Skip to main content
Daylyf
Features How it works FAQ For hosts
Get started
Privacy Policy Terms of Service Your Data Rights & Account Deletion Cookie & Tracking

Daylyf Privacy Policy

Last updated: 25 June 2026

Data Controller: Daylyf Ltd

ICO registration number to be added before launch._
Contact: [email protected]

This is a starting draft based on Daylyf's product reality (UK launch, Supabase backend, Stripe Identity KYC, Stripe payments, expo-camera live capture, OpenAI for copy/pricing assistance, Resend for email, Cloudflare Turnstile for CAPTCHA). Have a UK/EU privacy lawyer review and finalise before public release.


1. Who we are

Daylyf is a UK-based marketplace that lets verified guests book private homes and spaces by the hour for daytime use only. Daylyf is strictly day-use; overnight stays are not permitted. This Privacy Policy explains what personal data we collect when you use our mobile app, what we do with it, who we share it with, and the rights you have under the UK GDPR and EU GDPR.

By creating a Daylyf account or using the Daylyf app, you agree to this Privacy Policy. If you do not agree, please do not create an account.

2. The data we collect

2.1 Account & profile data

Data Source Purpose
Name, email, password (hashed) You, via signup Account creation, sign-in
Phone number You SMS verification, host/guest coordination
Profile photo You, via camera or library Trust signal on your profile
Account role (guest / host / admin) Daylyf Determines features available to you
Verified flags (email, phone, ID, proof of address) Daylyf systems + Stripe Identity KYC and Booking Access Gate

2.2 Identity verification (Tier 1 KYC)

We use Stripe Identity to verify your government-issued ID and run a liveness check. Stripe collects and processes:

  • Photo of your ID document (passport, driving licence, national ID)
  • A short selfie/liveness video
  • Document metadata (issuer, expiry, document type)

Daylyf does not store your ID document image. We store only the verification outcome (approved / rejected / pending) and the Stripe Identity session reference. Stripe's processing is governed by their own privacy policy: https://stripe.com/privacy

2.3 Tier 2 verification (proof of address)

If you choose to upload proof of address (utility bill, council tax, bank statement) for a Tier 2 trust badge, we store the document in encrypted Supabase Storage. Only Daylyf admins reviewing your submission can read it. Approval status is host-visible; the document itself is not.

2.4 Listing data (hosts)

Hosts upload property titles, addresses, descriptions, amenities, prices, house rules, capacity, check-in instructions, and live-captured room photos (gallery uploads are blocked). We extract photo EXIF metadata for fraud-prevention purposes and watermark every check-in photo. We retain a hash of the original capture for chain-of-custody.

2.5 Booking & messaging data

Data Stored where Why
Booking time slot, party size (adults, children, pets) bookings table Service delivery
Pet type when applicable bookings table Host preparation
Vehicle registration (if parking) bookings table Host parking control
Guest ↔ host chat messages messages table In-app coordination
Enquiries (pre-booking questions) enquiries table Pre-booking screening

2.6 Forensic check-in data

When you arrive at a booked space and tap "Clock in", Daylyf may capture:

  • A live photo from your device camera (not gallery)
  • Device-attested EXIF metadata (timestamp, optional GPS)
  • A text watermark with booking code, time, and what3words address
  • Coarse geolocation to confirm proximity to the listing

This data is retained for the duration of your stay plus 90 days for dispute resolution, then deleted.

2.7 Payment data

When Stripe payments go live (planned), Stripe (and Stripe Connect for hosts) will process card numbers, billing addresses, and bank/payout details. Daylyf does not see or store full card numbers. We store only Stripe customer / connected-account references and the booking-level transaction outcome.

2.8 Device & technical data

  • Device type, OS version, app version
  • Push notification token (Expo Push)
  • IP address (from your device when calling our backend)
  • Login country — when you sign in, we derive the country your request came from to help detect suspicious account access. We store only the country (never the IP address used to determine it), and we keep these login-country records for 90 days.
  • Language, locale, timezone
  • App crash logs and basic analytics (when we ship Sentry / analytics)

2.9 AI-assisted features

If you use AI Auto-Generate (descriptions, pricing suggestions, local guides), we send the input you provide (e.g. property title, amenities) plus minimal context to OpenAI. We do not send your name, email, ID document, or chat conversations. OpenAI's data handling: https://openai.com/policies

2.10 What we do not collect

  • We do not sell personal data.
  • We do not run third-party advertising trackers inside the app.
  • We do not access your contacts, calendar, microphone, or photo library without an explicit OS-level prompt and a clear in-app reason.
  • We do not record audio.

3. Why we process your data (lawful bases under UK GDPR Article 6)

Purpose Lawful basis
Creating and securing your account Contract (Art. 6(1)(b))
Verifying your identity (KYC) Legal obligation + Legitimate interest in fraud prevention (Art. 6(1)(c) and (f))
Processing bookings and payouts Contract
Sending transactional emails (booking confirmations, password reset) Contract
Sending marketing emails Consent (Art. 6(1)(a)) — opt-in only, opt-out always available
Detecting fraud, abuse, account takeover Legitimate interest
Complying with court orders, regulatory requests Legal obligation

4. Who we share data with (sub-processors)

We use the following processors. Each is bound by GDPR-compliant Data Processing Addenda.

Processor Purpose Data shared Region
Supabase (Supabase Inc.) Database, auth, storage, realtime Account, listing, booking, messaging data EU/US (configurable)
Stripe Identity KYC / liveness ID document, selfie, name US (with SCCs)
Stripe Payments / Connect Payments and host payouts (planned) Card / payout data Global
Resend Transactional email Email address, message content US (with SCCs)
Cloudflare Turnstile Bot/CAPTCHA defence at signup & login Challenge token, IP Global edge
OpenAI Optional AI copy / pricing suggestions Listing inputs you provide US (with SCCs)
Expo / EAS Push Push notifications Device push token, message body US
Apple App Store / Google Play App distribution Subject to platform privacy Global
what3words Address resolution at check-in Listing GPS coordinates UK/Global

We do not share personal data with anyone else except where legally required (court orders, law enforcement requests with valid legal basis).

5. International data transfers

Some of our processors are located outside the UK / EEA (notably Stripe, OpenAI, Resend). When we transfer your data outside the UK / EEA, we rely on:

  • The UK Adequacy Regulations where they apply (e.g. EU member states), or
  • Standard Contractual Clauses (SCCs) with the UK International Data Transfer Addendum, or
  • Other appropriate safeguards under UK GDPR Article 46.

6. How long we keep your data

Data Retention
Account & profile While your account is active + 30 days after deletion request
KYC outcome 5 years after account closure (anti-fraud / regulatory)
Booking & payment records 7 years (UK tax / accounting law)
Messages between guest and host 2 years after the booking ends
Check-in photos & EXIF 90 days after stay ends
Marketing email opt-in record Until you opt out, then 12 months proof-of-consent
Login-country records 90 days
Server logs / IP / device data 90 days

After these periods, data is deleted or irreversibly anonymised.

7. Your rights under UK / EU GDPR

You have the right to:

  1. Access the personal data we hold about you ("Subject Access Request").
  2. Rectify inaccurate data (most fields you can edit yourself in-app).
  3. Erase your data ("right to be forgotten") — see Section 8 below.
  4. Restrict or object to processing.
  5. Data portability — receive your data in a structured, machine-readable format.
  6. Withdraw consent at any time (e.g. unsubscribe from marketing).
  7. Lodge a complaint with the Information Commissioner's Office (ICO): https://ico.org.uk/make-a-complaint/

To exercise any of these rights, email [email protected] or use the in-app Profile → Legal & Account → Manage my data flow. We respond within 30 days.

8. How to delete your account

You can delete your Daylyf account at any time:

  • In the app: Profile → Legal & Account → Delete my account.
  • By email: [email protected] from your registered address.

Deletion removes your profile, avatar, listings (if no active bookings), enquiries, and chat messages. We retain a minimal legally-required footprint (KYC outcome, booking and payment records) for up to 7 years as required by UK law.

If you have active or upcoming bookings as a guest, you must cancel them before deletion. If you are a host with active bookings, you must complete or cancel them first. Daylyf will not silently void a counterparty's reservation.

Your in-app deletion flow is enforced and irreversible after a short cooling-off window.

9. Cookies & similar technology

The Daylyf mobile app does not use cookies in the traditional web sense. Our marketing and legal websites at daylyf.com use a small number of strictly-necessary and analytics cookies — see our separate Cookie Policy.

10. Security

We protect your data with:

  • TLS encryption in transit, AES at rest (Supabase managed)
  • Row-Level Security on every database table
  • Role-based access controls and JWT verification on every API call
  • Cloudflare Turnstile bot defences on signup and login
  • Per-user rate limits on sensitive endpoints (Stripe Identity sessions, AI suggestions)
  • Account lockouts after repeated failed sign-in attempts
  • Forensic camera capture (no gallery upload) to deter fake listings
  • Separate encrypted storage buckets for KYC and proof-of-address documents

No system is perfectly secure. If we ever experience a personal data breach affecting your data, we will notify the ICO within 72 hours and notify affected users without undue delay.

11. Children

Daylyf is not directed to children under 18. We do not knowingly collect data from anyone under 18. Children may appear in a booking party (as "Children" count and to sit on the booking record) but the booking and account holder must be 18+.

12. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top of the document reflects the most recent change. Material changes will be notified in-app and by email at least 14 days before they take effect.

13. Contact

  • Privacy questions: [email protected]
  • Data protection contact: [email protected]
  • Postal address: Daylyf Ltd, 32 Balfour Road, Northampton NN2 6JR, United Kingdom
  • ICO complaints: https://ico.org.uk/make-a-complaint/

End of Privacy Policy.

← Back to Daylyf homepage · Questions: [email protected] · [email protected]

Daylyf

Premium UK daycations — guests and hosts, one trusted platform.

© Daylyf. All rights reserved.

Explore How it works FAQ Download
Legal Privacy Policy Terms of Service Cookie Policy Data & deletion
Support Questions about your account, bookings, hosting, or your data?