1. Who We Are & Legal Basis
Bookly Technologies LTD ("Bookly", "we", "us", "our"), a limited liability company incorporated in Ghana (company registration number CS141510726), is the operator of the Bookly student hostel booking platform. We are the Data Controller for all personal data processed through the platform, as defined under the Data Protection Act, 2012 (Act 843). Bookly is completing its registration with the Data Protection Commission of Ghana. Our registration number will be published here once issued. Until then, we process personal data in line with the principles set out in Act 843. Our Data Protection Supervisor can be contacted at support@booklyapp.co. Use this address for any privacy-related question, access request, correction request, deletion request, or complaint.
2. Data We Collect
2.1 Students
When you register and use Bookly as a student, we collect: • Account data: full name, email address, phone number, gender, and (if you add one) an emergency contact's name and phone number. • Booking data: university index number, programme and year of study, hostel and room selected, payment amounts, payment dates, booking status, balance due dates. • Reservation data (Management-only hostels): your reservation code and the details you give when reserving (name, phone, email, university, programme, level of study, gender, index number, emergency contact), the pay-by date and the reservation's status. • Payment receipts: if you upload proof of a payment made directly to a hostel, we store the file (image or PDF) and what you enter with it (amount, date, method, reference and note), together with the hostel's decision on it. • Tenancy agreements: if you sign a hostel's tenancy agreement in the app, we store the signed agreement, the name you signed with and the time you signed. • Chat data: messages and images you send in room and hostel chats. Messages are stored on our servers as sent; they are not end-to-end encrypted. Our database rules limit access to the people in that chat. Bookly staff may access messages only to investigate a report, resolve a dispute, keep users safe, or where the law requires it. See Section 5 for how long chat is kept. • Maintenance reports, ratings and reviews you submit. • Device & notification data: device type, operating system version, and FCM token for push notifications. • Error reports: if the app runs into an error, a technical report (app version, screen, error details and your user ID) so we can fix it. • Location: if you allow it, the app uses your device's location to show where you are on a hostel's map. It is used on your device only and is not stored by Bookly. • Local app storage: see Section 9.
2.2 Hostel Owners
When you register as a Hostel Owner, or join a hostel's team, we collect: • Account data: full name, email address, phone number, gender. • Listing data: hostel name, location, room details, photos, videos, amenities, pricing, balance due dates. • Transaction data: bookings received, amounts processed, platform fee records, payments you record or confirm. • Payout account data (Bookly Payments hostels): your Paystack subaccount code and the bank account details used for payouts. • Student payment details (Management-only hostels): the bank and Mobile Money accounts (account name, number, bank or network, branch) and payment instructions you enter for students to pay into. These are shown to students holding a reservation at your hostel and to your team. • Team data: the names, phone numbers, emails and permissions of staff you invite. • Subscription and billing records. • Activity records: a log of important actions on your hostel, such as who changed payment details or confirmed a payment, and when. • Location: if you use your current location to place your hostel on the map, your device location is used once to set the pin. Only the hostel's map position is stored. • Chat data: as described in Section 2.1. • Device & notification data: device type, OS version, FCM token.
2.3 Sensitive Data Treatment
University index numbers can be cross-referenced with university records to identify a specific student. We treat index numbers as sensitive personal data and apply strict access controls: only the student themselves, the hostel where the student has booked or reserved (the Hostel Owner and team members they have given access to), and Bookly support staff investigating a specific complaint can access this data.
2.4 Data We Do Not Collect
Bookly does not collect or store: • Credit or debit card numbers (all payment data is handled exclusively by Paystack); • National ID or Ghana Card numbers; • University enrolment records or academic data beyond index number; • Your device's location (see Sections 2.1 and 2.2); • Biometric data, fingerprints, or facial recognition data.
3. Why We Collect It (Legal Basis)
• To provide the service: account creation, bookings and reservations, payment processing, receipt review, subscriptions, and sending confirmations by in-app notification, SMS and email. Legal basis: performance of a contract. • To send notifications: push notifications, SMS and email about booking and reservation status, payment deadlines and reminders. Legal basis: legitimate interest / consent. • To enable chat: in-app messaging between students, and between students and hostels. Legal basis: performance of a contract / legitimate interest. • To keep accounts and payments safe: security logs, alerts to hostel owners when payment details change, and fraud prevention. Legal basis: legitimate interest. • To investigate disputes: transaction, reservation, receipt and account data used to investigate and determine outcomes. Legal basis: legitimate interest. • To comply with legal obligations: retaining transaction records for accounting, tax and potential legal proceedings. Legal basis: legal obligation. • To fix problems: error reports used to find and fix faults in the app. Legal basis: legitimate interest.
4. How We Share Your Data
4.1 With Hostels
When a student books or reserves at a hostel, the following data is shared with that hostel (the Hostel Owner and team members they have given the relevant access): • Full name; • Phone number and email address; • University index number, programme, level of study and gender; • Emergency contact, where given when reserving; • Booking or reservation details (room, amounts, balance due date or pay-by date); • Payment receipts the student uploads for that hostel. When a student holds a reservation at a Management-only hostel, the hostel's student payment details (Section 2.2) are shown to that student. Hostels are required to use student data solely for managing the accommodation. They may not use it for marketing, share it with third parties, or retain it beyond the end of the accommodation period without the student's explicit consent. Section 9 of our Terms & Conditions documents this restriction as an enforceable obligation on Hostel Owners.
4.2 With Service Providers (Cross-Border Transfer)
Bookly relies on the following service providers to operate the platform. Some involve transferring your personal data outside of Ghana. By using the platform, you consent to these transfers as permitted under Section 47 of the Data Protection Act, 2012. • Paystack (Ghana / Nigeria): processes student payments on Bookly Payments hostels and hostels' subscription payments. Paystack's own Privacy Policy applies to data processed by them. Bookly does not receive or store card details. • Supabase (servers in Frankfurt, Germany, EU): provides our database, file storage (including payment receipts and signed agreements) and authentication. Data is stored under a data processing agreement. The EU has data protection standards equivalent to or stronger than Act 843. • Firebase / Google Cloud (servers in the United States): provides push notification infrastructure. Device tokens are stored on Firebase servers. Google has SCC (Standard Contractual Clauses) protections in place. • Google Maps Platform (United States): displays maps in the app. Google may receive your IP address and the map areas you view. Opening directions takes you to Google Maps, where Google's own privacy policy applies. • Resend (United States): sends our emails, such as account, booking and reservation emails and security alerts to hostel owners. • Vynfy: sends our SMS messages, such as one-time verification codes and reservation messages. Your phone number and the message are passed to Vynfy to deliver them. • Upstash (servers globally): provides rate-limiting infrastructure to protect against abuse. Only request counters keyed to a phone number or network address are stored, and they expire within minutes.
4.3 With Authorities
We will disclose personal data to law enforcement, regulatory authorities, or courts where we are legally required to do so, where disclosure is necessary to investigate suspected fraud or illegal activity, or to protect the rights, property, or safety of Bookly, its users, or the public.
4.4 We Do Not Sell Your Data
Bookly does not sell, rent, or trade personal data to third parties for commercial or marketing purposes. We do not display advertising in our platform.
5. Data Retention
• Account data: retained for the lifetime of your account. Deleted within 30 days of a valid account deletion request, subject to exceptions below. • Booking, reservation and transaction records, including payment receipts, payment confirmations and signed tenancy agreements: retained for a minimum of 5 years from the date of the transaction, for accounting, tax, and legal compliance purposes. This data is retained even if you delete your account. • Chat messages: retained for up to 12 months after the related room's bookings have ended (i.e. after the booking is cancelled, archived, or the academic year covered by the booking has concluded), then automatically and permanently deleted. • Hostel activity records (such as changes to payment details): retained for up to 5 years for security and dispute purposes. • Dispute records: retained for 5 years from the date of resolution. • Error reports: automatically deleted after 30 days. • One-time verification codes: expire within minutes and are replaced on the next request. • Device / notification tokens: deleted upon account deletion or when a new token replaces an old one.
6. Security & Breach Notification
We implement the following security measures: • All data is transmitted over encrypted connections (HTTPS / TLS 1.2+); • All stored data, including uploaded files, is encrypted at rest by our hosting provider; • Database access is protected by row-level security (RLS): each user can only access the data they are entitled to see; • Payment receipts are kept in private storage and can only be opened through short-lived links by the student who uploaded them and the hostel team members allowed to review them; • Hostel owners are alerted whenever their hostel's payment details are changed; • Authentication is handled by Supabase with industry-standard secure token management; • Access to production systems is restricted to authorised personnel only; • Edge function calls are gated by authentication and per-operation authorisation checks. No system is completely secure. If we become aware of a data breach that is likely to result in risk to your rights or freedoms (e.g. identity theft, financial harm), we will: • Notify affected users within 72 hours of becoming aware of the breach, or as soon as reasonably practicable thereafter; • Notify the Data Protection Commission as required under Act 843; • Provide a clear description of the breach, the categories of data affected, the measures taken or proposed, and the steps you can take.
7. Your Rights as a Data Subject
Under the Data Protection Act, 2012 (Act 843), you have the following rights regarding your personal data: • Right of access: you may request a copy of the personal data we hold about you. • Right to rectification: you may request correction of inaccurate or incomplete data. • Right to erasure: you may request deletion of your personal data, subject to our legal retention obligations described in Section 5. • Right to object: you may object to processing based on legitimate interest. • Right to data portability: you may request your data in a structured, machine-readable format. • Right to withdraw consent: where processing is based on consent, you may withdraw that consent at any time. To exercise any of these rights, contact us at support@booklyapp.co. We will acknowledge your request within 48 hours and respond fully within 30 days. If you are not satisfied with how we have handled your data or your request, you have the right to lodge a complaint with the Data Protection Commission of Ghana: • Website: dataprotection.org.gh • Email: info@dataprotection.org.gh • Address: Data Protection Commission, GP-GPS GA-040-7773, Adabraka, Accra
8. Children's Privacy
The Bookly platform is not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has registered on our platform, please contact us immediately at support@booklyapp.co.
9. Local Storage on Your Device
The Bookly app stores certain data locally on your device to function: • Authentication tokens: allow you to remain signed in between sessions. Stored securely using platform-provided secure storage (encrypted at rest). • Firebase push-notification token: allows us to send you push notifications. • User preferences: app settings such as notification preferences and theme selection. • Cached listing data: hostels and rooms you have recently viewed, to speed up the app. You can clear this data at any time by uninstalling the app, or for the web version, by clearing your browser storage. Clearing storage will sign you out and lose any unsaved preferences. Bookly does not use third-party advertising cookies, tracking pixels, or cross-site analytics.
10. Third-Party Links
The Bookly app may contain links to third-party websites or services. Bookly is not responsible for the privacy practices of third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via in-app notification and/or email at least 14 days before changes take effect. The version number and effective date will be updated with each revision.
Contact Information
Email: support@booklyapp.co Response time: within 48 hours on business days (Monday–Friday, excluding Ghanaian public holidays).