Draft — pending legal review
This text describes in plain words how we work today. It will be finalised after a legal review, before the official launch.
Privacy policy
Last updated: 25 September 2026
We need a few details to send your request to the places to stay you picked. Here we explain what they are, what we do with them and how you stay in control.
1. Who we are
The data controller is StayRequest. Full company details (legal name, address, VAT number) will be added here before the official launch.
For anything about your data, email [email protected].
2. What data we collect
Account: name, email, password (stored hashed), phone if you add it, and the language you use.
Google sign-in: if you use it, Google gives us your name, email and an account identifier.
Requests: destination, dates, guests, budget, notes and the places to stay you picked.
Offers and bookings: price, dates, confirmation code, status.
Technical data: IP address, device type for your sessions, and error reports.
In your browser we only store your sign-in key and your settings (language, currency, appearance). We do not use advertising cookies.
3. Why we use it
To run the service: send your request, show you the offers and confirm your booking (performance of a contract, Article 6(1)(b) GDPR).
To email you about requests, offers and bookings (performance of a contract).
To keep the platform secure, prevent abuse and fix errors (legitimate interest, Article 6(1)(f)).
For accounting and tax obligations related to bookings (legal obligation, Article 6(1)(c)).
We do not send you marketing messages without your consent.
5. Transfers outside the EU
Some providers may process data outside the European Economic Area. When they do, we rely on the safeguards the GDPR provides, such as the European Commission's standard contractual clauses.
6. How long we keep it
We keep your account details and requests for as long as your account exists.
If you delete your account, we delete your personal details. If you have made bookings, we keep them anonymised for as long as accounting law requires.
Technical logs are kept for a limited time and then deleted.
7. Your rights
You have the right to access, rectify and erase your data, to restrict processing, to data portability and to object. You can do most of this yourself from your Profile. For the rest, email [email protected] and we will reply within one month.
If you think we have not respected your data, you can complain to the Hellenic Data Protection Authority (www.dpa.gr).
8. Security
All communication is encrypted (HTTPS), passwords are stored hashed and, when you change your password, we sign out your other devices.
9. Changes
If we make material changes to this policy, we will tell you by email or in the app before they take effect.