Trust & Safety at AmarStay
This page is maintained by the AmarStay team to answer common questions about how we handle security, privacy and data on our platform. It is editable project content and not an independent certification.
Authentication & accounts
Accounts are created with email and password or Google sign-in. Sessions are protected by short-lived access tokens issued by our backend provider; we do not store passwords in our application database.
Hosts must be manually verified by our team before their listings can go live.
Listing & booking verification
Every property is reviewed by our admin team before being marked verified and shown publicly. Bookings move from pending to payment_pending to confirmed only after our team reviews the payment proof submitted by the guest.
Data in transit
All traffic to AmarStay is served over HTTPS. API requests from the app to our backend use authenticated, same-origin server functions.
What we store
We store the information you provide to create an account (name, email, phone), property details you publish as a host, booking records, and payment reference screenshots uploaded for manual verification.
Profile email and phone are never returned to other users through our APIs — only your display name and (for hosts) the WhatsApp number you choose to publish on your listings.
Messages between guests and hosts are only readable by the two participants and our admins for safety review.
Privacy requests & contact
To request a copy of your data or to delete your account, contact the AmarStay team from the email address on your account. We will respond within a reasonable time frame.
Reporting a security issue
If you believe you have found a security vulnerability, please contact the AmarStay team privately before sharing details publicly so we can investigate and fix the issue.
Looking for our listings? Explore stays.