What are my obligations for my guests' data?
This surprises most hosts, so it is worth being direct: under the GDPR you are a data controller in your own right. Your guests' names, email addresses, phone numbers and stay dates are personal data that you decide the use of. We process it on your behalf, which makes us your processor.
That split has practical consequences.
A guest asks you, not us. If a guest wants a copy of their data or wants it deleted, the request lands with you, and the deadline is one month. We will help you answer it — write to [email protected] and we will get you what is in the system.
You need somewhere to state what you do. Guests are entitled to know what you collect, why, how long you keep it and who else sees it. A short privacy notice on your own site covers this. It does not need to be long; it needs to be true.
Our data processing agreement covers the arrangement between us. It is published at /dpa and it sets out what we do with the data you put in, who our subprocessors are, and what happens when you leave.
Be careful what you collect. Passport and ID details, where local law requires you to register guests, are a more sensitive category than an email address. Collect only what the law actually requires, keep it only as long as required, and do not keep copies in your personal email.
Marketing needs a basis. Writing to a past guest about your own property is usually defensible; adding them to a list they never asked for is not. Tell people at the point you take the address, and make it easy to stop.
This is general information rather than legal advice. If you let at scale, or across several countries, an hour with a local lawyer is worth more than any article.
Last reviewed 2026-08-26