Privacy Policy
Last updated: 2026-09-27
Hospedora is a management platform for short-term rentals and small guesthouses (bookings, guests, online check-in, messaging, invoicing, SIBA reporting, smart locks and the property's website), available in the browser and as a mobile app for iPhone and Android. This policy explains what personal data we process, why, who we share it with, for how long, and your rights. The Portuguese version prevails in case of discrepancy.
1. Who we are and how to contact us
The Hospedora service is provided by Filipe Goucha, sole trader (empresário em nome individual), tax number (NIF) 226324354, professional address Rua do Búzio 66, 7500-016 Costa de Santo André, Portugal ("Hospedora", "we").
Contact for any data protection matter: geral@hospedora.com. We have not appointed a data protection officer: the law only requires one for public bodies or where the core activities consist of regular and systematic monitoring of people on a large scale or large-scale processing of special categories of data (Art. 37 GDPR), which is not our case.
We process personal data in two different roles:
- Controller for account data: the people who sign up to Hospedora (property owners and staff) and people who contact us.
- Processor (Article 28 GDPR) for the data of guests and other people each property records on the platform. The property is the controller: it decides what data is collected and why, and guests exercise their rights with the property. We process that data only on the property's instructions, under the data processing agreement that is part of the Terms of Service.
2. Account data (we are the controller)
What data we process and where it comes from:
- Identity and contact: name, email and preferred language, which you give us when you sign up. If you were invited to a property's team, your email was given to us by the person who invited you.
- Sign-in: the codes sent to your email (stored only as a hash and valid for a short time) and, for older accounts that have one, the password (stored only as a hash). If you sign in with Google or Microsoft, we receive from that provider the account identifier, your name and verified email — nothing else.
- Data about the property you create: name, tax number, address, contacts, photos, and the bank details you choose to show in guest messages.
- Technical and security data: IP address and browser of each session, server logs, the audit log of actions taken in the property, and devices registered for notifications.
- Your subscription (plan, free trial, payments once available) and the messages you send us.
What we use it for, and the legal basis (Art. 6(1) GDPR):
- Creating and running your account, providing the service, support, and service notices (end of trial, changes, security): performance of the contract (point (b)).
- Billing the service and keeping tax documents: legal obligation (point (c)).
- Protecting the platform, detecting abuse, preventing repeated use of the free trial and defending legal claims: legitimate interests (point (f)) in keeping the service secure and fair. You can object to this processing (section 7).
- Sending push notifications: you are asked for permission the first time and can turn them off at any time in your device settings.
Identity and contact data are needed to have an account: without them we cannot provide the service. We make no automated decisions with legal effects on you, do no profiling, do not sell data, run no advertising, and use no third-party analytics or advertising tools on the website or in the app.
3. Guest data (we are a processor)
On behalf of each property we store: identity and contacts of guests and their companions (including children), bookings and payments, messages and communications, online check-in data (including the identity data required by law), reviews and copies of issued tax documents. We do not store payment card data.
Identity document numbers are stored encrypted (AES-256-GCM) and used only for the mandatory SIBA report; the screen only shows the last 4 characters. Check-in identity data is deleted automatically after the retention period set by the property — by default 400 days after check-out, to cover the one year for which the law requires accommodation reports to be kept (Portuguese Law 23/2007, Art. 16) — except while reports are still pending.
Foreign guest registration (SIBA reports to AIMA, Portugal's immigration agency) is the property's legal obligation; the platform sends the reports on the property's instructions, and the property is responsible for them.
Invoicing: when a property connects certified invoicing software (Moloni or Hostkit), the data needed for the invoice is sent there, and that software keeps the tax documents for the legal period of 10 years.
Emails to guests are sent from the property's own mailbox, which the property connects to the platform. Notifications to the property's team may include the guest's name (for example, "New message · Ana Silva").
Properties have tools to export a guest's data and to anonymise a guest; anonymisation keeps only what the law requires (invoices and proof of the SIBA report). Guests should contact the property to exercise their rights; if they contact us directly, we forward the request promptly and help the property respond.
4. Who we share data with
Providers that process data on our behalf (our sub-processors), under contracts requiring them to protect it:
- InstantNode — server and database hosting, in a data centre in the Netherlands (European Economic Area). Uploaded files (photos, documents) are kept on the same server.
- Apple (Apple Distribution International Ltd., Ireland) — sending platform emails from geral@hospedora.com (iCloud Mail), storing the encrypted backups (iCloud Drive), and iPhone notifications (APNs). Backups are encrypted before they leave the server, with a key only we hold: Apple cannot read their content. Apple may process data outside the EEA under the European Commission's standard contractual clauses.
- Expo (650 Industries, Inc., USA) — relaying notifications to the mobile app. Certified under the EU-US Data Privacy Framework.
- Google (Google LLC, USA, and Google Ireland Ltd.) — Android notifications (Firebase Cloud Messaging). Certified under the EU-US Data Privacy Framework, with standard contractual clauses as an additional safeguard.
- Cloudflare, Inc. (USA) — domain name resolution (DNS). Requests to the site do not go through Cloudflare, only the address lookup. Certified under the EU-US Data Privacy Framework.
When you choose to sign in with Google or Microsoft, that provider processes your data as an independent controller under its own privacy policy; we receive only what section 2 describes.
Integrations a property chooses to connect, with its own account and under its own contract with each provider: Moloni and Hostkit (invoicing, Portugal), Beds24 (booking channels, Germany), Nuki (smart locks, Austria), TTLock (smart locks, Hangzhou Sciener, China) and the property's mailbox (for example Google or Microsoft). The platform sends each only what the connected feature needs — locks, for example, receive the access code, the booking reference, the room name and the validity dates, without the guest's name. The property is responsible for assessing those providers, including transfers outside the EEA (China has no adequacy decision).
Recipients by law: AIMA (SIBA reports), the Portuguese Tax Authority (through the property's invoicing software) and other authorities where the law requires.
Transfers outside the European Economic Area: US providers certified under the EU-US Data Privacy Framework are covered by the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR); in other cases, and should that decision cease to apply, the Commission's standard contractual clauses apply (Art. 46). You can ask us for a copy of the applicable safeguards.
5. How long we keep data
- Account: while it is active. When you delete it, the account is deleted immediately. Properties where you are the only owner are closed at once and their data (guests, bookings, files) is deleted or anonymised after 30 days; what the law requires us to keep (invoices and SIBA records) stays until the legal period ends.
- Backups: taken daily, encrypted, and kept for 14 days on the server and 60 days in iCloud Drive. Deleted data disappears from them as the oldest backups are removed, at most 60 days later. Until then they would only be used to restore the service after an incident.
- Signed-in sessions (IP and browser): until the session ends or expires.
- A property's audit log: while the property exists on the platform.
- Server logs: up to 30 days, unless needed to investigate a security incident.
- Check-in identity data: until the period set by the property (by default 400 days after check-out).
- Guests' tax documents: 10 years, in the property's invoicing software. Tax documents for your subscription: 10 years (tax obligation).
- Messages you send us: as long as needed to deal with them and at most 3 years after the last exchange.
6. Deleting your account
You can delete your account at any time, free of charge: in the mobile app (Settings → "Delete account") or in the back office on the web at https://app.hospedora.com (user menu → "Delete account"). Before deletion we show which properties will be closed with it and ask for a code sent to your email. If you cannot sign in, request deletion by email to geral@hospedora.com from the account's address.
Download anything you need first: certified tax documents stay in the property's invoicing software, but data that only exists on the platform will no longer be available.
7. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection (in particular to processing based on legitimate interests), and to withdraw at any time any permission you gave, without affecting what was done before. Many of these you can exercise directly on the platform (edit your profile, turn off notifications, delete your account); for the rest write to geral@hospedora.com. It is free; we may ask you to confirm your identity. We reply within one month, extendable by two further months for complex requests, in which case we will tell you.
You may also lodge a complaint with the Portuguese data protection authority (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, www.cnpd.pt, or with the authority where you live or work.
8. Security
Connections are always encrypted (HTTPS with HSTS); identity document numbers and integration credentials are stored encrypted; sign-in codes are stored only as hashes; each property's data is restricted to its members; sensitive actions are audit-logged; backups are daily, encrypted, and restores are tested.
If there is a personal data breach, we notify the CNPD within 72 hours where the law requires and tell the people affected when there is a high risk to them. If a breach affects guest data, we notify the property without undue delay so it can meet its own obligations.
9. Cookies and on-device storage
- Back office: only strictly necessary cookies — the signed-in session cookie (and a short 5-minute copy of it, so the database is not queried on every request) and, when you sign in to the app with Google or Microsoft, a temporary 10-minute cookie linking the start and end of that process. Your browser also stores, on your device, whether you prefer the sidebar open or closed. None of these needs consent, because the service you asked for does not work without them.
- Hospedora website: uses no cookies. Fonts are served from our own server, with no requests to third parties.
- Mobile app: stores your session in the device's secure storage and, if you allow notifications, the device's notification identifier. It has no advertising or analytics tools.
- A property's guest guide and website: if the property turns them on, they can show a Google Maps map and activity suggestions from GetYourGuide. That content is loaded directly from Google's and GetYourGuide's servers, which receive the visitor's IP address and may use their own cookies or identifiers, under their own policies. The weather forecast is fetched by our server, with no visitor data.
10. Children
Hospedora is intended for adults (18+) who manage properties. Children's data is only processed as guest data (for example, companions in the check-in and SIBA report), on behalf of and under the responsibility of the property.
11. Changes
If we change this policy in a material way, we will tell you by email or on the platform before the change takes effect. The date of the current version is at the top of this page.