Privacy Policy
Privacy Policy
Last updated: July 2026
Your privacy matters to us. This Privacy Policy explains in detail what personal data StayIt collects, why we collect it, on which legal bases, who we share it with, whether it leaves the UK or the EEA, how long we keep it, how we protect it, and which rights you have under the UK General Data Protection Regulation and the Data Protection Act 2018, the EU General Data Protection Regulation (GDPR) — which applies to our users in the European Union — and other applicable national law. Please read it together with our Terms & Booking Policies.
1. Data controller and contact
The controller of your personal data is RENT ABOUT LTD, a private limited company incorporated in England and Wales on 12 November 2023 under company number 15277425, with its registered office at Daresbury Innovation Centre, Keckwick Lane, Daresbury, Warrington, WA4 4FS, United Kingdom ("StayIt", "we", "us").
For all privacy matters — questions, requests, complaints — contact us at info@nordora.net. Where a Data Protection Officer is appointed, they can be reached at the same address. We are a fully digital service and handle privacy requests through the email channel; we will always confirm receipt of a rights request.
2. Personal data we collect
2.1 Data you give us directly
- Account and profile data: first and last name, email address, phone number, password (stored only as a cryptographic hash — we cannot read it), profile photo, date of birth, place of residence, spoken languages and any "about" description you choose to publish on your profile.
- Identity verification data: data from your government-issued identity document and the outcome of verification checks. Verification is performed on our behalf by a specialised third-party verification provider acting under a data-processing agreement; we receive the verification result and only the minimum document data needed to record that you are verified.
- Listing data (hosts): property address and location, photos, descriptions, amenities, sleeping arrangements, prices, availability calendars, house rules, cancellation option and payout account details.
- Booking and stay data: reservations, check-in and check-out dates, number of guests, unique booking references, instalment schedules and their payment status, modifications, cancellations, reviews and ratings you give and receive.
- Communications: messages exchanged with other users through the platform, correspondence with our support team — including the Support & Help form (first name, last name, email, phone, booking reference and your message) — and email correspondence with us.
- Payment and payout data: billing name, selected payment method, transaction amounts, currencies, timestamps and unique transaction references; for hosts, payout method and account identifiers. Full card numbers never touch our servers — they are collected and processed directly by our licensed payment service providers in their own secure environments.
2.2 Data collected automatically
- Technical data: IP address, device type and identifiers, operating system, browser type and version, screen size, language and time-zone settings.
- Usage data: pages viewed, searches performed (destination, dates, guests), listings opened, features used, referring pages, session timestamps and interaction logs.
- Cookies and similar technologies: see section 11 for the full explanation of what we set and why.
- Security and authentication data: login events and their outcomes, password-reset events, and passkey (WebAuthn) public-key credentials. A passkey credential stored with us contains a public key and technical metadata only — it contains no biometric data; your fingerprint or face never leaves your device.
2.3 Data we receive from third parties
- Verification outcomes and anti-fraud signals from our identity verification provider;
- payment confirmations, failures, refunds, chargebacks and dispute data from payment service providers;
- claim-related data from our insurance partner when an insurance or Payment Protection case is opened;
- basic profile data (name, email, profile photo) from Google or Facebook if you choose social sign-in;
- information other users provide about you — for example a host reporting damage, or a guest reporting an issue with a stay.
3. Purposes and legal bases for processing
- Operating your account and the marketplace — registration, profiles, listings, search, messaging, reviews. Legal basis: performance of a contract (Art. 6(1)(b)).
- Processing bookings — reservations, booking references, confirmations, modifications, cancellations and refunds. Legal basis: performance of a contract.
- Payments, instalments and payouts — executing transactions through licensed providers, generating unique transaction references, operating monthly instalment schedules and secure payment links, releasing and documenting host payouts. Legal basis: performance of a contract; legal obligation (Art. 6(1)(c)) for payment, accounting and record-keeping rules.
- Identity verification and fraud prevention — verifying users through our third-party provider before key actions; detecting, investigating and preventing fraudulent, abusive or illegal activity, including off-platform payment attempts. Legal basis: legitimate interests (Art. 6(1)(f)) in a safe and trusted marketplace; legal obligation where verification is required by law.
- Insurance and Payment Protection — arranging property insurance for eligible stays, handling claims with our insurance partner, paying hosts under Payment Protection and pursuing recovery of unpaid amounts from defaulting guests. Legal basis: performance of a contract; legitimate interests in operating the protections we promise.
- Customer support — receiving Support & Help requests, using your booking reference to locate your case, resolving complaints and disputes, and keeping records of how they were resolved. Legal basis: performance of a contract; legitimate interests.
- Service communications by email — booking confirmations, receipts, payment reminders, instalment payment links, security alerts, verification outcomes and policy updates. These are operational messages, not marketing, and cannot be opted out of while you use the service. Legal basis: performance of a contract.
- Marketing communications — news, recommendations and offers, only where you have opted in (or, where permitted, for our own similar services with an opt-out); every message contains an unsubscribe link. Legal basis: consent (Art. 6(1)(a)); legitimate interests where soft opt-in applies.
- Legal, tax and regulatory compliance — bookkeeping and audit, responding to lawful requests from courts and authorities, sanctions screening where applicable, and reporting of platform seller data to tax authorities under DAC7 and equivalent UK rules. Legal basis: legal obligation.
- Improving and securing the platform — aggregated analytics, performance monitoring, debugging, testing and development of new features, and security monitoring. Legal basis: legitimate interests; consent where required for non-essential cookies.
Where we rely on legitimate interests we balance them against your rights and freedoms, and you may object at any time (see section 9).
4. Automated decision-making
We use automated checks to flag risk — for example unusual payment patterns, repeated failed verifications or signals associated with fraud. Flags normally lead to human review rather than automatic exclusion. Where an automated decision would produce legal or similarly significant effects for you, you have the right to obtain human intervention, to express your point of view and to contest the decision by contacting info@nordora.net.
5. Who we share your data with
- The other party to your booking. When a booking is confirmed, host and guest each receive what is needed for the stay: name, profile photo, contact details, booking dates and the booking reference. Before confirmation, only limited profile information is visible.
- Identity verification provider. A specialised third-party service that verifies identity documents on our behalf, as our processor, under a data-processing agreement.
- Payment service providers. Licensed institutions — card acquirers, PayPal, bank-transfer providers — that execute payments under PSD2 and UK payment regulation. For the execution of the transaction they act as independent controllers under their own privacy policies.
- Insurance partner. Our regulated insurer, for arranging the included property cover and handling claims; claim files include the booking data and evidence relevant to the claim.
- Debt recovery. Where Payment Protection has paid a host and the guest's debt has passed to us, we may share the necessary data with debt-collection agencies or legal representatives to recover the amount.
- IT service providers. Hosting, database, email delivery, backup, monitoring and security vendors, acting as processors under data-processing agreements.
- Professional advisers and authorities. Lawyers, auditors and accountants under confidentiality; tax authorities (including DAC7 reporting), courts, regulators and law-enforcement bodies where the law requires or permits it.
- Corporate transactions. In a merger, acquisition, restructuring or asset sale, data may be transferred to the successor subject to confidentiality safeguards and this Policy.
We do not sell your personal data, and we do not share it with third parties for their own advertising.
6. International transfers
We store data primarily within the United Kingdom and the European Economic Area. Transfers between the UK and the EEA are covered by the applicable adequacy decisions. Where a provider processes data outside the UK and the EEA, we ensure an adequate level of protection through adequacy regulations or decisions, the UK International Data Transfer Agreement or Addendum, or the European Commission's Standard Contractual Clauses, with supplementary measures where necessary. You may request a copy of the relevant safeguards via info@nordora.net.
7. How long we keep your data
- Account and profile data: for the life of your account; on deletion, removed or anonymised except where retention is required below.
- Booking, payment, payout and instalment records: for the statutory accounting and tax retention periods — generally 6 years in the UK and up to 10–11 years where other national law applies.
- Identity verification records: only as long as necessary for the verification purpose and any legal retention duty; document images are held by the verification provider under its own retention schedule.
- Insurance and Payment Protection files: for the limitation periods applicable to the underlying claims.
- Support and dispute correspondence: as long as needed to handle the matter and to establish, exercise or defend legal claims.
- Security logs: for a limited rolling period proportionate to the security purpose.
- Marketing consents and suppression lists: for as long as needed to honour your choice.
When a retention period ends, data is deleted or irreversibly anonymised.
8. Your rights
- Access (Art. 15): obtain confirmation that we process your data, and a copy of it together with the key information about the processing.
- Rectification (Art. 16): have inaccurate data corrected and incomplete data completed — most profile data you can edit yourself in your account.
- Erasure (Art. 17): have your data deleted where no legal ground for retention remains — note that booking, payment and tax records must be kept for statutory periods.
- Restriction (Art. 18): require us to hold but not otherwise process data in defined situations, for example while a contested accuracy issue is checked.
- Portability (Art. 20): receive data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection (Art. 21): object to processing based on legitimate interests on grounds relating to your situation, and to direct marketing at any time — in which case we stop marketing to you immediately.
- Withdraw consent (Art. 7(3)): at any time, with effect for the future, without affecting the lawfulness of prior processing.
- Complain: to a supervisory authority — for users in the United Kingdom this is the Information Commissioner’s Office (ICO, ico.org.uk); users in the European Union may complain to the data protection authority of their country of residence, place of work or the place of the alleged infringement.
To exercise any right, email info@nordora.net from the address linked to your account (or provide equivalent proof of identity — we must not hand your data to someone impersonating you). We respond within one month; for complex or numerous requests the GDPR allows an extension of up to two further months, and we will tell you if we need it. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.
9. Security
We protect personal data with technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS/HTTPS) across the platform;
- passwords stored only as strong cryptographic hashes;
- support for passkeys (WebAuthn) — phishing-resistant, passwordless sign-in; biometric data never leaves your device;
- segregation of payment processing to licensed providers, so full card data never reaches our systems;
- role-based access controls and the need-to-know principle for staff access;
- logging, monitoring and alerting on authentication and administrative actions;
- unique references on every booking and transaction, making records traceable and auditable;
- regular backups and tested recovery procedures.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to you, we will notify the competent supervisory authority within 72 hours as required by Articles 33–34 GDPR, and we will inform you directly where the risk is high.
10. Email communications
As a fully digital service we communicate primarily by email. Operational emails — booking confirmations, receipts, instalment payment links, payment reminders, verification results, security alerts and policy notices — are part of the service and are sent to your registered address for as long as you use the platform. Marketing emails are separate, optional, and always contain a working unsubscribe link. Keep your email address up to date; notices sent to your registered address are deemed delivered.
11. Cookies and similar technologies
- Strictly necessary cookies — session and authentication cookies, security tokens (including CSRF protection), load-balancing and your language and currency choices. These are required for the platform to function and are set without consent, in line with the ePrivacy rules.
- Functional cookies — remember non-essential preferences to improve your experience; used with your consent where required.
- Analytics cookies — help us understand aggregate usage (which pages are visited, where errors occur) so we can improve the platform; used only with your consent where required, and configured to minimise identification.
You can manage cookies at any time through your browser settings and, where shown, our cookie controls. Blocking strictly necessary cookies may break core functions such as login and checkout. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
12. Children
StayIt is intended for adults. You must be at least 18 to create an account, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact info@nordora.net and we will delete it.
13. Third-party links and services
The platform contains links to third-party services — for example the payment pages of our payment providers, the verification flow of our identity partner, or social sign-in. Those services process your data under their own privacy policies, which we encourage you to read. This Policy covers only processing for which RENT ABOUT LTD is the controller.
14. Changes to this Policy
We may update this Policy from time to time — for example when we add features, change providers or when the law changes. For material changes we will notify you in advance by email or by a prominent notice on the platform, and the "Last updated" date at the top of this page will always tell you which version you are reading. Continued use of the platform after the effective date constitutes acknowledgement of the updated Policy.
This Policy is provided for transparency under Articles 13–14 GDPR and equivalent UK provisions. It does not constitute legal advice. In case of discrepancies between translations, the English version prevails unless mandatory local law provides otherwise.
