We are Kafka Technologies, doing business as HostelReply ("Company," "we," "us," or "our"), a company registered in Australia. We operate the website hostelreply.com (the "Site"), as well as any other related products and services ("Services").

This Privacy Policy describes how and why we collect, hold, use, and disclose your personal information when you use our software and services. We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as well as applicable privacy laws in other jurisdictions where our Services are used.

Questions or concerns? Contact us using the details in Section 15 below.

Summary of Key Points

What personal information do we collect? Information you provide directly (account details, payment info), information collected automatically (usage data, device info), and information from third-party services you connect to our platform.
Do we process sensitive information? We do not intentionally collect or process sensitive information as defined under the Privacy Act 1988 (Cth).
Do we use third-party service providers? Yes. We use Stripe to process payments and Supabase to store and manage data. Both are bound by contractual obligations to protect your information.
Is your information transferred overseas? Yes. Your information may be stored and processed in the United States and other countries via Stripe and Supabase.
What are your rights? You have the right to access and correct your personal information. Depending on your location, you may have additional rights under local privacy laws (GDPR, CCPA).
How do you exercise your rights? Contact us at the details in Section 15. We will respond within a reasonable timeframe and in accordance with applicable law.

1. What Information Do We Collect?

Information you provide to us

We collect personal information that you voluntarily provide to us, including when you:

All personal information you provide must be true, complete, and accurate. Please notify us of any changes.

Information collected automatically

When you access our Services, we automatically collect certain technical and usage information, including:

This information is used to maintain the security and performance of our Services, diagnose technical issues, and improve the user experience. It is stored via Supabase (see Section 4).

Information from third-party sources

We may receive information about you from third parties, such as social login providers (e.g. Google, GitHub) if you choose to register or sign in using a third-party account, or marketing analytics platforms, if applicable.

2. How Do We Use Your Information?

We process your personal information for the following purposes:

We will only process your personal information where we have a lawful basis to do so. For users in the EEA/UK, our lawful bases include performance of a contract, compliance with legal obligations, legitimate interests, and consent.

3. Payment Processing — Stripe

We use Stripe, Inc. ("Stripe") to process all payment transactions. When you make a payment through our Services, your payment card information is submitted directly to Stripe and is not stored on our servers. Stripe is a PCI DSS-compliant payment processor.

Stripe may collect and process your name, billing address, email address, payment card details, and transaction history in accordance with their own privacy policy, available at stripe.com/privacy. By making a payment through our Services, you agree to Stripe's terms and privacy policy.

We receive from Stripe only limited transaction data necessary to manage your subscription (e.g. subscription status, last four digits of your card, and payment confirmation).

4. Data Storage and Infrastructure — Supabase

We use Supabase, Inc. ("Supabase") as our backend infrastructure provider. Supabase provides database, authentication, and storage services that power our platform. Your account information, usage data, and any content you create or upload within our Services may be stored on Supabase's infrastructure.

Supabase stores data on Amazon Web Services (AWS) infrastructure. By default, this data is stored in the United States, though Supabase offers regional hosting options. Please refer to Supabase's privacy policy at supabase.com/privacy for further details.

We have data processing agreements in place with Supabase that require them to process your personal information only in accordance with our instructions and applicable privacy laws.

5. When and With Whom Do We Share Your Information?

We may share your personal information in the following circumstances:

We do not sell your personal information to third parties.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies (such as local storage and session tokens) to:

We may also use third-party analytics tools that collect anonymised or aggregated usage data to help us improve our platform.

Most browsers allow you to control or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our Services.

7. International Data Transfers

We are an Australian company, but our Services are used worldwide and our key infrastructure providers (Stripe and Supabase) operate primarily in the United States. As a result, your personal information may be transferred to, stored in, and processed in countries other than Australia.

Under the Australian Privacy Principles (APP 8), we take reasonable steps to ensure that any overseas recipient handles your personal information in a manner consistent with the APPs. We do this by:

For users in the European Economic Area (EEA) or United Kingdom (UK), we rely on appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses (SCCs), where applicable.

8. How Long Do We Keep Your Information?

We retain personal information for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law (such as for tax, accounting, or legal record-keeping purposes).

When you close your account, we will delete or anonymise your personal information within a reasonable period, subject to any legal retention obligations. Some information may be retained in backup archives for a limited period before it is permanently deleted.

9. Do We Collect Information From Minors?

Our Services are intended for use by individuals who are at least 18 years of age. We do not knowingly collect, solicit, or process personal information from children under 18. If you believe we have inadvertently collected information from a minor, please contact us immediately using the details in Section 15 and we will take prompt steps to delete that information.

10. Your Privacy Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as well as applicable laws in other jurisdictions, you have certain rights with respect to your personal information. These are described in Sections 11 and 12 below.

11. Australian Privacy Rights

If you are located in Australia, you have the right to:

To exercise these rights, please contact us using the details in Section 15. We will respond to your request within 30 days, as required by the Privacy Act 1988 (Cth).

12. Additional Rights for International Users

European Economic Area (EEA) and United Kingdom (UK) — GDPR

If you are located in the EEA or UK, you have the following additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:

To exercise your GDPR rights, contact us at the details in Section 15. You also have the right to lodge a complaint with your local data protection authority.

California (USA) — CCPA

If you are a California resident, you have the right under the California Consumer Privacy Act (CCPA) to:

To exercise your CCPA rights, please contact us using the details in Section 15.

13. Do-Not-Track Features

Some web browsers include a Do-Not-Track ("DNT") setting. There is currently no uniform standard for recognising and responding to DNT signals. We do not currently alter our data collection practices in response to DNT signals. If a standard is adopted in the future, we will update this Privacy Policy accordingly.

14. Do We Update This Policy?

We may update this Privacy Policy from time to time. The updated version will be identified by a revised "Last updated" date at the top of this policy. Where changes are material, we will notify you by email or by displaying a prominent notice within the Services prior to the change taking effect. We encourage you to review this policy periodically.

15. How Can You Contact Us?

If you have questions, concerns, or complaints about this Privacy Policy or our privacy practices, you may contact our Privacy Officer at:

Kafka Technologies

Australia

Email: info@hostelreply.com

Website: www.hostelreply.com

We will endeavour to respond to all enquiries within 30 days.

16. How Can You Access, Update, or Delete Your Data?

You may request access to, correction of, or deletion of your personal information by contacting us using the details in Section 15. You can also update certain account information directly through your account settings within the Services.

Upon a verified request to delete your account and data, we will deactivate your account and delete or anonymise your personal information from our active systems within a reasonable timeframe, subject to any legal obligations to retain certain records.