Privacy Policy
Last updated: July 20, 2026
inStay is an independent guide that helps guests understand what's included at their all-inclusive resort. This policy explains what information the inStay website (getinstay.com) and the inStay mobile app collect, why, and the choices you have. We keep data collection to the minimum needed to do our job.
Who we are
inStay is operated by Sadeam (sole proprietor: Essam Elhassanain), based in Egypt. For any privacy question or request, contact essa91m@gmail.com.
What the website collects
The only personal information the website collects is what you voluntarily enter into the "pre-arrival tips" form:
- Email address โ so we can send you the practical, time-sensitive things to know before you arrive at the resort you selected.
- Selected resort โ recorded with your email so we send you the right guide.
These submissions are handled by Netlify, which hosts the website and processes form entries on our behalf. We use your email only to send you inStay content and never share or sell it. You can unsubscribe or ask us to delete your email at any time โ see Deleting your data. The website does not use advertising or cross-site tracking cookies.
What the app collects
The inStay app is offline-first. The resort guides are bundled in the app, and your activity stays on your device. Specifically:
- On-device preferences โ your chosen resort, stay dates, saved plan and checklist progress, unlocked resort guides, and language. This is stored locally on your phone and is not sent to us. Deleting the app removes it.
- Accuracy feedback โ if you tap "still correct" or "out of date" on a fact, that signal helps us keep guides accurate. It is tied to the fact, not to your identity.
- Anonymous usage analytics (from the app's public launch) โ via Google Firebase Analytics, to understand which features are used and fix problems. This includes app and device information (such as device model, OS version, app version, and a random app-instance identifier). It is not linked to your name or email.
- Anonymous sign-in (from the app's public launch) โ the app may create an anonymous account (a random ID) so your unlocked guides and feedback work reliably. It does not require or store your name, email, or phone number.
- Purchases โ the one-time "unlock this resort" purchase is processed by Apple or Google and managed with RevenueCat. We receive a confirmation that the purchase happened and which resort was unlocked. We never see or store your card details.
The app does not use GPS or your location, does not access your photos or contacts, does not show ads, and does not sell your data.
Third-party services we rely on
- Netlify โ website hosting and pre-arrival form processing. (privacy)
- Google Firebase โ anonymous analytics and anonymous sign-in in the app (from launch). (privacy)
- RevenueCat + Apple App Store / Google Play โ processing the one-time resort unlock. (RevenueCat privacy)
- Unsplash โ some mood photographs are served from Unsplash; this does not involve your data.
How long we keep data
- Email โ kept until you unsubscribe or request deletion.
- On-device app data โ kept until you delete the app or clear it in the app's settings.
- Anonymous analytics โ retained according to Firebase's default retention (up to 14 months).
Where your data is processed
Our providers (Netlify, Google, RevenueCat, Apple, Google Play) may process and store data on servers outside your country, including in the United States and the EU. They maintain their own security and compliance programs.
Your rights
You can ask us to access, correct, or delete your data, and to stop emailing you. To do so, follow the steps on Deleting your data or email essa91m@gmail.com. If you are in the EU/UK, you also have rights under the GDPR; our lawful basis for the email list is your consent, and for anonymous analytics it is our legitimate interest in improving the app.
Children
inStay is intended for adults planning and enjoying a resort stay, and is not directed to children under 13. Some covered resorts are adults-only. We do not knowingly collect data from children.
Security
All traffic to the website and app services is encrypted in transit (HTTPS). No method of storage or transmission is perfectly secure, but we limit what we collect precisely to reduce risk.
Changes to this policy
We may update this policy as the app evolves (for example, when analytics and purchases go live at the app's public launch). We'll change the "last updated" date above and, for significant changes, note it in the app or on this page.
This document is a plain-language template, not legal advice. For a production launch we recommend a review by a qualified professional. Need this in another language? Email us โ we can provide Russian or Arabic versions.