Privacy Policy
Last updated: 17 August 2026
1. Introduction and Scope
Sta.Res ("Sta.Res", "we", "us", "our") operates a student accommodation platform available on the web at stares.co.za and as a mobile application on iOS and Android (together, the "Service"). The Service helps students discover residences, submit and track accommodation applications, manage their stay, report incidents, and use a peer-to-peer marketplace. It also helps property managers and business partners list and manage properties, and helps institutions and NSFAS reviewers process and approve student applications and funding status.
This Privacy Policy explains, in detail, what personal information Sta.Res collects through the Service, why we collect it, the legal basis for that processing under South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA"), how long we keep it, who we share it with, and the rights you have over your own information. It applies to every account type on the Service: student, property manager, account manager, C-level/business partner, institution representative, and NSFAS reviewer.
This policy does not apply to any third-party website or service you may reach through a link on the Service (see Section 19), or to information you provide directly to a property partner, institution, or NSFAS outside the Service.
2. Definitions
| Term | Meaning |
|---|---|
| Personal information | Information relating to an identifiable, living natural person or, where applicable, an identifiable, existing juristic person (e.g. a property partner business), as defined in section 1 of POPIA. |
| Processing | Any operation performed on personal information, including collection, storage, use, sharing, and deletion. |
| Responsible party | The entity that determines the purpose and means of processing personal information — Sta.Res, in respect of account and platform data. |
| Operator | A third party that processes personal information on behalf of and under the instruction of Sta.Res (e.g. our cloud hosting provider) — also called a "sub-processor" in this policy. |
| Data subject | The person to whom personal information relates — you, as a Sta.Res user. |
| Special personal information | A category of personal information POPIA treats with extra care (e.g. information about a child, or certain identifiers). Sta.Res collects South African ID numbers from property partners for verification purposes — see Section 4. |
3. Who We Are (Responsible Party)
For the purposes of POPIA, the responsible party for personal information processed through the Service is:
| Field | Detail |
|---|---|
| Registered entity name | AITLA TECHNOLOGY GROUP |
| Registration number | 2024/144696/07 |
| Registered address | 1 Louw St, Bryanston, Sandton, Gauteng 2191 |
| Information Officer | Matodzi Ronewa Given |
| Information Officer contact | given@aitla.co.za | 079 122 2635 |
| Information Officer registration status | Registered |
| General support contact | support@stares.co.za |
4. Information We Collect — Full Data Inventory
The table below is a field-level inventory of the personal information Sta.Res collects and stores, based on the platform's live data model. It is intentionally granular so that it can be cross-checked directly against the "App Privacy" data-collection disclosure submitted to the Apple App Store and Google Play, and against any POPIA data-mapping exercise.
| Category | Specific data points | Source | Purpose | POPIA legal basis |
|---|---|---|---|---|
| Account credentials | Username, email address, password (stored hashed, never in plain text) | Provided by you at signup | Authenticate you and secure your account | Contract necessity |
| Identity and demographic data | Full name, first name, date of birth, gender | Provided by you at signup/onboarding | Verify identity/eligibility, personalise the Service | Consent / contract necessity |
| Contact details | Mobile number, emergency contact name, emergency contact mobile number | Provided by you | Communicate with you; safety contact in case of an incident | Consent |
| Academic / institution data | Institution, institution short code, campus, year of study | Provided by you | Match you to eligible accommodation; share with institution reviewers where relevant | Contract necessity / legitimate interest |
| Funding / NSFAS data | NSFAS funding status, NSFAS application status | Provided by you; confirmed by NSFAS/institution reviewers | Determine funding-linked accommodation eligibility and route applications for funding review | Consent / legal obligation (NSFAS reporting) |
| Application and booking records | Application ID, property, room type, term, date applied, application status, allocated room, rent due and due date | Generated when you apply or are allocated a room | Process and track your accommodation application and stay | Contract necessity |
| Uploaded documents | ID document, student card, proof of registration, NSFAS proof, guardian ID, proof of income, lease agreement, signed contract, and other supporting files (file name, type, size, checksum, storage location) | Uploaded by you or, for some document types, a property/institution reviewer | Verify identity, eligibility, and process your application or lease | Consent / contract necessity |
| Marketplace listings | Listing title, description, price, images, seller username | Provided by you when you list an item | Operate the peer-to-peer student marketplace | Consent |
| Amenity bookings | Amenity, booking date, booking time, status | Provided by you when you make a booking | Manage amenity reservations at your residence | Contract necessity |
| Incident / maintenance reports | Report title, category, priority, description, status, evidence photos/files | Provided by you when you report an issue | Track, action, and resolve accommodation issues | Legitimate interest / contract necessity |
| Check-in / check-out records | Status, notes, linked application and property | Created by you or an admin during move-in/move-out | Manage the occupancy lifecycle of your stay | Contract necessity |
| Support communications | Name, email, phone, category, subject, and message content | Provided by you when you contact support | Respond to and resolve your query | Consent / legitimate interest |
| One-time verification codes (OTP) | OTP code, purpose (login/signup/reset), delivery status | Generated by Sta.Res, sent to your email | Verify it is really you at login, signup, and password reset | Contract necessity |
| Security and usage logs | Login timestamp, success/failure, IP address, browser/device user agent, an internal activity log of actions on your account, and an audit trail of record changes | Captured automatically by the Service | Detect and investigate fraud, abuse, and security incidents; maintain a change-history record | Legitimate interest |
Sta.Res does not collect precise device location, contacts, calendar, health, biometric, or advertising identifier data. If a future release of the mobile app requests any additional device permission (camera, photo library, push notifications, etc.), this policy and the App Store "App Privacy" disclosure will be updated before that permission is requested.
5. How We Collect Information
5.1 Directly from you
Most of the information in Section 4 is provided directly by you: when you create an account, complete onboarding, submit an application, upload a document, post a marketplace listing, book an amenity, report an incident, or contact support.
5.2 Automatically
Some information is generated automatically as you use the Service: login and activity logs, IP address, device/browser user agent, session cookies, and CSRF tokens.
5.3 From institutions, NSFAS, and property partners
Where you apply to a property, your institution, an NSFAS reviewer, or a property manager may add information to your application record — for example an application status decision, a funding confirmation, or a document review outcome.
6. Legal Basis for Processing (POPIA)
POPIA requires that processing of personal information be justified on one of several lawful grounds. Sta.Res relies on the following grounds, as indicated per data category in Section 4:
- Consent — you have given clear consent for us to process your information for a specific purpose (for example, your emergency contact details, or a marketplace listing).
- Contract necessity — processing is necessary to perform the contract between you and Sta.Res, or to take steps at your request before entering into that contract (for example, processing your application to a property).
- Legal obligation — processing is necessary to comply with a legal obligation, including reporting obligations linked to NSFAS-funded accommodation.
- Legitimate interest — processing is necessary for Sta.Res's or a third party's legitimate interests (for example, security logging to prevent fraud), balanced against your rights and reasonable expectations.
7. How We Use Your Information
- Create and manage your account, and authenticate you at login
- Process and route accommodation applications, including sharing relevant application details with the property manager, institution, and/or NSFAS reviewer involved in that specific application
- Operate the marketplace, amenity bookings, incident reporting, check-in/check-out, and notices features
- Send transactional email such as OTP codes, confirmations, and notices via Microsoft 365 (Microsoft Graph) and Azure Communication Services
- Respond to support requests you submit
- Maintain login, activity, and audit logs for account security, fraud prevention, and troubleshooting
- Meet legal, regulatory, or institutional reporting obligations tied to student accommodation and NSFAS funding
Note on payments
Sta.Res does not currently process card, EFT, or bank payments inside the app. Any payment screens or amounts shown are informational only. If in-app payment processing is introduced in the future, this policy will be updated before that feature is enabled, and the payment processor will be named in Section 10.
8. Automated Decision-Making and Profiling
Sta.Res does not use your personal information for automated decision-making that produces legal or similarly significant effects about you (for example, automatically approving or rejecting an accommodation or funding application without human review). Application, funding, and accreditation decisions are made by a property manager, institution representative, or NSFAS reviewer, not by an algorithm.
9. Data Retention Schedule
Sta.Res's policy is to keep personal information only for as long as necessary for the purposes described in this policy, or as required by law. The table below sets out our retention commitments by data category.
| Data category | Retention period | Basis |
|---|---|---|
| Account and profile data | For as long as your account is active; deleted upon a verified in-app account deletion request (see Section 15) | Contract necessity; POPIA data minimisation |
| Applications, documents, and lease/check-in records | For the duration of the relevant tenancy, plus 5 years, in line with standard South African financial and educational record-keeping practice | Legal obligation; legitimate interest in dispute resolution |
| NSFAS / institution-linked funding records | For the period required by the relevant institution or NSFAS reporting cycle, which may exceed Sta.Res's standard retention period | Legal obligation |
| One-time verification codes (OTP) | 24 hours, or until used, whichever is sooner | Contract necessity; security |
| Login, activity, and audit logs | 12 months on a rolling basis | Legitimate interest in security and fraud prevention |
| Support messages | 24 months after the query is resolved | Legitimate interest in service quality |
| Marketplace listings and amenity bookings | Until you remove the listing/booking, or your account is deleted | Consent; contract necessity |
Retention periods above are policy commitments. Where they are not yet enforced by an automated purge job (for example, scheduled deletion of security logs older than 12 months), engineering should implement that enforcement so the platform's behaviour matches this policy.
10. Who We Share Information With
10.1 Recipients on the platform
- Property managers/partners you apply to, book with, or report an issue to receive the application, contact, and issue details needed to act on your request.
- Institutions and NSFAS reviewers receive the funding/accreditation status and application details tied to applications routed to them for review.
10.2 Sub-processors (operators)
Sta.Res uses the following service providers to operate the platform. Each processes personal information only on our instructions and under a data-processing agreement or equivalent terms.
| Provider | Purpose | Data involved | Region |
|---|---|---|---|
| Microsoft Azure SQL Database | Primary application database | All categories in Section 4 except raw uploaded files | South Africa North (Azure region) |
| Microsoft Azure Blob / Data Lake Storage | Storage of uploaded documents, photos, and evidence files | Uploaded documents, incident evidence, marketplace/property images | South Africa North (Azure region) |
| Microsoft 365 / Microsoft Graph API | Sending transactional email (OTPs, confirmations, notices) | Name, email address, and message content of the email sent | Microsoft-managed (global service) |
| Azure Communication Services (email) | Sending transactional and no-reply email | Recipient email address and message content | Africa region endpoint (auto-emails.africa.communication.azure.com) |
10.3 What we do not do
- We do not sell personal information.
- We do not share personal information with advertisers, ad networks, or data brokers.
- We do not use third-party advertising or analytics SDKs in the mobile app.
10.4 Legal disclosures
We may disclose personal information where required by law, in response to a valid court order or regulatory request, or to protect the rights, safety, or property of Sta.Res, our users, or the public.
11. Cross-Border and Regional Data Storage
Sta.Res's primary database (Azure SQL) and file storage (Azure Blob / Data Lake) are hosted in Microsoft Azure's South Africa North region, meaning your data is stored within South Africa. Some sub-processors (see Section 10.2), such as Microsoft 365 / Microsoft Graph used for sending email, operate as globally managed services and may process data outside South Africa as part of their standard email delivery infrastructure. Where personal information is processed outside South Africa, we rely on the relevant sub-processor's data-protection safeguards and, where required by POPIA section 72, take reasonable steps to ensure a comparable level of protection.
12. Cookies, Sessions, and Tracking Technologies
| Name / type | Purpose | Duration |
|---|---|---|
| Session cookie | Keeps you signed in to the Service | Cleared on logout or session expiry |
| CSRF token | Protects form submissions from cross-site request forgery | Tied to your active session |
We do not use third-party advertising or cross-site tracking cookies.
13. Data Security Measures
- Passwords are stored using a salted one-way hash (never in plain text) and are never included in API responses.
- All traffic to the Service is encrypted in transit (HTTPS/TLS).
- All state-changing requests are protected against cross-site request forgery (CSRF).
- Access to administrative functions is restricted by role (student, property manager, account manager, C-level, institution, NSFAS, app admin).
- Security-sensitive actions are recorded in an internal audit and activity log.
- Uploaded files are stored in access-controlled cloud storage rather than on the application server.
No system is completely secure, and we cannot guarantee the absolute security of information transmitted to us. If we become aware of a security incident affecting your personal information, we will follow the process described in Section 17.
14. Your Rights as a Data Subject
Under POPIA, you have the right to:
- Be notified that personal information about you is being collected, and why
- Ask us to confirm what personal information we hold about you, free of charge, and to access it
- Ask us to correct or update inaccurate, incomplete, misleading, or outdated information
- Ask us to delete or destroy personal information we no longer have authority to keep, or object to specific processing on reasonable grounds
- Withdraw consent you previously gave, where processing is based on consent, without affecting processing that already took place
- Object to processing of your personal information for purposes of direct marketing
- Lodge a complaint with the Information Regulator if you believe we have not handled your information lawfully (see Section 20)
To exercise any of these rights, contact us using the details in Section 22. We will respond within a reasonable period and, where we are unable to fulfil a request, explain why.
15. Account and Data Deletion
You can permanently delete your Sta.Res account directly inside the app, without needing to contact support or visit a website: go to Profile > Danger Zone > Delete My Account, confirm your password, and type DELETE to confirm.
When you delete your account, Sta.Res immediately and permanently removes:
- Your login credentials and profile information
- Your applications, saved rooms, and lease/check-in records
- Documents and files you uploaded, and incident reports you filed
- Marketplace listings and amenity bookings associated with your account
- Your login and activity log history
Records that reference your account but belong to another party's data (for example, an audit log entry for an action taken on a property, or a support message) are retained but anonymised: your username is removed from those records rather than the record itself being deleted, so that other users' and the platform's own operational records remain intact.
Account deletion is irreversible. If you are the account manager for a property partner business, or hold the platform's global administrator role, deletion may be restricted; contact support@stares.co.za for assistance.
16. Children's Privacy
Sta.Res is intended for use by prospective and current higher-education students and is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us using the details in Section 22 and we will take steps to remove it.
17. Data Breach Notification
If Sta.Res becomes aware that personal information has been accessed or acquired by an unauthorised person, we will, as required by POPIA section 22, notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the breach, unless a public body responsible for the prevention, detection, or investigation of offences requests a delay. The notification will describe the possible consequences of the breach, the measures taken or to be taken to address it, and a recommendation on steps you can take to mitigate its effects.
18. Marketing Communications and Opt-Out
Sta.Res does not currently send marketing or promotional communications; email sent to you is transactional (for example, OTP codes, application status updates, and support responses). If this changes, we will only send marketing communications with your consent, and every such communication will include a clear way to opt out.
19. Third-Party Links and Integrations
The Service may link to third-party websites, such as the websites of the AITLA Technology Group, Staruts Construction & Projects, or MeetSA referenced in our footer. This Privacy Policy does not apply to those third-party sites, and we encourage you to review their own privacy policies.
20. Complaints — Regulatory Contact
If you believe Sta.Res has processed your personal information unlawfully, you have the right to lodge a complaint with South Africa's Information Regulator:
| Field | Detail |
|---|---|
| Regulator | The Information Regulator (South Africa) |
| Complaints email | POPIAComplaints@inforegulator.org.za |
| Physical address | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 |
| Website | www.inforegulator.org.za |
Regulator contact details verified via inforegulator.org.za at the time this document was drafted (17 August 2026) — reconfirm before publishing, as these details can change.
21. Changes to This Policy — Version History
We may update this policy as the Sta.Res platform changes, for example if we introduce in-app payments or a new sub-processor. Material changes will be communicated through the app or by email, and the version history below will be updated.
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | 17 August 2026 | Initial detailed draft, based on the live Sta.Res data model. |
22. Contact Us
Questions, requests, or complaints about this policy or your personal information can be sent to:
support@stares.co.za
Information Officer: Matodzi Ronewa Given, given@aitla.co.za
Deputy Information Officer: Raphasha Ombetshela Anniba, anniba@aitla.co.za
1 Louw Street, Bryanston, Sandton, Gauteng 2191