StayBooks · Last updated 25 September 2026
StayBooks provides bookkeeping tools for short-term-rental hosts and property managers at staybooks.app. This policy explains what personal data we handle, why, on what legal basis, and what rights you have.
The data controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS], Poland (NIP [NIP]). For any question or request about your data, contact privacy@staybooks.app.
When you sign in — with Google or with an email and password — we receive your email address, a unique account identifier and, for Google sign-in, your name. We use these to authenticate you and to keep your data separate from every other account.
Everything you enter or import: reservations, invoices you issue, expenses and vendor bills, maintenance records, apartment and commission settings, and owner and buyer details you save for invoicing. This is stored in our backend so it is available across your devices and to collaborators you invite.
If you use the “Ask us” chat button on our homepage, we receive the question you write, the email address you give us so we can reply, and your browser's preferred language so we can answer in it. You do not need an account for this. To stop the form being abused, we also count messages per visitor per hour using a one-way hash of your IP address; the address itself is not stored.
If you use payout validation, you upload a bank statement export (CSV or XLSX) from your bank. We parse it in order to match incoming transfers against the payouts recorded in your account. What we store from it is the transaction data needed for that matching — dates, amounts, currency and the transaction description or reference — together with which payouts you confirmed or rejected. We do not ask for, and have no access to, your online banking credentials, and we cannot move money.
PDF invoices you attach to an expense are stored so you can open them again later.
Your imports and records can contain personal data about people who are not StayBooks users — typically a guest's first name on a reservation, and the name and contact details of an apartment owner or a vendor you invoice. You decide what to put into the product; we process it only to provide the service to you. Channel exports are stored as they are imported, and we do not enrich them or use them for any purpose of our own.
Subscriptions are processed by Stripe. We store your subscription status, plan, apartment count and renewal dates. Card details are entered directly with Stripe and never pass through StayBooks.
We do not use advertising or third-party analytics, we do not track you across other websites, and we do not sell or rent your data or share it with data brokers.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service: storing, displaying, reconciling and exporting your bookkeeping data | Performance of a contract (Art. 6(1)(b)) |
| Sharing access with collaborators you invite, and sending them an invitation email | Performance of a contract (Art. 6(1)(b)) |
| Taking payment and managing your subscription | Performance of a contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c)) |
| Service emails about your trial or subscription ending | Legitimate interest in keeping you informed about your own account (Art. 6(1)(f)) |
| Answering a question you send through the chat button on our website | Steps taken at your request before entering into a contract, or legitimate interest in answering enquiries (Art. 6(1)(b) and (f)) |
| Keeping the service secure and diagnosing faults | Legitimate interest in a reliable, secure service (Art. 6(1)(f)) |
| Understanding which features are used, and where people get stuck, so the product can be improved | Legitimate interest in improving the service (Art. 6(1)(f)) |
We do not send marketing email and do not operate mailing lists.
Data is stored in Google Firebase — Authentication, Cloud Firestore, Cloud Storage and Cloud Functions — hosted in the European Union (europe-west1). Access rules mean only you and the collaborators you invite can read your account's data.
| Processor | What it handles |
|---|---|
| Google Firebase | Authentication, database, uploaded files, hosting, backend functions |
| Stripe | Subscription payments and card details (entered directly with Stripe) |
| Twilio SendGrid | Delivery of invitation and subscription emails, and of website questions to our inbox |
| Anthropic | Answering questions you put to the in-app assistant (see below) |
| PostHog | Usage analytics, hosted in the European Union (see below) |
These providers act on our instructions under data processing agreements. Some are established in the United States; where personal data is transferred outside the European Economic Area, it is covered by the European Commission's Standard Contractual Clauses and the safeguards those providers maintain.
StayBooks includes an assistant you can open to ask questions about the product or about your own records. It is answered by a language model operated by Anthropic, PBC in the United States. Nothing is sent to Anthropic unless you open the assistant and ask something — it is not running in the background, and it does not read your data unless a question requires it.
When you ask a question, what is sent is: the question itself and the rest of that conversation, a summary of your account (apartment and owner names, how many records you hold, the period your data covers), and the results of whatever read-only lookups are needed to answer. Those results can include reservation rows — which carry guest first names only, as explained above — along with payout, invoice and maintenance figures for the period you asked about.
What is never sent: the bank statement files you upload, the invoice PDFs you upload, your card details, and your password. The assistant can only read; it cannot change, delete or send anything on your behalf, and it cannot see any account but your own.
Anthropic processes this to produce the answer and does not use it to train its models. Conversations are held in your browser for the length of the session and are not stored by us once you close it.
To understand which parts of StayBooks are actually used and where people get stuck, we record a small set of actions using PostHog, on their European Union hosting. This data does not leave the EEA.
What is recorded: the pages you open, and a fixed set of actions you take — creating an account, setting up an apartment's commission or an owner, completing an import, reconciling a bank statement, saving an invoice or changing its status, saving a manual reservation, exporting a report or your reservations, recording a fee or a maintenance issue, uploading a supplier invoice, starting or cancelling a subscription, and inviting a collaborator. We do not record your clicks or keystrokes generally — only the actions in that list.
What those records contain is counts and categories only: how many reservations an import covered, how many lines an invoice had, the currency code, the billing interval you chose, the access level on an invitation. They do not contain guest names, apartment or owner names, invoice amounts, payout figures, or anything you imported or uploaded. Each record is linked to your account identifier, email address and name, so that a sequence of actions can be read as one account's rather than mixed with everyone else's.
We do not record your screen. Session recording is switched off both in our PostHog project and in the application code, so no recording of your bookkeeping screens is ever made.
No analytics cookie is set, and nothing is stored on your device for this purpose. Your actions are attributed to your account using the identifier you are already signed in with. You can object to this processing at any time using the contact details below.
We keep your data for as long as your account is active. You can edit or delete individual records at any time, remove collaborators, or ask us to delete your account and everything in it. Invoices and records we must keep for tax or accounting law are retained for the period that law requires. Questions sent through the website chat button are deleted a year after they are sent. Email delivery logs at SendGrid, payment records at Stripe and usage analytics at PostHog expire according to those providers' own retention periods.
Under the GDPR you have the right to:
.xlsx at any time, without asking us;Write to privacy@staybooks.app to exercise any of these. If you believe we have handled your data unlawfully, you may complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl), or to the authority where you live.
Data is encrypted in transit and at rest by our infrastructure providers. Access to each account's data is enforced by server-side security rules rather than by the application alone, so another user cannot read your data even by manipulating the client. Access to production systems is limited to the operator.
If this policy changes, the updated version is posted at this URL with a new "last updated" date. If a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect.
Questions or requests about this policy or your data: privacy@staybooks.app.
StayBooks is an independent tool and is not affiliated with, endorsed by, or sponsored by Airbnb, Inc. or Booking.com. "Airbnb" and "Booking.com" are trademarks of their respective owners.