Privacy policy
What HostelSathi collects, why, where it is stored and how to get it back. This covers both the marketing site and the application.
Last updated
Who controls the data
A hostel using HostelSathi is the controller of its residents' records: it decides what to collect and why. HostelSathi is the processor, acting on that hostel's instructions.
If you are a student and want your record corrected or removed, ask your hostel first — they hold it and can act on it directly.
What we collect
Three categories, and nothing beyond what the product needs to work:
- Account data — name, email address and a hashed password for anyone who signs in. Passwords are hashed with bcrypt and are never stored or logged in readable form.
- Operational data your hostel enters — student records, room and bed allocations, fee ledgers and payments, attendance, leave requests, complaints, notices, and documents uploaded against a student.
- Technical data — sign-in attempts, and audit records of sensitive changes, kept so that a compromised account or a disputed payment can actually be investigated. Audit entries are append-only and redact secrets.
What we do not do
We do not sell your data, share it with advertisers, or use one hostel's records to train anything. There is no advertising or third-party analytics tracking in the application.
Who else processes it
We rely on a small number of infrastructure providers, each doing one job:
- A managed PostgreSQL database, which holds the operational records.
- Resend, which delivers transactional email — verification links, password resets and notifications.
- Object storage — Amazon S3, Cloudflare R2 or Cloudinary depending on the deployment — for uploaded documents and images.
- Vercel, which hosts and serves the application.
How long we keep it
Operational records are kept while your subscription is active, and for 30 days after it ends so you can still export them. Nothing is deleted without an explicit request from you.
Some things expire sooner on their own: a nightly job clears expired verification and password-reset tokens, stale sign-in attempt records, and uploads that were begun but never attached to a record.
Getting your data out, or deleted
Every list in the application exports to CSV, and receipts and statements export to PDF — at any time, without asking us. For a full export or a deletion request, email us and we will confirm within one working day.
Cookies
HostelSathi sets one cookie: the session cookie that keeps you signed in. It is not used for tracking, and there are no advertising or analytics cookies — which is why you are not asked to consent to any.
Changes and contact
If this policy changes materially we will update the date at the top of this page and notify account owners by email. Questions go to hostelsathii@gmail.com.
