Estayo

Privacy Policy

Last updated: 19 March 2026

1. Overview

Estayo ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, and protect your personal information when you use our platform.

2. Information We Collect

Information you provide:

  • Account information — name, email address, password, phone number, profile photo, university.
  • Listing information — property details, photos, pricing, location, amenities.
  • Community content — posts, comments, votes.
  • Messages — direct messages between users on the platform.
  • Booking information — dates, pricing, check-in/out details.

Information collected automatically:

  • Device type, browser, and operating system.
  • IP address and approximate location.
  • Pages visited and actions taken on the Platform.
  • Cookies and similar tracking technologies.

3. How We Use Your Information

  • To create and manage your account.
  • To display listings and facilitate bookings.
  • To enable messaging between hosts and guests.
  • To operate community features (posts, comments, voting).
  • To send notifications about bookings, messages, and account activity.
  • To improve the Platform and user experience.
  • To detect and prevent fraud or misuse.
  • To comply with legal obligations.

4. Information Sharing

We do not sell your personal information. We may share information with:

  • Other users — your public profile, listings, and community posts are visible to other users.
  • Service providers — hosting (Vercel), database (Neon), image storage (Cloudinary), and analytics tools that help us operate the Platform.
  • Legal authorities — when required by law or to protect the safety of our users.

5. Data Storage & Security

  • Your data is stored securely using encrypted connections (SSL/TLS).
  • Passwords are hashed using bcrypt — we never store plain-text passwords.
  • Our database is hosted on Neon (PostgreSQL) in the Sydney, Australia region (ap-southeast-2).
  • Images are stored on Cloudinary with secure URLs.

6. Your Rights

Under Australian Privacy Law (Privacy Act 1988), you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — request correction of inaccurate information.
  • Deletion — request deletion of your account and associated data.
  • Portability — request your data in a machine-readable format.

To exercise these rights, contact us at admin@estayo.com.au.

7. Cookies

We use essential cookies for authentication (session tokens). We do not use third-party advertising cookies. You can disable cookies in your browser settings, but this may affect Platform functionality.

8. Third-Party Links

The Platform may contain links to external websites (e.g., Facebook groups). We are not responsible for the privacy practices of these external sites.

9. Children

Estayo is not intended for users under 18 years of age. We do not knowingly collect information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of significant changes via email or a notice on the Platform.

11. Contact

For privacy-related enquiries, contact us at admin@estayo.com.au.