[EFFECTIVE DATE], [confirm], [8 years], [period required by KYC/AML rules], [period], [indefinitely, minimal].
Operated by HASU AURORA PRIVATE LIMITED
Effective date: [EFFECTIVE DATE] · Last updated: 18 August 2026
This Policy sets how long HASU AURORA PRIVATE LIMITED retains personal and business data on the 8055 Stays Platform, and how we delete or anonymise it. It implements the DPDP Act principle of storage limitation: we keep personal data only for as long as necessary to fulfil the purpose it was collected for, or as required by law, after which we delete or irreversibly anonymise it.
We apply:
| Store | Contents | Location |
|---|---|---|
| Neon PostgreSQL (Core) | Profiles, workspaces, listings, reservations, messages, reviews, media metadata | Singapore |
| Auth store (Cloudflare D1, Better Auth) | Credentials (hashed), sessions, OAuth tokens (encrypted), MFA secrets, IP/user-agent | Cloudflare edge |
| Cloudflare R2 / Images | Message attachments, listing media | Cloudflare edge |
| Upstash / Redis | Ephemeral cache, rate-limit counters | [confirm] |
| PostHog | Consent-gated analytics events | United States |
"Active" in the table below means while your account/booking relationship is ongoing.
| Data category | Retention period | Basis / reason |
|---|---|---|
| Account & profile (name, email, phone, display name, profile photo, preferences) | Identifying profile/contact data removed when terminal deletion starts after the 30-day cancellation period | No longer needed after the cancellable window |
| Authentication credentials (hashed password, MFA secrets, backup codes) | Deleted when terminal deletion starts | No longer needed once deletion is terminal |
| Sessions & auth network data (session tokens, approximate network/device metadata) | Sessions revoked immediately; minimised security metadata retained up to 90 days | Security and abuse prevention |
| OAuth tokens (Google/Apple) | Until you disconnect the provider or close the account | Needed only while social login active |
| Reservations & booking records (itinerary, traveler snapshot, special requests, status) | [8 years] from the end of the financial year of the stay | Tax/accounting & contractual/limitation-period reasons |
| Financial & invoicing records (invoices, transaction records, payout records) (applies once payments live) | [8 years] (align with Income-tax/Companies Act record-keeping) | Statutory tax & accounting retention |
| KYC / verification status (Host onboarding: last-4 tax ID, KYC/banking status) | Active + [period required by KYC/AML rules] after relationship ends | Legal/regulatory verification obligations |
| Guest–Host messages & attachments | 2 years after the related booking, subject to a legal/safety hold | Support, safety, and dispute resolution |
| Reviews & ratings (public body, private feedback, responses) | Retained while the listing/marketplace is active; may be anonymised on account closure rather than deleted | Integrity of public marketplace reviews |
| Listings & property media | While listing is active + [period] after de-listing | Operate the marketplace; restore/audit |
| Support tickets, disputes, safety reports | 5 years after closure | Handle recurrence, disputes, and legal claims |
| Audit & compliance logs (admin actions, moderation, permission changes, lifecycle evidence) | 7 years | Security, compliance, and evidence |
| Analytics events (PostHog) | Up to 12 months; deletion requests remove the person keyed by internal user ID | Product improvement; minimised |
| Diagnostic / error data | Up to 90 days | Stability; sanitised, no credentials or message bodies |
| Account export archives | 7 days, then encrypted object, wrapped key and grants are removed | Short-lived fulfilment of an access request |
| Marketing consent & suppression records | Until consent withdrawn + a suppression record kept [indefinitely, minimal] | Honour opt-outs |
| Cache & rate-limit counters | Ephemeral (minutes–days) | Performance; transient |
| Backups | Rolling backups retained up to 35 days, then overwritten | Disaster recovery |
We may retain specific data beyond the periods above where necessary to:
When the reason for a hold ends, the data returns to the normal schedule.
This Policy is reviewed at least annually and whenever we add a data category, store, or subprocessor. Data-category rows must be kept consistent with the Privacy Policy.
Contact: support@hasuaurora.com · Grievance Officer: Sukshith GM, support@hasuaurora.com.