Legal
Privacy Policy
Last updated: 27 June 2026
This page is maintained by Stayr to answer common privacy questions about the Stayr platform. It is not legal advice and is not a certification. If anything is unclear, please contact us.
1. Who we are
Stayr ("Stayr", "we", "us") provides AI-built direct-booking websites for short-stay hosts. We are the data controller for the personal data described in this policy.
Legal entity: People Matters BV — VAT/Company nr. BE0883971589 — Vismarkt 11, 3000 Leuven, Belgium.
Privacy contact: privacy@stayr.ai
2. What we collect
- Account data: name, email, password hash, profile picture, display name.
- Property content you submit: listing URL, photos, descriptions, location, pricing, booking links.
- Contact & support messages you send us via the contact form.
- Billing data: subscription status and Stripe customer ID. Card details are processed by Stripe — we never see them.
- Usage data: pages viewed, features used, retrieval-score events, error logs.
- Technical data: IP address, browser/user-agent, device, language.
3. Why we use it (legal bases)
- To provide the service — performance of contract (GDPR Art. 6(1)(b)).
- To process payments & subscriptions — contract and legal obligation (Art. 6(1)(b)/(c)).
- To improve the product & AI features — legitimate interest (Art. 6(1)(f)).
- To send service emails — contract.
- Optional analytics cookies — your consent (Art. 6(1)(a)), withdrawable at any time.
4. Subprocessors
We rely on the following processors. Each handles data only on our instructions:
- Lovable Cloud (database, auth, storage) — hosted in the EU.
- Stripe — payment processing and billing.
- Lovable AI Gateway — AI generation and retrieval-score features.
5. How long we keep data
- Account & property data: as long as the account exists, then deleted within 30 days of closure.
- Contact form messages: up to 24 months.
- Invoices & billing records: 7 years (legal accounting requirement).
- Server & error logs: up to 90 days.
6. International transfers
Data is hosted primarily in the EU. Where a subprocessor (e.g. Stripe) processes data outside the EEA, transfers are protected by Standard Contractual Clauses approved by the European Commission.
7. Cookies
We use two categories of cookies / local storage:
- Strictly necessary — sign-in session, security, language. These are always on.
- Optional analytics — only set after you click "Accept all" in the cookie banner.
You can change your choice anytime on the Cookie preferences page.
8. Your rights under GDPR
If you're in the EU/EEA or UK you have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your account and data (right to erasure).
- Export your data in a machine-readable format (portability).
- Object to or restrict certain processing.
- Lodge a complaint with your local data protection authority.
Signed-in users can export or request deletion from Account → Privacy & data (or email privacy@stayr.ai). We respond within 30 days.
9. Security
Data is encrypted in transit (TLS) and at rest. Access is restricted to authorised staff. We monitor for vulnerabilities continuously. No online service is 100% secure — if you spot an issue, please email security@stayr.ai.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced by email or in-app at least 14 days before they take effect.