StaySpectWatch the product tour

STAYSPECT ยท LEGAL

Privacy policy

Effective date: 30 September 2026

This notice explains how the StaySpect application handles account information and property inspection records, and what happens when you export your data or delete your account.

Company and privacy contact

The StaySpect application is operated by StaySpect. For privacy questions, requests about your personal information, account deletion assistance, or legal enquiries, contact admin@stayspect.com.

Information used by the application

How this information is used

Information supports account access, property and stay management, inspection capture, guest review, evidence comparison, transactional notifications, and auditability. Authorized members of the relevant organization can access operational records according to their roles. Guests receive access through scoped review links.

Device permissions

Camera, photo-library, and location access support capture and property workflows when you grant permission. You can manage permissions in your device settings. Optional biometric quick login uses the device's authentication system; StaySpect does not receive your biometric templates. A refresh token may be stored in secure device storage for quick login.

Service providers and hosting

The application uses Amazon Web Services for authentication, application processing, database storage, private media storage, and transactional email. The current application environment is hosted in the US East (Northern Virginia) region. The public website is delivered through CloudFront's global network. Map features use Google Maps. Where an authorized operator requests AI-assisted comparison, selected inspection images may be processed by Amazon Bedrock. AI output is advisory and requires human review.

Private media and sharing

Inspection originals and personal images are held in private storage. Authorized downloads use time-limited links. Anyone who receives a valid download or review link may be able to use it until it expires, so avoid forwarding such links to unauthorized people. Operational evidence may itself contain personal information; capture only what is needed for the inspection.

Export my data

In Settings, choose Export my data to download a JSON file containing your account attributes, profile, memberships, personal-media download links, and summaries of your own audit actions. Shared operational records, other users' details, passwords, and authentication tokens are excluded. The export and media links expire after five minutes. The generated export is scheduled for deletion from service storage after one day; downloaded copies remain under your control.

Delete my account

In Settings, choose Delete my account, review the consequences, and type DELETE to confirm. Signed-in API access is blocked as soon as the request is accepted. A background process removes the authentication account, profile, personal images (including stored versions), exports, and memberships. Cleanup normally completes within 30 minutes and retries if a service is unavailable. Previously issued personal-media upload links are allowed to expire before a final cleanup pass. You can also request account deletion on the web.

Operational and audit records are retained. Deleting an account does not delete properties, stays, inspections, original inspection evidence, guest responses, review findings, or audit history. These records can include names, contact details, images, and identifiers originally entered as part of the operation. A minimal account-deletion marker is retained to prevent old authentication tokens from restoring access. Other authorized organization members keep access to retained records. If you are the only owner, arrange another authorized owner before deleting your account.

Retention and recovery copies

Operational evidence and audit records do not currently have a universal automatic deletion deadline; retention is managed separately from account deletion for operational traceability and audit purposes. Guest review access is disabled when its stay or inspection is archived or terminated; the underlying operational evidence and audit history remain preserved. Backup and recovery copies can remain until the relevant recovery window expires; account deletion is applied to active service records and should be preserved during a recovery. Keeping a record for audit purposes does not make every retention period legally appropriate in every jurisdiction.

Your choices and questions

You can edit your profile, export account information, delete your account, request deletion through the web deletion page, and control device permissions. Guests should contact the host or property manager who invited them about information in a stay or inspection record. Depending on applicable law, additional rights may apply to access, correction, erasure, restriction, or complaints to a relevant authority. The Legal Portal explains the available self-service controls and the limits of inspection records.