Last updated: 23 July 2026
This privacy policy covers the "Hola Stay" application (the "App") — an internal tool for managing short-term rental apartments (bookings, settlements, invoices, property documents). The App runs on mobile devices (Android, iOS), Mac computers and in a web browser. This policy explains what data the App processes, where it is stored and who it is entrusted to.
*Polska wersja / Polish version: Polska wersja
The controller of personal data processed in the App is:
For any matter regarding personal data and this policy, please contact contact@holastay.eu.
The App is a business tool for the owner and the team servicing the apartments. It is not intended for guests or the general public.
Access requires signing in with three credentials: company number, e-mail address and password. Accounts are created only by an administrator — the App offers no self-registration. Each company has its own separated data space; a user of one company cannot access another company's data.
Data is stored in two places at the same time:
Cloud data is written into a space assigned to the company number and protected by server-side access rules — reading and writing are possible only for signed-in members of that company.
Attachments (scans, photos, generated PDF documents) are stored on the device and, to the extent enabled by the administrator, also in the company file storage in the European Union.
| Processor | Scope | Location |
|---|---|---|
| Google Ireland Limited (Firebase: Firestore, Cloud Storage, Cloud Functions, Authentication; Google Cloud Vision) | storing and synchronising App data, automatic booking import, reading text from scanned documents (OCR) in the browser and desktop versions | European Union |
| IdoBooking | booking system — source of reservations (read-only) | as stated in the provider's documents |
| OpenAI — only when the "cloud AI" mode, disabled by default, is switched on | generating assistant replies | outside the EEA |
Document scanning in the browser and desktop versions reads text from the image using Google Cloud Vision in the European Union region — the image is transmitted solely to read its text and is not retained outside the company file storage. On phones, reading happens entirely on the device.
Firebase services are configured so that App data is stored on servers in the European Union. If, within the provider's services, data is transferred outside the European Economic Area, this takes place on the basis of standard contractual clauses approved by the European Commission.
The App downloads bookings from the IdoBooking system through an iCal feed — read-only. The App neither writes nor modifies anything in IdoBooking.
Downloading happens in two ways: directly from the App, and periodically (roughly every 15 minutes) through a server-side service running in the European Union, which writes bookings into the company cloud. Thanks to this the schedule stays current even when nobody has the App open.
The booking system provider (IdoBooking) is a separate entity — its processing rules are described in that provider's documents.
The App does not track users, does not use an advertising identifier (IDFA), contains no ads and no third-party analytics tools. It does not profile users or guests.
Data processed in the App is never sold or shared for marketing purposes. Beyond the processors listed in section 5, data may be passed on only to:
"Cloud AI" assistant mode (optional, disabled by default): if the administrator enables "AI (cloud)" in Settings and enters an API key, the content of the query and property data (e.g. Wi-Fi, hours, address) are sent to the model provider (OpenAI) to generate a reply. When the mode is off, the assistant works locally and no data is sent to that provider.
The administrator can export the company data into a single backup file and store it outside the App (e.g. on a drive or external medium). Such a file contains personal data — responsibility for storing it securely rests with the administrator.
Some data is subject to mandatory archiving required by law and is kept for the period required by it, in particular: (a) guest registration data (traveller register — SES/Guardia Civil) and (b) settlement documentation and invoices (accounting and tax regulations). We do not delete this data before the legally required period has passed.
Remaining data is kept for as long as it is needed for the day-to-day operation of the apartments — both in the company cloud and in the local copy on devices. Deleting data in the App also removes it from the company cloud.
Data is processed on the basis of the controller's legitimate interest (handling bookings and settlements) and legal obligations (traveller register, accounting and tax documentation).
Data subjects (including guests) have the right to: access their data, rectification, erasure, restriction of processing, objection and data portability, as well as the right to lodge a complaint with a supervisory authority (in Spain: Agencia Española de Protección de Datos). To exercise these rights, please contact: contact@holastay.eu.
The rights to erasure and objection are limited to the extent that the law imposes an obligation to retain data (including the SES traveller register and accounting/tax documentation). In that scope, data is deleted only after the legally required period has passed.
We apply the following safeguards:
Accounts are created and removed by the administrator. A request to delete an account or data can be submitted to contact@holastay.eu or through the form available at: Account & data deletion
Deletion covers the account data and the company data linked to that account, except for data subject to mandatory legal archiving (section 11), which is deleted once the required period has passed.
The App is a business tool and is not directed at children. We do not knowingly collect children's data. Data of minors may appear only to the extent required by registration regulations (traveller register), when a minor is a participant of a stay.
This policy may be updated. The current version is available in the App (Settings → Privacy and data) and at https://hola-stay.web.app/polityka-prywatnosci/en. The date of the last update appears at the top of the document.
For matters regarding privacy and personal data: HolaStay — contact@holastay.eu — +34 625 088 586