Privacy Policy — "Hola Stay" app

Last updated: 23 July 2026

This privacy policy covers the "Hola Stay" application (the "App") — an internal tool for managing short-term rental apartments (bookings, settlements, invoices, property documents). The App runs on mobile devices (Android, iOS), Mac computers and in a web browser. This policy explains what data the App processes, where it is stored and who it is entrusted to.

*Polska wersja / Polish version: Polska wersja


1. Data controller

The controller of personal data processed in the App is:

For any matter regarding personal data and this policy, please contact contact@holastay.eu.


2. Nature of the App

The App is a business tool for the owner and the team servicing the apartments. It is not intended for guests or the general public.

Access requires signing in with three credentials: company number, e-mail address and password. Accounts are created only by an administrator — the App offers no self-registration. Each company has its own separated data space; a user of one company cannot access another company's data.


3. What data is processed


4. Where data is stored

Data is stored in two places at the same time:

  1. In the company cloud — in the database and file storage of Google Firebase (Firestore and Cloud Storage), on servers located in the European Union. This lets the team work on shared, up-to-date data across all devices.
  2. Locally on the device — as a working copy that allows the App to be used without an internet connection (offline mode). Once the connection is restored, data synchronises with the company cloud.

Cloud data is written into a space assigned to the company number and protected by server-side access rules — reading and writing are possible only for signed-in members of that company.

Attachments (scans, photos, generated PDF documents) are stored on the device and, to the extent enabled by the administrator, also in the company file storage in the European Union.


5. Processors and server locations

ProcessorScopeLocation
Google Ireland Limited (Firebase: Firestore, Cloud Storage, Cloud Functions, Authentication; Google Cloud Vision)storing and synchronising App data, automatic booking import, reading text from scanned documents (OCR) in the browser and desktop versionsEuropean Union
IdoBookingbooking system — source of reservations (read-only)as stated in the provider's documents
OpenAI — only when the "cloud AI" mode, disabled by default, is switched ongenerating assistant repliesoutside the EEA

Document scanning in the browser and desktop versions reads text from the image using Google Cloud Vision in the European Union region — the image is transmitted solely to read its text and is not retained outside the company file storage. On phones, reading happens entirely on the device.

Firebase services are configured so that App data is stored on servers in the European Union. If, within the provider's services, data is transferred outside the European Economic Area, this takes place on the basis of standard contractual clauses approved by the European Commission.


6. Source of booking data (IdoBooking)

The App downloads bookings from the IdoBooking system through an iCal feed — read-only. The App neither writes nor modifies anything in IdoBooking.

Downloading happens in two ways: directly from the App, and periodically (roughly every 15 minutes) through a server-side service running in the European Union, which writes bookings into the company cloud. Thanks to this the schedule stays current even when nobody has the App open.

The booking system provider (IdoBooking) is a separate entity — its processing rules are described in that provider's documents.


7. Device permissions


8. No tracking, no ads

The App does not track users, does not use an advertising identifier (IDFA), contains no ads and no third-party analytics tools. It does not profile users or guests.


9. Data recipients

Data processed in the App is never sold or shared for marketing purposes. Beyond the processors listed in section 5, data may be passed on only to:

"Cloud AI" assistant mode (optional, disabled by default): if the administrator enables "AI (cloud)" in Settings and enters an API key, the content of the query and property data (e.g. Wi-Fi, hours, address) are sent to the model provider (OpenAI) to generate a reply. When the mode is off, the assistant works locally and no data is sent to that provider.


10. Backups

The administrator can export the company data into a single backup file and store it outside the App (e.g. on a drive or external medium). Such a file contains personal data — responsibility for storing it securely rests with the administrator.


11. Retention period

Some data is subject to mandatory archiving required by law and is kept for the period required by it, in particular: (a) guest registration data (traveller register — SES/Guardia Civil) and (b) settlement documentation and invoices (accounting and tax regulations). We do not delete this data before the legally required period has passed.

Remaining data is kept for as long as it is needed for the day-to-day operation of the apartments — both in the company cloud and in the local copy on devices. Deleting data in the App also removes it from the company cloud.


12. Legal basis and data subject rights (GDPR)

Data is processed on the basis of the controller's legitimate interest (handling bookings and settlements) and legal obligations (traveller register, accounting and tax documentation).

Data subjects (including guests) have the right to: access their data, rectification, erasure, restriction of processing, objection and data portability, as well as the right to lodge a complaint with a supervisory authority (in Spain: Agencia Española de Protección de Datos). To exercise these rights, please contact: contact@holastay.eu.

The rights to erasure and objection are limited to the extent that the law imposes an obligation to retain data (including the SES traveller register and accounting/tax documentation). In that scope, data is deleted only after the legally required period has passed.


13. Security

We apply the following safeguards:


14. Account and data deletion

Accounts are created and removed by the administrator. A request to delete an account or data can be submitted to contact@holastay.eu or through the form available at: Account & data deletion

Deletion covers the account data and the company data linked to that account, except for data subject to mandatory legal archiving (section 11), which is deleted once the required period has passed.


15. Children

The App is a business tool and is not directed at children. We do not knowingly collect children's data. Data of minors may appear only to the extent required by registration regulations (traveller register), when a minor is a participant of a stay.


16. Changes to this policy

This policy may be updated. The current version is available in the App (Settings → Privacy and data) and at https://hola-stay.web.app/polityka-prywatnosci/en. The date of the last update appears at the top of the document.


17. Contact

For matters regarding privacy and personal data: HolaStay — contact@holastay.eu — +34 625 088 586