Privacy Policy
Last updated: 2026-09-29
This policy explains what personal data Stayolo collects, why, who we share it with, how long we keep it, and the rights you have over it. It covers both hosts (our customers) and guests (people who book a stay through a host's website).
1. Who is responsible for your data
These roles matter, because they determine who you exercise your rights against.
| Data | Controller | Our role |
|---|---|---|
| Host account data (name, email, login, plan, billing) | Stayolo | Controller |
| Guest booking data (name, email, phone, stay dates, messages) | The host who owns the property | Processor, on the host's instructions |
| Aggregate product usage we collect for our own decisions | Stayolo | Controller |
In plain terms: we are responsible for your host account. For guest data the host is responsible, and we process it on their behalf under the Data Processing Agreement.
Contact: Finest Spaces Studio Ltd, 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF · Company no. 16561913 · [email protected]
2. What we collect
If you are a host:
- Account: name, email address, hashed password, email-verification status, creation date.
- Property content you enter or import: descriptions, photos, amenities, prices, policies, house rules, address and approximate coordinates.
- Billing: subscription plan and interval, and identifiers from our payment provider. We never see or store your card number.
- Payout connection: the identifier of the payment account you connect, so bookings pay you directly.
- Operational records: calendar sync URLs and their status, promo codes, email delivery logs.
If you are a guest:
- Booking details: name, email, phone, country, stay dates, number of guests, price and payment status.
- Messages you exchange with your host through the platform.
- Any review you choose to leave after a stay.
- Questions you type into the on-site booking assistant, where the host has enabled it.
Everyone: a strictly necessary session cookie when signed in, aggregate page-view counts per property — a daily total, not tied to you — and, on our own pages and only if you accept it, Google Analytics.
We do not knowingly collect special-category data (health, religion, political opinions, biometrics), and we ask that you do not enter it into free-text fields such as notes or messages.
3. Why we use it, and our legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account | Host account data | Contract — 6(1)(b) |
| Build and host your booking website | Property content | Contract — 6(1)(b) |
| Take and manage bookings | Guest booking data | Contract — 6(1)(b), on the host's instructions |
| Send booking confirmations and stay emails | Guest contact + booking details | Contract — 6(1)(b) |
| Take subscription payments | Billing identifiers | Contract — 6(1)(b) |
| Keep the service secure, prevent abuse, rate-limit | IP address, session data | Legitimate interests — 6(1)(f) |
| Improve the product using aggregate usage counts | Non-identifying view counts | Legitimate interests — 6(1)(f) |
| Answer support requests | Whatever you send us | Legitimate interests — 6(1)(f) |
| Meet accounting, tax and legal obligations | Transaction records | Legal obligation — 6(1)(c) |
| Optional marketing email to hosts | Host email address | Consent — 6(1)(a), withdrawable at any time |
4. Who we share it with
We do not sell personal data, and never have. We share it only with the categories of provider needed to run the service:
| Category | What they receive | Why |
|---|---|---|
| Payment processing | Guest and host payment details, transaction data | To take guest payments and bill subscriptions |
| Email delivery | Recipient address and message content | To deliver booking and account email |
| Hosting and database | Service data, encrypted in transit | To run the application |
| Listing import | The listing URL you submit | To read a listing you ask us to import |
| AI service providers | Property details and the guest's typed question | To power the optional on-site booking assistant |
| The host of the property you booked | Your booking and contact details | So they can host your stay — the purpose of the service |
A current list of our sub-processors is kept at /subprocessors, where hosts can also ask to be notified before we add a new one.
We may also disclose data where legally required — a court order or regulator — or to establish or defend legal claims.
5. International transfers
Some providers process data outside the UK and the European Economic Area. Where they do, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK law applies, together with additional safeguards such as encryption in transit and data minimisation. The categories affected and the safeguard applied to each are listed on the sub-processors page. You may request a copy of the relevant clauses from [email protected].
6. How long we keep it
| Data | Retention |
|---|---|
| Host account | While the account is open, then 30 days after deletion is requested |
| Booking records | 7 years from the stay, to meet accounting and tax obligations |
| Guest contact details held for a host | Until the host deletes them, or 3 years after the last stay |
| Messages between host and guest | 3 years after the stay |
| Email delivery logs | 12 months |
| Page-view counts (aggregate, non-identifying) | 24 months |
| Password reset / email verification tokens | 1 hour and 24 hours; deleted on use |
| Backups | Rolling 30 days, after which deleted records fall out automatically |
7. Your rights
If you are in the UK, EEA or Switzerland you have the rights below. They apply to hosts and guests alike — though for guest data it is often quicker to ask the host directly, since they control it.
- Access (Art. 15) — a copy of the personal data we hold about you, plus the information in this policy.
- Rectification (Art. 16) — correction of anything inaccurate or incomplete.
- Erasure (Art. 17) — deletion, where no overriding obligation requires us to keep it. Booking records subject to tax law are the usual exception.
- Restriction (Art. 18) — ask us to pause processing while a dispute or accuracy check is resolved.
- Portability (Art. 20) — your data in a structured, machine-readable format, or sent to another provider where technically feasible.
- Objection (Art. 21) — object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds.
- Withdraw consent (Art. 7(3)) — at any time where processing relies on consent. This does not affect processing already carried out.
- No automated decision-making (Art. 22) — we do not make decisions producing legal or similarly significant effects about you by automated means alone.
- Complain (Art. 77) — to your local supervisory authority, or to the Information Commissioner's Office (ICO). You need not come to us first, though we would like the chance to help.
To exercise any of these, email [email protected]. We respond within one month, extendable by two further months for complex requests — we will tell you if we need that extension. There is no charge unless a request is manifestly unfounded or excessive. We may ask for enough information to confirm your identity before acting.
8. Cookies
We use a strictly necessary cookie to keep you signed in, which needs no consent because you asked to sign in. On our own marketing pages and dashboard we also use Google Analytics, which sets cookies and therefore loads only after you accept it — decline and nothing is requested from Google. It never runs on a host’s property website. We use no advertising cookies and no cross-site tracking, and you can change your answer at any time on the cookies page.
9. Security
- Passwords are stored using a salted, computationally hard hash — never in readable form.
- All traffic is encrypted in transit with TLS.
- Sessions use a signed, HTTP-only cookie that JavaScript cannot read.
- Email confirmation and password-reset links are single-use and expire.
- Card details never reach our servers; they are handled by our payment provider.
- Access to production data is limited to those who need it to operate the service.
If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform affected users without undue delay.
10. Children
The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
Changes are posted here with the date above updated. Where a change materially affects your rights we will notify account holders by email before it takes effect.
Questions about this policy, or about data we hold? Email [email protected] and we will come back to you.