StayGap

Privacy policy

Effective 29 September 2026

Staygap helps an accommodation operator offer an extra night, a gap night, early check-in, or late checkout on a reservation the operator already holds. The Meta app that connects WhatsApp is named Stylabs. This policy explains what Staygap collects, why it is used, who receives it, and how to ask for deletion. It covers the operator app, guest offer pages, and the WhatsApp connection made through Meta.

This page describes the service as it works today. A guest should also read the accommodation operator's own privacy notice.

Who we are

Staygap is a service operated by Stylabs Technologies Private Limited (CIN U72200MH2015PTC262130), the company behind stylabs.in. Its registered office is Deserve Group, next to Buddha Kapil Vastu, opposite University Premises, CST Road Junction, Kalina, Santacruz East, Mumbai, Maharashtra 400098, India. The Meta app is named Stylabs. This operator app, and this policy, are published at staylabs.webthehook.site.

Privacy and deletion requests go to staygap@stylabs.com. Staygap has not appointed a data protection officer or an EU representative.

Our role and the operator's role

For an operator account, sign-in, and running the service, Staygap decides why that account information is used.

When an operator connects a property system or a WhatsApp Business account, Staygap handles that operator's guest information so the operator can prepare an offer. The operator decides which guests are offered an extra night or a change to arrival or departure, and the operator is responsible for its own privacy notice and for permission to contact those guests.

If you are a guest, contact the operator about the reservation. You can also email Staygap. Where the operator controls the record, Staygap will pass your request to that operator.

Information we handle

Business accounts

Name, email address, a hash of the password, the organization name, and the person's role. The person supplies this when they register or when they are invited.

Reservations and guests

From the operator or a connected property system such as Hostaway: guest name, guest email, stay dates, property, booking status, channel, and price. The stored property-system record keeps phone fields and party-size counts, including a count of children when that system sent a number. It does not keep the rest of that payload, such as an address, a document, notes, or a child's name. A row imported before this limit can still hold the older record until the next sync replaces it. A conversation import keeps the conversation id, the listing id, the reservation id, and the participant name. It does not keep the message thread.

Offers and payments

The kind of offer (extra night, gap night, early check-in, or late checkout), the price, and whether the guest paid. Prices are calculated from the reservation dates, empty nights, and the operator's prices and rules. When a guest pays, Staygap stores the amount, currency, and payment status returned by Stripe or Razorpay. The card is entered on the payment provider's page. Staygap does not receive or store the full card number.

Technical information

The server may record the IP address, time, and path of a request so the service can run and be protected. Staygap does not use an analytics or advertising product.

Do not send an identity document, a full payment card number, or a bank account number through an offer or a message. Staygap does not ask for them.

Why we use it

  • To create and protect an operator account, and to show that organization's properties and stays.
  • To read reservations and empty nights and prepare an offer the operator can send.
  • To show a guest offer page and record whether it was paid.
  • To create WhatsApp templates on the account the operator connected, and to send a template the operator chooses.
  • To show delivery status for those WhatsApp messages.
  • To investigate abuse and fix failures.

Staygap does not sell personal information. Staygap does not use an operator's guest list to advertise Staygap, or any other business, to those guests. Staygap does not send personal information to an AI service. Offer prices are calculated by the rules above, not by a model.

Staygap uses an operator's account information to perform the service that operator signed up for: creating the account, signing the person in, and showing that organization's properties and stays. Staygap uses technical logs to protect the service and to investigate abuse. Guest reservation and messaging information is handled on the operator's instructions so the operator can prepare and send an offer. The operator decides the basis for contacting the guest. Staygap does not use that guest information to market Staygap.

WhatsApp and other Meta information

Connect WhatsApp opens Meta's Embedded Signup. The operator signs in with Facebook and chooses the WhatsApp Business account to connect. Staygap receives a short-lived code and exchanges it for a business access token issued by Meta. Staygap encrypts that token and uses it only for the connected account. When Meta requires a registration PIN for a new Cloud API number, Staygap encrypts that PIN with the token.

Staygap asks only for these two permissions:

whatsapp_business_management

Staygap uses this permission to read the WhatsApp Business account id, phone number, and display name, to create the operator's standard message templates on that account, and to subscribe the account to webhooks. For example, after a successful connect Staygap creates a stay-update template and stores the template name, language, category, text, and Meta's review status (pending, approved, or rejected).

whatsapp_business_messaging

Staygap uses this permission to send an approved template from the operator's own WhatsApp number to a guest number the operator chooses, and to receive delivery updates from Meta. For example, when the operator sends an arrival reminder, Staygap stores the WhatsApp message id, direction, message type, time, delivery status (sent, delivered, read, or failed), the other person's WhatsApp id, and whether Meta marked the message billable.

The message text is not stored. The contact address book is not stored.

Meta may keep the message on WhatsApp's systems under Meta's own Cloud API rules, including a limited retention period Meta publishes for that service. That copy is Meta's. Staygap does not keep one, and Staygap does not turn on Meta's optional AI reply features.

If the number also stays on the WhatsApp Business app, Staygap asks Meta to report sync progress. Staygap stores that progress. It does not store the contact list or the content of past chats.

Staygap does not request Facebook friends, posts, Pages, ad accounts, Instagram accounts, or catalogs. A share button that opens WhatsApp or Gmail on the operator's own device sends that message from their device. Staygap does not receive the text of that share. Staygap does not connect to Google. Staygap does not send guest messages through Hostaway unless that option is turned on for the installation. It is off by default.

Email and WhatsApp messages

The sending business is the accommodation operator, using the operator's own WhatsApp number or the operator's own mailbox. An offer can be an extra night, a gap night, early check-in, or late checkout.

On an opportunity, Send to guest opens WhatsApp or Gmail on the operator's device with a draft. The operator sends it. Staygap does not receive that message. From Integrations, the operator can send an approved template through WhatsApp's Cloud API. Staygap stores the template's wording and the delivery status described above. It does not store the sent message text.

WhatsApp allows a business to message someone outside a conversation that person started only if that person gave the business their mobile number and agreed to be contacted on WhatsApp. Staygap does not collect or store that agreement. The operator is responsible for it. A reservation, by itself, is not that agreement.

Staygap keeps a suppression list for each organization. The list stores a one-way hash of a phone number or an email address, not a second address book. An owner or admin can add a guest. A request to staygap@stylabs.com is added the same way after it is checked. A promotional WhatsApp template, and every offer share, checks that list and the reservation flag before anything is sent. A utility stay message, such as an arrival reminder, can still be sent. A later import from the property system does not clear a recorded opt-out. Staygap does not add an unsubscribe link. The guest can also block the business in WhatsApp. Staygap does not send its own marketing to guests. Staygap does receive WhatsApp delivery and read receipts, and it stores that status. It does not use an email open pixel or a link click tracker.

Who else receives it

  • People the operator allows into that organization.
  • Meta, because WhatsApp delivers the message, reviews templates, and hosts the connected business account. Meta handles that information under its own terms.
  • The property system the operator connected, such as Hostaway, as the source of listings and reservations. That provider also handles information under its own notice.
  • Stripe or Razorpay, to process a guest payment. They receive the amount and the payment result.
  • Cloudflare, which serves the public address of this site. The operator app, the API, and the PostgreSQL database for this deployment run on the computer that operates the service. Staygap has not placed that computer in a fixed cloud region.
  • A public authority when the law requires a disclosure.

One Staygap customer cannot see another customer's guests, tokens, or WhatsApp account. Staygap does not sell personal information and does not share it for advertising across other sites.

Meta, Hostaway, Stripe, and Razorpay process the information they receive in the places described in their own notices. When a person uses the service from another country, information is processed on the computer above and by those providers. Staygap has not put a standard contractual clause, or another published transfer tool, in place.

How long we keep it

While the organization account is open, Staygap keeps that account's operator, property, reservation, offer, template, and message-status records. Staygap has not set a shorter automatic expiry.

Disconnecting WhatsApp deletes that connection, the encrypted token and PIN, and the message-status rows for that number. It does not delete reservations already imported, and it does not delete the stored template records for that WhatsApp account. Those remain until the organization is deleted or you ask for deletion.

Payment records may be kept where tax or accounting law requires it. Staygap has not set a separate retention period for server logs. Logs are the output of the running process. They are not copied into a published archive. Staygap does not run a separate backup archive. Deleting an active row removes the copy Staygap controls.

Security

Business tokens and registration PINs are encrypted before they are stored. Each organization can access only its own records. The public site is served over HTTPS. No system can guarantee absolute security.

Delete your data

Anyone can ask Staygap to delete personal data we hold about them. This section is the deletion instructions for the Stylabs app. Staygap does not yet receive Meta's automatic deletion callback, so an email to the address below is how a deletion request is handled.

Staygap replies to a complete request within 30 days. When that request is carried out, the active records it covers are deleted from the database Staygap controls. Staygap does not run a separate backup archive, so there is no second copy with its own expiry date. A record stays only when tax, accounting, or abuse prevention requires it, and the reply names what is kept and why. This is a review of the email. It is not an automatic deletion job.

Guest data

Email staygap@stylabs.com with the phone number or email that received the message or the offer. Staygap deletes the guest name, guest email, and stored phone fields it holds for that guest, the offer records for that stay, and the message-status rows whose WhatsApp id matches that phone. It also adds the guest to that organization's suppression list so a later promotional message is not sent. A guest request does not delete the operator's business token, the WhatsApp connection, the templates, or the organization.

User account

Email staygap@stylabs.com from the account email address and ask to delete that user. Staygap deletes that user account. It does not delete the organization, its reservations, or its WhatsApp connection unless an owner or admin also asks for that and the request names the organization.

Organization and WhatsApp connection

  1. Sign in, open Settings, then Integrations, and choose Disconnect on the WhatsApp number. That deletes that number's connection, the stored business token and PIN, and the message-status rows for that number. It does not delete the organization or its reservations.
  2. To delete the whole organization, an owner or admin emails staygap@stylabs.com from an account that belongs to that organization and names it. Staygap then deletes the organization. That removes its properties, reservations, offers, WhatsApp connection, encrypted token, templates, and message-status rows, except a payment record the law requires Staygap to keep.

Staygap does not treat a guest request, or a request from someone who is not an owner or admin of that organization, as authority to disconnect WhatsApp or delete the organization.

People who connected with Facebook

  1. On Facebook, open Settings and privacy, then Settings, then Apps and websites, and remove Stylabs. That stops that Facebook login from using Staygap.
  2. Also email staygap@stylabs.com with the Facebook account or the WhatsApp number you connected. Removing the app on Facebook does not, by itself, reach Staygap today, and it does not delete the operator's business token.

Cookies and similar technologies

The operator app keeps the sign-in in an httpOnly cookie named staygap_session. Page scripts cannot read it. The cookie is sent only to Staygap, with SameSite set to Lax. It lasts two hours by default and is renewed while the operator is using the app. It is used only to keep that person signed in. Staygap does not use analytics or advertising cookies, and it does not use a cookie to follow people across other sites.

Your choices

Email staygap@stylabs.com to ask for access, a correction, a copy, or deletion, or to object to a use. Staygap may ask you to show that you control the email or phone on the record. Staygap replies and says what was deleted, or what a law requires it to keep. A request about a reservation is handled with the operator that holds the booking. You can also complain to a data protection authority where the law gives you that right.

How offers are chosen

Staygap suggests an offer from the reservation dates, whether nearby nights are empty, and the prices and rules the operator set. It does not use an AI provider, and it does not send guest information to a model to make that decision. The operator chooses whether to send the offer.

Children

Staygap is for property operators. It is not directed at children under 13. A reservation may include a party-size count that includes children. A new import does not keep a child's name or contact details. A row imported before this limit is replaced on the next sync. If you believe a child's profile is still stored, email staygap@stylabs.com.

Changes

When this policy changes, Staygap updates the effective date at the top of this page.

Contact

Privacy and deletion requests: staygap@stylabs.com

Sign in