Legal

Privacy Policy

Effective date: 18 July 2026 · Last updated: 18 July 2026

This Privacy Policy explains how StayInBio ("we", "us") collects, uses, and protects personal data when you use our website, booking pages, and related services (the "Service"). StayInBio is the data controller for the processing described here, within the meaning of the EU General Data Protection Regulation (GDPR).

1. Data we collect

From hosts:

  • Account data: name, email address, password (hashed), profile photo.
  • Listing data: property descriptions, photos, pricing, availability calendars.
  • Billing data: subscription status and payment details, processed by our payment provider — we never store full card numbers.

From guests:

  • Booking request data: name, email address, phone number (if provided), requested dates, party size, and any message you send to a host.

Automatically:

  • Usage and device data: IP address, browser type, pages visited, timestamps, and approximate location, collected via server logs and cookies (see section 6).

2. Why we process it (purposes and legal bases)

  • Providing the Service — creating your account, publishing booking pages, delivering booking requests to hosts (performance of a contract, Art. 6(1)(b) GDPR).
  • Billing — processing subscription payments and invoices (contract and legal obligation, Art. 6(1)(b) and (c)).
  • Security and improvement — preventing fraud and abuse, debugging, and improving the Service (legitimate interest, Art. 6(1)(f)).
  • Communications — service emails such as booking notifications and account notices (contract); product news only with your consent, which you can withdraw at any time (Art. 6(1)(a)).
  • Legal compliance — tax, accounting, and responding to lawful requests (legal obligation, Art. 6(1)(c)).

3. Hosts as independent controllers

When a guest submits a booking request, we deliver that data to the host. The host processes guest data for their own purposes (managing the booking, payment, and stay) and acts as an independent data controller for that processing. StayInBio is not responsible for how hosts handle guest data outside the Service. Guests should direct questions about a host's data handling to the host.

4. Sharing of data

We do not sell personal data. We share it only with:

  • Hosts, when you submit a booking request to them;
  • Service providers acting as processors under contract (hosting, email delivery, payment processing, analytics);
  • Authorities, when required by law or to protect our rights, users, or the public;
  • A successor entity in the event of a merger, acquisition, or asset sale, with notice to you.

5. International transfers

We store data within the European Economic Area where possible. Where a service provider processes data outside the EEA, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, with additional safeguards where needed.

6. Cookies

We use strictly necessary cookies for login sessions and security, and — only with your consent — analytics cookies to understand how the Service is used. You can withdraw cookie consent at any time via the cookie settings link in the footer, and manage cookies in your browser. We do not use third-party advertising cookies.

7. Retention

  • Account and listing data: for as long as your account exists, then deleted or anonymised within 30 days of account deletion.
  • Booking request data: 24 months after the request, unless the host deletes it sooner.
  • Billing records: 7 years, as required by Dutch tax law.
  • Server logs: up to 12 months.

8. Security

We apply appropriate technical and organisational measures, including encryption in transit (TLS), hashed passwords, access controls, and regular backups. No system is completely secure; if a breach affects your rights and freedoms, we will notify you and the supervisory authority as required by law.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected and, in certain cases, data erased;
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time, without affecting prior processing.

To exercise these rights, email privacy@stayinbio.com. We respond within one month. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.

10. Children

The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced by email or in-product before they take effect. The "Last updated" date above reflects the current version.

12. Contact

StayInBio · Amsterdam, the Netherlands
Privacy questions: privacy@stayinbio.com

© 2026 StayInBio