Privacy Policy

How QuietStay handles personal data — yours and your guests’. Effective 25 August 2026.

Who we are

QuietStay is operated by Offer2Stay Ltd, part of the Offer2Stay group. Offer2Stay Ltd · Company no. 17248175 · Registered office: 128 City Road, London, EC1V 2NX, United Kingdom · Not VAT registered. Contact for anything in this policy: enquiries@quietstay.co.uk. We operate under UK data protection law (UK GDPR, the Data Protection Act 2018 and PECR).

The data we process

Hosts (our customers — we are the controller). Name and email (and Google profile basics if you sign in with Google); your team members’ emails and roles; your property content (text, photos, house rules, recommendations, WiFi and entry details you choose to store); billing records and Stripe customer/subscription identifiers; the notification settings you choose; support emails you send us; and a log of emails we send you (address, template, status).

Guests (your host is the controller — we process on their behalf). Page views inside a guidebook (which screens, when — no names); questions typed to the text concierge and the answers given, stored so the host can review and improve the guidebook (don’t include personal details you wouldn’t share with your host); and, only where you choose to give them, your name, email, phone, stay dates and messages for store orders, reviews, notes to the host, “send me the guidebook” and problem reports. If your host connects a booking calendar, your stay dates arrive from that calendar; your surname and (optionally) your email are the ones you type into the guidebook to unlock your code or let the host know you’ve arrived.

Guest marketing lists. Where a host has switched the guest list on, the form in a guidebook that asks for a guest’s email — to claim the host’s offer, or to have the guidebook sent over — lets the guest tick to hear from the host, and — separately — to hear from Offer2Stay. We record which boxes were ticked, the exact wording shown, when, and a hash of the IP address, so a consent can be evidenced later. A ticked Offer2Stay box also writes the guest’s email address and first name to Offer2Stay’s own list, with the region and property type of the stay and which guidebook it came from. See Sharing with Offer2Stay below.

Marketing-site visitors. With your consent (banner), a first-party page-view beacon (path, referrer origin, a random per-tab session id kept in sessionStorage — no cookie, no name), Vercel Analytics, and — where we are running adverts — the Meta pixel with its server-side counterpart, so we can tell which adverts brought people here. Without consent, none of it loads and no advertising event is sent from our servers either. This never applies inside a guest guidebook.

Everyone. Server logs and abuse-prevention counters (IP address, route, timestamp) for security and rate limiting, kept short-term.

Why, and on what lawful basis

  • Contract — running your account, building and serving guidebooks, billing, team invites, sending stay messages your host has set up.
  • Legitimate interests — securing the service and preventing abuse (rate limits, logs), improving the product from aggregate usage, and sending hosts service messages about their account (usage warnings, trial reminders, payment failures).
  • Consent — marketing-site analytics (the banner), guest marketing emails such as “book direct next time” (only where the guest opted in; every email has an unsubscribe link), passing a guest’s email address to Offer2Stay for Offer2Stay’s own list where the guest ticked that separate box, and voice features (off).
  • Legal obligation — keeping billing records for tax purposes.

Who processes data for us

We do not sell personal data and do not use it for third-party advertising. These providers process data on our instructions:

  • Supabasedatabase, authentication, file storage (guidebook photos) (EU (London/Frankfurt region)).
  • Vercelhosting, edge network, and — with your consent — Vercel Analytics page-view stats (EU/US, standard contractual clauses).
  • Stripepayments and payouts (card details never reach us) (EU/US, Stripe DPA).
  • Resendtransactional and (opt-in) marketing email delivery, bounce handling (US, standard contractual clauses).
  • OpenAItext concierge answers, guidebook drafting, translations fallback — no training on your data under the API terms (US, standard contractual clauses).
  • DeepLguidebook translations (ES/FR/DE) (EU).
  • Apifyimporting a public listing (Airbnb, Booking.com, Vrbo, Offer2Stay listings) you paste in — the listing URL only (EU).
  • Google Maps (embed)the map on a guest guidebook page — it loads only when a guest taps “Show map”; Google sets its own cookies when it does (US, Google DPA).
  • Google Fontsthe typeface pairs a host can choose for a guidebook — the guest’s browser fetches the font files from Google (IP address, user agent) (US, Google privacy policy).
  • Open-Meteothe local weather forecast shown in a guidebook — the guest’s browser requests it with the property’s coordinates (so Open-Meteo sees the guest’s IP address), never the guest’s own location (EU).
  • ElevenLabsvoice concierge — switched OFF; no guest data is sent while it is off (US).
  • Sentryerror monitoring (stack traces; emails and cookies are stripped before sending) (EU/US, standard contractual clauses).

Where a provider is outside the UK, transfers rely on the UK International Data Transfer Addendum / standard contractual clauses or an adequacy decision.

One recipient is not a processor. It receives data as a controller in its own right, which means it decides what it does with it and answers for that itself:

  • Offer2Staythe guest’s email address and first name, where the guest has ticked the separate box asking for offers from them — for their own marketing list, which they run themselves (UK — separate controller, not our processor).
  • Meta (Facebook)ONLY if you accepted analytics in the banner, and only on the marketing site: that you viewed a page, started a guidebook or subscribed, plus Meta’s own advertising cookies and — where you gave us one — a one-way SHA-256 hash of your email address so Meta can tell whether you came from one of our adverts. Never your name, your property, your guests or anything from a guidebook. Decline analytics and nothing at all is sent. (US/EU — separate controller for its advertising, not our processor).

Sharing with Offer2Stay

Where a host has switched it on, the form in a guidebook that asks for a guest’s email carries a second, separate tick box, unticked by default: Email me occasional offers from Offer2Stay, our sister brand for direct bookings — the same company behind QuietStay. Roughly every couple of months, never more than once a month. Privacy notice: https://www.offer2stay.co.uk/privacy

If — and only if — a guest ticks that box, we pass their email address and first name to Offer2Stay for Offer2Stay’s own marketing list, along with the region and property type of the stay. It is a separate list from the host’s: Offer2Stay and QuietStay are both operated by Offer2Stay Ltd. Offer2Stay runs its own direct-booking marketing list, which you opt into separately. Contact: enquiries@quietstay.co.uk. Offer2Stay decides what it sends and is the controller for that list, so ask them to see or delete what they hold — their notice is at www.offer2stay.co.uk/privacy. Our lawful basis for the transfer is your consent, and we record the exact wording you agreed to and when, so we can show you later.

Every Offer2Stay email carries an unsubscribe link, and the send is rate-limited in our code — never more than once a month, and in practice roughly every couple of months. Leaving the box unticked changes nothing else: you still get your guidebook, and it is never a condition of anything.

How long we keep things

One thing to be straight about first: apart from the email scrub below, nothing here is deleted by a timer. The periods are the points from which we may delete something, and the deletions we do are done by hand or at your request — so please read “90 days” as the earliest we would remove your content, not the day it vanishes. If you want something gone, ask us and we will delete it.

  • Host account and property content — kept while your subscription is active, and for at least 90 days after it lapses or is cancelled, so you can come back and carry on. After that we may delete it. To remove it yourself at any time, use Settings → Danger zone, which permanently deletes every property, guidebook, store item and guest record (your login stays — email us to remove that too).
  • Concierge chat logs and guidebook view stats — while the owning guidebook exists; hosts can delete a guidebook at any time, which removes them.
  • Guest contacts, orders, notes and reports — while the owning account exists, so hosts keep their history; guests can ask their host, or us, to delete them.
  • Guest marketing list entries — the host’s list and the Offer2Stay list are kept while each list is running, with the consent record that goes with them. Unsubscribing stamps the entry as unsubscribed and it is never re-subscribed, so the record stays as proof you asked us to stop; ask and we will delete it outright instead.
  • Email logs — the recipient address is deleted automatically 30 days after we send, by a nightly job. This is the one retention job that runs on its own. The template name and delivery status stay on the record after that so we can answer “did that email arrive?”.
  • Marketing-site analytics events — the page-view records described above (path, referrer origin, per-tab id). We keep them no longer than we need to, and would not expect to hold them beyond 13 months; there is no job that removes them, so we delete them when we review, or on request.
  • Security logs and rate-limit counters — rate-limit counters are deleted automatically once their window is well past (within a couple of days). Server and error logs live with our hosting and error-monitoring providers and expire on their schedules; we keep no separate copy.
  • Billing records — as long as tax law requires (currently 6 years).

Cookies, consent and local storage

Strictly necessary (no consent needed): your login session (Supabase auth token), a cookie that remembers your cookie choice (qs_consent, 6 months), and small local flags such as “dismissed this notice” or your recent store orders on a device.

Analytics (only with your consent on the marketing site): Vercel Analytics and our own page-view beacon. Guest guidebook pages never load these.

Third-party embeds on guest pages: a map loads only when you tap “Show map”; a video embed, if a host adds one, loads from the video provider. Each may set its own cookies once loaded.

Change or withdraw your choice at any time:

Your rights

You can ask for a copy of your personal data, correction, deletion, restriction, portability, or to object to processing based on legitimate interests, and you can withdraw consent at any time. Guests should usually ask their host first (the host is the controller), but you can also email us and we will help. Email enquiries@quietstay.co.uk and we’ll respond within a month. If you think we’ve handled your data badly you can complain to the ICO (ico.org.uk).

Changes

If this policy changes materially we’ll tell hosts by email or in the dashboard. The effective date at the top always reflects the current version.

See also our Terms & Conditions.