Privacy Policy — English
Effective Date: August 18, 2025
This Privacy Policy explains how HeloStays (“we”, “us”, or “our”) collects, uses, and protects your information when you use our mobile app and related services.
1. Information We Collect
We may collect the following types of personal data:
- Account Information: Email address, password, first and last name, phone number, country, and gender (used to comply with strict hospitality laws in Iraq related to the marital/status requirements for male and female guests staying in the same property).
- Identity Verification: Government-issued ID (such as passport, driver’s license, or national ID) and a recent profile photo, to verify that the person booking matches the identity document.
- Payment Information: Limited payment details necessary to process bookings via our payment partners. We do not store full card numbers on our own systems.
- Device Information: Device type, operating system (e.g., iOS or Android), and basic technical data needed to run the app and maintain security.
- Location Information: Approximate device location while the app is in use, to show nearby listings and relevant content. Location access is optional and controlled from your device settings.
- Profile Photo: Used during account creation and in some cases for identity verification and in-app display.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your HeloStays account.
- Verify your identity, including matching your photo to your government ID where required.
- Show relevant listings, including those near your location (if you grant location access).
- Process and confirm bookings, handle cancellations, and manage support requests.
- Comply with local regulations in Iraq related to guest identity and gender-based lodging rules.
- Protect our platform, users, and partners from fraud, abuse, and security threats.
- Improve our services and user experience over time.
3. Service Providers and Third Parties
We work with carefully selected third-party service providers that help us operate the HeloStays platform. These may include:
- Cloud hosting and data storage providers.
- Identity verification and security services.
- Payment processors that handle your booking payments securely.
- Services that provide maps, geolocation, and related features within the app.
- Email, SMS, and push notification providers.
These providers are only allowed to process your data on our behalf and under our instructions, and they are required to apply appropriate security measures. We do not give them permission to use your data for their own marketing.
4. Data Storage and Security
All personal data—including profile photos and ID documents—is stored in secure, encrypted cloud infrastructure. We apply industry-standard technical and organizational measures to protect your data, including encryption in transit and at rest, access controls, and logging. Access to sensitive information is limited to authorized personnel who need it to perform their job.
5. Data Retention and Deletion
We retain your personal data only as long as necessary to provide our services and meet legal, regulatory, and security requirements.
- Identity documents: Deleted after successful verification unless we are legally required to retain them (for example, for compliance or fraud-prevention reasons). When we must retain them, we strictly limit who can access them and for how long.
- Account information: Kept for as long as your account remains active. If you request account deletion, we delete your personal data within 30 days, unless we must retain certain data under applicable law.
- Payment-related data: Kept only as long as necessary to process transactions, handle disputes, chargebacks, and refunds, then deleted or irreversibly anonymized.
- Location data: Used only while the app is active (if you grant permission); we do not store it long term for profiling.
- Backups: Your data may remain in encrypted backups for up to 90 days after deletion, after which it is automatically overwritten or destroyed.
Account deletion: You can request deletion of your account and associated personal data from within the HeloStays app under Account > Account and data management > Delete My Account, or by contacting us at support@helostays.com . After confirming your identity, we will delete your data in line with the timelines above, unless we are legally required to retain some information.
6. Data Sharing
We do not sell your personal data. We only share data in the following situations:
- With service providers: As described in Section 3, for hosting, payments, messaging, identity verification, and other core services.
- To comply with the law: When required by law, regulation, court order, or a valid legal request from authority.
- To protect rights and safety: When necessary to protect you, other users, our staff, or our platform from fraud, abuse, or security threats.
- Business transfers: In connection with a merger, acquisition, or sale of all or part of our business, in which case we will ensure that the receiving party is bound by obligations consistent with this Policy.
- With your consent: When you specifically ask us to share information, for example with a travel companion or accommodation provider.
7. Children’s Privacy
You must be at least 18 years old to use HeloStays. We do not knowingly collect personal information from children under 18. If you believe that a minor has provided us with personal data, please contact us so we can remove it.
8. Location Data
We may request access to your device’s location while you are using the app to show nearby listings and relevant options. Granting location access is optional and can be controlled entirely through your device settings. If you disable location, some features may be limited, but you can still browse and book stays.
9. Contact Us
If you have questions or concerns about this Privacy Policy or how your data is handled, please contact us at: support@helostays.com .
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app and, where appropriate, by email. The “Effective Date” at the top indicates when the latest version took effect.
11. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data, subject to legal and contractual limitations.
- Withdraw consent where our processing is based on consent (for example, location access).
- Manage app permissions (camera, photos, location, notifications) via your device settings.
You can exercise these rights by using the controls within the app (Account > Account and data management > Delete My Account) or by contacting us at support@helostays.com . We may ask you to verify your identity before responding to your request.
12. International Data Transfers
HeloStays is an Iraqi-owned company headquartered in the United Arab Emirates and primarily serving stays in Iraq. Your data may be processed in these locations and in other countries where our service providers operate. We take steps to ensure that any cross-border transfers comply with applicable data-protection laws and that your information remains protected.