StayEdge

Privacy notice

StayEdge processes personal data on behalf of the hotels listed on the platform. We follow data minimisation and purpose limitation: we collect only what is needed for your booking and legally required guest verification.

Purpose. Your identity document details are used only to verify your identity for this hotel stay, as hotels are required to maintain a verified guest register.

What is processed. Document type, document number, the name and date of birth on the document and (if you upload it) an image of the document. The number is sent securely to our verification provider and only the last 4 digits are kept. Uploaded images are deleted immediately after reading.

What is stored. The verification result, the provider's reference ID and the masked document number — never your full Aadhaar or document number, and never the document image.

Who can see it. Only authorised front-desk staff and administrators of the hotel you booked. Every access is logged.

How long. Verification records are kept for 180 days and then purged.

Your rights. You may withdraw consent, request access, correction or erasure, or raise a grievance at any time from the Privacy centre. Withdrawal does not affect processing already done; you would then need to verify at the front desk.

Notice version 1.0

Record of personal data processed

DataPurposeBasisStorageRetention
consent record (notice version, time, IP)
Consent
Demonstrate valid consentLegal obligation (accountability)DatabaseLifetime of related records
email
Contact
Booking confirmations and service communicationConsent / legitimate useDatabase, AES-256 encrypted + HMAC blind indexUntil 1095 days after last stay (hotel-configurable)
phone
Contact
Guest contact and de-duplication of profilesConsent / legitimate useDatabase, AES-256 encrypted + HMAC blind indexUntil 1095 days after last stay (hotel-configurable)
address / city / state
Contact
Guest registration and invoicingConsent / legal obligation (guest register)Database, address encryptedUntil 1095 days after last stay (hotel-configurable)
payment reference / amount / method
Financial
Collect payment and reconcileContract / legal obligation (tax records)Database (no card data; handled by gateway)As required by tax law (typically 8 years)
first_name / last_name
Identity
Identify the guest for booking, check-in and invoicingConsent / legitimate use for the service requestedDatabase (plain text, tenant-isolated)Until 1095 days after last stay (hotel-configurable)
date_of_birth
Identity
Identity matching during verification (optional)ConsentDatabase, AES-256 encryptedUntil 1095 days after last stay (hotel-configurable)
document_number
Identity document
Verify guest identity via KYC APIConsent (explicit, purpose-specific notice)NOT STORED – only masked last 4 digits + keyed HMAC180 days from verification
verification result / reference ID
Identity document
Proof that identity was verified for check-inConsent / legal obligationDatabase180 days from verification
document image
Identity document
Extract details via OCR APIConsentEncrypted temporary file, deleted immediately after OCR processingMinutes (processing only)
extracted name / DOB
Identity document
Match document with guest profileConsentDatabase, AES-256 encrypted180 days from verification
booking_guests.name / age
Stay
Record of occupants for the stayLegal obligation (guest register) / legitimate useDatabaseUntil 1095 days after last stay (hotel-configurable)
IP address / user agent
Technical
Security monitoring and accountabilityLegitimate use (security)Database (append-only)As per security policy
API call metadata
Technical
Usage metering and troubleshootingLegitimate useDatabase (PII redacted)90 days

Contact our privacy team at privacy@yourcompany.com.