Privacy policy
Staywally is a product of Nammastack. This policy explains what Nammastack, the company that operates Staywally, collects, why, and what you and your guests can ask us to do about it. It covers the guest portal, the staff and admin consoles, and our marketing site. In this policy “Staywally”, “we”, “us” and “our” mean Nammastack.
01Who is responsible for what
When a hotel uses Staywally, the hotel is the data fiduciary for its guests’ information and we are the data processor acting on its instructions. For our own marketing site and for hotel staff accounts, we are the fiduciary.
This means a guest’s request to see or delete their data is normally answered by the hotel. We will help the hotel answer it, and we will act directly if the hotel no longer exists.
02What we collect about guests
A guest session holds the room number, the stay dates, the language chosen, and whatever the guest types into a request, order or chat message. Where a PMS is connected, it also holds the guest’s name and, if the hotel has configured it, their contact details.
We do not ask guests for an account, a password, a date of birth or a government ID. We do not place advertising or analytics cookies in the guest portal.
03What we collect about staff
Name, work email, phone number, role, department and shift pattern, plus a log of actions taken in the console. Passwords are stored only as salted hashes.
04How long we keep it
Guest sessions, including chat, are deleted 30 days after checkout unless the hotel has chosen a longer window for dispute handling, capped at 12 months.
Operational records used for analytics are retained for the term of the hotel’s plan and deleted within 30 days of cancellation. Invoices are retained for eight years as Indian tax law requires.
05Where it lives
All production data is stored in AWS ap-south-1 (Mumbai). Backups remain in the same region. Enterprise customers may request a different region.
A small number of sub-processors receive limited data to deliver specific features — payments, SMS and WhatsApp delivery, translation, and error reporting. The current list is published in the Trust Center and we give 30 days’ notice before adding one.
06Who can see it
Hotel staff see only their own property, and within it only what their role allows. Our own team cannot enter a hotel’s console without recording a reason; that access defaults to read-only, expires after 30 minutes, and is written to the hotel’s audit log where the hotel can see it.
07Your rights
Under the Digital Personal Data Protection Act 2023 you may ask for access to your data, correction of it, erasure, and information about who it has been shared with. Write to privacy@staywally.com and we will respond within 30 days.
If you are unhappy with our response you may complain to the Data Protection Board of India.
08Changes to this policy
We will email the account owner of every hotel at least 30 days before a material change takes effect, and note the change at the top of this page.