MyStay90 Visit MyStay90

MyStay90 website privacy policy

This policy explains optional website sign-in, administrator access and public service settings at mystay90.web.app.

Effective: 13 September 2026

Optional sign-in and identity

Browsing the public website does not require login. If you choose Google sign-in, Firebase receives account identity information such as your name, email, Google account identifier and, if supplied, a profile image. The site may display your name or email; it does not display your profile image. Firebase Authentication stores an account record and sign-in metadata even for visitors without administrator access.

Google permissions and data use

Only basic Google sign-in permissions are requested. The site does not request cloud-platform or access Gmail or Drive content. A Firebase ID token identifies the visitor. The designated administrator's user ID and administrator claim are checked by Firestore Security Rules before any settings write. Public settings contain provider information, messenger destinations, menu switches and enquiry-field settings.

Storage and retention

The website uses in-memory Firebase Authentication persistence. Closing or reloading the page clears that page session and any unposted administrator draft. Firebase Authentication account records remain until deleted by an authorized operator. Firestore stores the current public assistance settings, a revision number and publication time; enquiry submissions are not stored. Historical settings from the earlier development version may remain in Firebase Remote Config. Google may retain authentication and service logs under its own policies.

Sharing and service providers

Google provides sign-in, Firebase Authentication, Hosting and Firestore. These services process account, configuration and technical connection information needed to operate the site. Published provider settings are publicly readable and delivered to the mobile app. Google user data is not sold, shared with advertising networks, used for advertising, or used to train generalized AI or machine-learning models. Authorized project operators may access records allowed by their administrative permissions.

Google API data commitments

MyStay90's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information is used only to provide the administrator features described here.

Mobile app users and enquiries

The administrator website receives no passport, family, reporting-date, address or enquiry-form data from the mobile app. Enquiry values are handed to LINE or WhatsApp only when the app user chooses that action and sends the message. The mobile app's optional Analytics and device-storage practices are explained in the MyStay90 app privacy policy.

Your choices and deletion

You can browse without signing in, decline sign-in, sign out, or remove MyStay90 from your Google Account connections. Revoking access does not automatically delete your Firebase Authentication account record or previously published settings. Contact the operator to request deletion of your website account record or correction of published business contact information. Google service logs and historical configuration may remain under the service's retention rules.

Security

The website uses HTTPS. Firestore Security Rules independently enforce the designated administrator's Firebase user ID, verified Google identity and administrator claim. Changing the browser interface does not grant write access. Atomic publication checks the document version to prevent overwriting a newer edit. No private key or administrator credential is embedded in website files.

Contact and policy changes

For privacy questions or account deletion requests, contact the MyStay90 operator at the address below. Policy updates will be published on this page with a revised effective date.

mystayvisa@gmail.com