Privacy Policy
Last updated 13 August 2026
This Privacy Policy explains how Al Wafaa Group ("Stay71 Manage", "we", "us", "our") collects, uses, and protects personal data in connection with Stay71 Manage (the "Service"). It applies to Operator staff who use the Service directly, and describes how tenant personal data entered into the Service by Operators is handled.
This policy is written with the United Arab Emirates' Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") in mind. Where an Operator enters tenant personal data into the Service, the Operator is the data controller for that data and we act as a data processor on the Operator's instructions — see our Data Processing Addendum for how that relationship works.
1. Data we collect
We collect and process the following categories of personal data through the Service:
- Operator staff data — full name, email, phone number, role, and the buildings a staff member is scoped to, collected when an organisation is set up or a staff member is added.
- Tenant data entered by Operators — full name, phone number, email, nationality, Emirates ID or passport number, employer, visa expiry date, and documents (such as ID or contract scans) an Operator's staff choose to upload for their own tenants.
- Financial and tenancy records — rent amounts, payment and cheque details, ledger entries, bank transaction references, and expense records, entered by Operators to manage their own accounts. We do not collect bank card numbers; payments recorded in the Service are logged as records of transactions that occurred elsewhere (bank transfer, cheque, cash).
- Usage data — standard technical data such as login timestamps and an authentication session cookie, needed to keep staff securely signed in.
2. Why we process this data
- To provide the Service — creating and maintaining organisation, tenancy, and financial records the Operator asks us to store.
- To generate documents an Operator requests, such as rent receipts and tenancy agreements.
- To maintain the audit trail the Service is built around — records are soft-deleted rather than erased, so occupancy and payment history remains available for compliance and dispute resolution.
- To operate, secure, and improve the Service, including detecting and preventing misuse.
- To communicate with Operator staff about their account, including service notices and, where consented to, product updates.
- To comply with our own legal obligations.
3. How data is kept separate and secure
The Service is built so that one Operator's data is never visible to another. Every record is tagged to a single organisation, and access is enforced at the database level — a member of staff can only query the rows their role and organisation permit, not merely the rows the application interface happens to show them. Data is encrypted in transit (HTTPS) and at rest by our infrastructure providers. Access within an Operator's own organisation is limited by role, so for example a supervisor cannot see financial data a super admin can.
4. Who we share data with
We do not sell personal data. We share it only with the infrastructure providers that host the Service on our behalf (currently Supabase for database and authentication, and Vercel for application hosting), under their own data protection commitments, and — if and when an Operator enables an optional feature such as WhatsApp or email reminders in the future — with the messaging provider needed to deliver that feature. We may also disclose data where required by law, court order, or to protect the rights, safety, or property of Stay71 Manage, an Operator, or others.
5. International transfers
Our infrastructure providers may process data on servers located outside the UAE. Where that happens, we require providers to maintain security and confidentiality commitments consistent with the standards this policy describes.
6. Data retention
Consistent with how the Service is built, records are not permanently deleted when an Operator removes a tenant, tenancy, or transaction — they are marked as deleted and excluded from normal views, but retained for audit, compliance, and dispute-resolution purposes. An Operator who closes their account can request export of their data; after a reasonable period, data is retained only as required for legal or audit purposes, or deleted, in each case consistent with applicable law.
7. Rights of data subjects
Individuals whose personal data is held in the Service — whether staff or tenants — may have rights under the PDPL and other applicable law to access, correct, or request deletion of their data, or to object to certain processing. Tenants should raise these requests with the Operator who manages their tenancy, since the Operator controls that data; the Operator may contact us for assistance in fulfilling the request. Operator staff can contact us directly using the details below.
8. Cookies
The Service uses a single essential cookie to keep a signed-in session active. We do not use advertising or third-party tracking cookies.
9. Children
The Service is intended for use by business staff and is not directed at children. Tenant records may relate to any individual an Operator lawfully houses, including minors as part of a family tenancy, but such data is entered and controlled by the Operator, not provided by the minor directly to us.
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified in the same way as changes to our Terms of Service.
11. Contact
For privacy questions or requests, contact hello@stay71.com, or write to Al Wafaa Group, Mezzanine Floor, Atrium Building, 28th Street, Abu Hail, Deira, Dubai, UAE.