StayCore
Privacy Policy
Last updated: 10 July 2026
This policy explains what data StayCore processes when a hotel uses our software to run its operations, and when a guest interacts with that hotel through StayCore.
1. Who we are
StayCore is a hotel management system built and operated by Connate Coders (“we”, “us”, “our”). Hotels and their branches (“Hotel”, “you”, “your business”) use StayCore to run front-desk, billing, housekeeping, restaurant, staff and guest-facing operations.
For the personal data of hotel guests processed through StayCore, the Hotel is the data controller and Connate Coders acts as the data processor, operating the software on the Hotel’s instructions. For data about the Hotel’s own account (owner/staff logins, billing with us), Connate Coders is the controller.
2. What we process
On behalf of a Hotel, StayCore stores and processes:
- Guest booking details: name, contact number, email, stay dates, room and rate information
- Government ID documents collected for check-in (e.g. Aadhaar, passport) — stored as private files accessible only via short-lived signed URLs, never public links
- Stay, folio and payment records: charges, invoices, GST details, payment status and Razorpay transaction references
- Guest communications sent through the platform, including WhatsApp messages where a Hotel has enabled that channel
- Hotel staff accounts: name, email/phone, role, and activity relevant to audit logging
3. How it is used
Data is used strictly to deliver the hotel management service the Hotel has subscribed to:
- Creating and managing bookings, check-in/check-out, and room assignment
- Generating folios, GST invoices, and reconciling payments
- Sending booking confirmations, stay-related updates, and authentication messages to guests
- Housekeeping, restaurant, and staff-operations workflows within the Hotel
- Security, fraud prevention, audit logging, and support to the Hotel
4. Third-party processors
We rely on a small number of specialist processors to run StayCore. We do not sell data to anyone, and these processors only receive what is necessary to perform their function:
- Razorpay — payment processing for guest and subscription payments
- Supabase — database, authentication, and file storage hosting (including signed-URL document access)
- Meta / WhatsApp Business Platform — guest messaging, only for Hotels that have enabled WhatsApp communication
- Transactional email delivery providers — booking confirmations and account notifications
5. WhatsApp / Meta messaging
Where a Hotel enables WhatsApp messaging, StayCore sends business-initiated utility and authentication messages (for example, booking confirmations, check-in reminders, or OTP-style verification) through the WhatsApp Business Platform.
A guest who no longer wishes to receive WhatsApp messages can opt out through WhatsApp itself, or by asking the Hotel or Connate Coders directly; opt-outs are honored.
6. Data retention
Data is retained for as long as the Hotel’s StayCore account is active, and for the periods required under Indian law — including hospitality record-keeping (e.g. guest register requirements) and tax/GST record retention rules. When a Hotel closes its account, data is retained only as long as legally required and then deleted or anonymized.
7. Security
Secrets and credentials are encrypted; guest identity documents are never exposed via public URLs and are only accessible through short-lived signed links. Sensitive actions are recorded in immutable audit logs. Each Hotel’s data is isolated from every other Hotel’s data at the application and database level.
8. Your rights
Depending on applicable law (including India’s Digital Personal Data Protection Act), you may have rights to access, correct, or request deletion of your personal data. Guests should first contact the Hotel they stayed with, as the Hotel controls that data; the Hotel may in turn route the request to us. You can also write to us directly (see Contact below) and we will support the Hotel in actioning a valid request. See our Data Deletion page for the concrete process.
9. Children
StayCore is not directed at children, and we do not knowingly collect data from children independent of a lawful guest stay booked by an adult.
10. International transfers & India (DPDP)
StayCore primarily serves hotels operating in India and stores data with providers offering region-appropriate hosting. Where data is processed by a service provider outside India, we expect that provider to maintain safeguards consistent with India’s Digital Personal Data Protection Act, 2023 and applicable rules.
11. Contact
Questions about this policy, or a request relating to your data, can be sent to team@connatecoders.com or by phone at +91-6388835366.