StayHint

Privacy Policy

Last updated: 12/07/2026

This Privacy Policy describes how StayHint collects, uses and protects your personal data when you use the platform. We respect your privacy and process data in accordance with the General Data Protection Regulation (GDPR).

1. Who we are

StayHint (“we”, “us”) is the Greece-based service that operates the stayhint.com website and the application at app.stayhint.com, and is the controller of the personal data described in this policy. For any question about this policy or about how we handle your data, contact us at [email protected].

2. What data we collect

Account details: full name, email address and password (stored encrypted).

Property & guide details: the internal name of the property, the subdomain or your own domain, and the guest guide content you enter (e.g. Wi‑Fi, arrival/check‑in instructions, house rules, points of interest, photos).

Billing details: business name, VAT number, address and any other details you enter for the issuing of invoices.

Payment details: amounts, bank references and transaction identifiers handled through the payment provider.

Contact & support requests: the details and messages you submit through the relevant forms.

Usage data: an activity history (which user did what and when) for security and transparency purposes.

3. Purposes & legal basis for processing

Providing the service (building and publishing your property’s digital guest guide) — performance of a contract.

Handling payments and issuing invoices — performance of a contract and legal obligation.

Communication, support and platform security — legitimate interest.

4. The public guest guide

The guide content you enter (e.g. property information, arrival instructions, house rules, local recommendations, photos) is published publicly on your guide page and is accessible to anyone who has the link or scans the QR code — that is the purpose of the service. Do not publish third-party personal data in your guide without a lawful basis. Your account, payment and billing details are never shown publicly.

5. Recipients & third parties

The payment provider (Stripe), for processing card payments.

The email delivery provider, for notifications and invoices.

The hosting provider, with data stored in a datacenter within the European Union, in accordance with the GDPR.

Cloudflare, as a content delivery network (CDN) protecting and accelerating the platform.

Google Analytics, for anonymous/aggregated traffic measurement and service improvement.

AADE (the Greek tax authority), as an optional source for automatically retrieving billing details from a VAT number (Greek VAT numbers only, and only when you choose to use it).

We share data only with the providers above, and only to the extent required to operate the service. We do not sell, rent or otherwise make your personal data available to third parties for advertising purposes.

6. Retention period

We keep your data for as long as your account exists and for as long as our legal obligations require (e.g. tax records). Accounts and properties are deleted recoverably for a reasonable period before permanent deletion.

7. Your rights

You have the right to access, rectify, erase, restrict and port your data, as well as the right to object to processing. To exercise your rights, contact us at [email protected]. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).

8. Cookies

The platform uses cookies that are strictly necessary for it to work (sign-in, security), as well as statistics cookies through Google Analytics for anonymous traffic measurement. We do not use advertising cookies. For non-essential cookies we ask for your consent, which you can withdraw at any time.

9. Security

We take reasonable technical and organisational measures to protect your data (password encryption, secure connections, per-property access control).

10. Changes to this policy

We may update this policy. The date of the last update is shown at the top of the page.