1. Introduction
Welcome to StayCore AI (the "App"), listed in mainland China under the full application name StayCore AI酒店智能工作台. Both names refer to the same App. We understand the importance of your personal information and are committed to protecting all personal information you provide. This Privacy Policy applies to all personal information you submit through the App's mobile client and related H5 web pages.
Operator: This service is operated by Walling Tech Limited (Chongqing Walling Zhilv Technology Co., Ltd., the "we" / "us").
Please read and fully understand this Privacy Policy before using the App. If you do not agree with any part of this Privacy Policy, please immediately stop using the App. We obtain consent through an explicit in-app action; continued use does not substitute for consent.
2. Information We Collect
2.1 Information You Actively Provide
- Account Information: email address, name, and password (passwords are stored encrypted; we cannot recover them in plaintext)
- Business Contact Numbers: hotel front desk phone numbers, guest contact phone numbers, feedback callback numbers, and other phone numbers you voluntarily provide (used for hotel information display, guest-service follow-up, and issue handling)
- Hotel Operating Information: hotel name, hotel address, room types, brand VI colors, brand logo, marketing copy templates
- Hotel Materials: hotel photos, room photos, and facility photos you actively upload (used for AI content generation and image processing)
- Guest Communication Content: chat text between you and guests, complaint records, check-in guide content
2.2 Information We Collect Automatically
- Device Information: device model, operating system and version, app version, device unique identifier (used for multi-device management and push notifications)
- Usage Data: feature usage records, credit consumption logs, login / logout timestamps, crash and error logs
- Raw AI Interaction Data: prompts, necessary business context, AI responses, model information, and call status submitted when you actively use AI features, for service-quality review and product improvement; this content may include personal information or hotel operating information that you submit
- Voice data is collected only when you use voice features. Front desk recording retention is off by default. If the hotel owner or a hotel-authorized delegated administrator enables it, original audio is encrypted and kept for seven days for service review and disputes, with private playback limited to that hotel owner or an active delegated administrator and automatic deletion at expiry. Clearing the screen does not delete history or recordings.
2.3 Permission Request Timing
- Microphone permission: requested only when you actively enter the phone-translation assistant, tap a voice-input button, press and hold to speak, or otherwise use a voice feature. It is used for real-time speech recognition, call translation, or voice-message processing. We do not request microphone permission before you use a related voice feature.
- Camera / photo permissions: requested only when you actively take a photo, scan a code, upload an avatar, or upload hotel materials, and only to complete the image processing or recognition operation you selected.
- Notification permission: used only to display service notifications such as orders, complaints, chats, and system announcements. You can disable it in system settings.
2.4 Information We Do Not Collect
We do not collect sensitive personal information such as your government-issued ID number, bank card number, precise GPS location, contacts, SMS content, or full photo-library indexes.
Sensor information: We do not read specific sensor lists such as accelerometers or gyroscopes, and we do not collect sensor data to identify devices or users.
Direct identifiers in Smart Guest Profiling: When Smart Guest Profiling is used, we do not collect, transmit, or store guest names, document numbers, phone numbers, ID-document photos, face photos, or other direct identifiers. The system only uses redacted service profile fields such as nationality, age range, gender, and room type to generate service suggestions.
2.5 Automatic Startup and Background Alerts (China Android)
China Android background alerts: after accepting this policy, while signed in with Keep background alerts enabled, the app can automatically start its alert service after a device restart or app update to receive guest messages and work-order alerts. It does not open screens or other apps. Turn it off in Notification settings or sign out to stop the service and disable restart recovery. Delivery still depends on system notification, battery and network settings.
Restart recovery is disabled by default and enabled only when all these conditions are met. We request renewed consent when this policy changes and store the accepted version and time locally on your device. Without acceptance of the current policy, JPush is not initialized and background alerts are not restored. Restart recovery is used for these work alerts, not advertising.
3. How We Use Information
We use the collected information solely for the following purposes:
- Provide, maintain, and improve the App's core business features (AI content generation, photo retouching, translation, complaint handling, guest profiling, etc.)
- Account registration, login, and multi-device management (via email OTP or password login; up to 6 simultaneous devices per account, with the oldest device signed out automatically when exceeded)
- Processing the business contact numbers you voluntarily submit for hotel information display, guest-service follow-up, and feedback callback
- Credit billing, subscription management, billing history queries
- Send service notifications, system announcements, and exception alerts via push channels
- Review AI service quality, diagnose errors, and improve features under controlled access
- Continuously improve the product based on anonymized aggregate statistics
Important Statement: We do not use your personal information for advertising, profile reselling, or any commercial purpose unrelated to the services.
4. Third-Party Sharing
We do not sell, lease, or otherwise provide your personal information to third parties, except in the following circumstances:
- Functional Service Calls: To provide AI content generation, image processing, push notifications, payments, maps, and content moderation, we transmit the minimum data necessary to corresponding third-party services through our backend proxy or related web pages (see the Third-Party SDK and External Service List in Section 5)
- Legal Requirements: When required by law, regulation, or competent authorities
- Safety Protection: When necessary to protect the personal or property safety of you or the public
We do not sell your personal information to any third party for marketing purposes.
5. Third-Party SDK and External Service List
To provide complete services, the App integrates necessary third-party SDKs or invokes external services through our backend and related web pages when you actively use the relevant features. Device-side SDKs are initialized as needed only after you accept this Privacy Policy and sign in; external services receive only the minimum data required to complete the requested function.
5.1 JPush (Aurora Push)
- Provider: Shenzhen Hexun Huagu Information Technology Co., Ltd.
- Purpose: Push business notifications such as orders, complaints, and chat messages to your device
- Information Collected: Device identifier (Registration ID), OS version, device model, network status
- Trigger: Initialized only after acceptance of the current Privacy Policy and sign-in
- Privacy Policy: https://www.jiguang.cn/license/privacy
5.1.1 Xiaomi Push — China Android Builds
- Provider: Beijing Xiaomi Mobile Software Co., Ltd.
- Purpose: Deliver guest messages, orders and work alerts through the Xiaomi channel integrated with JPush.
- Information processed: App package, version and running status; device and system information; notification settings; message content and creation, delivery and click times. Xiaomi states that the current network type and SIM carrier name are read locally and are not uploaded to its servers.
- When used: After privacy consent and sign-in, when the Xiaomi channel is configured. Background alerts may resume after a device restart or app update while the account remains signed in and background alerts remain enabled. You can disable background alerts in the app or disable notifications in system settings.
- Privacy policy: Xiaomi Push Privacy Policy
5.1.2 HONOR Push — China Android Builds
- Provider: Shenzhen Honor Software Technologies Co., Ltd. or its affiliates, depending on the service region.
- Purpose: Deliver guest messages and work-order alerts through the HONOR channel integrated with JPush.
- Information processed: Anonymous Application Identifier (AAID), PushToken, APPID and app package name.
- When used: As needed on configured devices, only after acceptance of the current Privacy Policy and sign-in. See Section 2.5 for automatic startup conditions and how to disable it.
- Privacy policy: https://developer.honor.com/cn/docs/11002/guides/sdk-data-security
5.1.3 Huawei Push (HMS Push) — China Android Builds
- Provider: Huawei Software Technologies Co., Ltd.
- Purpose: Deliver guest messages, orders and work alerts through the Huawei channel integrated with JPush.
- Information processed: Basic app information, device model, operating system and system settings, network and carrier information, SSID and IP address. Huawei states that system settings, carrier information, SSID and IP address are processed locally and are not uploaded to its servers.
- When used: Called as needed only after acceptance of the current Privacy Policy and sign-in. On non-Huawei devices, the SDK may start HMS Core to establish a push connection and authenticate the service; this does not open another app screen. Turn off background alerts in app notification settings or notifications in system settings.
- Privacy policy: https://developer.huawei.com/consumer/cn/doc/hmscore-guides/sdk-data-security-0000001050042177
5.2 Third-Party AI Services
- Purpose: Content generation and processing features such as OTA listing generation, hotel photo AI retouching, poster design, city exploration map, and phone translation
- Information Collected: Only the materials you actively upload (hotel photos, brand colors, copy, text awaiting translation, etc.)
- Trigger: When you actively initiate the corresponding feature, invoked through our backend proxy; the frontend never connects directly to any third-party AI endpoint
- Transmission Security: TLS 1.2+ encrypted throughout; not retained after processing
- Data Isolation: Account information, contacts, location, and other personal information unrelated to the generation feature are not transmitted
5.3 Map and Location Services (Web APIs / Web Maps)
- Provider: AutoNavi Software Co., Ltd.
- Integration: Place queries use Web Service APIs through our backend; the City Exploration H5 page loads the Web JavaScript API only when needed. The Android and iOS installation packages do not include the Amap native SDK
- Purpose: City exploration maps, hotel address lookup, nearby attraction display, and launching external map navigation
- Information Collected: Hotel coordinates, destination coordinates, POI keywords, and other map query parameters that you actively enter, select, or confirm. The App currently does not request device GPS permissions
- Trigger: When you actively open map-related features, search for places, or start navigation
- Privacy Policy: https://lbs.amap.com/pages/privacy/
5.4 Alibaba Cloud Content Moderation (Green SDK)
- Provider: Alibaba Cloud Computing Co., Ltd.
- Purpose: Identify illegal or non-compliant content in user-generated content (forum, chat, complaint, avatar) to ensure platform safety
- Information Collected: Text or image content awaiting moderation (called by our backend; frontend does not connect directly)
- Privacy Policy: https://help.aliyun.com/document_detail/158676.html
5.5 WeChat Pay SDK
- Provider: Tenpay Payment Technology Co., Ltd.
- Purpose: Membership subscription and credit top-up payments (Android)
- Information Collected: Necessary payment information (order amount, order number); no bank card information
- Trigger: Triggered only when you actively initiate a payment
- Privacy Policy: https://pay.weixin.qq.com/
5.6 Alipay SDK
- Provider: Alipay (China) Network Technology Co., Ltd.
- Purpose: Membership subscription and credit top-up payments (Android)
- Information Collected: Necessary payment information (order amount, order number); no bank card information
- Trigger: Triggered only when you actively initiate a payment
- Privacy Policy: https://render.alipay.com/
5.7 Apple In-App Purchase (StoreKit) — iOS Only
- Provider: Apple Inc.
- Purpose: Membership subscription and credit top-up on iOS
- Information Collected: Handled independently by Apple; we do not access your Apple ID or payment credentials
- Data We Receive: Only the purchase receipt token (transactionId / receipt) returned by Apple, which our server uses to verify transaction authenticity with Apple and grant the corresponding subscription benefits or credits. We do not receive your Apple ID, payment method, card information, or full transaction details
- Server-to-Server: We use Apple's App Store Server API to validate receipts and receive App Store Server Notifications V2 to synchronize subscription lifecycle events (auto-renewal, refunds, upgrades, downgrades, etc.)
List Update Notice: This list will be updated alongside product feature updates. If third-party SDKs or external services are added or changed, we will update this page and notify you in the App.
6. Information Storage and Security
6.1 Security Measures
- Transport Encryption: All data transmission uses TLS 1.2+ encryption
- Storage Protection: Login passwords use one-way bcrypt hashing; sensitive configuration fields such as API keys are encrypted at rest with AES-256-GCM
- Access Control: RBAC-based permission isolation; strict cross-hotel data segregation
- Security Auditing: Regular vulnerability scanning, penetration testing, and security compliance reviews
- Disaster Recovery: Periodic off-site backups and disaster-recovery drills
6.2 Security Incident Response
In the event of a personal information security incident, we will, in accordance with applicable laws, promptly inform you of the basic facts of the incident, its potential impact, the remedial measures we have taken or will take, and the actions you may take. We will notify you via in-app push, email, or other reasonable means; if individual notification is impractical, we will issue a public announcement through reasonable and effective channels.
7. Data Retention and Deletion
7.1 Retention Period
We retain your personal information only for the period necessary to fulfill the purposes stated in this Privacy Policy, after which we will delete or anonymize it. Raw AI prompts, necessary context, responses, and call status are retained in our MySQL database and BullMQ task queue for no more than 30 days, after which they are automatically deleted. Any data retained longer for product improvement or model training must first be irreversibly de-identified or anonymized; raw interaction data is not directly placed in a long-term training dataset.
7.2 Deletion After Account Closure
You may close your account via "Settings → Account Security → Delete Account". After closure:
- Your account information, hotel operating data, and uploaded materials will be permanently deleted or irreversibly anonymized within 30 days
- Raw AI interaction records and remaining queue jobs associated with the account are deleted immediately when the account is closed; the same rule applies to AI data associated with a deleted hotel
- Where law requires longer retention (e.g., transaction records), we will retain only for the minimum necessary period and apply access restrictions
- Account deletion is irreversible — please proceed with caution
8. Your Rights
You have the following rights regarding your personal information:
- Access: View your profile in "Settings → Profile"; review logged-in devices in "Account Security"
- Correction: Update your name, avatar, contact information, etc., in "Settings → Profile"
- Deletion: Permanently delete your account and all associated data via "Settings → Account Security → Delete Account" (requires typing "DELETE" to confirm)
- Withdraw Consent: Withdraw consent to this Privacy Policy by deleting your account or contacting us via email; you will then be unable to continue using the App
- Export: Request to export your core business data via the contact channels below; we will respond within 15 business days
- Complaint: If you believe our processing has harmed your legitimate rights, submit a complaint via the contact channels below; we will respond within 15 business days
9. Cookies and Local Storage
The mobile app itself does not use browser cookies. We store the following on your device locally to improve the user experience:
- Login token (JWT)
- Privacy policy consent status and version number
- Language preference, font-size preference, brand VI local cache
Guest-facing H5 pages (web pages accessed by hotel guests) use the browser's localStorage to store essential information such as language preferences and do not use any third-party tracking technologies.
You can clear the above local storage by "clearing app data" or uninstalling the App.
10. Protection of Minors
The App is a B2B professional tool for hospitality industry practitioners and is not intended for users under 18 years of age.
If we discover that we have collected personal information from a minor without verifiable guardian consent, we will delete such information immediately. If you are a guardian and discover that a minor has registered for the App without your consent, please contact us via the channels below and we will assist with handling.
11. Multi-Jurisdiction Supplement
The App provides services to hotel operators across multiple regions. The following supplements apply by region:
11.1 Mainland China Users
Your personal information processing activities are governed by the Personal Information Protection Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Cybersecurity Law of the People's Republic of China, and related implementing regulations. You are entitled to rights including the right to be informed, the right to decide, the right of access and copy, the right of correction and deletion, the right to withdraw consent, the right to data portability, and the right to request explanations.
11.2 Hong Kong SAR Users
Your personal data processing activities are governed by the Personal Data (Privacy) Ordinance (PDPO, Cap. 486). You may, in accordance with the Ordinance, request access to or correction of your personal data, or withdraw consent.
11.3 Southeast Asia Users
- Singapore: Personal Data Protection Act 2012 (PDPA)
- Thailand: Personal Data Protection Act B.E. 2562 (2019) (PDPA)
- Malaysia: Personal Data Protection Act 2010 (PDPA)
- Indonesia: UU Pelindungan Data Pribadi (UU PDP)
- Vietnam: Decree 13/2023/ND-CP on Personal Data Protection (PDPL)
The data-subject rights you are entitled to under the laws of your country / region remain effective. Please exercise them via the contact channels below.
11.4 Other Regions
If your region has applicable local data protection laws, the rights you are entitled to under such laws remain effective. Please exercise them via the contact channels below.
12. Changes to This Privacy Policy
This policy may be updated due to business adjustments, product iteration, or changes in laws and regulations. Updated policies will be announced in the App, and material changes will require you to re-confirm consent via an in-app pop-up. Changes requiring renewed consent take effect for you only after your explicit acceptance in the dialog.
You can always view the latest version and update date on this page.
13. Contact Us