Draft for attorney review

Draft Privacy Policy

Data collection, photo evidence, support records, emails, analytics, and payment-provider disclosure.

Not final legal terms

This document is a planning draft. It should be reviewed, revised, and approved by qualified counsel before TrustStay uses it as public legal policy.

Purpose

Prepare a privacy draft for counsel to align with U.S. and any future international requirements.

Attorney focus

Confirm disclosures for account details, DOB, phone, address, photos, support tickets, and admin logs.
Confirm retention periods and deletion/access rights.
Confirm third-party processor language for Supabase, Stripe, Resend, Google, Vercel, analytics, and maps.

Information collected

Account details: name, email, phone, date of birth, gender, address, country, profile details, preferences, and login provider details.
Listing and owner details: property descriptions, address/location, photos, stay type, shared spaces, prices, amenities, verification status, payout status, and admin review notes.
Booking details: dates, guest count, pricing, payment identifiers, receipt numbers, booking status, review status, support actions, and cancellation/refund records.
Evidence and support data: owner photos, guest arrival photos, turnover photos, timestamps, support tickets, messages, dispute notes, safety/habitability reports, AI/photo review labels, moderation records, owner/guest history signals, and admin activity logs.
Communication preferences and delivery records: email notifications, support emails, accommodation alerts, unsubscribe status, and future SMS/phone support consent if enabled.

How information is used

To create accounts, listings, bookings, support tickets, and notifications.
To verify cleanliness, review arrival evidence, resolve disputes, moderate accounts, prevent fraud, and improve platform safety.
To send booking, support, alert, feedback, and operational emails.
To comply with payment, tax, legal, safety, and fraud-prevention obligations.

Photo evidence

Cleanliness, turnover, and arrival photos may be used as evidence in booking decisions, support tickets, refunds, disputes, owner quality scoring, guest trust scoring, listing review, fraud prevention, and admin moderation. Final policy should define who can see these photos, how long they are retained, and how deletion requests are handled.

Third-party services

TrustStay may use Supabase for database/auth/storage, Stripe for payments and payouts, Resend for email, Vercel for hosting, Google for OAuth/maps/address autocomplete, and other service providers. Final policy should list current providers and explain when data is shared.

Sensitive data and payment details

TrustStay should not store full card numbers, Apple Pay credentials, PayPal credentials, full bank account details, SSNs, ITINs, government ID images, or biometric face-match data in the app database unless counsel approves the exact provider, consent, retention, and security process. Payment, payout, and identity details should be handled by approved providers where possible. Counsel should confirm if collected DOB/address details create additional obligations.

Security and retention

Final policy should describe security safeguards, evidence retention, backup practices, admin access controls, deletion/access requests, incident response, and retention exceptions for disputes, fraud, taxes, legal claims, and safety investigations.

Review note

After counsel finalizes this document, update the matching public TrustStay policy page and keep this legal-review draft archived for launch records.