PRIVACY POLICY
Version 1.0 | Last updated: August 1, 2026.
1. Who is the data controller
The data controller for the StayPicker portal is JP Atelier d.o.o., Ulica Vjekoslava Klaića 14, 10000 Zagreb, Croatia, OIB: 83933848262.
For questions related to privacy protection and exercising rights, contact us at: [email protected].
RELATIONSHIP WITH THE HOST
As a rule, the host has a separate processing manager for the data required for the execution of the accommodation, communication with the guest, registration in eVisitor, issuing invoices and fulfilling their own legal obligations. His identity and contact are available with the offer and in the booking confirmation.
2. To whom the Policy applies
2.1. The policy applies to portal visitors, guests, persons involved in a reservation, registered hosts, their authorized persons, persons sending inquiries or complaints, and newsletter recipients.
3. What data we process
| Category | Examples |
|---|---|
| Identification and contact information | name, surname, email, phone, address, country, language |
| Reservation information | property, dates, number and age categories of guests, special requests, booking rules, booking number |
| Data of persons traveling | name and other information required for confirmation, legal guest registration or reservation execution, when provided by the reservation holder |
| Payment Information | amount, currency, transaction status, masked card data, IBAN, PSP identifier, returns and chargeback; complete card data is processed by PSP. |
| Communication and support | messages, complaints, documents and evidence related to the reservation |
| Technical data | IP address, device, browser, operating system, access time, logs, security events and cookie identifiers |
| Host and partner information | identity, OIB/TIN, VAT ID, address, registration, solution, IBAN, tax residency, real estate data, authorized persons and DAC7 data |
| Content and Feedback | reviews, ratings, photos and other content voluntarily posted by the user |
| Marketing data | consent, topic choices, newsletter interactions and communication settings |
4. Where do we get the data from
- directly from website visitors when they search, make a reservation, contact support or sign up for the newsletter;
- from the reservation holder who enters the companion's details;
- from the host, MyRent system and related channel manager/PMS integrations;
- from payment service providers, banks and fraud prevention systems;
- from public registers and reliable sources when checking hosts and tax data;
- automatically through cookies, logs and similar technologies.
5. Purposes and legal basis
| Purpose | Legal basis and clarification |
|---|---|
| Search, reservation and contract execution | contract execution or actions at the request of the guest prior to entering into a contract; includes booking confirmation, forwarding to the host, support and change management. |
| Billing, Refunds, and Fraud Prevention | execution of the contract, legal obligation and legitimate interest of protecting users, funds and platform. |
| User Account and Security | performance of contracts and legitimate interest in authentication, system protection, logging and investigation of abuse. |
| Legal, tax and accounting obligations | legal obligation, including fiscalization, accounts, keeping documentation, requests from competent authorities and DAC7. |
| Complaints and legal claims | legal obligation and legitimate interest to prove, defend and resolve disputes. |
| Service Improvement and Basic Analytics | legitimate interest in understanding how the portal works with data minimization; consent is used for analytical cookies. |
| Newsletter and personalized marketing | consent, except where direct marketing is permitted by another legal basis with the right to object. |
| Reviews and content moderation | enforcement of platform terms, legitimate interest in reliability and security, and legal obligations under the DSA. |
| Host Verification and Offers | legal obligation and legitimate interest in preventing fraud, protecting guests, and complying with platform policies. |
6. Mandatory and voluntary data
6.1. Data marked as mandatory is required for booking, payment, legal verification or fulfillment of the accommodation. If you do not provide it, we may not be able to confirm the booking, make a payment to the host or provide a certain feature. Voluntary data, such as marketing interests, is not a requirement for booking.
7. With whom we share data
| Recipient | Purpose |
|---|---|
| Host / accommodation provider | for confirmation, communication, check-in, eVisitor, invoicing, reservation fulfillment and complaint resolution. |
| Payment service provider and banks | for authorization, collection, payment, refund, chargeback procedures and fraud prevention. |
| MyRent and technical providers | hosting, cloud, e-mail, customer support, security, analytics, communication and maintenance, according to data processing agreements. |
| Accountants, auditors, legal and tax advisors | to the extent necessary to provide professional services and with an obligation of confidentiality. |
| Tax Administration and other competent authorities | when processing is necessary for fiscalization, DAC7 reporting, legal requirements, court orders or protection of rights. |
| Insurers and claims adjusters | when it is necessary to process a request, fraud, or security incident. |
| Affiliates or business acquirer | to the extent necessary for the reorganization, investment or transfer of the business, with appropriate safeguards. |
8. International Transfers
8.1. We primarily aim to process data within the European Economic Area (EEA). If the service provider processes data outside the EEA, we use an adequacy decision, standard contractual clauses or other legally permitted mechanism and assess the necessary additional safeguards.
9. Storage periods
| Dataset | Deadline / criteria |
|---|---|
| Reservations, billing, invoices and tax documentation | at least during the statutory deadlines; relevant accounting documents as a rule for at least 11 years, unless other regulation requires otherwise. |
| User account | while active and up to 5 years after closure, except when longer retention is necessary due to reservations, disputes or legal obligations. |
| Communication and objections | at least 1 year for legal records of complaints, and usually up to 5 years for proving and defending legal claims. |
| Security and technical logs | usually from 1 to 24 months, depending on the purpose, risk level and incident. |
| Marketing Consent | until withdrawal of consent or a maximum of 3 years from the last relevant interaction, while keeping minimal evidence of withdrawal to comply with the no-contact order. |
| DAC7 and host verification | during the period prescribed by tax and other mandatory regulations. |
| Failed requests without reservation | usually up to 12 months, unless earlier deletion is requested or longer retention is justified due to a dispute or legal obligation. |
10. Cookies and similar technologies
10.1. Essential cookies are used for security, session, shopping cart, language and basic functionality and do not require consent when they are strictly necessary.
10.2. Analytical, personalization and marketing cookies are only activated after the appropriate selection in the consent interface. Refusal must be available as easily as acceptance.
10.3. The user can change the settings at any time via the "Cookie Settings" link. A detailed list of cookies, providers, purposes and duration is published in a separate Cookie Policy upon first visit to the site.
11. Automated decision-making and profiling
11.1. We may use automated indicators to detect fraud, security risk, duplicate bookings and ranking results. As a rule, such processing does not produce a legal effect solely by an automated decision.
11.2. If a decision is introduced that produces legal or similarly significant effects solely by automated processing, we will provide specific information about the logic, significance and consequences before its implementation and allow for human intervention where prescribed.
12. Data security
12.1. We implement measures appropriate to the risk, including access control, authentication, transmission encryption, backups, logging, segmentation, contractual obligations of executors, vulnerability management and incident response plan.
13. Your rights
- right to information and access to personal data;
- the right to correct inaccurate or supplement incomplete data;
- the right to erasure when there is no longer a valid basis for processing, subject to legal exceptions;
- the right to restriction of processing;
- the right to data portability when the processing is based on a contract or consent and is carried out by automated means;
- the right to object to processing based on legitimate interest, in particular direct marketing;
- the right to withdraw consent at any time without affecting the previous lawfulness of the processing;
- the right not to be subject to solely automated decision-making in cases prescribed by the GDPR;
- the right to file a complaint with the Personal Data Protection Agency (AZOP).
Send your request to [email protected]. For data protection reasons, we may request reasonable verification of your identity. We will respond within the time frame set by GDPR, with the possibility of an extension for complex requests with a justification.
14. Data of other persons and children
14.1. When the reservation holder provides the details of a companion, they are obliged to inform them of this and refer them to this Policy. They must not provide more information than is necessary.
14.2. The portal is not intended for independent conclusion of contracts by children. We process the data of minors only when they are necessary for booking, legal registration and accommodation and they are submitted by a responsible adult.
15. DAC7 information for hosts
15.1. StayPicker may collect and submit to the Tax Administration data on hosts, properties, fees, number of reservations and rental days in accordance with DAC7 and Croatian regulations.
15.2. The legal basis is a legal obligation. Processing information is provided to the host prior to collection and reporting. Failure to provide mandatory information may result in suspension, account closure or withholding of payment when required by law.
15.3. The host shall be provided with an overview of the data reported on him, within the scope prescribed by law, no later than the legal deadline.
16. Third-party links and services
16.1. The Portal may contain links to host websites, PSPs, maps, social networks and other services. These providers may be separate controllers and their policies apply to them. We recommend that you read them before using them.
17. Policy Changes
17.1. We may update this Policy to reflect changes in processing, providers, or regulations. The new version will be posted with the effective date.
17.2. If the change materially affects the rights of users, we will provide a prominent notice or direct notification where appropriate. The new purpose requiring consent will not apply without new valid consent.
18. Contact and complaint to the supervisory authority
For privacy issues:
JPAtelier doo / StayPicker
Ulica Vjekoslava Klaića 14
10000 Zagreb, Croatia
E-mail: [email protected]
Supervisory authority:
Agency for Personal Data Protection (AZOP)
Ul. Metela Ožegovića 16
10000 Zagreb, Croatia
www.azop.hr
APPENDIX A. List of key implementers and partners
| Provider | Service | Processing location | Transmission mechanism / Link |
|---|---|---|---|
| [PSP NAME] | Payment and Returns | Dublin, Ireland | Stripe |
| [CLOUD] | Data storage | USA, California | Cloudflare |
| [HOSTING] | Hosting | Lithuania | Hostinger |
| [E-MAIL / CRM] | Communication and customer support | Croatia | myRent CRM |
| [ANALYTICS] | Analytics with consent | Croatia | myRent |