Effective Date: 10 July 2026 Last Updated: 10 July 2026
CampusStay Ghana ("CampusStay," "we," "us," or "our") is a mobile and web platform operated by AMANITEX ENTERPRISE, a sole proprietorship registered in the Republic of Ghana (Registration No. BN682380626; TIN P006735386X) with the Office of the Registrar of Companies (ORC), based in Accra, Greater Accra, Ghana. CampusStay connects students with hostel, homestay, and private-rental accommodation near Ghanaian university campuses, and provides related services including roommate matching, in-app messaging, video property tours, reviews, and secure online payments.
This Privacy Policy explains what personal data we collect through the CampusStay app and website, why we collect it, how long we keep it, how we use and share it, and the choices and rights available to you. It applies to everyone who uses CampusStay: students, property managers/hosts ("Managers"), and administrators.
By creating an account or otherwise using CampusStay, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Platform. If you are accepting this Policy on behalf of a business (for example, a hostel management company), you confirm that you have authority to do so and that "you" in this Policy includes that business.
CampusStay supports three account types, and this Policy describes data practices for each:
When you register, we collect your name, email address, phone number, gender, profile picture, and account role (student, manager, or admin). Students may also provide their school, faculty, department, and level. Managers may provide a business name. We also record how your account was created (email/password, Google Sign-In, or Sign in with Apple) and, where relevant, whether you used Apple's private email relay.
Ghanaian law and platform safety require every user to verify their identity before transacting. We collect:
These documents are reviewed by our administrators and are stored securely in Firebase Storage with access restricted to the account owner and authorized CampusStay staff. We treat ID document numbers and images as sensitive personal data and apply heightened access controls to them, as described in Section 9.
Managers who list a property must submit proof of ownership or authority to let the property, which may include property documents, a recent utility bill, and photographs of the property. These are reviewed before a listing is marked "Verified" and visible to students.
When you make or receive a booking, we collect booking details (property, room, duration in semesters, total amount, amount paid, deposit/part-payment status, confirmation deadline) and payment metadata such as the transaction reference, amount, payment channel (Mobile Money, Visa, or Mastercard), and status. We do not collect or store your full card number, CVV, or Mobile Money PIN — these are entered directly into Paystack's secure checkout and never touch CampusStay's servers (see Section 7.2).
To show distances to campus and display properties on the map, we collect property coordinates (set by Managers) and, with your device permission, your approximate or precise device location to help center the map and calculate distance to nearby campuses (KNUST, University of Ghana, UCC, UDS, UEW, and others). You can decline location access; some map-based features will then rely on manually entered search terms instead.
If you opt into roommate matching, we collect lifestyle and preference data you choose to share: budget, sleep schedule, cleanliness habits, and preferences such as quietness, sociability, non-smoking, religious observance, and study habits, along with a short bio and optional photo, and which other students' profiles you have liked. This data is used to calculate a compatibility score with other students and is visible to other students you are matched or connected with. Participation in roommate matching is optional and separate from your core student profile.
We collect the content of messages sent through in-app chat (between students, and between students and managers), support tickets you raise (category, subject, description, and any screenshots you attach), and disputes you file (type, description, and related booking/transaction references).
This includes property reviews (ratings for cleanliness, security, water supply, internet, management, and value for money, plus written comments), and video tours uploaded by Managers. Video tours are processed, compressed, and may be watermarked before publication, and we record engagement metrics such as views, likes, saves, and watch time on them.
We use Firebase Analytics, Firebase Crashlytics, and Firebase Performance Monitoring to automatically collect device information (device model, operating system and version, app version, language settings), app usage events (screens viewed, features used, video views/watch time, search filters used), crash logs and stack traces, and performance metrics (load times, network conditions). This helps us fix bugs and improve the app. We also use Firebase App Check (backed by reCAPTCHA v3 on web) to verify that requests to our backend come from genuine CampusStay app instances rather than bots or tampered clients.
If you enable notifications, we collect a device token (via Firebase Cloud Messaging) to deliver booking updates, payment confirmations, messages, and announcements to your device.
Like most apps, our servers and infrastructure providers automatically log certain technical information whenever you use CampusStay, including your IP address, approximate network-based location, mobile network/carrier information, browser type and version (web app), and timestamps of requests. This information is primarily used for security, fraud prevention, debugging, and service reliability, and is generally not linked to your identity beyond what is necessary for those purposes.
Depending on the features you use, the CampusStay app may request the following device permissions: camera and photo library (to capture or upload ID documents, property photos, video tours, and profile pictures), location (to center the map and calculate distance to campus), and notifications (to deliver push alerts). You can grant or deny each permission through your device's operating-system settings, and can change your choice at any time; declining a permission may limit the corresponding feature.
We use the information described above to:
Under Ghana's Data Protection Act, 2012 (Act 843), we process your personal data on the following bases: (a) performance of a contract with you (e.g., processing a booking or payment you requested, verifying your identity so you can transact); (b) your consent (e.g., optional roommate-matching data, marketing notifications, location access, device permissions); (c) legitimate interests, balanced against your rights (e.g., fraud prevention, platform security, dispute resolution, service improvement); and (d) legal obligation (e.g., financial record-keeping, responding to lawful requests from Ghanaian authorities). Where we rely on consent, you may withdraw it at any time as described in Section 11.
Some of the information CampusStay collects — notably Ghana Card/Student ID numbers, ID document images, and the selfie-with-ID used for identity verification — is treated as sensitive personal data requiring extra care. We collect this data only where necessary for identity verification and fraud prevention, restrict internal access to authorized administrators on a need-to-know basis, and do not use it for any purpose other than verification, dispute resolution, and legal compliance, unless you separately consent to another use.
We do not sell your personal data. We share information only as follows:
Payments are processed by Paystack, a licensed payment service provider. When you pay, you are redirected to Paystack's secure checkout; your card/Mobile Money credentials are handled entirely by Paystack and never stored by CampusStay. CampusStay's servers only receive a transaction reference, amount, status, and payment channel via Paystack's API and webhook, verified through our Cloud Functions (initializePayment, verifyPayment, paystackWebhook, and processRefund) — our Paystack secret key is never exposed to the app. See Paystack's own privacy policy for how they handle your payment details.
CampusStay is built on Google Firebase, and your data is processed and stored using: Firebase Authentication (login/identity), Cloud Firestore (database), Firebase Storage (ID documents, property photos, video tours), Cloud Functions (Paystack integration, server-side business logic), Firebase Cloud Messaging (push notifications), Firebase Analytics, Crashlytics, and Performance Monitoring (diagnostics), and Firebase App Check (bot/abuse protection). Google Maps Platform is used to render maps and calculate distances to campus. These providers process data on our behalf under their own data processing and security commitments, and CampusStay configures access controls (Firestore/Storage security rules) to restrict who can read or write each category of data.
Administrators can access verification submissions, bookings, payments, reviews, support tickets, and disputes as needed to review identity/property verifications, resolve disputes and support requests, moderate content (including removing listings, reviews, or video tours that violate our policies), and suspend accounts that breach our Terms. Administrator actions on sensitive records (verification decisions, suspensions, refunds) are logged in an internal audit trail.
We may disclose information if required by Ghanaian law, court order, or a valid request from a government or regulatory authority, or where necessary to protect the rights, property, or safety of CampusStay, our users, or the public.
If CampusStay is involved in a merger, acquisition, financing, or sale of assets, user information may be transferred as part of that transaction, subject to this Policy (or a policy offering equivalent protections). We will notify you of any such change in ownership or control of your personal data.
The CampusStay web app uses cookies and similar technologies (such as local storage and Firebase's reCAPTCHA v3 App Check token) to keep you signed in, remember preferences, and protect against automated abuse. We also use Firebase Analytics, which may set identifiers to measure usage and understand how visitors interact with the web app. We do not currently use cookies for third-party behavioral advertising. You can control cookies through your browser settings, though disabling them may limit some features (e.g., staying logged in, or being protected by App Check).
We retain personal data for as long as your account is active and as needed to provide the service. Specifically:
If you delete your account (see Section 12), we delete or anonymize personal data that is not otherwise required to be retained for legal, accounting, or dispute-resolution purposes.
We take reasonable technical and organizational measures to protect your data, including: encryption in transit (HTTPS/TLS) for all app-to-server communication; Firestore and Storage security rules that restrict data access by role (student, manager, admin) and ownership; sensitive local data (e.g., auth tokens) stored using flutter_secure_storage rather than plain shared preferences; Firebase App Check to block traffic from unverified app instances; server-side handling of all Paystack secret keys and refund logic through Cloud Functions, never on-device; role-based administrator access limited to what is needed to perform verification, moderation, and support duties; and an internal audit log of administrator actions on verification, disputes, and account status. Passwords for email/password accounts are hashed and managed by Firebase Authentication using industry-standard algorithms — CampusStay never stores your password in plain text.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will take reasonable steps to investigate, contain, and, where required by the Data Protection Act, 2012 (Act 843), notify affected users within the applicable timeframe.
The roommate-matching compatibility score described in Section 3.6 is generated automatically by comparing self-reported profile fields (school, budget, sleep schedule, cleanliness, and lifestyle preferences). This scoring is a convenience feature to help you find potential roommates faster; it does not make any binding decision on your behalf, does not affect your access to the Platform, and you remain free to disregard match suggestions and choose any roommate you wish. CampusStay does not otherwise use fully automated decision-making that produces legal or similarly significant effects on you without an opportunity for human review (for example, account suspensions and verification rejections are reviewed by a human administrator).
Under the Data Protection Act, 2012 (Act 843) and subject to applicable exceptions, you have the right to:
To exercise these rights, contact us using the details in Section 17. We will verify your identity before actioning a request and will respond within a reasonable time and in accordance with Act 843. We may decline or limit a request where permitted by law — for example, where data must be retained for an active dispute, ongoing verification review, or a legal/financial record-keeping obligation.
You may request account deletion at any time by contacting support. We will delete or anonymize your personal data within a reasonable period, except for data we are required or permitted to retain under Section 9. Note that if your account is suspended by an administrator for violating our Terms, certain data (e.g., verification and dispute records) may be retained to document the reason for suspension and to prevent re-registration for serious violations such as fraud, regardless of a subsequent deletion request.
You can enable or disable push notifications at any time from your device settings or in-app notification preferences. Transactional notifications (e.g., booking confirmations, payment receipts, verification outcomes) may still be sent by email where necessary for the service even if push notifications are disabled, as these are not marketing communications. Where we send promotional announcements or platform updates, you may opt out at any time via your notification preferences or by using the unsubscribe option in the communication itself, without affecting transactional messages.
CampusStay is intended for university students (typically 18 and older) and property managers, and is not directed at children under 18. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, please contact us so we can investigate and delete it as appropriate.
Firebase and Google Cloud infrastructure may process and store data on servers located outside Ghana. Where this occurs, Google maintains contractual and technical safeguards for cross-border data transfers (such as Google's Cloud Data Processing Addendum and standard contractual clauses), which we rely on to help ensure your data receives an adequate level of protection consistent with the Data Protection Act, 2012 (Act 843). By using CampusStay, you acknowledge that your data may be processed outside Ghana as described in this Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
AMANITEX ENTERPRISE (trading as CampusStay Ghana) Email: amanitexenterprise@gmail.com Phone: +233 59 690 4884 Address: Accra, Greater Accra, Ghana
You may also raise a request through the Support section of the app. We aim to acknowledge privacy-related requests promptly and resolve them within a reasonable timeframe consistent with Act 843.
CampusStay may contain links to third-party sites (e.g., Paystack's checkout page, external maps, social media). We are not responsible for the privacy practices of third-party sites, and we encourage you to review their privacy policies before providing them with personal data.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will update the "Last Updated" date above and, for material changes, provide notice through the app or by email in advance of the change taking effect where practicable. Continued use of CampusStay after changes take effect constitutes acceptance of the revised Policy.
This Privacy Policy is governed by the laws of the Republic of Ghana, including the Data Protection Act, 2012 (Act 843) and the Electronic Transactions Act, 2008 (Act 772).
*This Privacy Policy should be read together with our Terms & Conditions and Help Center.*