← All legal documents

Draft — not yet finalized. This document still contains unresolved placeholder text and has not been approved for publication: [EFFECTIVE DATE], [confirm], [8 years], [period required by KYC/AML rules], [period], [indefinitely, minimal].

Data Retention Policy — 8055 Stays

Operated by HASU AURORA PRIVATE LIMITED

Effective date: [EFFECTIVE DATE] · Last updated: 18 August 2026


1. Purpose and principles

This Policy sets how long HASU AURORA PRIVATE LIMITED retains personal and business data on the 8055 Stays Platform, and how we delete or anonymise it. It implements the DPDP Act principle of storage limitation: we keep personal data only for as long as necessary to fulfil the purpose it was collected for, or as required by law, after which we delete or irreversibly anonymise it.

We apply:


2. Where data lives (for context)

Store Contents Location
Neon PostgreSQL (Core) Profiles, workspaces, listings, reservations, messages, reviews, media metadata Singapore
Auth store (Cloudflare D1, Better Auth) Credentials (hashed), sessions, OAuth tokens (encrypted), MFA secrets, IP/user-agent Cloudflare edge
Cloudflare R2 / Images Message attachments, listing media Cloudflare edge
Upstash / Redis Ephemeral cache, rate-limit counters [confirm]
PostHog Consent-gated analytics events United States

3. Retention schedule

"Active" in the table below means while your account/booking relationship is ongoing.

Data category Retention period Basis / reason
Account & profile (name, email, phone, display name, profile photo, preferences) Identifying profile/contact data removed when terminal deletion starts after the 30-day cancellation period No longer needed after the cancellable window
Authentication credentials (hashed password, MFA secrets, backup codes) Deleted when terminal deletion starts No longer needed once deletion is terminal
Sessions & auth network data (session tokens, approximate network/device metadata) Sessions revoked immediately; minimised security metadata retained up to 90 days Security and abuse prevention
OAuth tokens (Google/Apple) Until you disconnect the provider or close the account Needed only while social login active
Reservations & booking records (itinerary, traveler snapshot, special requests, status) [8 years] from the end of the financial year of the stay Tax/accounting & contractual/limitation-period reasons
Financial & invoicing records (invoices, transaction records, payout records) (applies once payments live) [8 years] (align with Income-tax/Companies Act record-keeping) Statutory tax & accounting retention
KYC / verification status (Host onboarding: last-4 tax ID, KYC/banking status) Active + [period required by KYC/AML rules] after relationship ends Legal/regulatory verification obligations
Guest–Host messages & attachments 2 years after the related booking, subject to a legal/safety hold Support, safety, and dispute resolution
Reviews & ratings (public body, private feedback, responses) Retained while the listing/marketplace is active; may be anonymised on account closure rather than deleted Integrity of public marketplace reviews
Listings & property media While listing is active + [period] after de-listing Operate the marketplace; restore/audit
Support tickets, disputes, safety reports 5 years after closure Handle recurrence, disputes, and legal claims
Audit & compliance logs (admin actions, moderation, permission changes, lifecycle evidence) 7 years Security, compliance, and evidence
Analytics events (PostHog) Up to 12 months; deletion requests remove the person keyed by internal user ID Product improvement; minimised
Diagnostic / error data Up to 90 days Stability; sanitised, no credentials or message bodies
Account export archives 7 days, then encrypted object, wrapped key and grants are removed Short-lived fulfilment of an access request
Marketing consent & suppression records Until consent withdrawn + a suppression record kept [indefinitely, minimal] Honour opt-outs
Cache & rate-limit counters Ephemeral (minutes–days) Performance; transient
Backups Rolling backups retained up to 35 days, then overwritten Disaster recovery

4. Deletion, anonymisation, and backups


5. Legal holds and exceptions

We may retain specific data beyond the periods above where necessary to:

When the reason for a hold ends, the data returns to the normal schedule.


6. Review

This Policy is reviewed at least annually and whenever we add a data category, store, or subprocessor. Data-category rows must be kept consistent with the Privacy Policy.

Contact: support@hasuaurora.com · Grievance Officer: Sukshith GM, support@hasuaurora.com.