Privacy Policy

Bookly — student hostel booking platform
Version 1.2
Bookly is committed to protecting your personal data. This Privacy Policy explains what we collect, why we collect it, how we use and protect it, and your rights under the Data Protection Act, 2012 (Act 843) and related Ghanaian legislation. It applies to all users of the Bookly mobile and web application.

1. Who We Are & Legal Basis


Bookly Technologies LTD ("Bookly", "we", "us", "our"), a limited liability company incorporated in Ghana, is the operator of the Bookly student hostel booking platform. We are the Data Controller for all personal data processed through the platform, as defined under the Data Protection Act, 2012 (Act 843).

Bookly is in the process of registering with the Ghana Data Protection Commission. Our registration number will be displayed here once issued. In the interim, we operate in accordance with the principles set out in Act 843 and will complete formal registration before public launch.

Our Data Protection Supervisor can be contacted at support@booklyapp.co. Use this address for any privacy-related question, access request, correction request, deletion request, or complaint.

2. Data We Collect


2.1 Students

When you register and use Bookly as a student, we collect: • Account data: full name, email address, phone number, gender. • Booking data: university index number, hostel and room selected, payment amounts, payment dates, booking status, balance due dates. • Chat data: messages sent and received within the platform. Messages between roommates and between students and hostel owners are encrypted with a room-specific passphrase. Bookly does not have access to your unencrypted message content during normal operation. See Section 5 (Retention) for how long encrypted chat is stored. • Device & notification data: device type, operating system version, and FCM token for push notifications. • Local app storage: see Section 9. • Usage data: app features used and interaction timestamps (collected anonymously for product improvement purposes only).

2.2 Hostel Owners

When you register as a Hostel Owner, we collect: • Account data: full name, email address, phone number, gender. • Listing data: hostel name, location, room details, photos, amenities, pricing, balance due dates. • Transaction data: bookings received, amounts processed, commission records. • Paystack subaccount data: subaccount code and bank account details used for payouts. Bank account numbers are stored in encrypted form. • Chat data: as described in Section 2.1 (messages with your tenants are encrypted with a room-specific passphrase). • Device & notification data: device type, OS version, FCM token.

2.3 Sensitive Data Treatment

University index numbers can be cross-referenced with university records to identify a specific student. We treat index numbers as sensitive personal data and apply strict access controls: only the student themselves, the Hostel Owner of the room booked, and Bookly support staff investigating a specific complaint can access this data.

2.4 Data We Do Not Collect

Bookly does not collect or store: • Credit or debit card numbers (all payment data is handled exclusively by Paystack); • National ID or Ghana Card numbers; • University enrolment records or academic data beyond index number; • Location or GPS data from your device; • Biometric data, fingerprints, or facial recognition data.

3. Why We Collect It (Legal Basis)


• To provide the service: account creation, booking management, payment processing, and sending booking confirmations. Legal basis: performance of a contract. • To send notifications: push notifications about booking status, payment due dates, and balance reminders. Legal basis: legitimate interest / consent. • To enable chat: in-app messaging between students, between students and hostel owners. Legal basis: performance of a contract / legitimate interest. • To investigate disputes: transaction and account data used to investigate and determine outcomes. Legal basis: legitimate interest. • To comply with legal obligations: retaining transaction records for accounting and potential legal proceedings. Legal basis: legal obligation. • To improve the platform: anonymous usage analytics. Legal basis: legitimate interest.

4. How We Share Your Data


4.1 With Hostel Owners

When a student completes a booking, the following data is shared with the relevant Hostel Owner: • Full name; • Phone number and email address; • University index number; • Booking details (room, amount paid, balance due date). Hostel Owners are required to use this data solely for managing the accommodation. They may not use student data for marketing, share it with third parties, or retain it beyond the end of the accommodation period without the student's explicit consent. Section 9 of our Terms & Conditions documents this restriction as an enforceable obligation on Hostel Owners.

4.2 With Service Providers (Cross-Border Transfer)

Bookly relies on the following service providers to operate the platform. Some involve transferring your personal data outside of Ghana. By using the platform, you consent to these transfers as permitted under Section 47 of the Data Protection Act, 2012. • Paystack (Ghana / Nigeria): processes all payments. Paystack's own Privacy Policy applies to data processed by them. Bookly does not receive or store card details. • Supabase (servers in Frankfurt, Germany — EU): provides our database and authentication infrastructure. Account data, booking data, and encrypted chat data are stored on Supabase servers under a data processing agreement. The EU has data protection standards equivalent to or stronger than Act 843. • Firebase / Google Cloud (servers in the United States): provides push notification infrastructure. Device tokens are stored on Firebase servers. Google has SCC (Standard Contractual Clauses) protections in place. • Resend (United States): processes transactional emails (account verification, password resets, booking confirmations). Email content is transient and not retained beyond delivery. • Termii (Nigeria / Africa): processes OTP SMS for phone verification. Phone numbers are passed to Termii for verification only and not retained by them beyond the verification window. • Upstash (servers globally): provides rate-limiting infrastructure. Only anonymous request counters are stored, no personal data.

4.3 With Authorities

We will disclose personal data to law enforcement, regulatory authorities, or courts where we are legally required to do so, where disclosure is necessary to investigate suspected fraud or illegal activity, or to protect the rights, property, or safety of Bookly, its users, or the public.

4.4 We Do Not Sell Your Data

Bookly does not sell, rent, or trade personal data to third parties for commercial or marketing purposes. We do not display advertising in our platform.

5. Data Retention


• Account data: retained for the lifetime of your account. Deleted within 30 days of a valid account deletion request, subject to exceptions below. • Booking and transaction records: retained for a minimum of 5 years from the date of the transaction, for accounting, tax, and legal compliance purposes. This data is retained even if you delete your account. • Chat messages (encrypted): retained for up to 12 months after the related room's booking has ended (i.e. after the booking is cancelled, archived, or the academic year covered by the booking has concluded). After 12 months from booking end, encrypted chat messages for that room are automatically and permanently deleted. Note that even before deletion, Bookly cannot read message contents because they are encrypted with a passphrase only the room participants can derive. • Dispute records: retained for 5 years from the date of resolution. • Device / notification tokens: deleted upon account deletion or when a new token replaces an old one. • Anonymous usage data: retained indefinitely (cannot be linked back to any individual).

6. Security & Breach Notification


We implement the following security measures: • All data is transmitted over encrypted connections (HTTPS / TLS 1.2+); • Database access is protected by row-level security (RLS) — each user can only access their own data; • Authentication is handled by Supabase with industry-standard secure token management; • Sensitive fields (bank account numbers, chat content) are stored in encrypted form at rest; • Access to production systems is restricted to authorised personnel only; • Edge function calls are gated by JWT authentication and per-operation authorisation checks. No system is completely secure. If we become aware of a data breach that is likely to result in risk to your rights or freedoms (e.g. identity theft, financial harm), we will: • Notify affected users within 72 hours of becoming aware of the breach, or as soon as reasonably practicable thereafter; • Notify the Data Protection Commission as required under Act 843; • Provide a clear description of the breach, the categories of data affected, the measures taken or proposed, and the steps you can take.

7. Your Rights as a Data Subject


Under the Data Protection Act, 2012 (Act 843), you have the following rights regarding your personal data: • Right of access: you may request a copy of the personal data we hold about you. • Right to rectification: you may request correction of inaccurate or incomplete data. • Right to erasure: you may request deletion of your personal data, subject to our legal retention obligations described in Section 5. • Right to object: you may object to processing based on legitimate interest. • Right to data portability: you may request your data in a structured, machine-readable format. • Right to withdraw consent: where processing is based on consent, you may withdraw that consent at any time. To exercise any of these rights, contact us at support@booklyapp.co. We will acknowledge your request within 48 hours and respond fully within 30 days. If you are not satisfied with how we have handled your data or your request, you have the right to lodge a complaint with the Data Protection Commission of Ghana: • Website: dataprotection.org.gh • Email: info@dataprotection.org.gh • Address: Data Protection Commission, GP-GPS GA-040-7773, Adabraka, Accra

8. Children's Privacy


The Bookly platform is not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has registered on our platform, please contact us immediately at support@booklyapp.co.

9. Local Storage on Your Device


The Bookly app stores certain data locally on your device to function: • Authentication tokens: allow you to remain signed in between sessions. Stored securely using platform-provided secure storage (encrypted at rest). • Firebase push-notification token: allows us to send you push notifications. • User preferences: app settings such as notification preferences and theme selection. • Cached listing data: hostels and rooms you have recently viewed, to speed up the app. You can clear this data at any time by uninstalling the app, or for the web version, by clearing your browser storage. Clearing storage will sign you out and lose any unsaved preferences. Bookly does not use third-party advertising cookies, tracking pixels, or cross-site analytics.

10. Third-Party Links


The Bookly app may contain links to third-party websites or services. Bookly is not responsible for the privacy practices of third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.

11. Changes to This Privacy Policy


We may update this Privacy Policy from time to time. We will notify registered users of material changes via in-app notification and/or email at least 14 days before changes take effect. The version number and effective date will be updated with each revision.

Contact Information


Email: support@booklyapp.co Response time: within 48 hours on business days (Monday–Friday, excluding Ghanaian public holidays).