Data and privacy
What we collect, why, who sees it, and what happens to it afterward. Written to match how the software actually works, not how pages like this are usually written.
Privacy policy in progress. A formal document needs to be drafted by a lawyer practicing in Belarus: it determines the legal basis for processing, the country where data is stored, and retention periods. Until there's an answer, we won't invent retention periods or claim a legal basis.
Instead, below is the platform's actual behavior. It's built to hold up under any answer: we collect less than we could.
What's collected
- Account: name, email address or phone number, password (stored only as a hash).
- Listings: description, photos, address.
- Bookings: dates, amounts, check-in and check-out marks.
- Messages between tenant and host.
- Reviews.
- Identity documents — only if you submit them yourself.
What we deliberately don't keep
- IP addresses — only as a hash. That's enough to link abuse together, and not enough to reconstruct a history of your movements.
- The session token itself isn't stored. Only its hash sits in the database, so a database leak doesn't hand an attacker your open sessions.
- The action log keeps diffs, not copies. What changed is recorded, not a snapshot of the whole object.
- Guest registration data isn't collected at all.
The exact flat address
Before a booking is confirmed, the map shows only the neighborhood. Publishing the exact address of an empty flat isn't a convenience question — it's a safety question for the host.
Identity documents
Their submission is currently switched off and will stay off until a legal decision is made. The system is already built for that switch to be safe:
- a separate, private storage bucket — the application won't start if it's the same one used for photos;
- only the reviewer handling the case can read the document — not support, not a moderator, not finance, not even an administrator;
- every time a document is opened, it's recorded in a log that can't be altered or erased;
- staff sections only unlock after a second factor, never a password alone.
Who sees the messages
The other party — always. Platform staff — only when handling a dispute or complaint. Messages are checked automatically for attempts to move the conversation off the platform, and if part of a message is hidden, the sender is told plainly why.
Closing an account
The “Account” section lets you close your account. It also lists honestly what happens and what stays — for example, financial records and dispute materials are kept, because erasing them would destroy the other side's evidence.
Full data deletion isn't built yet and is waiting on the same legal decision. We won't say “data is deleted” while the bytes are still there.