Privacy policy
Last updated: Aug 11, 2026
This page sets out what personal data Stayed collects, on what basis, how long it is kept and what you can ask for. It is written to be read.
1.Who processes your data
Questions and requests under this policy: info@stayed.io.
2.What we collect
- Account: email, display name, role and language. Optionally a city, phone number and short bio. An account is also created for you when you book, with the email you entered. There is no password; you sign in with a link to that same address.
- Bookings: name, email, phone, dates, how many guests, your note to the venue and the amount. The venue you book sees them.
- Reviews: rating, title, text, month of stay and trip type. For a review without an account: a name and an email for contact.
- Review votes: a signed cookie that carries no name, and a hash of the IP address.
- Job applications: name, email, phone, cover letter and a CV file.
- Business accounts: the organisation, its places, photos, and the Paddle customer and subscription identifiers. Card details never pass through us and are not stored here.
- Technical: the IP address is stored hashed so abuse can be investigated. The host's server logs contain the address and the request.
- A callback request from the business page: a name, and whichever of phone or email you left.
3.Why we collect it, and on what basis
- Performance of a contract: the account, posting a review, running a subscription and its paid features.
- Legitimate interest: protection against bots and fake reviews, platform security, and basic traffic statistics.
- Consent: applying to a job listing. Withdrawable at any time, without affecting what was done before.
- Legal obligation: accounting and tax records for payments.
4.Cookies
There are no advertising cookies and nothing here follows you between sites. That is also why there is no consent banner: every cookie below is necessary for the service to work.
Page views are counted through Vercel Analytics. It sets no cookie and creates no identifier that follows you elsewhere.
- Sign-in cookie: keeps the session for up to 30 days.
- Voting cookie: allows one vote per review without identifying you by name.
- Signed anti-bot token: lives up to an hour, the time it takes to fill in a form.
5.How long we keep it
- IP hash on a review or a vote: 90 days, then deleted automatically.
- A job application and the attached CV: until the consent period ends. The file is deleted along with the record.
- Sessions and sign-in links: until they expire.
- An account with deletion requested: a 30-day wait so a mistake can be undone, then it is deleted.
- Accounting records for payments: the period set by law.
- A callback request: up to 12 months after the last contact, then deleted.
6.Who else sees your data
We use providers that process data on our behalf, under contract and with access only to what they need. Data is never sold and never handed over for advertising.
Some of these providers process data outside the EU. Those transfers run on the European Commission's standard contractual clauses.
- Vercel: application hosting and storage for uploaded files.
- Neon: the database.
- Google Workspace: outgoing email, including sign-in links.
- Paddle.com Market Ltd: payments. Paddle is the merchant of record and an independent controller for payment data, see its privacy notice.
- An employer with a listing: sees the data of applicants to that listing only.
7.What is public and what is not
- Public: the review, the rating, the display name and the owner's reply.
- Your email address is never public.
- Job applications are not public. Only the employer behind the listing sees them.
- After an account is deleted, its reviews remain without a name and without a link to a profile.
8.Your rights
Write to info@stayed.io from your account email. We answer within one month.
Deletion you can also ask for yourself, from the account screen, without writing to us. The same screen calls it off while the waiting period is still running.
If you believe we are handling your data unlawfully, you can complain to the Commission for Personal Data Protection.
- Access to the data we hold about you.
- Correction of inaccurate data.
- Erasure.
- Restriction of processing.
- Portability in a machine-readable form.
- Objection to processing based on legitimate interest.
- Withdrawal of consent you have given.
9.Security
Traffic runs over HTTPS. No passwords are stored, because signing in uses a one-time link. Access to the admin screens is by role.
If a breach puts your rights at risk, we notify the Commission for Personal Data Protection within 72 hours, and you where the risk is high.
10.Children
The service is not intended for children under 16. If we learn that an account belongs to a child, we delete it.
11.Changes to this policy
Changes appear on this page with a new date at the top. Material ones are emailed as well.