Skip to content

Draft — pending legal review

This text describes in plain words how we work today. It will be finalised after a legal review, before the official launch.

Privacy policy

Last updated: 25 September 2026

We need a few details to send your request to the places to stay you picked. Here we explain what they are, what we do with them and how you stay in control.

1. Who we are

The data controller is StayRequest. Full company details (legal name, address, VAT number) will be added here before the official launch.

For anything about your data, email [email protected].

2. What data we collect

Account: name, email, password (stored hashed), phone if you add it, and the language you use.

Google sign-in: if you use it, Google gives us your name, email and an account identifier.

Requests: destination, dates, guests, budget, notes and the places to stay you picked.

Offers and bookings: price, dates, confirmation code, status.

Technical data: IP address, device type for your sessions, and error reports.

In your browser we only store your sign-in key and your settings (language, currency, appearance). We do not use advertising cookies.

3. Why we use it

To run the service: send your request, show you the offers and confirm your booking (performance of a contract, Article 6(1)(b) GDPR).

To email you about requests, offers and bookings (performance of a contract).

To keep the platform secure, prevent abuse and fix errors (legitimate interest, Article 6(1)(f)).

For accounting and tax obligations related to bookings (legal obligation, Article 6(1)(c)).

We do not send you marketing messages without your consent.

4. Who we share it with

The places to stay you pick: they see your name and the request details. When you book, they also receive your email and, if you gave it, your phone number.

Providers that help us run the service, only as far as needed: hosting and file storage, email delivery, error monitoring and, if you use it, Google for sign-in.

We never sell or rent your data.

5. Transfers outside the EU

Some providers may process data outside the European Economic Area. When they do, we rely on the safeguards the GDPR provides, such as the European Commission's standard contractual clauses.

6. How long we keep it

We keep your account details and requests for as long as your account exists.

If you delete your account, we delete your personal details. If you have made bookings, we keep them anonymised for as long as accounting law requires.

Technical logs are kept for a limited time and then deleted.

7. Your rights

You have the right to access, rectify and erase your data, to restrict processing, to data portability and to object. You can do most of this yourself from your Profile. For the rest, email [email protected] and we will reply within one month.

If you think we have not respected your data, you can complain to the Hellenic Data Protection Authority (www.dpa.gr).

8. Security

All communication is encrypted (HTTPS), passwords are stored hashed and, when you change your password, we sign out your other devices.

9. Changes

If we make material changes to this policy, we will tell you by email or in the app before they take effect.

Back to top