Privacy policy
Last updated:
YStay handles sensitive data: identities, stays, supporting documents, inspection evidence. Our default posture is confidentiality — private storage, mediated and signed access, hosting in Europe, and logging of sensitive transitions.
This policy is written from our record of processing activities. It describes each processing activity separately: what we collect, why, who has access to it and how long we keep it.
Data controller
The YStay platform is published by [TO BE COMPLETED: registered company name], [TO BE COMPLETED: legal form] with a share capital of [TO BE COMPLETED: share capital], registered under number [TO BE COMPLETED: company registration number], EU VAT number [TO BE COMPLETED: EU VAT number], whose registered office is located at [TO BE COMPLETED: registered office address].
The company is being incorporated: the fields above are displayed as placeholders until registration is effective. They will be filled in, on this page and in the legal notice, in the same deployment.
For any question about your personal data and to exercise your rights: privacy@ystay.app. For anything else: contact@ystay.app.
Who is responsible for what
YStay does not play the same role for every piece of data it handles. The split depends on the processing activity, and it determines who you should address your rights to.
- YStay is the data controller for its own customer relationship: host accounts and team members, billing and subscriptions, support requests, launch mailing list and compliance Radar alerts.
- YStay is the data controller for the guest account itself — sign-in details, language, preferences, device tokens, any insurance certificate uploaded: an account spans several hosts and belongs to the running of the platform. YStay is, by contrast, a processor acting on behalf of the host for that guest's stay data: reservation, access, check-in and check-out, StayProof evidence, messages with the host. The host is the controller towards their guest; we process on their behalf and on their instructions.
- YStay is a processor acting on behalf of the landlord for long-term rental applications (YStay Classic). A rental applicant is not a guest: the landlord decides the purpose and the retention of their file.
| You are | Address your rights to | Our role |
|---|---|---|
| A host, or a member of a host team | YStay — privacy@ystay.app | Data controller |
| A guest — account, preferences, support | YStay — privacy@ystay.app | Data controller |
| A guest — reservation, stay, evidence | The host you booked with | Processor for the host |
| A long-term rental applicant | The landlord you applied to | Processor for the landlord |
| Subscribed to the launch list or to Radar alerts | YStay — privacy@ystay.app | Data controller |
Host accounts
Purpose: allow a host — an individual or a company — to create and manage their account, properties and listings, reservations, team and billing.
- Data subjects: individual hosts, representatives of host companies, members invited to an account (manager, team member, read-only).
- Data: identity (name, display name), contact details (phone, postal address), company details (legal name, company number, VAT number, invoice legal mentions), contract signature image, payment provider customer identifier, trial and suspension status with its reason.
- Recipients: authorised YStay staff; yourself and the members you invite, within the limits of their role; Stripe for billing; netcup for database hosting.
- Isolation: every business query is scoped to the owning account. A host never sees another host's data.
- We measure how your account uses the platform — features switched on, steps completed — in order to improve the service. Those measurements rely on our legitimate interest, cover account data only, and are never shared or sold.
Members of a host team
Purpose: allow a person invited by a host — manager, team member, read-only — to access their account within the limits of their role, and attribute every action to its author.
- Data subjects: the people a host invites onto their account, whether employees, agents or contractors.
- Data: name, email address, role granted, date and version of the individual terms of use accepted, activity logs (who did what, and when).
- Data controller: YStay. You are not a party to the contract between YStay and the host who invites you, but we are indeed the ones processing this data, to run their account and keep the platform secure.
- Retention: with the host's account, according to the periods set out below; your personal access ends as soon as the account holder withdraws it.
Guest accounts
Purpose: allow a guest to manage their reservation, access codes and messages from an account or a token link, and to upload an insurance certificate when the host requires one.
- Data subjects: guests and primary occupants of a reservation.
- Data: identity (first name, last name), phone, language, default billing address, payment provider customer identifier, device tokens for mobile notifications, insurance certificate with its validity dates and the reason for any rejection.
- Recipients: authorised YStay staff; the host of the reservation concerned; Expo for notification delivery; Stripe where a payment is involved.
- Uploaded documents are held in private storage: they are never served from a public URL, only through a signed, time-limited link.
- Your stay data — reservation, access, check-in and check-out, property inspection, messages with your host — does not fall under this section: it is processed on behalf of your host, who is the controller for it. The corresponding notice is shown to you at booking time, before you enter your contact details.
Reservations and stays
Purpose: manage the life cycle of a short-term reservation — dates, occupants, price, status, originating channel — and the related stay, from arrival to departure.
- Data subjects: the primary guest of a reservation, named even without an account, and the host.
- Data: stay dates, number of adults, children and infants, name, email and phone of the primary contact, language, arrival notes, total amount and currency, price breakdown, status, channel (direct or distribution platform), public reservation token.
- Recipients: the host who owns the reservation, authorised YStay staff, the originating distribution platform where the reservation comes from one (Airbnb, Booking.com and others, through Su-API/STAAH), and the payment provider where applicable.
Rental applications (long-term letting)
Purpose: assemble and review an application for a long-term rental, with automated field extraction to speed up the landlord's review.
This is the most sensitive processing activity on the platform. The automated analysis never decides: it extracts, classifies and flags. The decision to accept or reject an application belongs to the landlord, who may override anything the tool produces.
- Data subjects: rental applicants.
- Data: last name, first name, email, phone, employment type, employer, monthly income, DossierFacile status and reference; and, through automated extraction, the content of the document itself — raw extracted text, recognised fields, category and confidence level.
- Recipients: the landlord who owns the application, authorised YStay staff, DossierFacile where the applicant requests a verification.
- Before you upload your first document, the applicant area shows you a dedicated notice: who is responsible for your file (the landlord), which documents may be asked of you — the list in French decree No. 2015-1437 of 5 November 2015 is exhaustive —, what the automated analysis does and does not do, and how to withdraw your application. You accept it before uploading anything.
StayProof evidence (property inspections)
Purpose: build a check-in and check-out inspection and evidence of the stay that can be relied on in a dispute — deposit, damage — with an AI-assisted comparison between arrival and departure.
That analysis is bounded, explainable and editable by the host: it never decides on its own and produces no sanction. The host remains the author of the approval or the rejection.
When an inspection is closed, a cryptographic fingerprint of the file — photos, answers, signature — is written to the audit log, where it is kept for thirty-six months like the other sensitive transitions. It makes a later export of the file possible to authenticate, and it remains readable in the log after the file itself has been deleted, for as long as those thirty-six months have not elapsed.
- Data subjects: the guest (respondent, signatory) and the host (approval or rejection).
- Data: checklist answers, photos, guest signature, completion, approval and rejection timestamps with the reason, generated summary, result of the comparison analysis.
- Recipients: the host concerned, authorised YStay staff, Anthropic for the comparison analysis.
- Retention: 24 months after the stay by default; the host, who is the controller for this processing, may extend that period to up to five years from the settings of their account (account holder). Thirty days before deletion, the host is notified and can download the complete file.
Support requests
Purpose: handle support requests from hosts, team members and guests, and alert our on-call rota when access is blocked during an ongoing stay, outside business hours.
Two channels coexist, and they do not collect the same thing.
- From your account area (host, team member or signed-in guest): the content of your messages, the files you attach, the category, priority, status and context of the request. Every time our team opens a thread, that access is logged.
- From the public form, without signing in (“I can no longer sign in”, “I am requesting the deletion of my account”): your message and, instead of your email address, a cryptographic fingerprint of it. Your address is not stored in clear text in any column. A resume link lets you continue the conversation.
- That second channel is deliberately minimised: the person using it is not identified as a customer. Exchanges there are kept for 30 days after the last message, against 24 months for signed-in channels.
- Recipients: authorised YStay staff; Resend for email delivery and the OVH SMS gateway for on-call alerts.
Compliance alert (Radar)
Purpose: let you know when the short-term rental rules of your municipality change, or when we check them for the first time. Your assessment never triggers any prospecting.
- Data controller: YStay.
- Legal basis: your consent, given through a checkbox that is never pre-ticked and then confirmed by a click in the email we send you (double opt-in). Without that confirmation your address is never used for a mailing, and it is deleted after 30 days.
- Data collected: your email address, the INSEE code of the municipality you want to be alerted about (five characters, for example 74010), the language and the page you came from. No IP address, no advertising profiling, no sale or sharing with third parties for prospecting purposes.
- What we never keep: the result of your assessment. No status, no risk amount, none of your answers — the calculation runs in your browser and nothing leaves it. No column in our database could hold them.
- Retention: until you unsubscribe, then 3 years so that consent and its withdrawal can be evidenced (CNIL recommendation for prospects). The municipality disappears with the record, on the same schedule: it creates no additional retention.
- Withdrawal: every email carries an unsubscribe link that requires no sign-in, and the withdrawal is immediate — you can also use the unsubscribe page.
- Changing the municipality you follow: a new request from Radar fills in the municipality if you had not declared one. To change it, unsubscribe and subscribe again, or write to us: we do not let an anonymous form redirect the alerts of an already confirmed address.
- Hosting: European Union. Recipient: Resend, for delivery.
Audit logs
Purpose: record who did what and when on the platform's sensitive transitions — reservation, lock opening, check-in and check-out, incident, signature, document, a support request opened by our team — for evidence and security purposes.
These logs are kept for 36 months. They are only accessible to authorised YStay staff; internal reads of a support thread are never exposed to the host.
Legal bases
Each processing activity relies on one of the bases set out in Article 6 GDPR. The table below states the one we rely on for each. They are under review with our legal counsel at the time of this publication; this section will be updated if any of them changes.
| Processing activity | Legal basis relied on |
|---|---|
| Host accounts | Performance of the contract; legal obligation for invoices |
| Members of a host team | Performance of the contract entered into with the host; legitimate interest for activity logs |
| Guest accounts | Performance of the contract, on behalf of the host |
| Reservations and stays | Performance of the contract, on behalf of the host |
| Rental applications (Classic) | Performance of the contract or pre-contractual steps taken at your request |
| StayProof evidence | Legitimate interest of the host in securing contractual evidence |
| Support requests | Performance of the contract for signed-in channels; legitimate interest in remaining reachable for the public form |
| Launch list and Radar alerts | Your consent |
| Audit logs | Legitimate interest: security and accountability of sensitive actions |
Retention periods
The periods below are the ones we apply. The end of the relationship is the termination date where one exists; failing that, it is set at 24 months of actual account inactivity.
A reservation is anonymised three years after the stay: the name, email, phone of the primary contact and the arrival notes are removed, the aggregates remain. The invoice for the same stay, however, carries your name and must be kept for ten years under accounting obligations. After anonymisation, your identity remains in only two places: billing records (10 years) and the evidence of your acceptance of the terms (version, date, name, email address — 5 years, 10 years for a consumer).
These are maximum retention periods, not the description of an already fully automated erasure: the corresponding deletion and anonymisation mechanisms are being rolled out with our deployments. You can request the deletion of your account at any time (see “Your rights”).
Three periods depart from the three-year rule, and they are not ours to set: the French Act of 21 June 2004 requires every content host to keep the civil identity of an account holder for five years after the account is closed, and the connection data recorded at sign-up for one year. Evidence of your acceptance of our terms is kept for five years after the end of the contract, ten years if you contracted as a consumer.
- This evidence of acceptance is never displayed — neither in your account area nor on the site — and serves no other purpose: it establishes, in the event of a dispute, which version you accepted, when and from which device.
| Data | Retention period | Then |
|---|---|---|
| Host or guest account | 3 years after the end of the relationship | Deletion |
| Civil identity of a host account holder | 5 years after the account is closed | Deletion — content host obligation, Article 6-II of the French Act of 21 June 2004 and decree No. 2021-1362 |
| Connection data recorded when the account was created (excluding the evidence of acceptance, above) | 1 year | Deletion — same obligation |
| Evidence of acceptance of the terms (version, date, signatory, IP address and browser at the time of acceptance) | 5 years after the end of the contract — 10 years for a consumer host | Deletion |
| Invoices and accounting records | 10 years from issuance | Retention required by law |
| Reservations and stay data | 3 years after the end of the stay | Anonymisation — occupancy and revenue statistics are kept |
| Rejected rental application | 3 months | Deletion |
| Accepted rental application | Term of the lease, then 5 years | Deletion |
| StayProof evidence | 24 months after the stay by default; the host, who is the controller for this processing, may extend that period to up to five years from the settings of their account (account holder). Thirty days before deletion, the host is notified and can download the complete file | Deletion |
| Audit logs | 36 months | Deletion |
| Support requests from your account area | 24 months after resolution | Content and attachments are erased, the trace of the exchange remains |
| Support requests from the public form | 30 days after the last message | Content, attachments and the email fingerprint are erased |
| Launch list and Radar alerts | Until you unsubscribe, then 3 years — 30 days if the subscription is never confirmed | Deletion |
Recipients and processors
We sell no data and share none for third-party prospecting. The providers below are our processors: they act on our behalf, on our instructions, and only for the role stated.
- Two tools, where your host uses them, are their providers and not ours: the smart lock they connect with their own account, and the dynamic pricing tool they switch on themselves. Their dealings with those providers do not fall under this policy.
- Our own accounting is handled with a provider established in France. It only ever touches our billing data, never your guests' stay data.
| Processor | Role | Location |
|---|---|---|
| netcup GmbH | Hosting of the application, the database and the cache | Vienna data centre, Austria — European Union |
| Cloudflare, Inc. | Storage of private documents and media, network protection and domain names | Storage in European Union jurisdiction; company established in the United States |
| Vercel Inc. | Hosting of the public website and the dashboard | United States |
| Resend, Inc. | Delivery of transactional emails | United States |
| 650 Industries, Inc. (Expo) | Distribution of the mobile apps and delivery of notifications | United States |
| OVH SAS | Delivery of authentication SMS and on-call alerts | France — European Union |
| Anthropic, PBC | AI-assisted analysis (see “Artificial intelligence”) | United States |
| STAAH (Su-API) | Distribution of listings and intake of reservations from partner platforms | New Zealand or India depending on the entity |
| Yousign SAS | Electronic signature of leases (long-term letting) | France — European Union |
Third parties acting on their own account
Three third parties receive some of your data on their own account, and not on our instructions. They are responsible for their own processing; their privacy policies apply in addition to ours.
| Third party | What it receives | Location |
|---|---|---|
| Stripe Payments Europe, Ltd. | Payments, deposits and the host's connected account | Ireland — European Union |
| DossierFacile | Verification of a rental application, where the applicant requests it | France — French public service |
| Distribution platforms (Airbnb, Booking.com, etc.) | Origin of the reservation where it comes from one | Depending on the platform, under their own terms |
Transfers outside the European Union
Part of our processing never leaves the European Union; the rest relies on providers established elsewhere. Both are named below, provider by provider.
Some of our providers are established outside the European Union. Every transfer rests on an appropriate safeguard within the meaning of Chapter V GDPR, stated below; you may obtain a copy of it on request at privacy@ystay.app.
The core application, the database, the storage of your documents and media and the geocoding of addresses do remain in the European Union.
| Provider | Transfer safeguard |
|---|---|
| Vercel Inc. — United States | Data Privacy Framework, with standard contractual clauses as a fallback |
| Resend, Inc. — United States | Data Privacy Framework, with standard contractual clauses as a fallback |
| 650 Industries (Expo) — United States | Safeguard relied on: the European Commission's standard contractual clauses — document being filed |
| Anthropic, PBC — United States | Safeguard relied on: the European Commission's standard contractual clauses, together with a transfer impact assessment — document being filed |
| STAAH (Su-API) — New Zealand or India | Safeguard relied on: an adequacy decision, or standard contractual clauses depending on the contracting entity — document being filed |
| Cloudflare, Inc. — United States | Storage in European jurisdiction; for the network, the safeguards of the Cloudflare agreement — document being filed |
Security
The measures below are the ones in service. They do not claim to be exhaustive and evolve with the platform.
- Encryption of traffic between your browser, our mobile apps and our servers.
- Documents and media held in private storage, served only through signed, time-limited links. No sensitive file is exposed through a public URL.
- Strict isolation per account: every business query is scoped to the account that owns the data.
- Two-factor authentication available on host accounts.
- Logging of sensitive transitions, kept for 36 months.
- Sealing of inspection files by a fingerprint written to the audit log.
- Encrypted backups allowing point-in-time restoration.
Artificial intelligence
Several features of the platform are assisted by a language model. They assist: none of them decides. No content sent is used to train a model, and no automated processing produces a legal effect concerning you within the meaning of Article 22 GDPR.
None of these features applies to all of your data: each one only receives what is submitted to it, at the moment it is used, and nothing is sent outside those moments. The data sent is set out below.
The provider of these features is Anthropic, PBC (United States). The content sent is not used to train its models and is kept by it for no more than thirty days. The transfer is covered by the European Commission's standard contractual clauses, together with a transfer impact assessment; the corresponding document is being filed and you may ask us where it stands at privacy@ystay.app.
| Feature | What is sent | What it does not do |
|---|---|---|
| Comparison between the check-in and check-out inspections | The checklist answers and observations, without any photo or identity | No deduction from the deposit, no finding of liability |
| Writing and translating listings and guidebooks | The text written by the host, without any guest data | No publication without the host's approval |
| Suggesting a reply to a guest | The message thread, first name included | No message sent without the host reading it |
| Extracting the fields of a rental application document | The content of the uploaded document | No score, no ranking, no selection recommendation |
Your rights
You have the rights set out in Articles 15 to 22 GDPR. Send your request to privacy@ystay.app; if you are a guest or a rental applicant, address the host or landlord concerned first (see “Who is responsible for what” above) — if you write to us directly, we forward your request and assist in answering it.
Article 12 GDPR gives us one month to reply, extendable by two months where your request is complex; we then tell you and explain why.
Where your request concerns processing for which the host or the landlord is the controller, we forward it to them within five working days, tell you we have done so, and assist them in answering. We never answer on the merits in their place.
- Access: obtain a copy of the data we hold about you.
- Rectification: correct inaccurate or incomplete data, directly from your account area for most fields.
- Erasure: request the deletion of your account from the dedicated page, from your account area or from our mobile apps. The request is reviewed by our team before it is carried out. Some data is kept where a legal obligation requires it — your invoices, for ten years.
- Restriction: ask us to freeze the processing of your data while a dispute is being examined.
- Objection: object to processing based on our legitimate interest, on grounds relating to your particular situation.
- Portability: receive the data you provided to us in a structured, machine-readable format.
- Withdrawal of consent: at any time, for the launch list and Radar alerts, without affecting mailings already sent.
- Complaint: you may lodge a complaint with the CNIL (cnil.fr), the French supervisory authority, at any time.
- Refusal: any refusal is notified to you with its reason, a reminder of your right to lodge a complaint with the CNIL and of your right to a judicial remedy.
Changes to this policy
This policy may change with the platform and with the legal review under way. The version in force is the one published on this page; its last update date appears at the top of the page.
We encourage you to read it again when you use the service.