Skip to content
StaydiaTripsYour account

Privacy policy

Last updated: 10 October 2026

This translation is provided for convenience; the Spanish version prevails.

1. Controller

[to be configured: company name] (NIF [to be configured: tax ID (NIF)]), address [to be configured: registered address]. Contact for data protection: ayuda@staydia.com.

2. What we process, why and on what basis

PurposeDataLegal basis
Account and sign-inName, email, password (hashed), sessionsContract
Bookings, payments and refundsBooking details, guests, amounts; card data are handled by Stripe, not by usContract
Messages between guest and host and support incidentsMessage contentContract
Guest registrationIdentity document, nationality, date of birth, address of each guestLegal obligation (Royal Decree 933/2021)
Security, fraud prevention and auditIP, access logs, actionsLegitimate interest
Tax reporting of hosts (DAC7)Host identification and incomeLegal obligation
Measurement (only if enabled)Pseudonymous browsing dataConsent

3. Recipients

Some providers may process data outside the EEA; they do so under adequacy decisions (such as the EU-US Data Privacy Framework) or standard contractual clauses.

4. Retention

5. Security

Passwords are hashed; secrets and guest registration data are stored encrypted (AES-256-GCM); every administrative action is logged.

6. Your rights

You can request access, rectification, erasure, objection, restriction and portability by writing to ayuda@staydia.com, and withdraw consent at any time. You may also complain to the Spanish Data Protection Agency (www.aepd.es). Cookies are explained in the cookie policy. Staydia is not intended for children under 14.