Legal
Privacy Policy
Last updated June 18, 2026
How StayPrimePH handles account, listing, booking, payment, messaging, security, and privacy-rights data.
Information we collect
StayPrimePH collects account data such as name, email address, role, phone number when provided, password hash, email verification status, session records, and one-time token records for email verification, email change, password reset, admin MFA, and account deletion verification.
The platform collects marketplace data such as listing details, property location fields, pricing, amenities, rules, availability, booking packages, uploaded listing images, wishlists, bookings, reviews, guest-host messages, support conversations, safety reports, disputes, cancellations, host reports, and host expenses.
Payment and payout data includes booking amounts, payment method labels, payment status, provider or manual transaction references, refund and rejection records, platform ledger records, payout settings, tax settings, and protected payout or tax identifiers. StayPrimePH does not intentionally store full card numbers, bank login credentials, or raw tax and payout identifiers when tokenization or encryption is available.
Security and compliance data includes trusted-origin checks, CSRF validation results, rate-limit state, login failure audit records with hashed email and IP values, password reset events, email change events, role change events, admin listing decisions, payment decisions, account anonymization records, and immutable audit logs for compliance-critical actions.
If users sign in with Google or Facebook, StayPrimePH may receive basic profile information made available by that provider, such as name, email address, provider account identifier, and profile image, depending on the permissions approved by the user.
Host listing drafts and preferences may be stored temporarily in the user's browser while the host creates a listing. Users should avoid entering unnecessary sensitive details into drafts and should sign out on shared devices.
How information is used
StayPrimePH uses personal data to create and secure accounts, verify email addresses, support password reset and admin MFA, maintain sessions, route users by role, and revoke sessions after sensitive account changes.
Marketplace data is used to publish and review listings, show search results, process bookings, manage host calendars and reports, support guest-host messaging, moderate support requests, investigate disputes, prevent double booking, and enforce platform rules.
Payment, payout, tax, and ledger data is used to support checkout, manual or provider-confirmed payment review, refunds, cancellations, payout settings, tax workflows, accounting, fraud prevention, and dispute resolution.
Security and audit data is used to detect abuse, throttle risky activity, investigate account takeover attempts, prove admin and payment decisions, preserve compliance evidence, debug incidents, and protect users and the platform.
StayPrimePH may use contact details to send account notices, email verification links, password reset links, admin MFA codes, booking updates, payment updates, support replies, safety notices, privacy request updates, and legal or compliance notices.
Service providers and data sharing
StayPrimePH shares personal data only when needed to operate hosting, database, storage, email, authentication, payment, fraud-prevention, support, analytics, error-monitoring, rate-limiting, security, backup, legal, accounting, or compliance workflows.
Current or planned operational providers may include Vercel, Supabase, Cloudinary or other media storage, PayMongo or other payment providers, Resend or other email providers, Upstash Redis, Sentry, Google, Facebook/Meta, GitHub, and related infrastructure providers.
Hosts and guests may receive booking, listing, message, profile, and payment-status information that is necessary to complete a booking, host a stay, resolve a support issue, or enforce marketplace rules.
Admins and authorized support personnel may access account, listing, booking, message, support, payment-reference, and audit data when needed for moderation, support, fraud prevention, dispute handling, payment review, privacy request handling, or legal compliance.
Some providers and recipients may process data outside the Philippines. StayPrimePH uses reasonable operational, contractual, and security safeguards for personal data handled by service providers.
Retention and deletion
StayPrimePH applies retention rules designed around the actual system: ordinary messages may be retained for up to 730 days, support messages for up to 365 days, closed support reports for up to 1,095 days, admin logs for up to 365 days, ordinary audit logs for up to 2,555 days, and unpublished listing drafts for up to 30 days.
Immutable audit logs for listing approval or rejection, payment approval, payment rejection, payment refund, and verified account anonymization are preserved as compliance evidence and are not deleted by ordinary retention pruning.
Booking, payment, payout, tax, ledger, refund, cancellation, safety, fraud-prevention, dispute, accounting, and legal records may be retained longer when needed for operational integrity, legal obligations, tax or accounting requirements, chargeback defense, abuse prevention, or user protection.
When an account deletion request is verified and approved, StayPrimePH may anonymize profile data, remove login material, revoke sessions, mark related hosted listings as rejected where applicable, and retain only records that are reasonably needed for security, accounting, compliance, dispute, or legal reasons.
Backups and provider logs may retain copies for a limited period according to backup rotation, security, and provider operations. Records subject to a legal hold, open dispute, payment review, fraud investigation, or safety incident may be retained until the issue is resolved.
Your privacy choices
Users may access or correct many account details in account settings. Changing a login email requires password reauthentication and verification of the new email address before the login email is replaced.
Users may request a machine-readable export of account data from privacy settings after email verification. Export requests are recorded in account privacy settings.
Users may request account deletion from privacy settings after email verification. Deletion requests require one-time email verification before admin review or verified anonymization is completed.
Users may request help accessing, correcting, exporting, blocking, objecting to, or deleting personal data by using account privacy tools, contacting support, or emailing privacy@stayprimeph.com.
Marketing preferences can be changed in account notification settings. Essential account, security, booking, payment, support, privacy, legal, and compliance notices may still be sent when needed to operate the service.
Users can remove a social-login connection through their Google or Facebook account settings, but should also contact StayPrimePH if they want platform account data reviewed for export, deletion, or anonymization.
Security and incidents
StayPrimePH uses safeguards such as HTTPS-only production access, secure HTTP-only session cookies, trusted-origin checks, CSRF protections, server-side authorization checks, email verification, admin MFA, host step-up authentication for payout-related settings, password hashing, session revocation after sensitive changes, rate limiting, and provider secret management.
Sensitive identifiers such as tax IDs and payout identifiers are minimized, encrypted, tokenized, or reduced to display-safe values where possible. Logs and error monitoring should scrub raw emails, tokens, passwords, tax IDs, payout identifiers, and other sensitive personal data.
Audit logs are used for accountability. Compliance-critical audit records are designed to be append-only so payment decisions, listing decisions, and verified account anonymization cannot be silently changed or deleted through normal application flows.
No internet service can guarantee perfect security, so users should protect login credentials, avoid sharing one-time links, reset emails, or admin MFA codes, keep devices secure, and report suspicious activity promptly.
If StayPrimePH identifies a personal data breach that requires notice, it will assess the incident, preserve relevant records, reduce harm where practical, and notify affected users and regulators when required by applicable law.
Cookies and local storage
StayPrimePH uses secure session cookies to keep users signed in and to protect authenticated requests. Session cookies should be HttpOnly, Secure in production, and SameSite=Lax.
The application avoids storing auth or session tokens in localStorage. Browser storage may be used for non-token preferences or temporary host listing drafts, and draft data should be cleared after publish or logout where practical.
Users can clear browser storage through their browser settings, but doing so may remove draft progress or local preferences.
Operator and contact details
StayPrimePH is operated by Livewise Construction, trading as stayprimeph, in the Philippines.
Business address: 2nd Floor block 1 lot 5 Congressional Road Rainbow Subdivision Bagungbong Caloocan, Caloocan, Philippines, 1421.
Support email: support@stayprimeph.com. Privacy and data requests: privacy@stayprimeph.com. Phone: 0956 673 9577.