# Privacy Policy — StayLok

This summary explains what StayLok collects, why, where it lives, and what you control. The full in-app policy governs; this page is the plain-language version for quick review. Last updated: 2026.

## Who we are

StayLok operates a rental marketplace for PGs, hostels, flats, and rooms in the Chandigarh Tricity. For any privacy question or request, email [hello@staylok.com](mailto:hello@staylok.com) with the subject "Data request".

## What we collect

- **Account data** — name, email address, phone number, and a hashed password (never stored in plain text). Owners additionally have listing business details.
- **Listing and booking data** — property details, photos you upload, booking requests, dates, and status.
- **Messages** — chats between tenants and owners. Message text is end-to-end encrypted: encryption keys are generated on your device and your private key never leaves it. The server stores only ciphertext.
- **Favorites and app preferences** — stored locally on your device.
- **Diagnostics** — if the app crashes, an error report (message and stack trace) may be sent so we can fix the bug. It contains no message content.

## What we do NOT do

- No third-party advertising trackers or ad SDKs.
- No selling of personal data — to anyone, ever.

## Where data lives

Account, listing, booking, and ciphertext message data are stored on managed cloud infrastructure (Supabase Postgres with authentication by Supabase Auth) behind the staylok.com API. Property images are stored as uploads served from the site. Local preferences live in encrypted device storage (secure store) or app storage on your own device.

## Third parties that process data

- **Supabase** — database and authentication infrastructure.
- **Vercel** — application hosting and serverless API.
- **Map tile providers** (OpenStreetMap/CARTO) — loading a map reveals your IP address to the tile server.

## Your controls

- **Access and correction** — view and edit your profile in the app, or email us.
- **Deletion** — email "Data request" to delete your account, listings, and personal data; deletion requests are honored within 30 days.
- **Logout** clears your session token from the device.
- **Chat keys** are device-local; losing your device means old chats cannot be decrypted by anyone, including us.

## Children

StayLok is intended for adults (16+); we do not knowingly collect data from children under 16. Contact us if you believe a minor has an account.

## Changes

Material changes to this policy will be announced in the app before taking effect.

## Related pages

- [About StayLok](https://staylok.com/about)
- [Contact](https://staylok.com/contact) — for any data request
- [Agent index (llms.txt)](https://staylok.com/llms.txt)
