Privacy Policy — identity verification
Last updated: 2026-10-10 · Version 2.0
This policy explains how Hostly (“we”, “our”) collects, processes, stores, and shares personal data when you verify your identity at the request of your host (“the controller”) — the property owner or manager of your stay.
We act as a data processor on behalf of your host. Your host decides why your data is processed (typically the check-in formalities required for your stay, such as the Moroccan guest registration form); we carry out that processing for them.
1. Who we are
The service is operated by HOSTLY SARL, Technopark, Boulevard Dammam, Bureau 315, 20000 Casablanca, Morocco (RC 667073 · ICE 003686819000003). Contact for any question about your data: legal@hostly.ma.
2. What data we process
- Identity document images — the photo of your passport, or both sides of your ID card (plus the full camera frame, used to detect photos of screens or printouts).
- Extracted document fields — name, document number, date of birth, nationality, place of birth, expiry date, sex, issuing authority, machine-readable zone.
- Selfie — a short series of frames from your front camera, including one taken as the selfie screen opens, used to compare your face with the document and to check that a live person is present.
- Check results — face-match, liveness and document-authenticity scores. We do not keep face templates beyond the comparison itself.
- Technical data — IP address and the country it indicates, device type, timestamps, and your host’s booking reference.
3. Legal basis
Processing rests on your host’s legal basis — typically a legal obligation (guest registration laws) or the performance of your booking. Comparing your face with your document is biometric processing: by starting the verification you give your explicit consent to it, and you can instead ask your host to check your identity another way. This processing is carried out in accordance with Moroccan law 09-08 and, where it applies, the GDPR (Art. 6 and Art. 9).
4. Sub-processors
We use the following providers to deliver the service:
- Amazon Web Services (storage, document reading, face comparison) — EU region (Ireland).
- Supabase — database. EU region.
- Vercel — application hosting.
None of them may use your data for their own purposes.
5. Retention
Identity-document images and selfies are deleted automatically 30 days after the verification is decided, and verifications that are started but never finished are deleted after 14 days. A minimal record (reference, status, dates) is kept as proof that the verification took place, for as long as your host’s legal obligations require.
6. Your rights
You have the right to:
- Access — receive a copy of the data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — have your data removed.
- Objection and restriction — oppose or pause the processing, for legitimate reasons.
- Complaint — lodge a complaint with a supervisory authority (CNDP in Morocco, or the authority of your country, e.g. CNIL in France).
Address requests to your host first. If they cannot resolve your request, write to legal@hostly.ma. We respond within 30 days.
7. International transfers
Your data is stored in the European Union. Where it is transferred outside Morocco or the EU/EEA, the transfer is covered by appropriate safeguards (such as the European Commission’s Standard Contractual Clauses).
8. Security
- Encrypted connections (TLS) for every exchange.
- Encrypted storage; photos are never public and are only shown through short-lived signed links.
- Each host only ever sees the verifications of their own guests.
- Results sent to your host are signed and time-stamped.
- Limited attempts and rate limiting to prevent abuse.
9. Changes
We publish any material change to this policy on this page.
10. Contact
HOSTLY SARL, Technopark, Boulevard Dammam, Bureau 315, 20000 Casablanca, Morocco — legal@hostly.ma.