Privacy Policy
Effective: 13 July 2026 Last updated: 13 July 2026
StayCrew (also referred to as we, us, and our) is an operational coordination platform for hotels and hotel groups. This Privacy Policy explains how personal data is handled across the StayCrew services: the employee mobile and web application, the Control Center administration console, the Guest Services QR portal, public hotel pages, and this website.
1. Introduction and scope
This policy applies to the people who interact with StayCrew:
- Hotel and hotel-group employees who use the StayCrew application.
- Hotel and group administrators who manage StayCrew in the Control Center.
- Guests who open a hotel or room QR code to request services, and visitors to public hotel pages.
- People who contact us for support or request a product demonstration through this website.
2. Who is responsible for your data
StayCrew provides and operates the service. For most account, security, and technical processing described here, StayCrew determines how data is handled. For employee and operational data that a hotel or hotel group enters and uses to run its operation, that organization typically determines why and how the data is processed and may act as the data controller, while StayCrew processes the data to provide the service. For privacy questions or to exercise your rights, contact StayCrew at [email protected]; hotel employees may also contact their own hotel administrator.
3. Personal data we process
The personal data we process depends on how you use StayCrew. It may include:
- Work profile: your display name, employee code (used to sign in), and your hotel, group, department, and position, provided by your employing hotel or group.
- Preferences: your chosen language, application theme, notification setting, and work-schedule windows.
- Authentication data: your password, stored only as a salted, hashed value, and sign-in session records, stored only as a hashed token reference.
- Operational records you create: requests, inquiries and maintenance reports, reminders, shift handovers, work permissions, lost-and-found entries, tasks, and their status history, which may contain room numbers and free-text notes you enter.
- Attachments: images or files you attach to inquiries, reports, or lost-and-found items, held in private storage.
- Guest service requests: for guests, the room number, room-owner name, and any note entered when submitting a request through a hotel or room QR code.
- Device push tokens: if you enable notifications, a device token used to deliver them.
- Limited technical data: a network (IP) address used only transiently to protect the service against abuse, and a per-request identifier used in diagnostic logs.
- Crash diagnostics: if crash monitoring is enabled, error and stack-trace reports sent to our monitoring provider, together with limited technical context the monitoring SDK attaches automatically — such as app version, operating-system version, device model or class, and runtime and environment. These reports are scrubbed of personal identifiers before sending (see the next section).
- Website: if you submit the demo-request form, the contact and organization details you provide; if you email support, your message.
4. What we do not collect
StayCrew is built for hotel operations, not for advertising or profiling. We do not:
- collect payment-card or financial-account details; Guest Services can display prices, but StayCrew does not process payments;
- collect precise or background location;
- use advertising identifiers or tracking identifiers, serve ads, or track you for advertising;
- use website or in-application analytics or behavioural tracking;
- access your microphone or contacts;
- request broad or continuous access to your photo library — StayCrew accesses only the photos or files you explicitly select or capture (see 'Notifications and device permissions');
- attach your user identity, IP address, request bodies, authentication tokens, or sensitive content to crash diagnostics — these are removed or masked before a report is sent;
- sell your personal data.
5. Where your data comes from
- From your employing hotel or group and its administrators, who create your account and assign your hotel, department, and position.
- From you, when you set your password and display name, adjust preferences, enter operational content, or submit a guest service request.
- From the service itself, which generates records such as session references, audit history, task points, and request identifiers.
- From your device and network activity, limited to what is needed to deliver notifications and protect the service.
6. Why we process data and our legal bases
We process personal data for defined purposes and rely on the legal bases recognized under the Saudi Personal Data Protection Law (PDPL). We do not rely on consent for every activity.
- To provide hotel-operations features, route work, and deliver notifications: to perform the service and for the hotel's legitimate operational interest.
- To authenticate authorized users and manage organizations, hotels, and permissions: to perform the service and for the legitimate interest in controlled access.
- To protect accounts and the service, prevent abuse, and investigate incidents: for the legitimate interest in security and, where applicable, a legal obligation.
- To handle guest service requests submitted through a QR code: to fulfil the request and for the hotel's legitimate interest in serving its guests.
- To provide support and respond to your enquiries: to handle your request.
- To keep operational and audit records and meet applicable legal obligations: for legal obligation and the legitimate interest in accountability.
- To keep the service reliable using scrubbed crash diagnostics: for the legitimate interest in a stable, secure service.
- For optional device notifications: based on the notification setting you control.
7. Who we share data with
We share personal data only as needed to run the service:
- Your hotel or hotel group, and its authorized employees and administrators, who can see the operational records relevant to their role and scope.
- Infrastructure and technical providers that operate the platform on our behalf under appropriate obligations: Supabase (database and file storage), DigitalOcean (application hosting), Google Firebase Cloud Messaging (push-notification delivery), and Sentry (scrubbed crash monitoring).
- Email-forwarding and mailbox providers that handle messages you send to our support address (currently Porkbun email forwarding and Google email services).
- Google's Gemini API, only where a hotel administrator enables the optional AI-assistance features (these are disabled by default until enabled through approved production configuration). Prompts are designed to minimize direct identifiers, but authorized operational text may be processed to generate advisory text; you should not enter unnecessary sensitive personal data into AI-assisted fields.
- Professional advisers, or government and judicial authorities, where we are lawfully required or permitted to disclose.
- We do not sell personal data, and we do not share it for advertising.
8. International data transfers
StayCrew's infrastructure providers may process or store data in data centres located outside the Kingdom of Saudi Arabia. Where personal data is transferred outside the Kingdom, we apply the safeguards required by the PDPL and its data-transfer regulation where required — such as transferring to jurisdictions recognized as providing an adequate level of protection, or using appropriate contractual, organizational, and technical safeguards.
9. How long we keep data
We keep personal data only as long as needed for the purposes above, and we apply category-based criteria rather than a single universal period:
- Sign-in sessions remain active until you sign out, an administrator revokes them, your account is anonymized, or a security action ends them; there is no automatic session expiry. Signing out invalidates the session and removes that device's notification token.
- Your work profile and preferences are kept while your account is active.
- Operational and audit records are kept for operational continuity, security, dispute handling, and legal requirements, and each hotel may apply its own retention configuration.
- Attachments on inquiries and reports may carry a defined expiry; guest QR room sessions are short-lived (about 24 hours).
- Scrubbed crash diagnostics are retained by our monitoring provider for a limited diagnostic period.
10. Account deletion and anonymization
You can ask to have your StayCrew account removed. In StayCrew, account deletion means anonymization of your personal data together with disabling of access; it is not an immediate hard deletion of every record.
- You can request deletion from inside the application under Settings, from our public page at staycrew.app/account-deletion, or by contacting your hotel administrator or our support team; a hotel administrator can also process a request on your behalf.
- When a request is processed, your account is disabled, sign-in is permanently prevented, and all active sessions and registered devices are signed out.
- Your identifying details, such as your display name and any stored email or phone, are removed or replaced with a neutral label, so you are no longer identifiable in the application.
- Some operational, security, audit, and legal records are retained in anonymized form. A restricted, non-reusable internal identifier (your employee code) may be retained for uniqueness and audit integrity; it is no longer used to sign in, but it may remain personal or pseudonymous where your organization can still associate it with you.
- Because a hotel or group controls its own employee and operational records, that organization may need to take part in the process.
11. Your privacy rights
Subject to the PDPL and applicable exemptions, you have the right to be informed about processing; to access your personal data; to obtain it in a readable, clear format; to have inaccurate or incomplete data corrected or completed; to request destruction of your personal data where applicable; to withdraw consent where processing is based on consent; and to complain to the competent authority, the Saudi Data and AI Authority (SDAIA). To exercise any of these rights, contact us at [email protected]; hotel employees may also contact their hotel administrator. We handle valid requests without undue delay and generally free of charge. If you are not satisfied with our response, you may escalate to SDAIA.
12. How we protect data
We use reasonable technical and organizational measures appropriate to the service, including:
- strict separation between hotels and groups, so data stays within its tenant;
- server-enforced authorization and scope checks on every request;
- encrypted transport (HTTPS), with passwords stored only as salted hashes;
- session tokens stored only as hashed references, with immediate session revocation on sign-out or deletion;
- restricted service credentials, secret redaction in logs, rate limiting, audit records, and monitoring.
- No online service can be guaranteed to be completely secure, but we work to protect your data and to respond to incidents, including notifying the competent authority and affected individuals where required.
13. Notifications and device permissions
- Notifications are optional and controlled by the notification setting in the application; you can turn them off, and on mobile you can also manage the system notification permission.
- If notifications are enabled, a device push token is stored to deliver them, and it is removed when you sign out or your account is anonymized.
- StayCrew does not request broad or continuous photo-library access; it accesses only the photos or files you explicitly select or capture — for example, when you use the camera or your device's picker to attach a photo to a lost-and-found item.
14. Guest QR codes and public pages
- Opening a room QR code starts a short-lived session that links your browser to that hotel and room; it stores no guest data, embeds no secrets, and is not a guest account.
- When you submit a guest service request, the room number, room-owner name, and any note you enter are shared with the hotel's staff, who handle the request.
- QR links are provided by the hotel; you should not probe, guess, share, or misuse QR codes or their links.
- Public hotel pages show hotel-authored business information; they are not personal profiles.
15. Children
StayCrew's employee application is intended for authorized adult hotel and hotel-group personnel, not for children. Guest services accessed through a hotel or room QR code are intended to be offered under the relevant hotel's supervision. StayCrew does not knowingly collect personal data from children through the employee application.
16. Changes to this policy and how to contact us
We may update this Privacy Policy as the service evolves or as required by law. We will change the last-updated date shown above and, where changes are material, communicate them through appropriate channels. This policy is made available before and at the point of data collection. For questions or requests about privacy, contact [email protected].