Privacy policy
Last updated October 3, 2026
This is a starting template. Have it reviewed by qualified counsel for your jurisdiction before launch.
1. Who we are
Dormly acts as a data processor for the organizations that use it to manage their hostels, and as a controller for account and billing information of our direct customers.
2. Data we process
Account data: names, email addresses and phone numbers of users.
Operational data entered by customers: resident profiles, room allocations, attendance, leave, complaints, visitor logs, fee records and documents.
Billing data: handled by Stripe. We store subscription status and invoice references, never full card numbers.
3. How data is protected
Each organization's data is isolated in the database using Row Level Security policies. Access within an organization is limited by role.
Files are stored in private buckets and served through short-lived signed URLs. Data is encrypted in transit and at rest by our infrastructure providers.
4. Sub-processors
Supabase (database, authentication, storage), Stripe (payments), Resend (transactional email) and our hosting provider.
5. Retention and deletion
Customer data is retained for the life of the subscription. After cancellation, customers can request export or deletion of their organization's data.
6. Your rights
Residents should contact their hostel operator first. You can also reach us at support@dormly.app to exercise access, correction or deletion rights.