1. The short version
We collect what is needed to make and manage a booking, keep your account working and improve the service. We do not sell personal data, we do not run third-party advertising trackers, and we keep data only as long as we need it.
2. What we collect
Depending on how you use Stayora:
- Account data: name, email, password hash, preferred currency
- Booking data: guest names, contact details, dates, payment brand and last four digits (never the full card number)
- Preferences stored on your device: theme, currency, guest wishlist
- Technical data: IP address, browser type and pages visited, used for security and aggregate analytics
3. How we use it
To process bookings and payments, send confirmations and service messages, prevent fraud, respond to support requests and understand which parts of the site work well. We only send marketing email if you opt in, and every message has an unsubscribe link.
5. How long we keep it
Account data until you delete your account. Booking records for the period required by tax law (typically 7 years), anonymised after the stay where possible. Technical logs for 90 days.
6. Your rights
You can access, correct, export or delete your data from Account > Settings, or by contacting us. You can object to processing and complain to your local data-protection authority.
7. Security
Passwords are hashed with bcrypt, sessions are cookie-based and expire, and all traffic is encrypted in transit. Card details never touch our servers.
8. About this demo
This build runs locally with synthetic data. Any details you type into forms are kept in the local database or logged to the console for demonstration only.
Questions about any of this? Contact us and a human will answer.