Privacy Policy

Your Privacy Matters

We are committed to protecting your privacy and ensuring the security of your personal information. This policy explains how we collect, use, and safeguard your data.

Last updated: December 2024

Privacy at a Glance

What We Collect

Personal information for bookings, usage data for improvements, and communication records for support.

How We Protect It

Industry-standard encryption, access controls, regular security audits, and strict data handling policies.

Your Control

Access, correct, or delete your data anytime. Opt-out of communications and control your privacy settings.

Third Parties

Limited sharing with hostel partners and trusted service providers only when necessary for service delivery.

Information We Collect

Personal Information

When you create an account, make a booking, or contact us, we collect personal information including your name, email address, phone number, gender, and role (tenant, staff, hostel admin, or app admin). All sensitive personal data is encrypted using industry-standard AES-256 encryption before storage.

Authentication Data

We collect and store encrypted password hashes, JWT tokens (expiring every 24 hours), and session information to secure your account and provide seamless access to our services.

Location Information

We collect your location data (with permission) to help you find nearby hostels, calculate distances, and provide location-based services. This includes GPS coordinates, city, state, and area information.

Device and Usage Information

We automatically collect device information, IP address, browser type, pages visited, and usage patterns to improve our platform performance and user experience.

Communication Data

We store communications between you and HostelFlow, including support tickets, complaint records, and customer service interactions for quality assurance and dispute resolution.

Push Notification Data

We collect FCM (Firebase Cloud Messaging) tokens to send you important updates about bookings, payments, and hostel-related notifications.

How We Use Your Information

Service Provision

We use your information to provide, maintain, and improve our hostel booking services, process payments, and facilitate communications between you and hostel providers.

Personalization

Your data helps us personalize your experience, recommend suitable accommodations, and send you relevant updates about hostels in your preferred locations.

Customer Support

We use your information to respond to your inquiries, resolve issues, and provide customer support services.

Legal Compliance

We may use your information to comply with applicable laws, regulations, legal processes, or governmental requests.

Information Sharing

Hostel Partners

We share necessary booking information with hostel providers to facilitate your accommodation. This includes your name, contact details, and booking preferences.

Service Providers

We work with trusted third-party service providers for payment processing, analytics, and customer support. These partners are bound by strict confidentiality agreements.

Legal Requirements

We may disclose your information when required by law, court order, or to protect the rights, property, or safety of HostelFlow, our users, or others.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.

Data Security

Data Encryption

All sensitive personal data (names, emails, phone numbers) is encrypted using AES-256 encryption before database storage. We use deterministic encryption for searchable fields and standard encryption for other sensitive data.

Authentication Security

We use JWT tokens with 24-hour expiration, secure password hashing with bcrypt, and automatic token refresh mechanisms. All authentication data is encrypted and stored securely.

Role-Based Access Control

Access to personal information is strictly controlled through role-based permissions (tenant, staff, hostel admin, app admin). Each role has limited access to only the data necessary for their function.

Secure Communication

All data transmission is protected using HTTPS/SSL encryption. API endpoints require proper authentication and authorization headers for access.

Data Isolation

User data is isolated by role and hostel assignment. Staff can only access data for their assigned hostels, and tenants can only access their own information.

Regular Security Audits

We conduct regular security assessments, vulnerability testing, and code reviews to identify and address potential security issues in our systems.

Your Rights

Access and Portability

You have the right to access, review, and receive a copy of the personal information we hold about you.

Correction and Updates

You can update or correct your personal information through your account settings or by contacting our customer support.

Deletion

You may request deletion of your personal information, subject to certain legal and operational requirements.

Opt-out

You can opt-out of marketing communications at any time by using the unsubscribe link in our emails or updating your preferences.

Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience on our platform. These help us remember your preferences, analyze usage patterns, and provide personalized content.

Essential Cookies

Required for basic website functionality, security, and user authentication.

Analytics Cookies

Help us understand how users interact with our platform to improve services.

Preference Cookies

Remember your settings and preferences for a personalized experience.

Marketing Cookies

Used to deliver relevant advertisements and track marketing campaign effectiveness.

You can manage your cookie preferences through your browser settings. For more details, see our Cookie Policy.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce our agreements.

Authentication Tokens24 hours (JWT expiration)
Account InformationUntil account deletion
Booking Records7 years for legal compliance
FCM TokensUntil device uninstall or token refresh
Communication Logs3 years for support purposes
Usage Analytics2 years for service improvement

Questions About Your Privacy?

If you have any questions about this privacy policy or how we handle your data, we're here to help and provide clarity.