Privacy

Privacy Policy

This Policy describes the information Laloke actually handles, why it is used, and the providers that support the marketplace.

Version:
2026-08-20
Effective:
August 20, 2026

This Privacy Policy explains how Osalution LLC, operator of the Laloke product, handles information through the Laloke website, marketplace, and supporting services. It does not replace notices supplied directly by independent providers such as Stripe.

We handle account and profile details such as email, display name, role, Host type, and password-derived security records. Hosts provide location, address, coordinates, availability, capacity, amenities, equipment, prices, listing media, and private verification media. Users may submit booking details, ratings, messages, reports, cancellation reasons, and support communications.

Laloke stores one-way password hashes, hashed refresh and password-reset tokens, encrypted authenticator secrets for Hosts and administrators, session and security-setup state, suspension state, and security audit records. The browser keeps a short-lived access token in memory or session storage, a non-secret session hint, and functional cart or preference data. The refresh token is placed in an HttpOnly cookie.

We process session and equipment windows, selected equipment, itinerary, status, canonical times, timezone offset, cancellation and rating eligibility, and integer-cent price, fee, earnings, refund, and settlement records needed to operate bookings.

Stripe hosts card entry and payment processing. Laloke does not intentionally receive or store card PAN or CVC. We do store payment and connected-account identifiers, status, amount, fee, transfer, refund, and reconciliation information needed to create Checkout, confirm payment, pay Hosts, resolve failures, and provide support.

If you choose current-location discovery, your browser asks permission and provides coordinates used to center marketplace search. Laloke does not claim to continuously track your device location. When you submit destination text, the server sends the query to Geoapify for geocoding. The service logs a hash rather than the raw destination query in its application event, and resolved coordinates and a display label can appear in shareable Browse URL state.

Listing media may be public when an eligible listing is published. Host verification media remains private and is exposed only through authorized, time-limited reads. Booking participants and authorized operators can access applicable messages. Ratings, reports, blocks, moderation state, and read state are processed to operate marketplace communication, reputation, and safety features.

We process request and route information, canonical network identity, record and provider identifiers, timestamps, error and transition context, availability and performance metrics, audit events, and aggregated marketplace analytics. Logs are intended to exclude passwords, raw tokens, authenticator seeds, reset links, signed media URLs, and private message bodies. Infrastructure providers may maintain separate access and security logs.

Information is used to provide accounts, discovery, listings, bookings, payments, payouts, messages, ratings, support, moderation, fraud and security controls, availability and capacity enforcement, service analytics, provider reconciliation, legal compliance, and platform maintenance.

We disclose information to the Customer, Host, or authorized operator as required for their role and booking relationship; to service providers that process it for Laloke; when reasonably necessary to protect users, enforce the service, or investigate misuse; and when required by law. Public listing fields are deliberately allowlisted and exclude Host security, billing, moderation, and private verification data.

Current provider categories include Stripe for payments and connected-account onboarding; Render for application and PostgreSQL hosting; AWS S3 for configured media-object storage; and Geoapify, using OpenStreetMap-derived data, for production destination and address geocoding. Email delivery and other infrastructure providers may receive the limited data needed for configured delivery or operations.

Laloke retains records for the operational, security, dispute, transaction, and legal purposes for which they are needed. Database backups and provider copies can have separate lifecycles. Laloke does not currently publish a comprehensive fixed retention schedule or offer instant self-service account deletion. Contact support for an account, privacy, access, correction, or deletion request; the response will depend on applicable law and records that must be retained.

Laloke uses role and ownership checks, explicit response allowlists, password hashing, encrypted authenticator material, protected refresh cookies, signed browser-to-API identity, provider verification, upload validation, and operational audit records. No online service can guarantee absolute security, and these controls are not a third-party compliance certification.

You can decline browser geolocation and search by destination instead. You can manage certain account and listing information through the product and can contact support about account or privacy requests. Browser controls can limit cookies or storage, but blocking strictly functional session data may prevent sign-in or Checkout from working.

The current version and effective date appear above. Material revisions use a new version, and authenticated users may be asked to acknowledge the current Privacy Policy before normal marketplace activity. Questions or requests can be sent to support@osalution.com. Jurisdiction-specific retention, privacy-rights, and regulatory wording should receive external legal review before broad public launch.