SwiftStay

Privacy Policy

Last updated: 2026

1. Who we are

SwiftStay is operated by GTQ LLC (“we”, “us”). We provide a direct booking engine for short-term rental hosts. This policy explains how we handle your personal data when you use our website and booking services.

2. What data we collect

  • Guests: name, email, booking dates, number of guests, optional notes.
  • Hosts: name, email, business information, listing details, payout account references.
  • Booking data: dates, pricing, payment status, Stripe session identifiers.
  • Technical data: IP address, browser type, pages visited (for security and abuse prevention).

We do not store full credit card numbers. Payment processing is handled entirely by Stripe.

3. How we use your data

  • To process and manage bookings and payments.
  • To send booking confirmations and notifications to hosts and guests.
  • To maintain availability calendars and prevent double-bookings.
  • To provide customer support and resolve disputes.
  • To detect and prevent fraud, abuse, and unauthorized access.
  • To comply with legal obligations.

4. Who we share data with

  • Stripe — payment processing (guest cards, host payouts).
  • Keycloak — host authentication and session management.
  • MxRoute — transactional email delivery (booking confirmations).
  • MinIO / cloud storage — listing photos.
  • Sentry — error tracking (anonymized where possible).

We never sell your data. We do not share it with advertising networks.

5. Data retention

Booking records are retained for the duration of the host’s subscription plus 7 years for tax and legal compliance. Guest PII (name, email) is retained with the booking record. You may request deletion at any time (see below).

6. Your rights (GDPR / CCPA)

Depending on your jurisdiction, you have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data (“right to be forgotten”).
  • Restriction — limit how we process your data.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to certain processing activities.
  • Withdraw consent — for processing based on consent (e.g., analytics).

To exercise any of these rights, email privacy@swiftstay.app.

7. International transfers

Your data may be processed in the United States or other countries where our service providers operate. We rely on standard contractual clauses and adequacy decisions where required.

8. Security

We use industry-standard measures: TLS encryption in transit, encrypted session cookies, OIDC authentication with PKCE, rate limiting, audit logging, and secrets managed via HashiCorp Vault. No system is perfectly secure, but we take reasonable steps to protect your data.

9. Children’s privacy

Our services are not directed at children under 16. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified via email or a prominent notice on this page.

11. Contact

Questions about this policy? Email privacy@swiftstay.app.