stay·manual
DemosFeaturesHow it worksPricing
Sign inGet started

Legal

Privacy Policy

Last updated: 2026-05-05

This Privacy Policy explains what personal information Edbo Apps (Pty) Ltd, a private company incorporated in South Africa with company registration number 2026/198667/07(“we”, “us”, “Edbo Apps”), collects when you use staymanual.app(the “Service”), why we collect it, how we use it, who we share it with, and the rights you have over it. We act as the responsible party (under the Protection of Personal Information Act, 2013 — POPIA) and the data controller (under the EU General Data Protection Regulation — GDPR) for the data described below.

This Policy is part of, and incorporated into, our Terms of Service. Defined terms used but not defined here have the meaning given in the Terms.

1. The short version

  • We only collect what we need to run the Service: your account email, the manual content you create, and basic guest-page analytics (scan + view counts).
  • We do not sell your data, ever.
  • Sub-processors (Supabase, Vercel, Sentry, Wise, Google Translate) help us deliver the Service. They are bound by their own privacy commitments.
  • You can ask for a copy of your data, or for it to be deleted, at any time by emailing edboapps@gmail.com.
  • We will delete your account data within 30 days of a verified deletion request, except where law requires we retain specific records longer.

2. Data we collect about you (Hosts)

When you sign up and use the Service as a host, we collect:

  • Account data: email address, hashed password (we never see your password in the clear — it is hashed by our authentication provider), and the timestamp + version of the Terms of Service / Privacy Policy you accepted at sign-up.
  • Profile data you choose to add: display name, short bio, location label, response-time hint, avatar image. All optional.
  • Property and manual content: property names, slugs, addresses or location labels you provide, manual text, uploaded images and videos, captions, and any custom sections you add.
  • Subscription / billing metadata: if and when paid plans launch, this will include the plan you are on and the IDs returned by our payment processor. Payment-card details are never stored by us; they live with the payment processor.
  • Operational metadata: timestamps of account creation, sign-in, content publish/unpublish, and similar events needed to operate the Service.

3. Data we collect about your guests

When a guest scans your QR code or opens your guest page, we record a minimal analytics event so you can see how often your manual is being used. Specifically:

  • The fact that a scan or page-view occurred, and which property it was for;
  • The IP-derived country code (e.g. “ZA”, “US”) — not the full IP address;
  • The browser User-Agent string and HTTP Referer header (if any);
  • A timestamp.

We do not place tracking cookies or use cross-site identifiers on the guest page. Known bots and link-preview fetchers are filtered out before any event is recorded.

4. Data we do NOT collect

  • We do not collect guest names, email addresses, phone numbers, payment details, ID documents, or any data your guests provide to you outside the Service.
  • We do not collect precise location data from your guests.
  • We do not store payment-card numbers.
  • We do not run third-party advertising or behavioural tracking on the guest page.

5. Why we process your data (lawful basis)

Under GDPR and equivalent regimes, we rely on the following lawful bases:

  • Performance of a contract — to provide the Service you signed up for (your account, your manual, your QR codes, your analytics).
  • Legitimate interests — to keep the Service secure, prevent abuse and fraud, monitor errors (Sentry), and produce aggregate analytics.
  • Legal obligation — to comply with tax, accounting, and other legal record-keeping requirements.
  • Consent — where you have given it, e.g. by ticking the acceptance checkbox at sign-up. You can withdraw consent at any time by emailing edboapps@gmail.com.

6. Who we share data with (sub-processors)

We use a small number of trusted vendors to operate the Service. Each is bound by a written agreement (or by their published terms) restricting them to processing data on our instructions.

  • Supabase — database, authentication, file storage. Hosts your account data and manual content.
  • Vercel — application hosting and serverless compute. Processes incoming HTTP requests.
  • Sentry — error monitoring. Receives stack traces and minimal request metadata when an error occurs.
  • Wise — payment processing for the optional tip jar. Only the data you choose to give them at the time of payment.
  • Google Translate— guest-page translation. When a guest uses the translate button, the page URL is opened in Google Translate; Google’s own privacy policy applies to that interaction.

We do not sell, rent, or trade personal data with anyone for advertising or marketing purposes.

7. Where data is stored and international transfers

Our infrastructure providers operate global networks; data may be stored or processed in countries outside your country of residence, including the European Union, the United Kingdom, and the United States. Where data leaves the European Economic Area or the United Kingdom, the transfer is governed by the European Commission’s Standard Contractual Clauses (or the UK equivalent), the recipient’s Binding Corporate Rules, or another lawful transfer mechanism.

Where data leaves South Africa, the transfer is conducted in accordance with section 72 of POPIA, which requires the recipient country or recipient to provide a level of protection substantially similar to POPIA.

8. How long we keep your data

  • Account & profile data: while your account is active. Deleted within 30 days after you close your account or we terminate it, except where retention is required by law.
  • Manual content: while your account is active. Deleted with the account.
  • Guest analytics events: retained for up to 24 months for trend analysis, then purged or aggregated.
  • Sub-processor logs(Vercel, Sentry, Supabase): retention follows each provider’s default retention policy, typically between 30 days and 12 months.
  • Records required by tax, accounting, or other law: retained for the period required by the relevant legislation (in South Africa, this is typically five years for tax records).

9. Your rights

Subject to applicable law, you have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Rectification — ask us to correct inaccurate or incomplete data;
  • Erasure (“the right to be forgotten”) — ask us to delete your data;
  • Restriction — ask us to suspend processing in specific circumstances;
  • Portability — receive your data in a machine-readable format;
  • Objection — object to processing based on legitimate interests;
  • Withdraw consent — where processing is based on your consent.

To exercise any of these rights, email edboapps@gmail.com from the address associated with your account. We will respond within 30 days. There is no charge for a first request; we may charge a reasonable administrative fee for repetitive or excessive requests.

How to delete your data: send an email to edboapps@gmail.comwith the subject line “Data deletion request — staymanual” and we will action the deletion within 30 days. We may need to verify your identity (typically by confirming you can receive email at the address registered to the account) before proceeding.

10. Right to complain

If you believe we have not handled your personal information properly, you can complain to the relevant supervisory authority in your country. In South Africa, that is the Information Regulator (inforegulator.org.za). In the European Union, the relevant national data-protection authority. In the United Kingdom, the Information Commissioner’s Office (ICO).

11. Cookies and similar technologies

On the Service we use a small number of strictly-necessary cookies to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies. The guest manual page uses no cookies at all by default.

Some sub-processors (Vercel, Sentry) may set cookies on the host-facing dashboard pages for security and error-monitoring purposes. These are operational, not advertising.

12. Children

The Service is not directed at children under 18 (or under 16 for users in the European Economic Area). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.

13. No automated decision-making

We do not use automated decision-making (including profiling) to produce legal or similarly significant effects about you. Every decision that materially affects an account — for example, suspending an account that we believe has breached our Terms — is reviewed by a human before it is taken.

14. Security

We take reasonable technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest provided by our infrastructure vendors, password hashing, row-level security on the database, and principle-of-least-privilege access for the small number of people who maintain the Service. No internet service can guarantee absolute security; in the unlikely event of a breach affecting your data, we will notify you and the relevant authorities as required by law.

15. California residents (CCPA / CPRA)

California residents have additional rights under the California Consumer Privacy Act and California Privacy Rights Act, including the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information for cross-context behavioural advertising. To exercise any CCPA/CPRA right, email edboapps@gmail.com.

16. Changes to this Policy

We may update this Privacy Policy from time to time. The version identifier at the top of this page reflects the current Policy. Material changes will be communicated by email and/or in-product notice at least 14 days before they take effect.

17. Contact us

Questions about this Policy or about how we handle your data? Email edboapps@gmail.com. The same address handles requests under POPIA, GDPR, CCPA/CPRA, and any other applicable privacy regime.

Edbo Apps (Pty) Ltd
Company registration number 2026/198667/07 (South Africa)
edboapps@gmail.com

stay·manual© 2026 staymanual.app
Sign inPricingDemo manualsHow it worksTermsPrivacyTip the makeredboapps@gmail.com
staymanual is operated by Edbo Apps (Pty) Ltd (registration 2026/198667/07, South Africa).