Legal
Privacy Policy
Last updated: 2026-05-21
This Privacy Policy explains what personal information Edbo Apps (Pty) Ltd, a private company incorporated in South Africa with company registration number 2026/198667/07(“we”, “us”, “Edbo Apps”), collects when you use staymanual.app(the “Service”), why we collect it, how we use it, who we share it with, and the rights you have over it. We act as the responsible party (under the Protection of Personal Information Act, 2013, known as POPIA) and the data controller (under the EU General Data Protection Regulation, known as GDPR) for the data described below.
This Policy is part of, and incorporated into, our Terms of Service. Defined terms used but not defined here have the meaning given in the Terms.
1. The short version
- We only collect what we need to run the Service: your account email, the manual content you create, and basic guest-page analytics (scan + view counts).
- We do not sell your data, ever.
- Sub-processors (Supabase, Vercel, Polar, Resend, Sentry, Google Translate) help us deliver the Service. They are bound by their own privacy commitments.
- You can ask for a copy of your data, or for it to be deleted, at any time by emailing support@staymanual.app.
- We will delete your account data within 30 days of a verified deletion request, except where law requires we retain specific records longer.
2. Data we collect about you (Hosts)
When you sign up and use the Service as a host, we collect:
- Account data: email address, the password you set (we never see it in a form we could read; it’s stored one-way scrambled so even we can’t recover it), and the timestamp and version of the Terms of Service and Privacy Policy you accepted at sign-up.
- Profile data you choose to add: display name, short bio, location label, response-time hint, avatar image. All optional.
- Property and manual content: property names, slugs, addresses or location labels you provide, manual text, uploaded images and videos, captions, and any custom sections you add.
- Subscription / billing metadata: if you subscribe to a paid plan (Solo, Studio, or Portfolio), this includes the plan you are on, the billing cycle (monthly), and the customer and subscription IDs returned by Polar (our payment processor and merchant of record). Payment-card details are never stored by us; they live with Polar.
- Operational metadata: timestamps of account creation, sign-in, content publish/unpublish, and similar events needed to operate the Service.
3. Data we collect about your guests
When a guest scans your QR code or opens your guest page, we record a minimal analytics event so you can see how often your manual is being used. Specifically:
- The fact that a scan or page-view occurred, and which property it was for;
- The country your guest is in (e.g. “ZA”, “US”), worked out from their internet address. We don’t keep the full address;
- The type of phone or browser the guest is using, and the page that sent them to yours (if any);
- A timestamp.
We do not place tracking cookies or use cross-site identifiers on the guest page. Known bots and link-preview fetchers are filtered out before any event is recorded.
4. Data we do NOT collect
- We do not collect guest names, email addresses, phone numbers, payment details, ID documents, or any data your guests provide to you outside the Service.
- We do not collect precise location data from your guests.
- We do not store payment-card numbers.
- We do not run third-party advertising or behavioural tracking on the guest page.
5. Why we process your data (lawful basis)
Under GDPR and equivalent regimes, we rely on the following lawful bases:
- Performance of a contract: to provide the Service you signed up for (your account, your manual, your QR codes, your analytics).
- Legitimate interests: to keep the Service secure, prevent abuse and fraud, watch for errors, and produce overall usage figures.
- Legal obligation: to comply with tax, accounting, and other legal record-keeping requirements.
- Consent: where you have given it, for example by ticking the acceptance checkbox at sign-up. You can withdraw consent at any time by emailing support@staymanual.app.
6. Who we share data with (sub-processors)
We use a small number of trusted vendors to operate the Service. Each is bound by their published terms or a written agreement restricting them to processing data on our instructions.
- Supabase: where your account, manual text, and uploaded photos and videos are stored, and the service that handles your sign-in.
- Vercel: where the website itself runs.
- Polar: handles paid-plan payments and acts as the seller of record. They see the billing details you enter at checkout. We never see or store your card number.
- Resend: sends the emails the Service generates (sign-in links, account confirmations, billing receipts).
- Sentry: lets us see when something on the site breaks so we can fix it.
- Google Translate: translates the guest page on demand when a guest taps the translate button.
Each provider operates under its own privacy policy. We do not sell, rent, or trade personal data with anyone for advertising or marketing purposes.
7. Where data is stored and international transfers
Our infrastructure providers operate global networks; data may be stored or processed in countries outside your country of residence, including the European Union, the United Kingdom, and the United States. Where data leaves the European Economic Area or the United Kingdom, the transfer is governed by the European Commission’s Standard Contractual Clauses (or the UK equivalent), the recipient’s Binding Corporate Rules, or another lawful transfer mechanism.
Where data leaves South Africa, the transfer is conducted in accordance with section 72 of POPIA, which requires the recipient country or recipient to provide a level of protection substantially similar to POPIA.
8. How long we keep your data
- Account & profile data: while your account is active. Deleted within 30 days after you close your account or we terminate it, except where retention is required by law.
- Manual content: while your account is active. Deleted with the account.
- Guest analytics events: retained for up to 24 months for trend analysis, then purged or aggregated.
- Service logs at our vendors(Vercel, Sentry, Supabase): retention follows each provider’s default retention policy, typically between 30 days and 12 months.
- Records required by tax, accounting, or other law: retained for the period required by the relevant legislation (in South Africa, this is typically five years for tax records).
9. Your rights
Subject to applicable law, you have the right to:
- Access: request a copy of the personal data we hold about you;
- Rectification: ask us to correct inaccurate or incomplete data;
- Erasure (“the right to be forgotten”): ask us to delete your data;
- Restriction: ask us to pause processing in specific circumstances;
- Portability: receive your data in a format a computer can re-read;
- Objection: object to processing based on legitimate interests;
- Withdraw consent: where processing is based on your consent.
To exercise any of these rights, email support@staymanual.app from the address associated with your account. We will respond within 30 days. There is no charge for a first request; we may charge a reasonable administrative fee for repetitive or excessive requests.
How to delete your data: send an email to support@staymanual.app with the subject line “Data deletion request, staymanual” and we will action the deletion within 30 days. We may need to verify your identity (typically by confirming you can receive email at the address registered to the account) before proceeding.
10. Right to complain
If you believe we have not handled your personal information properly, you can complain to the relevant supervisory authority in your country. In South Africa, that is the Information Regulator (inforegulator.org.za). In the European Union, the relevant national data-protection authority. In the United Kingdom, the Information Commissioner’s Office (ICO).
11. Cookies and similar technologies
On the Service we use a small number of strictly-necessary cookies to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies. The guest manual page uses no cookies at all by default.
Some sub-processors (Vercel, Sentry) may set cookies on the host-facing dashboard pages for security and error-monitoring purposes. These are operational, not advertising.
12. Children
The Service is not directed at children under 18 (or under 16 for users in the European Economic Area). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
13. No automated decision-making
We do not use automated decision-making (including profiling) to produce legal or similarly significant effects about you. Every decision that materially affects an account (for example, suspending an account that we believe has breached our Terms) is reviewed by a human before it is taken.
14. Security
We use industry-standard technical and organisational measures to protect personal data, including encryption in transit and at rest, hashed passwords, and restricted access controls. No internet service can guarantee absolute security; in the unlikely event of a breach affecting your data, we will notify you and the relevant authorities as required by law.
15. California residents (CCPA / CPRA)
California residents have additional rights under the California Consumer Privacy Act and California Privacy Rights Act, including the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information for cross-context behavioural advertising. To exercise any CCPA/CPRA right, email support@staymanual.app.
16. Changes to this Policy
We may update this Privacy Policy from time to time. The version identifier at the top of this page reflects the current Policy. Material changes will be communicated by email and/or in-product notice at least 14 days before they take effect.
17. Contact us
Questions about this Policy or about how we handle your data? Email support@staymanual.app. The same address handles requests under POPIA, GDPR, CCPA/CPRA, and any other applicable privacy regime.
Edbo Apps (Pty) Ltd
Company registration number 2026/198667/07 (South Africa)
support@staymanual.app