Privacy
Privacy Policy
1. Who we are
Stayvenia (“we”, “us”, “our”) is a hospitality software company. We build and operate guest-experience software for hotels and restaurants.
Stayvenia is in the process of incorporating as an Estonian private limited company (OÜ) via e-Residency; the application has already been submitted. This policy will be updated with the registered company number and address once incorporation is confirmed.
- Data Controller: Stayvenia OÜ (registration pending)
- Registered address: [Company registration pending — Stayvenia OÜ, Estonia]
- Contact: privacy@stayvenia.com
2. What this policy covers
This policy explains how we collect, use, store, and protect personal data when:
- You visit our website (stayvenia.com)
- You use our software products as a hotel or restaurant operator (“Customer”)
- A hotel or restaurant uses our software and you interact with it as a guest (“Guest”)
3. Data we collect and why
3a. Website visitors
- What: IP address, browser type, pages visited, time spent (via analytics)
- Why: to understand how our website is used and improve it
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR)
- How long: 12 months
3b. Customers (hotel and restaurant operators)
- What: name, email address, company name, billing information, login credentials, usage data
- Why: to provide our software services, process payments, and provide support
- Legal basis: Contract (Article 6(1)(b) GDPR)
- How long: duration of the contract + 3 years for billing records (legal obligation)
3c. Guests (people staying at or visiting our customers’ properties)
We process guest personal data on behalf of our hotel and restaurant customers. In this relationship:
- The hotel/restaurant is the Data Controller — they decide what data to collect and why
- Stayvenia is the Data Processor — we process that data only on their instructions
Guest data we may process on behalf of customers:
- What: name, email address, room/booking reference, feedback responses, ratings, satisfaction scores, language preference
- Why: to deliver the guest feedback and experience services our customers have contracted us for
- Legal basis: as directed by the Customer (hotel/restaurant) — typically consent or legitimate interests
- How long: as instructed by the Customer, subject to a maximum of 365 days for personal data, after which it is automatically anonymised. Anonymised aggregate data (ratings, scores without names) may be retained indefinitely for analytics.
4. How we share data
We do not sell personal data. We share data only with:
- Service providers who help us operate (e.g. Supabase for database hosting, Resend for email delivery, Vercel for hosting) — all under data processing agreements
- Our customers — their own data, as part of the service
- Legal authorities — only when legally required
All our service providers are GDPR-compliant and data is processed within the EU/EEA where possible. Our database is hosted in the EU (Ireland).
5. Your rights under GDPR
If you are in the EU/EEA, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (“right to be forgotten”)
- Restrict how we process your data
- Object to processing based on legitimate interests
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time (where consent is the legal basis)
For guests: please contact the hotel or restaurant directly, as they are the Data Controller for your data. They will action your request through our system.
For customers and website visitors: contact us at privacy@stayvenia.com. We will respond within 30 days.
As Stayvenia is incorporating in Estonia, our lead supervisory authority will be the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI), with whom we will register once Stayvenia OÜ is formed (aki.ee). You also have the right to lodge a complaint with the supervisory authority in your EU/EEA country of residence.
6. Data security
We protect personal data using:
- Encryption in transit (HTTPS/TLS) and at rest
- Row-Level Security (RLS) ensuring each hotel can only access their own data
- Access controls — staff access is role-based and logged
- Regular security testing and audits
7. Cookies
Our website uses minimal cookies for functionality and basic analytics. We do not use advertising cookies or sell data to advertisers. [Add full cookie table when cookie banner is implemented]
8. Changes to this policy
We will notify customers of material changes by email at least 30 days before they take effect. The latest version is always available at stayvenia.com/privacy.
9. Contact
- For any privacy questions: privacy@stayvenia.com
- For data subject requests: privacy@stayvenia.com
- For urgent security issues: security@stayvenia.com