Legal

Privacy policy

Last updated:

YStay handles sensitive data: identities, stays, supporting documents, inspection evidence. Our default posture is confidentiality — private storage, mediated and signed access, hosting in Europe, and logging of sensitive transitions.

This policy is written from our record of processing activities. It describes each processing activity separately: what we collect, why, who has access to it and how long we keep it.

Data controller

The YStay platform is published by [TO BE COMPLETED: registered company name], [TO BE COMPLETED: legal form] with a share capital of [TO BE COMPLETED: share capital], registered under number [TO BE COMPLETED: company registration number], EU VAT number [TO BE COMPLETED: EU VAT number], whose registered office is located at [TO BE COMPLETED: registered office address].

The company is being incorporated: the fields above are displayed as placeholders until registration is effective. They will be filled in, on this page and in the legal notice, in the same deployment.

For any question about your personal data and to exercise your rights: privacy@ystay.app. For anything else: contact@ystay.app.

Who is responsible for what

YStay does not play the same role for every piece of data it handles. The split depends on the processing activity, and it determines who you should address your rights to.

  • YStay is the data controller for its own customer relationship: host accounts and team members, billing and subscriptions, support requests, launch mailing list and compliance Radar alerts.
  • YStay is the data controller for the guest account itself — sign-in details, language, preferences, device tokens, any insurance certificate uploaded: an account spans several hosts and belongs to the running of the platform. YStay is, by contrast, a processor acting on behalf of the host for that guest's stay data: reservation, access, check-in and check-out, StayProof evidence, messages with the host. The host is the controller towards their guest; we process on their behalf and on their instructions.
  • YStay is a processor acting on behalf of the landlord for long-term rental applications (YStay Classic). A rental applicant is not a guest: the landlord decides the purpose and the retention of their file.
You areAddress your rights toOur role
A host, or a member of a host teamYStay — privacy@ystay.appData controller
A guest — account, preferences, supportYStay — privacy@ystay.appData controller
A guest — reservation, stay, evidenceThe host you booked withProcessor for the host
A long-term rental applicantThe landlord you applied toProcessor for the landlord
Subscribed to the launch list or to Radar alertsYStay — privacy@ystay.appData controller

Host accounts

Purpose: allow a host — an individual or a company — to create and manage their account, properties and listings, reservations, team and billing.

  • Data subjects: individual hosts, representatives of host companies, members invited to an account (manager, team member, read-only).
  • Data: identity (name, display name), contact details (phone, postal address), company details (legal name, company number, VAT number, invoice legal mentions), contract signature image, payment provider customer identifier, trial and suspension status with its reason.
  • Recipients: authorised YStay staff; yourself and the members you invite, within the limits of their role; Stripe for billing; netcup for database hosting.
  • Isolation: every business query is scoped to the owning account. A host never sees another host's data.
  • We measure how your account uses the platform — features switched on, steps completed — in order to improve the service. Those measurements rely on our legitimate interest, cover account data only, and are never shared or sold.

Members of a host team

Purpose: allow a person invited by a host — manager, team member, read-only — to access their account within the limits of their role, and attribute every action to its author.

  • Data subjects: the people a host invites onto their account, whether employees, agents or contractors.
  • Data: name, email address, role granted, date and version of the individual terms of use accepted, activity logs (who did what, and when).
  • Data controller: YStay. You are not a party to the contract between YStay and the host who invites you, but we are indeed the ones processing this data, to run their account and keep the platform secure.
  • Retention: with the host's account, according to the periods set out below; your personal access ends as soon as the account holder withdraws it.

Guest accounts

Purpose: allow a guest to manage their reservation, access codes and messages from an account or a token link, and to upload an insurance certificate when the host requires one.

  • Data subjects: guests and primary occupants of a reservation.
  • Data: identity (first name, last name), phone, language, default billing address, payment provider customer identifier, device tokens for mobile notifications, insurance certificate with its validity dates and the reason for any rejection.
  • Recipients: authorised YStay staff; the host of the reservation concerned; Expo for notification delivery; Stripe where a payment is involved.
  • Uploaded documents are held in private storage: they are never served from a public URL, only through a signed, time-limited link.
  • Your stay data — reservation, access, check-in and check-out, property inspection, messages with your host — does not fall under this section: it is processed on behalf of your host, who is the controller for it. The corresponding notice is shown to you at booking time, before you enter your contact details.

Reservations and stays

Purpose: manage the life cycle of a short-term reservation — dates, occupants, price, status, originating channel — and the related stay, from arrival to departure.

  • Data subjects: the primary guest of a reservation, named even without an account, and the host.
  • Data: stay dates, number of adults, children and infants, name, email and phone of the primary contact, language, arrival notes, total amount and currency, price breakdown, status, channel (direct or distribution platform), public reservation token.
  • Recipients: the host who owns the reservation, authorised YStay staff, the originating distribution platform where the reservation comes from one (Airbnb, Booking.com and others, through Su-API/STAAH), and the payment provider where applicable.

Rental applications (long-term letting)

Purpose: assemble and review an application for a long-term rental, with automated field extraction to speed up the landlord's review.

This is the most sensitive processing activity on the platform. The automated analysis never decides: it extracts, classifies and flags. The decision to accept or reject an application belongs to the landlord, who may override anything the tool produces.

  • Data subjects: rental applicants.
  • Data: last name, first name, email, phone, employment type, employer, monthly income, DossierFacile status and reference; and, through automated extraction, the content of the document itself — raw extracted text, recognised fields, category and confidence level.
  • Recipients: the landlord who owns the application, authorised YStay staff, DossierFacile where the applicant requests a verification.
  • Before you upload your first document, the applicant area shows you a dedicated notice: who is responsible for your file (the landlord), which documents may be asked of you — the list in French decree No. 2015-1437 of 5 November 2015 is exhaustive —, what the automated analysis does and does not do, and how to withdraw your application. You accept it before uploading anything.

StayProof evidence (property inspections)

Purpose: build a check-in and check-out inspection and evidence of the stay that can be relied on in a dispute — deposit, damage — with an AI-assisted comparison between arrival and departure.

That analysis is bounded, explainable and editable by the host: it never decides on its own and produces no sanction. The host remains the author of the approval or the rejection.

When an inspection is closed, a cryptographic fingerprint of the file — photos, answers, signature — is written to the audit log, where it is kept for thirty-six months like the other sensitive transitions. It makes a later export of the file possible to authenticate, and it remains readable in the log after the file itself has been deleted, for as long as those thirty-six months have not elapsed.

  • Data subjects: the guest (respondent, signatory) and the host (approval or rejection).
  • Data: checklist answers, photos, guest signature, completion, approval and rejection timestamps with the reason, generated summary, result of the comparison analysis.
  • Recipients: the host concerned, authorised YStay staff, Anthropic for the comparison analysis.
  • Retention: 24 months after the stay by default; the host, who is the controller for this processing, may extend that period to up to five years from the settings of their account (account holder). Thirty days before deletion, the host is notified and can download the complete file.

Support requests

Purpose: handle support requests from hosts, team members and guests, and alert our on-call rota when access is blocked during an ongoing stay, outside business hours.

Two channels coexist, and they do not collect the same thing.

  • From your account area (host, team member or signed-in guest): the content of your messages, the files you attach, the category, priority, status and context of the request. Every time our team opens a thread, that access is logged.
  • From the public form, without signing in (“I can no longer sign in”, “I am requesting the deletion of my account”): your message and, instead of your email address, a cryptographic fingerprint of it. Your address is not stored in clear text in any column. A resume link lets you continue the conversation.
  • That second channel is deliberately minimised: the person using it is not identified as a customer. Exchanges there are kept for 30 days after the last message, against 24 months for signed-in channels.
  • Recipients: authorised YStay staff; Resend for email delivery and the OVH SMS gateway for on-call alerts.

Launch mailing list (newsletter)

Purpose: let you know when the platform opens and send you occasional product news.

  • Data controller: YStay.
  • Legal basis: your consent, confirmed by a click in the email we send you (double opt-in). Without that confirmation your address is never used for a mailing, and it is deleted after 30 days.
  • Data collected: your email address, the language and the page you came from. No IP address, no advertising profiling, no sale or sharing with third parties for prospecting purposes.
  • Retention: until you unsubscribe, then 3 years so that consent and its withdrawal can be evidenced (CNIL recommendation for prospects). Records are then deleted automatically.
  • Withdrawal: every email carries an unsubscribe link that requires no sign-in, and the withdrawal is immediate.
  • Hosting: European Union. Recipient: Resend, for delivery.

Compliance alert (Radar)

Purpose: let you know when the short-term rental rules of your municipality change, or when we check them for the first time. Your assessment never triggers any prospecting.

  • Data controller: YStay.
  • Legal basis: your consent, given through a checkbox that is never pre-ticked and then confirmed by a click in the email we send you (double opt-in). Without that confirmation your address is never used for a mailing, and it is deleted after 30 days.
  • Data collected: your email address, the INSEE code of the municipality you want to be alerted about (five characters, for example 74010), the language and the page you came from. No IP address, no advertising profiling, no sale or sharing with third parties for prospecting purposes.
  • What we never keep: the result of your assessment. No status, no risk amount, none of your answers — the calculation runs in your browser and nothing leaves it. No column in our database could hold them.
  • Retention: until you unsubscribe, then 3 years so that consent and its withdrawal can be evidenced (CNIL recommendation for prospects). The municipality disappears with the record, on the same schedule: it creates no additional retention.
  • Withdrawal: every email carries an unsubscribe link that requires no sign-in, and the withdrawal is immediate — you can also use the unsubscribe page.
  • Changing the municipality you follow: a new request from Radar fills in the municipality if you had not declared one. To change it, unsubscribe and subscribe again, or write to us: we do not let an anonymous form redirect the alerts of an already confirmed address.
  • Hosting: European Union. Recipient: Resend, for delivery.

Audit logs

Purpose: record who did what and when on the platform's sensitive transitions — reservation, lock opening, check-in and check-out, incident, signature, document, a support request opened by our team — for evidence and security purposes.

These logs are kept for 36 months. They are only accessible to authorised YStay staff; internal reads of a support thread are never exposed to the host.

Retention periods

The periods below are the ones we apply. The end of the relationship is the termination date where one exists; failing that, it is set at 24 months of actual account inactivity.

A reservation is anonymised three years after the stay: the name, email, phone of the primary contact and the arrival notes are removed, the aggregates remain. The invoice for the same stay, however, carries your name and must be kept for ten years under accounting obligations. After anonymisation, your identity remains in only two places: billing records (10 years) and the evidence of your acceptance of the terms (version, date, name, email address — 5 years, 10 years for a consumer).

These are maximum retention periods, not the description of an already fully automated erasure: the corresponding deletion and anonymisation mechanisms are being rolled out with our deployments. You can request the deletion of your account at any time (see “Your rights”).

Three periods depart from the three-year rule, and they are not ours to set: the French Act of 21 June 2004 requires every content host to keep the civil identity of an account holder for five years after the account is closed, and the connection data recorded at sign-up for one year. Evidence of your acceptance of our terms is kept for five years after the end of the contract, ten years if you contracted as a consumer.

  • This evidence of acceptance is never displayed — neither in your account area nor on the site — and serves no other purpose: it establishes, in the event of a dispute, which version you accepted, when and from which device.
DataRetention periodThen
Host or guest account3 years after the end of the relationshipDeletion
Civil identity of a host account holder5 years after the account is closedDeletion — content host obligation, Article 6-II of the French Act of 21 June 2004 and decree No. 2021-1362
Connection data recorded when the account was created (excluding the evidence of acceptance, above)1 yearDeletion — same obligation
Evidence of acceptance of the terms (version, date, signatory, IP address and browser at the time of acceptance)5 years after the end of the contract — 10 years for a consumer hostDeletion
Invoices and accounting records10 years from issuanceRetention required by law
Reservations and stay data3 years after the end of the stayAnonymisation — occupancy and revenue statistics are kept
Rejected rental application3 monthsDeletion
Accepted rental applicationTerm of the lease, then 5 yearsDeletion
StayProof evidence24 months after the stay by default; the host, who is the controller for this processing, may extend that period to up to five years from the settings of their account (account holder). Thirty days before deletion, the host is notified and can download the complete fileDeletion
Audit logs36 monthsDeletion
Support requests from your account area24 months after resolutionContent and attachments are erased, the trace of the exchange remains
Support requests from the public form30 days after the last messageContent, attachments and the email fingerprint are erased
Launch list and Radar alertsUntil you unsubscribe, then 3 years — 30 days if the subscription is never confirmedDeletion

Recipients and processors

We sell no data and share none for third-party prospecting. The providers below are our processors: they act on our behalf, on our instructions, and only for the role stated.

  • Two tools, where your host uses them, are their providers and not ours: the smart lock they connect with their own account, and the dynamic pricing tool they switch on themselves. Their dealings with those providers do not fall under this policy.
  • Our own accounting is handled with a provider established in France. It only ever touches our billing data, never your guests' stay data.
ProcessorRoleLocation
netcup GmbHHosting of the application, the database and the cacheVienna data centre, Austria — European Union
Cloudflare, Inc.Storage of private documents and media, network protection and domain namesStorage in European Union jurisdiction; company established in the United States
Vercel Inc.Hosting of the public website and the dashboardUnited States
Resend, Inc.Delivery of transactional emailsUnited States
650 Industries, Inc. (Expo)Distribution of the mobile apps and delivery of notificationsUnited States
OVH SASDelivery of authentication SMS and on-call alertsFrance — European Union
Anthropic, PBCAI-assisted analysis (see “Artificial intelligence”)United States
STAAH (Su-API)Distribution of listings and intake of reservations from partner platformsNew Zealand or India depending on the entity
Yousign SASElectronic signature of leases (long-term letting)France — European Union

Third parties acting on their own account

Three third parties receive some of your data on their own account, and not on our instructions. They are responsible for their own processing; their privacy policies apply in addition to ours.

Third partyWhat it receivesLocation
Stripe Payments Europe, Ltd.Payments, deposits and the host's connected accountIreland — European Union
DossierFacileVerification of a rental application, where the applicant requests itFrance — French public service
Distribution platforms (Airbnb, Booking.com, etc.)Origin of the reservation where it comes from oneDepending on the platform, under their own terms

Transfers outside the European Union

Part of our processing never leaves the European Union; the rest relies on providers established elsewhere. Both are named below, provider by provider.

Some of our providers are established outside the European Union. Every transfer rests on an appropriate safeguard within the meaning of Chapter V GDPR, stated below; you may obtain a copy of it on request at privacy@ystay.app.

The core application, the database, the storage of your documents and media and the geocoding of addresses do remain in the European Union.

ProviderTransfer safeguard
Vercel Inc. — United StatesData Privacy Framework, with standard contractual clauses as a fallback
Resend, Inc. — United StatesData Privacy Framework, with standard contractual clauses as a fallback
650 Industries (Expo) — United StatesSafeguard relied on: the European Commission's standard contractual clauses — document being filed
Anthropic, PBC — United StatesSafeguard relied on: the European Commission's standard contractual clauses, together with a transfer impact assessment — document being filed
STAAH (Su-API) — New Zealand or IndiaSafeguard relied on: an adequacy decision, or standard contractual clauses depending on the contracting entity — document being filed
Cloudflare, Inc. — United StatesStorage in European jurisdiction; for the network, the safeguards of the Cloudflare agreement — document being filed

Security

The measures below are the ones in service. They do not claim to be exhaustive and evolve with the platform.

  • Encryption of traffic between your browser, our mobile apps and our servers.
  • Documents and media held in private storage, served only through signed, time-limited links. No sensitive file is exposed through a public URL.
  • Strict isolation per account: every business query is scoped to the account that owns the data.
  • Two-factor authentication available on host accounts.
  • Logging of sensitive transitions, kept for 36 months.
  • Sealing of inspection files by a fingerprint written to the audit log.
  • Encrypted backups allowing point-in-time restoration.

Artificial intelligence

Several features of the platform are assisted by a language model. They assist: none of them decides. No content sent is used to train a model, and no automated processing produces a legal effect concerning you within the meaning of Article 22 GDPR.

None of these features applies to all of your data: each one only receives what is submitted to it, at the moment it is used, and nothing is sent outside those moments. The data sent is set out below.

The provider of these features is Anthropic, PBC (United States). The content sent is not used to train its models and is kept by it for no more than thirty days. The transfer is covered by the European Commission's standard contractual clauses, together with a transfer impact assessment; the corresponding document is being filed and you may ask us where it stands at privacy@ystay.app.

FeatureWhat is sentWhat it does not do
Comparison between the check-in and check-out inspectionsThe checklist answers and observations, without any photo or identityNo deduction from the deposit, no finding of liability
Writing and translating listings and guidebooksThe text written by the host, without any guest dataNo publication without the host's approval
Suggesting a reply to a guestThe message thread, first name includedNo message sent without the host reading it
Extracting the fields of a rental application documentThe content of the uploaded documentNo score, no ranking, no selection recommendation

Your rights

You have the rights set out in Articles 15 to 22 GDPR. Send your request to privacy@ystay.app; if you are a guest or a rental applicant, address the host or landlord concerned first (see “Who is responsible for what” above) — if you write to us directly, we forward your request and assist in answering it.

Article 12 GDPR gives us one month to reply, extendable by two months where your request is complex; we then tell you and explain why.

Where your request concerns processing for which the host or the landlord is the controller, we forward it to them within five working days, tell you we have done so, and assist them in answering. We never answer on the merits in their place.

  • Access: obtain a copy of the data we hold about you.
  • Rectification: correct inaccurate or incomplete data, directly from your account area for most fields.
  • Erasure: request the deletion of your account from the dedicated page, from your account area or from our mobile apps. The request is reviewed by our team before it is carried out. Some data is kept where a legal obligation requires it — your invoices, for ten years.
  • Restriction: ask us to freeze the processing of your data while a dispute is being examined.
  • Objection: object to processing based on our legitimate interest, on grounds relating to your particular situation.
  • Portability: receive the data you provided to us in a structured, machine-readable format.
  • Withdrawal of consent: at any time, for the launch list and Radar alerts, without affecting mailings already sent.
  • Complaint: you may lodge a complaint with the CNIL (cnil.fr), the French supervisory authority, at any time.
  • Refusal: any refusal is notified to you with its reason, a reminder of your right to lodge a complaint with the CNIL and of your right to a judicial remedy.

Cookies and trackers

The marketing website uses no advertising cookie by default. Trackers subject to consent are blocked until you accept, and your choice can be revoked at any time.

Plausible is loaded without consent under the CNIL exemption for audience measurement: strictly limited to our own traffic statistics, without cookies, on aggregated and anonymous data.

The app.ystay.app dashboard only uses strictly necessary cookies — authenticated session, cross-site request forgery protection, language preference — which are exempt from consent.

TrackerPurposeRetentionConsent
AxeptioRemember your consent choice12 monthsEssential (exempt)
Plausible AnalyticsAnonymous audience measurement (no cookie)No storageExempt (CNIL audience measurement)
Attribution (ystay_utm_v1)Attach a contact to the campaign they came fromSession lifetimeSubject to your consent

Changes to this policy

This policy may change with the platform and with the legal review under way. The version in force is the one published on this page; its last update date appears at the top of the page.

We encourage you to read it again when you use the service.