HolistayHolistay
Log in

Privacy Policy

Last updated 2026-08-12

What we hold about you, why, and what you can do about it. The list of data is what actually exists in our database rather than a generic set.

1. Who is responsible for your data

Webshot (KvK 51317915), Sint Hubertse Binnenweg 49, 5454 GA Sint Hubert, the Netherlands, is the controller of the personal data described here. For anything about your data, write to privacy@holistay.io.

2. What we hold, and why

The list below is what actually exists in our database, not a generic set copied from elsewhere.

  • Your email address, and your name if you give one — to create your account and sign you in. Without it there is no account.
  • Sign-in links, with the time they were issued and used — to let you in and to stop a link being reused.
  • Listings you publish: address, description, photographs, video link, price, availability, and the noise assessment — to show your listing.
  • Bookings and negotiations: dates, amounts, messages between you and the other party — to run the booking, and to show both sides what was agreed.
  • For listings we prepared from a public website: the source address, what we took and when, and the record of approval or removal — so that any listing can be traced to where it came from, and so a refusal is not repeated.
  • Your IP address and browser at the moment you approve such a listing — as the record that you consented, which is the only reason we keep it.
  • Your country, derived from your connection at the moment you open a destination guide, to pre-fill the passport selector. It is used and discarded, never stored.

3. What we do not hold

We do not process payments, so we hold no card numbers, bank details or payment history. We do not run advertising trackers, we do not sell data, and we do not build profiles for advertisers.

The site sets no analytics or advertising cookies. The only things stored in your browser are your theme and text-size choice and the passport you selected on a destination guide — all of which stay on your device and are never sent to us.

4. The legal basis for each of those

Running your account, your listings and your bookings is performance of a contract with you. Keeping the provenance record for a migrated listing, and keeping the site secure, is our legitimate interest in being able to show where content came from and in preventing abuse — weighed against your interests, which is why that record is limited to what is needed to prove it.

Where we ask for consent — approving a listing we prepared, or marketing email — you can withdraw it at any time, and withdrawing it is as easy as giving it.

5. Who else sees it

Other users see what you would expect: a host sees the email and messages of a guest who books or makes an offer, and a guest sees the host’s listing and messages. Your email is not shown publicly on the site.

Our processors, who act only on our instructions:

  • Cloudflare — hosting, the database, and protection against attack. Data is stored in the EU where the platform allows it.
  • Resend — sending sign-in links and notifications. It sees your email address and the content of those messages.
  • Anthropic — used only by our internal tool that drafts listing text from a property’s own public website. It receives that website’s text, never guest data, and the content is not used to train models.
  • Unsplash — supplies the destination photographs. It does not receive anything about you.

6. Where it goes

Some of these processors are established outside the European Economic Area. Where data is transferred there, it is covered by the European Commission’s standard contractual clauses or an adequacy decision.

7. How long we keep it

Account data for as long as you have an account, and then deleted. Bookings and the messages attached to them for as long as we may need them for tax or a dispute, typically seven years.

Sign-in links expire in fifteen minutes and are cleared afterwards. Claim links for a prepared listing expire after thirty days. If you tell us a prepared listing is not yours, the listing and its photographs are deleted immediately and only the record of the refusal is kept, so that we do not contact you about it again.

8. Your rights

You can ask for a copy of your data, correct it, have it deleted, restrict or object to how we use it, and receive it in a portable form. Write to us and we will answer within a month.

If you think we have handled your data badly, tell us first at privacy@holistay.io. You also have the right to complain to the data protection authority where you live or work.

9. Security, and being straight about it

Sign-in links are single-use and short-lived. Claim tokens are stored only as a hash, so a copy of our database does not hand anyone a working link. Traffic is encrypted in transit.

No system is perfectly secure. If a breach affects you, we will tell you and the regulator within the time the law requires.

Questions about this page: hello@holistay.io

Explore

Where to?Destination guidesAll staysGuides

Hosting

Become a hostEarnings calculator

How it works

Price negotiationVideo toursCompared to Airbnb

Legal

Terms of servicePrivacy policy

© 2026 Holistay · Webshot, Sint Hubertse Binnenweg 49, 5454 GA Sint Hubert, the Netherlands · KvK 51317915 · VAT NL002515432B15