to unrelated promotions. You may contact support to withdraw optional communication preferences. Essential responses to your enquiry or security notices may still be necessary to provide the service.

4. Public information and owner sharing

Public listing pages can show owner-supplied photos, descriptions, locality, amenities, prices and availability. Private owner contact, protected exact address and precise coordinates must not be published in anonymous API or search-engine metadata. Eligible authenticated navigation can disclose a valid exact destination under the existing access rules. Logging in does not authorize publication of that destination to everyone.

When you request a callback, enquiry, visit or contact, the relevant owner receives the details needed to respond under the feature's existing privacy/business rules. A passive wishlist is not permission to disclose your phone number. Messages are shared with their participants and authorized support/moderation staff where needed for safety, disputes or lawful operations. Reports and internal administrative notes are not public reviews.

5. Suppliers and external destinations

Implemented services include Google sign-in; Google Maps links/directions; Leaflet maps using their configured tile/geocoding providers, including OpenStreetMap services where configured; MongoDB data storage; configured hosting; configured email delivery; and the StayJi chatbot service. Their actual data access depends on the feature and deployment. Opening WhatsApp support transfers the chosen message to WhatsApp under its own terms. A support link is not an automated WhatsApp integration.

Only enabled providers receive data. Email, OTP, AI or automation connectors that require configuration are not represented as active merely because code supports them. Consult support for the current enabled processors and hosting regions. Do not send sensitive information to the chatbot. If an external AI provider is enabled, its processing and retention must be disclosed before sending personal data; local/rules-based answers do not establish such a transfer. The supported external AI connector is OpenAI and is used only when explicitly configured.

6. Storage and cookies

Necessary session/local storage supports signed-in sessions, comparisons and form drafts. Server session/security cookies may be set where that feature is used. These are described in the Cookie & Storage Notice. External maps, Google sign-in and embedded content can contact their providers when used. The built-in sponsored-ad feature records impression and click counts when ads are displayed or opened. Sponsored links can take you to the advertiser; no external advertising-network tracker is implied. No assertion is made that a dormant analytics integration is collecting data. Non-essential trackers must be assessed and, where required, withheld until consent; withdrawing optional consent must be possible without accepting marketing.

7. Retention and deletion

We retain information only for purposes still necessary and lawful: active accounts and listings, requested histories, communications, support, security, disputed transactions and legally required records. Short histories may have configured item limits. Removing a record from your interface is not necessarily erasure of retained moderation or legal evidence.

On a verified closure/deletion request, we assess deletion, anonymization or restriction, identify any lawful retention exception, and explain the outcome and applicable timeframe. Backup copies age out under the applicable backup lifecycle and should not be restored to active use contrary to an approved deletion. There is no promise of instant deletion or unlimited retention; the operator must maintain and apply a documented retention schedule.

8. Security and incidents

Access controls, role/ownership checks, password hashing, validation, operational logging and transport/security measures reduce risk; no online system is absolutely secure. Authorized staff access should be limited to their duties. We investigate suspected breaches, contain them, preserve necessary evidence and notify affected people and authorities when required by the law in force. Report suspected compromise through Contact immediately; never provide your password or OTP to support.

9. Rights and requests in India

Subject to the law in force and applicable exceptions, you may request information/access, correction, updating, completion, erasure, withdrawal of consent, grievance redress and nomination where that right applies. The Digital Personal Data Protection Act and Rules have phased commencement; this notice does not claim every provision or statutory mechanism is already operative. We will honor applicable duties and explain any lawful refusal or retention need. Identity checks must be proportionate and must not require unnecessary sensitive documents.

Contact the privacy/support address shown below, identifying the account and request. Escalation to a competent authority or consumer forum remains available as provided by law. We will not charge an invented compulsory processing fee or demand waiver of rights to hear a complaint.

10. Children and vulnerable users

Accounts and contracts are intended for adults capable of contracting. Minors should involve a parent or lawful guardian and must not independently submit sensitive data or enter accommodation/payment arrangements through this platform. If we learn of children's data, we assess lawful removal/restriction and any required parental-consent safeguards. This statement is not a claim that age or parental identity has been technically verified for every visitor. Contact support if a child has submitted data.

11. Transfers, disclosure and changes

Service providers may process information outside India depending on hosting and configuration. Transfers must respect applicable legal restrictions and contractual/security safeguards; no universal India-only storage promise is made. Government/legal disclosures require a valid legal basis and should be limited to what is necessary. Relevant records may be preserved for lawful investigations or defence of claims, without authorizing indiscriminate disclosure.

Material changes receive a new version/date. Prior consents remain recorded; fresh consent will be sought where required. Read this notice with Terms, Grievance and Cookie & Storage Notice.