Clear expectations. Lasting trust.
Privacy notice
Last updated 25 September 2026
This notice explains what personal data Easycoliv for Operators collects about owners, operators, agents and their teams, why, who processes it, how long it is kept and how to ask for a copy or erasure.
Who this notice covers
Easycoliv for Operators is the operator workspace of Easycoliv. This notice covers the people who use it: property owners, PG and coliving operators, letting agents and their teammates. It also covers what you see about tenants who enquire about your listings.
What we collect
Your account
- Your name, the email address you sign in with and, if your account has one, a mobile number.
- Your language preference and when you last used the workspace.
Your business and team
- Business name, profile handle, type (owner, operator or agent), country, about text, website and, if you give it, a licence number.
- Team members, their roles and notification preferences, and invitations (the invitee's email address).
Location while on duty
- Only when a team member turns on location sharing in the Easycoliv for Operators app: their position, how accurate it is and when it was taken, while sharing is on. Nothing is recorded when it is off.
- Sharing stops when the member turns it off, after 12 hours, or when they leave the business. Each member sees their own route; the owner sees every member, and admins and managers see members with a lower role than their own.
Listings and photos
- Listing details, address, map pin, rooms, prices and availability.
- Photos. We remove location (EXIF and GPS) data, resize them to at most 1600 pixels on the longest side and save them as JPEG. The original upload is deleted.
Enquiries and leads
- For each enquiry: the tenant's name and contact number, move-in date, number of people, messages, status, notes and who on your team it is assigned to.
Verification
- The document type, the legal name, the document number (until the review is decided), its last four characters and a one-way fingerprint.
Billing
- Your plan, orders, invoices, amounts, GSTIN or tax id, and the payment provider's references. We never receive card, UPI or bank account details.
Security records
- An audit log of changes made in the workspace (who, what and when), with the IP address of the request.
- Short-lived sign-in sessions and rate-limit counters.
How we use it
- To send sign-in codes and keep you signed in.
- To publish, review and moderate listings, and to show them to tenants.
- To deliver enquiries and send lead, availability and renewal alerts.
- To show a business where its team members on duty are, when they choose to share it.
- To take payments and issue invoices.
- To verify businesses and award the Verified badge.
- To prevent abuse, investigate reports and keep the service secure.
- To answer your support and privacy requests.
Who processes it for us
- SendGrid: email sign-in codes and email notifications (link tracking is turned off).
- Razorpay: payments by businesses in India.
- Stripe: payments by businesses in other countries.
- Cloud hosting and S3-compatible object storage: the service itself, listing photos and invoices.
Tenants see what you publish: your business name, listings, verification badge, public profile, replies to reviews and the messages you send them. Webhooks you set up receive event data; lead events carry ids and statuses only, not tenant contact details.
This site runs no advertising or third-party analytics scripts. Some providers may process data outside your country.
How long we keep it
- Sign-in codes: 5 minutes, in memory only, never in the database.
- Sessions: 15 minutes for an access session, renewable for up to 30 days.
- Team invitations: they expire after 14 days.
- Leads: open leads with no activity for 180 days are closed. 180 days after a lead is closed, its message text is removed, unless a privacy request about it is open.
- Verification documents: the full number is deleted when the review is decided. The last four characters, legal name and fingerprint are kept.
- Photos: kept with the listing. Original uploads are deleted straight away.
- System events: published events are deleted after 90 days and webhook delivery records after 30 days.
- Locations shared while on duty: deleted after 30 days. Notifications in the workspace bell: deleted 90 days after they are read, and after 180 days at most.
- Audit log and billing records: kept for security and accounting.
How we protect it
- Mobile numbers, email addresses and verification document numbers are encrypted at rest (AES-256-GCM). Look-ups use keyed one-way hashes instead of the numbers themselves.
- Sign-in cookies are HTTP-only and sent over HTTPS only. Requests that change data must come from our own sites.
- Request logs leave out authorisation headers, cookies, phone numbers, email addresses and message text.
- Sign-in codes are limited to 5 a number or address an hour and 5 attempts a code.
- Webhooks are signed with HMAC-SHA256 so you can check they came from us.
Your choices and rights
You can view and change your profile, business details, team and notification settings in the workspace at any time.
To get a copy of your data, correct it or have it erased, contact the Easycoliv support team. Our staff handle each request, normally within 30 days. A copy is provided through a single-use download link that works for 15 minutes.
Erasure removes your name, mobile number and email address and blanks the text of any reviews you wrote. We keep what we need for tenants, the law and security: messages already exchanged with tenants, billing and audit records, and, for anyone banned from the service, the identifiers on the ban list.
Depending on where you live, data protection law may give you further rights, such as the right to complain to a regulator.
Cookies
We use only the cookies and browser storage the workspace needs. The Cookie notice lists each one.
Changes to this notice
We update this notice when what we collect or who processes it changes. The date at the top of this page shows the latest version.
Contact
Questions about privacy: contact the Easycoliv support team.
Other notices: Terms of service, Cookie notice and API terms of use.