Privacy Policy
Last updated: April 25, 2026
This Privacy Policy explains how ScanStay ("we", "us", "our") collects, uses, stores and protects personal data when you use our website, dashboard and digital welcome books (the "Service"). We are committed to processing your data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable laws.
1. Who we are
ScanStay provides a SaaS platform that allows short-term rental hosts (Airbnb, Booking.com and similar) to create digital welcome books accessible via QR code. For data protection purposes, ScanStay acts as a data controller for account and billing data, and as a data processor for content that hosts publish in their welcome books.
For any privacy-related question, contact us at privacy@scanstay.io.
2. What data we collect
2.1 Account data (hosts)
- Email address, name and password (hashed) — when you sign up.
- Subscription plan, billing details and payment status — managed via our payment provider Stripe.
- Properties, listings, photos, Wi-Fi credentials, instructions, upsell services and any other content you add to your welcome books.
2.2 Guest data (visitors of welcome books)
- Anonymous scan analytics: timestamp, language, coarse device info. We do not collect names, emails or precise location of guests.
- Upsell orders: if a guest places an order through a welcome book, we store the items requested, optional notes and contact details the guest voluntarily provides (e.g. phone number for confirmation).
2.3 Technical data
- IP address, browser type, operating system and pages visited — used for security, fraud prevention and aggregate analytics.
- Cookies and similar technologies — see Section 7.
3. How we use your data
We process personal data for the following purposes and on the following legal bases:
- Providing the Service (contractual necessity, Art. 6(1)(b) GDPR) — creating and maintaining your account, hosting welcome books, processing orders.
- Payments and billing (contractual necessity) — processing subscription payments via Stripe.
- Customer support (legitimate interest) — responding to your inquiries.
- Service improvement (legitimate interest) — aggregate analytics, debugging, security monitoring.
- Legal compliance (Art. 6(1)(c) GDPR) — keeping invoices and tax records as required by law.
- Marketing (consent, Art. 6(1)(a) GDPR) — only when you explicitly opt in. You can withdraw consent at any time.
4. Sharing your data
We do not sell your personal data. We share data only with trusted sub-processors that help us operate the Service:
- Supabase (database & authentication) — EU region.
- Stripe (payment processing) — Ireland / USA, with Standard Contractual Clauses.
- Google Cloud / AI providers (translations, AI suggestions) — only the content you submit for translation; no account or guest data attached.
- Email providers (transactional email delivery).
We may also disclose data when required by law, court order, or to protect our rights and the safety of our users.
5. International transfers
Where data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses approved by the European Commission and require adequate technical and organisational safeguards.
6. Data retention
- Account data — kept while your account is active and for up to 30 days after deletion (then permanently erased, except as required by law).
- Billing records — retained for the period required by tax law (typically 5–10 years).
- Scan analytics — anonymised and aggregated; retained for up to 24 months.
- Order data — retained while the order is active and for 12 months thereafter.
7. Cookies
We use strictly necessary cookies for authentication and session management, and optional analytics cookies to understand how the Service is used. You can manage cookie preferences via your browser settings or our cookie banner where applicable.
8. Your rights (GDPR)
You have the right to:
- Access your personal data and request a copy;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict or object to processing;
- Data portability (receive your data in a structured, machine-readable format);
- Withdraw consent at any time;
- Lodge a complaint with your local Data Protection Authority.
To exercise any of these rights, email privacy@scanstay.io. We respond within 30 days.
9. Security
We implement industry-standard security measures including encryption in transit (TLS), encrypted databases, hashed passwords, role-based access control and regular security audits. Despite these measures, no system is 100% secure; we encourage you to use strong, unique passwords.
10. Children
The Service is not directed to individuals under 16. We do not knowingly collect data from children. If you become aware that a child has provided us with data, please contact us.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or via the dashboard at least 14 days before they take effect.
12. Contact
ScanStay
Email: privacy@scanstay.io