What we collect — and what we never do
This is the plain-language summary of how StayLok handles personal data. It exists so tenants and owners can review our practices before trusting us with a booking. The full policy in the app governs in case of conflict. Last updated 2026.
What we collect
- Account data: name, email address, phone number, and a password that is stored only as a cryptographic hash — never in plain text.
- Listing and booking data: property details and photos you upload, booking requests, dates, and their status.
- Messages: chats between tenants and owners are end-to-end encrypted. Keys are generated on your device; your private key never leaves it. Our servers store only ciphertext nobody else can read.
- Favorites and preferences: stored locally on your device, not sold or profiled.
- Diagnostics: if the app crashes, an error report (message and stack trace) may be sent so we can fix the bug. It contains no message content.
What we never do
No third-party advertising trackers. No ad SDKs. And we do not sell personal data — to anyone, ever. That is a product principle, not just a policy line: our revenue comes from optional owner subscriptions, not from tenant attention.
Where your data lives
Account, listing, booking, and ciphertext message data are stored on managed cloud infrastructure — a Supabase Postgres database with authentication handled by Supabase Auth — behind the staylok.com API hosted on Vercel. Property photos are served from site storage. Your local preferences stay in encrypted device storage on your own phone or browser.
Third parties involved
- Supabase — database and authentication infrastructure.
- Vercel — application hosting and serverless API.
- Map tile providers (OpenStreetMap/CARTO) — loading a map necessarily reveals your IP address to the tile server.
Your controls
- Access & correction: view and edit your profile in the app, or email us.
- Deletion: email hello@staylok.com with the subject “Data request” and we delete your account, listings, and personal data within 30 days.
- Logout clears your session token from the device.
- Chat keys are device-local — losing your device means old chats cannot be decrypted by anyone, including us.
Children: StayLok is intended for people aged 16 and over; we do not knowingly collect data from children under 16. Questions about this policy? See Contact.