Dubrovnik Stays
Legal

Privacy Policy

Last updated 28 August 2026

This Privacy Policy explains what personal data Dubrovnik Stays (“we”) collects from guests and Owners, why, and how it is handled.

1. Data we collect

Account data

  • Name, email address, phone number, and password (stored as a salted hash, never in plain text).
  • Profile photo, if you choose to upload one.

Owner business data

  • Company name and address, Chamber of Commerce number, and VAT number, used for invoicing and payout compliance.
  • Bank account holder name and IBAN, used solely to pay out booking revenue.

Booking and payment data

  • Booking dates, guest count, and any message sent with a booking request.
  • A tokenized reference to your payment card (card brand, last four digits, and expiry date, plus a provider-issued mandate identifier). Your full card number, CVC, and expiry are sent directly to our payment provider and are never stored on Dubrovnik Stays' own servers.

Communications

  • Messages sent between guests and Owners about a specific apartment.
  • Contact form submissions.
  • Transactional emails we send you (booking confirmations, payment failures, payout notices) are logged for support and debugging purposes.

Usage data

  • Basic, non-identifying analytics such as which apartments are viewed and when, used to show Owners how their listings are performing.

2. How we use this data

  • To operate the booking flow: creating, approving, paying for, and fulfilling bookings.
  • To send transactional emails related to a booking (requests, approvals, payment status, cancellations).
  • To calculate and pay out Owner revenue, and to meet applicable tax and accounting obligations.
  • To respond to support requests and investigate reported abuse of the messaging system.
  • To show Owners aggregate performance analytics for their own listings.

We do not sell personal data to third parties, and we do not use booking or messaging data for advertising.

3. Who we share data with

  • The other party to a booking: a guest and Owner see each other's name and contact details once a booking request exists, so the stay can be coordinated.
  • Payment provider: processes card verification and charges; see Section 1 for what they receive directly rather than us.
  • Hosting infrastructure: our database and application servers, used solely to operate the Platform.

4. Data retention

We keep booking, payment, and invoicing records for as long as required by Croatian tax and accounting law. Account data is kept while your account is active and for a reasonable period after deactivation to resolve any outstanding disputes, after which it is deleted or anonymized.

5. Your rights

If you are in the EU/EEA, you have the right under the GDPR to request access to, correction of, or deletion of your personal data, and to object to or restrict certain processing. To exercise these rights, contact us via the contact page.

6. Security

Passwords are hashed, not stored in plain text. Access to Owner business and bank details is restricted to what is needed for payouts. Card numbers never touch our servers in raw form.

7. Changes to this policy

We may update this Privacy Policy from time to time; the “Last updated” date above reflects the latest revision.

8. Contact

For any privacy question or request, use the contact page.

This document is a template provided for a preview build of Dubrovnik Stays and is not legal advice. Before operating a real rental platform, have this policy reviewed by a qualified lawyer or data protection professional.