Privacy Policy
Last updated: August 9, 2026
We collect and use information to provide Staloom, not to create surprises. This policy explains what we collect, why we use it, who may receive it, how long we keep it, and how you can exercise your rights.
1. Who this policy covers
This Privacy Policy explains how Staloom processes personal information when you visit the service, create an account, search, list a property or experience, make or manage a booking, communicate with another participant or support, publish a story, use a ride feature, or contact us. Staloom acts as the service operator and may act as a controller, business, or processor depending on the feature and applicable law.
2. Information we collect
We collect account and profile information such as your name, email address, phone number, avatar, biography, languages, location, role, preferences, and verification status. We collect booking and service information such as dates, guests, enquiries, messages, property or experience details, ride details, reviews, refunds, payment status, and limited transaction identifiers. Providers may submit listing images, addresses, availability, rules, licences, payout details, and business information. We may collect stories, photos, videos, likes, comments, support requests, dispute reports, and moderation records that you submit. We may also combine content and metadata across features, sessions, and devices to operate, protect, and improve the service.
3. Information collected automatically
When you use Staloom, we may collect device and technical information such as IP address, browser and device type, session identifiers, approximate location, route or feature usage, security events, and error diagnostics. We use essential cookies and similar storage for sessions, authentication, security, preferences, and demo or draft functionality. We do not currently describe advertising or targeting cookies as part of the service; if that changes, this policy and the cookie controls will be updated before they are used where consent is required.
4. Why we use information
We use personal information to create and secure accounts; provide search, listings, bookings, payments, rides, messaging, support, reviews, stories, and related features; verify providers and prevent fraud or abuse; communicate service, safety, and transactional notices; personalise recommendations when enabled; improve reliability and user experience; administer refunds, disputes, affiliate earnings, and loyalty programmes; comply with legal obligations; and establish, exercise, or defend legal claims. We also use information for risk management, abuse prevention, analytics, quality assurance, and compliance, even if the same use is not described in every feature. We rely on the legal basis available in your jurisdiction, which may include contract, legitimate interests, legal obligations, consent, or protection of vital interests.
5. When information is shared
We share only the information reasonably needed for the relevant purpose. This can include sharing booking details with the guest, host, scout, agent, driver, or experience provider participating in that booking; payment and payout information with payment providers; account and contact details with hosting, storage, media, email, SMS, security, and customer-support vendors; information with professional advisers, insurers, or authorities when legally required; and aggregated or de-identified information for reporting and improvement. Direct provider messaging is booking-scoped. We do not make private wishlists, trips, unrelated role data, or precise private contact details public merely because a person has another Staloom role.
6. Public information and privacy boundaries
Information you choose to publish may be visible to other users, including a display name, public profile material, approved listing or experience details, reviews, and stories. We use approximate locations on public maps where the platform setting requires it. Precise addresses, private booking details, identity records, payout information, private messages, wishlists, and personal trips are restricted to the user, authorised booking participants, support, or administrators with a legitimate need. Do not publish information about another person unless you have permission and the legal right to do so. Staloom does not promise that content marked private can never become visible if there is a system error, legal requirement, or lawful investigation.
7. Retention and deletion
We keep information for as long as needed to provide the service, maintain account and financial records, enforce agreements, resolve disputes, investigate abuse, meet tax or legal obligations, and protect security. Account deletion removes or de-identifies information where practical, but some booking, payment, fraud-prevention, audit, moderation, or backup records may need to be retained for a lawful period. We may also retain limited records after account closure to prevent fraud, support repeated requests, or comply with legal obligations. Stories and other content may expire according to the platform setting; expiry does not guarantee immediate removal from backups, archives, logs, or records that must be preserved.
8. Your rights and choices
Depending on where you live, you may have rights to be informed, access, correct, delete, object to, restrict, or receive a copy of your personal information; withdraw consent; opt out of marketing; and complain to a data-protection authority. You can update available profile and preference fields in Settings, delete your account there, or contact privacy@staloom.com for an access, correction, export, deletion, or objection request. We may verify your identity and apply lawful exceptions, including records needed for a booking, payment, safety investigation, or legal claim.
9. International processing and security
Staloom and its service providers may process information in countries other than the country where you live. Where required, we use an appropriate legal transfer mechanism or other safeguard. We use reasonable technical and organisational measures such as access controls, authentication, encryption or secure transport where supported, minimisation, logging, and incident response. No internet transmission or storage system is completely secure, and we do not promise that any transfer mechanism or security control will prevent every unauthorised access event.
10. Children and policy changes
Staloom is intended for adults and is not designed for children under 18. We do not knowingly permit a child to create an account or make a booking. If you believe a child has submitted information, contact privacy@staloom.com. We may update this policy when our practices, providers, or legal obligations change. We will publish the new version with a new date and provide additional notice where required.
11. Driver and provider verification information
When you apply as a driver or another provider, we may process vehicle details, registration plates, licence and insurance expiry dates, inspection information, uploaded compliance documents, gallery media, operating location, verification decisions, and safety or support records. We use this information to assess eligibility, prevent fraud, match services, keep expired providers offline, respond to incidents, and meet legal or contractual duties. Access is limited to authorised verification, operations, support, security, and administrators who need it for those purposes; public profiles show only the information the product makes public.
12. Payments, communications, and service providers
Payment processors, identity or verification vendors, cloud hosting, media storage, email, SMS, mapping, analytics, security, customer-support, and professional advisers may process information on our instructions or under their own terms where they independently provide a regulated service. We share the minimum information needed, use contractual and technical safeguards where appropriate, and do not ask Staloom to receive or store full payment-card credentials. Booking, safety, legal, and account messages may be sent even when marketing preferences are disabled.
13. Security incidents and lawful disclosures
We maintain an incident-response process and may investigate, contain, preserve evidence, notify affected people or regulators when required, and cooperate with lawful requests. We may disclose information to courts, regulators, law enforcement, insurers, advisers, or another party when reasonably necessary to comply with law, protect people, investigate suspected fraud or abuse, enforce agreements, or defend Staloom and its users. We do not promise that any security measure will prevent every unauthorised access event, and we are not liable for losses caused by third-party attacks, device compromise, or your failure to protect your credentials.
14. Data-controller contact and requests
For privacy questions, requests, complaints, or a request to withdraw consent, contact privacy@staloom.com and include the account email or phone number, the request, and any reasonable identity verification needed to protect the account. If Staloom processes data for a provider or business customer, that customer may be the controller and Staloom may act as its processor; we will route or assist with the request as required. We may retain a record of the request and our response to demonstrate compliance and prevent repeat abuse. We may decline requests that would violate law, impede a legitimate investigation, or jeopardise security.
Privacy requests and questions: privacy@staloom.com