1. About This Policy

Masyaf is operated by Luxnation Hospitality Consulting GmbH ("Masyaf", "we", "us", "our"), a limited liability company incorporated under Austrian law. Because we are established in the European Union, this Privacy Policy is prepared in accordance with the EU General Data Protection Regulation ("GDPR") (Regulation (EU) 2016/679). We also comply with Egypt's Personal Data Protection Law (Law No. 151 of 2020, "PDPL") as the Masyaf application operates primarily in Egypt.

This Policy explains what personal data we collect through the Masyaf mobile application ("App"), why we collect it, how we use and protect it, who we share it with, and what rights you have.

2. Data Controller

CompanyLuxnation Hospitality Consulting GmbH
JurisdictionAustria (European Union)
Emailcontact@masyaf.app
Registered addressLeutascher Strasse 58, 6100 Seefeld in Tirol, Austria

For privacy questions or to exercise your rights, contact us at contact@masyaf.app.

3. Personal Data We Collect

3.1 Account and Profile Data

When you register, we collect your name, email address, and username. You may optionally provide a profile photo, a cover photo, a short bio, and a phone number. Phone numbers are optional and you control whether other users can see yours through the App's visibility settings. If you register using Apple Sign-In or Google Sign-In, we receive your name and email address from that provider.

3.2 Listing Data (Property Owners Only)

When you create a property listing, we collect the listing title, description, photos, nightly price, an optional contact phone number, and the property location (compound and city level). You control whether your listing phone number is visible to other users. Listing photos and your profile avatar are stored in publicly accessible cloud storage (Supabase/AWS) so they can be displayed within the App. Do not upload images that contain personal data you do not wish to be publicly viewable.

3.3 Activity Data

We record interactions within the App including: properties you like or save, accounts you follow, listing views, clicks, and shares you generate, and messages you send or receive. This data powers listing performance analytics for Owners and is used to personalise your experience and detect misuse.

3.4 Communication and Social Data

The content of messages you send and receive through the in-app messaging feature, notification data, and block lists (records of users you have blocked). Block list data is retained to prevent blocked users from contacting you even if they re-register.

3.5 Payment Data

When you pay an Ad Placement Fee, payment card details are entered directly into our payment processor (Stripe). Card details are handled entirely by Stripe and are never transmitted to, stored on, or accessible by Masyaf's own infrastructure. We receive only a transaction confirmation and metadata: amount, date, listing tier, and a listing identifier. Masyaf does not process payments between owners and guests — those are settled directly between the parties outside the App.

3.6 Technical and Usage Data

Device type, operating system version, app version, session identifiers, in-app navigation and feature usage, and crash or error data. Crash and error reporting is handled by Sentry, which runs on EU-hosted servers (de.sentry.io). We configure Sentry to avoid logging sensitive content such as message text or phone numbers in error contexts.

3.7 Push Notification Tokens

A device push token used to deliver notifications via Apple Push Notification Service (APNs) for iOS or Firebase Cloud Messaging (FCM) for Android, routed through Expo's notification infrastructure. Push tokens are stored in your account record and refreshed automatically by your operating system.

3.8 Future: Identity Verification Data

A future release of the App may introduce optional or mandatory identity verification through a third-party provider. If introduced, we will update this Policy and notify you in advance. No identity verification data is collected in the current version of the App.

3.9 Waitlist Data

If you submit your details through the waitlist form on masyaf.app, we collect your first name, last name, and email address. This data is stored in our Supabase database on AWS infrastructure in Ireland (EU) and is used solely to notify you when the App becomes available. You may request deletion by emailing contact@masyaf.app. Legal basis: consent (Art. 6(1)(a) GDPR).

4. How We Use Your Personal Data

5. Legal Bases for Processing (GDPR Article 6)

Processing ActivityLegal Basis (GDPR Art. 6)
Account creation and managementContract performance — Art. 6(1)(b)
Displaying property listingsContract performance — Art. 6(1)(b)
Ad Placement Fee processingContract performance — Art. 6(1)(b)
In-app messagingContract performance — Art. 6(1)(b)
Listing analytics (views, clicks, saves)Contract performance — Art. 6(1)(b)
Block lists and user safetyLegitimate interests — Art. 6(1)(f)
Message retention for safety / disputesLegitimate interests — Art. 6(1)(f)
Fraud prevention and securityLegitimate interests — Art. 6(1)(f)
App performance monitoring (Sentry)Legitimate interests — Art. 6(1)(f)
Push notificationsConsent — Art. 6(1)(a)
Compliance with legal obligationsLegal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, you have the right to object to that processing (see Section 9).

6. Third-Party Service Providers

We engage the following sub-processors who are contractually bound to process your data only as we direct:

ProviderServiceData locationTransfer safeguard
Supabase, Inc.Database, authentication, file storage, edge functionsAWS eu-west-1, Ireland (EU)Within EEA — no transfer required
Sentry, Inc.Crash reporting and error monitoringEU servers (de.sentry.io)Within EU — no transfer required
Expo, Inc.App delivery, OTA updates, push notification tokensUSASCCs
Apple Inc.Push notifications — iOS (APNs)USAEU–US DPF / SCCs
Google LLC (FCM)Push notifications — AndroidUSAEU–US DPF / SCCs
Stripe, Inc.Ad Placement Fee processingUSA / EUSCCs / DPA

We do not sell personal data to third parties and we do not share personal data with advertisers.

7. International Data Transfers

Luxnation Hospitality Consulting GmbH is an EU-based controller. GDPR protections apply to all personal data we process, regardless of where our users are located.

The majority of user data is stored by Supabase on AWS infrastructure in Ireland (eu-west-1), within the EEA. Error monitoring runs on Sentry's EU servers. No international transfer safeguards are required for these services.

Certain providers are based outside the EEA: Expo (USA), Apple APNs (USA), Google FCM (USA), and Stripe (USA/EU). For transfers to these providers, we rely on Standard Contractual Clauses ("SCCs") and, where applicable, the EU–US Data Privacy Framework ("DPF").

Egypt is not currently subject to an EU adequacy decision. As an Egyptian user, your data is governed by an EU-based controller and subject to full GDPR protections.

8. Data Retention

Data categoryRetention period
Account and profile dataDuration of account, plus 30 days after deletion request
Listing dataUntil you delete the listing or close your account
Activity data (likes, saves, follows, views)Duration of account
Message content and conversationsDuration of user relationship; deleted within 30 days of valid erasure request
Chat media (images sent in messages)Deleted automatically after a defined period
Block listsUntil you unblock the user or close your account
Payment and billing records7 years (Austrian statutory accounting obligation)
Push notification tokensDuration of account or until your device refreshes the token
Usage and analytics data24 months, then anonymised or deleted
Crash and error logs (Sentry)90 days

When you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law.

9. Your Rights

9.1 Rights Under the GDPR

9.2 Rights Under the Egyptian PDPL (Law No. 151/2020)

Egyptian users also have rights under the Egyptian PDPL including the right to be informed, the right of access, the right to rectification, and the right to erasure. To exercise any of these rights, contact us at contact@masyaf.app.

We will respond within 30 days and may need to verify your identity. Account and listing deletion can also be performed directly within the App.

10. Push Notifications

We deliver push notifications via Expo's notification infrastructure, routing through Apple APNs (iOS) and Google FCM (Android). You will be asked for permission when you first use the App. You may withdraw consent at any time through your device's notification settings or within the App.

11. Social Sign-In

If you sign in using Apple Sign-In or Google Sign-In, those providers share your name and email address with us solely for account creation. We do not receive your password or payment details from these providers.

12. Phone Number Visibility

Providing a phone number is optional. Where you include a phone number in your profile or listing, you control its visibility through the App's privacy settings. We recommend reviewing your visibility settings before publishing a listing.

13. Children's Privacy

The App is intended solely for users aged 18 and over. We do not knowingly collect personal data from individuals under 18. Contact contact@masyaf.app if you believe a minor has registered.

14. Data Security

We implement appropriate technical and organisational measures to protect personal data, including TLS-encrypted data transmission, database access controls and row-level security within Supabase, EU-located infrastructure for core user data, and Sentry configured to exclude sensitive content from error reports. In the event of a personal data breach, we will notify the Datenschutzbehörde and affected users as required under GDPR Article 33.

15. Changes to This Policy

We may update this Policy to reflect changes in our services, infrastructure, or legal requirements. We will notify you of material changes by in-app notification or email at least 14 days before they take effect.

16. Contact Us

For all privacy-related questions, data subject requests, or complaints:
contact@masyaf.app