Privacy Policy
Effective 6 September 2026
This Privacy Policy explains what personal data genXstay (operated by genXarc, "we", "us", "our") collects through the platform, why we collect it, who we share it with, and the choices available to property owners, their staff, and guests/tenants. It should be read alongside our Terms of Service.
1. Data we collect
Account data. Name, email, phone number, password (stored hashed, never in plain text), and role (owner, manager, delegate, guest, admin).
Owner verification (KYC) data. PAN and supporting documents submitted for identity verification, and the resulting verification status.
Property and tenancy data. Property address and details, room/bed configuration, guest name, contact details, ID-proof documents, move-in/move-out dates, rent and deposit amounts, ledger and payment-status history, other charges, maintenance requests, and food/meal preferences, entered by an owner/staff or, for self-service intake, submitted directly by a prospective guest via a QR-code link.
Financial records. Rent, deposit, and other-charge ledger entries, payment method and dates (payments themselves are collected by the owner directly — cash, UPI, bank transfer — genXstay records the transaction, it does not process the payment between owner and guest), GSTIN and GST settings an owner configures, and subscription billing/invoice records for the owner's own platform fees.
Uploaded files. ID-proof photos, expense receipts, and property documents/photos uploaded to the platform.
Usage and device data. Login sessions, IP address (used for rate limiting and abuse prevention), and basic device/browser information.
2. How we use this data
- To provide the core service: property, room/bed, guest, rent, deposit, expense, and maintenance management.
- To generate rent receipts, deposit receipts, and annual statements for guests.
- To verify owner identity (KYC) and reduce fraudulent accounts and listings.
- To process platform subscription billing and, where used, AI-credit purchases.
- To send transactional emails — OTP codes, password resets, staff invites, billing/trial notices, ownership-transfer and co-owner invites.
- To detect and prevent abuse, including rate-limiting logins, uploads, and API requests.
- To power optional AI-assisted receipt scanning, where an owner chooses to use it.
- To display public property listings and vacancy information an owner has chosen to publish.
We do not sell personal data, and we do not use guest or owner data for third-party advertising.
3. Who we share data with
Data is shared only as needed to run the service:
- Razorpay — processes owner subscription payments and AI-credit purchases.
- Setu — verifies owner PAN/KYC submissions where automated verification is configured.
- Resend — delivers transactional emails (OTP, password reset, invites, notifications).
- AI providers (Anthropic, Google, or Moonshot AI, depending on configuration) — process a photographed receipt image to extract expense details, only when an owner actively uses the "Scan receipt" feature. Receipt images sent for this purpose are used only to return the extracted data.
- The property owner and their authorized staff (managers/delegates) can see guest data relevant to the property/module they manage — this is inherent to how a tenancy is administered.
We do not share personal data with other third parties for their own marketing purposes, and we disclose data to law enforcement or regulators only where legally required.
4. Data retention
Account and tenancy data is retained for as long as the account is active. If a guest record is deleted by an owner in error or otherwise, a full snapshot is retained internally for recovery purposes, separate from the live guest list. Financial ledger records (rent, deposit, GST-relevant data) are retained for the period needed to satisfy applicable tax and accounting recordkeeping requirements, even after a tenancy ends.
When an owner account is closed, we retain the minimum data necessary for legal, billing-dispute, and fraud-prevention purposes, and otherwise work to remove or anonymize personal data within a reasonable period.
5. Security
Passwords are stored hashed, never in plain text. Sensitive actions (password reset, OTP, impersonation tokens) use short-lived, single-use tokens. Database access is protected by role-based application checks and PostgreSQL row-level security keyed to each record's owner, as defense-in-depth beyond the application layer. Uploaded files are validated by content rather than by their claimed file type before being stored. No method of transmission or storage is completely secure, but we apply industry-standard practices to protect the data you share with us.
6. Cookies and local storage
genXstay uses essential session cookies to keep you signed in and to protect against cross-site request forgery — these are required for the platform to function and are not used for advertising or third-party tracking. If you install genXstay as a Progressive Web App, your device may cache app assets locally to allow offline access to previously loaded pages.
7. Your rights and choices
- You can review and correct your account details from your Settings page at any time.
- An owner can request deletion of a guest record they manage (subject to the retention note above).
- You may request a copy of, or the deletion of, your personal data by contacting us at the email below — for a guest, we may need to confirm the request with the property owner where the data forms part of an active tenancy's financial/legal record.
- You can decline optional features (AI receipt scanning, public listing publication) without affecting core account access.
8. Children
genXstay is intended for use by adults managing or renting property, and is not directed at children.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above, and where reasonably practical, we'll notify account holders by email.
10. Contact
Questions about this Privacy Policy, or requests regarding your personal data, can be sent to support@genxarc.com.