STAYSPECT ยท LEGAL
Privacy policy
Effective date: 30 September 2026
This notice explains how the StaySpect application handles account information and property inspection records, and what happens when you export your data or delete your account.
Company and privacy contact
The StaySpect application is operated by StaySpect. For privacy questions, requests about your personal information, account deletion assistance, or legal enquiries, contact admin@stayspect.com.
Information used by the application
- Account and profile: your email address, account identifier, name, phone number, profile image, decoration image, language and appearance preferences, and organization memberships.
- Property operations: property and room details, stay dates, guest contact details entered by authorized users, inspection assignments, photos, videos, capture metadata, guest responses, findings, and review history.
- Technical records: authentication events, request identifiers, timestamps, and service diagnostics used to operate and protect the service.
How this information is used
Information supports account access, property and stay management, inspection capture, guest review, evidence comparison, transactional notifications, and auditability. Authorized members of the relevant organization can access operational records according to their roles. Guests receive access through scoped review links.
Device permissions
Camera, photo-library, and location access support capture and property workflows when you grant permission. You can manage permissions in your device settings. Optional biometric quick login uses the device's authentication system; StaySpect does not receive your biometric templates. A refresh token may be stored in secure device storage for quick login.
Service providers and hosting
The application uses Amazon Web Services for authentication, application processing, database storage, private media storage, and transactional email. The current application environment is hosted in the US East (Northern Virginia) region. The public website is delivered through CloudFront's global network. Map features use Google Maps. Where an authorized operator requests AI-assisted comparison, selected inspection images may be processed by Amazon Bedrock. AI output is advisory and requires human review.
Private media and sharing
Inspection originals and personal images are held in private storage. Authorized downloads use time-limited links. Anyone who receives a valid download or review link may be able to use it until it expires, so avoid forwarding such links to unauthorized people. Operational evidence may itself contain personal information; capture only what is needed for the inspection.
Export my data
In Settings, choose Export my data to download a JSON file containing your account attributes, profile, memberships, personal-media download links, and summaries of your own audit actions. Shared operational records, other users' details, passwords, and authentication tokens are excluded. The export and media links expire after five minutes. The generated export is scheduled for deletion from service storage after one day; downloaded copies remain under your control.
Delete my account
In Settings, choose Delete my account, review the consequences, and type DELETE to confirm. Signed-in API access is blocked as soon as the request is accepted. A background process removes the authentication account, profile, personal images (including stored versions), exports, and memberships. Cleanup normally completes within 30 minutes and retries if a service is unavailable. Previously issued personal-media upload links are allowed to expire before a final cleanup pass. You can also request account deletion on the web.
Operational and audit records are retained. Deleting an account does not delete properties, stays, inspections, original inspection evidence, guest responses, review findings, or audit history. These records can include names, contact details, images, and identifiers originally entered as part of the operation. A minimal account-deletion marker is retained to prevent old authentication tokens from restoring access. Other authorized organization members keep access to retained records. If you are the only owner, arrange another authorized owner before deleting your account.
Retention and recovery copies
Operational evidence and audit records do not currently have a universal automatic deletion deadline; retention is managed separately from account deletion for operational traceability and audit purposes. Guest review access is disabled when its stay or inspection is archived or terminated; the underlying operational evidence and audit history remain preserved. Backup and recovery copies can remain until the relevant recovery window expires; account deletion is applied to active service records and should be preserved during a recovery. Keeping a record for audit purposes does not make every retention period legally appropriate in every jurisdiction.
Your choices and questions
You can edit your profile, export account information, delete your account, request deletion through the web deletion page, and control device permissions. Guests should contact the host or property manager who invited them about information in a stay or inspection record. Depending on applicable law, additional rights may apply to access, correction, erasure, restriction, or complaints to a relevant authority. The Legal Portal explains the available self-service controls and the limits of inspection records.