Privacy Policy

Last updated: 2026-09-29

This policy explains what personal data Stayolo collects, why, who we share it with, how long we keep it, and the rights you have over it. It covers both hosts (our customers) and guests (people who book a stay through a host's website).

1. Who is responsible for your data

These roles matter, because they determine who you exercise your rights against.

DataControllerOur role
Host account data (name, email, login, plan, billing)StayoloController
Guest booking data (name, email, phone, stay dates, messages)The host who owns the propertyProcessor, on the host's instructions
Aggregate product usage we collect for our own decisionsStayoloController

In plain terms: we are responsible for your host account. For guest data the host is responsible, and we process it on their behalf under the Data Processing Agreement.

Contact: Finest Spaces Studio Ltd, 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF · Company no. 16561913 · [email protected]

2. What we collect

If you are a host:

  • Account: name, email address, hashed password, email-verification status, creation date.
  • Property content you enter or import: descriptions, photos, amenities, prices, policies, house rules, address and approximate coordinates.
  • Billing: subscription plan and interval, and identifiers from our payment provider. We never see or store your card number.
  • Payout connection: the identifier of the payment account you connect, so bookings pay you directly.
  • Operational records: calendar sync URLs and their status, promo codes, email delivery logs.

If you are a guest:

  • Booking details: name, email, phone, country, stay dates, number of guests, price and payment status.
  • Messages you exchange with your host through the platform.
  • Any review you choose to leave after a stay.
  • Questions you type into the on-site booking assistant, where the host has enabled it.

Everyone: a strictly necessary session cookie when signed in, aggregate page-view counts per property — a daily total, not tied to you — and, on our own pages and only if you accept it, Google Analytics.

We do not knowingly collect special-category data (health, religion, political opinions, biometrics), and we ask that you do not enter it into free-text fields such as notes or messages.

3. Why we use it, and our legal basis

PurposeDataLegal basis (GDPR Art. 6)
Create and run your accountHost account dataContract — 6(1)(b)
Build and host your booking websiteProperty contentContract — 6(1)(b)
Take and manage bookingsGuest booking dataContract — 6(1)(b), on the host's instructions
Send booking confirmations and stay emailsGuest contact + booking detailsContract — 6(1)(b)
Take subscription paymentsBilling identifiersContract — 6(1)(b)
Keep the service secure, prevent abuse, rate-limitIP address, session dataLegitimate interests — 6(1)(f)
Improve the product using aggregate usage countsNon-identifying view countsLegitimate interests — 6(1)(f)
Answer support requestsWhatever you send usLegitimate interests — 6(1)(f)
Meet accounting, tax and legal obligationsTransaction recordsLegal obligation — 6(1)(c)
Optional marketing email to hostsHost email addressConsent — 6(1)(a), withdrawable at any time

4. Who we share it with

We do not sell personal data, and never have. We share it only with the categories of provider needed to run the service:

CategoryWhat they receiveWhy
Payment processingGuest and host payment details, transaction dataTo take guest payments and bill subscriptions
Email deliveryRecipient address and message contentTo deliver booking and account email
Hosting and databaseService data, encrypted in transitTo run the application
Listing importThe listing URL you submitTo read a listing you ask us to import
AI service providersProperty details and the guest's typed questionTo power the optional on-site booking assistant
The host of the property you bookedYour booking and contact detailsSo they can host your stay — the purpose of the service

A current list of our sub-processors is kept at /subprocessors, where hosts can also ask to be notified before we add a new one.

We may also disclose data where legally required — a court order or regulator — or to establish or defend legal claims.

5. International transfers

Some providers process data outside the UK and the European Economic Area. Where they do, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK law applies, together with additional safeguards such as encryption in transit and data minimisation. The categories affected and the safeguard applied to each are listed on the sub-processors page. You may request a copy of the relevant clauses from [email protected].

6. How long we keep it

DataRetention
Host accountWhile the account is open, then 30 days after deletion is requested
Booking records7 years from the stay, to meet accounting and tax obligations
Guest contact details held for a hostUntil the host deletes them, or 3 years after the last stay
Messages between host and guest3 years after the stay
Email delivery logs12 months
Page-view counts (aggregate, non-identifying)24 months
Password reset / email verification tokens1 hour and 24 hours; deleted on use
BackupsRolling 30 days, after which deleted records fall out automatically

7. Your rights

If you are in the UK, EEA or Switzerland you have the rights below. They apply to hosts and guests alike — though for guest data it is often quicker to ask the host directly, since they control it.

  • Access (Art. 15) — a copy of the personal data we hold about you, plus the information in this policy.
  • Rectification (Art. 16) — correction of anything inaccurate or incomplete.
  • Erasure (Art. 17) — deletion, where no overriding obligation requires us to keep it. Booking records subject to tax law are the usual exception.
  • Restriction (Art. 18) — ask us to pause processing while a dispute or accuracy check is resolved.
  • Portability (Art. 20) — your data in a structured, machine-readable format, or sent to another provider where technically feasible.
  • Objection (Art. 21) — object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds.
  • Withdraw consent (Art. 7(3)) — at any time where processing relies on consent. This does not affect processing already carried out.
  • No automated decision-making (Art. 22) — we do not make decisions producing legal or similarly significant effects about you by automated means alone.
  • Complain (Art. 77) — to your local supervisory authority, or to the Information Commissioner's Office (ICO). You need not come to us first, though we would like the chance to help.

To exercise any of these, email [email protected]. We respond within one month, extendable by two further months for complex requests — we will tell you if we need that extension. There is no charge unless a request is manifestly unfounded or excessive. We may ask for enough information to confirm your identity before acting.

8. Cookies

We use a strictly necessary cookie to keep you signed in, which needs no consent because you asked to sign in. On our own marketing pages and dashboard we also use Google Analytics, which sets cookies and therefore loads only after you accept it — decline and nothing is requested from Google. It never runs on a host’s property website. We use no advertising cookies and no cross-site tracking, and you can change your answer at any time on the cookies page.

9. Security

  • Passwords are stored using a salted, computationally hard hash — never in readable form.
  • All traffic is encrypted in transit with TLS.
  • Sessions use a signed, HTTP-only cookie that JavaScript cannot read.
  • Email confirmation and password-reset links are single-use and expire.
  • Card details never reach our servers; they are handled by our payment provider.
  • Access to production data is limited to those who need it to operate the service.

If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform affected users without undue delay.

10. Children

The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

Changes are posted here with the date above updated. Where a change materially affects your rights we will notify account holders by email before it takes effect.

Questions about this policy, or about data we hold? Email [email protected] and we will come back to you.