- The personal information we will collect;
- Use of collected personal information;
- Who has access to the personal information collected;
- The rights of users who access and use the Stay Platform;
2. PERSONAL INFORMATION WE COLLECT
2.1 Information required to open a Stay Account.
When you perform certain functions on our Site, such as create an account, or book a stay, we may request that you provide the following information:
- First and last name;
- Date of birth;
- Email address;
- Phone number;
- Profile picture;
- Payment information;
- and other identifying documents, such as a government issued ID.
2.2 Information you may choose to give us.
You may choose to provide us with additional personal information. For example:
- when participating in promotions, engaging with other Stay Platform users, or in other optional activities
- when you add optional profile information, some of which may be visible on your public profile page
- when you share address book contact information
2.3 Information Automatically Collected by Using the Stay Platform and our Payment Services.
When you use the Stay Platform and Payment Services, we may automatically collect and store information about you, including information arising from your relationship with and through us and your use of the Stay Platform, such as:
- location information;
- IP address;
- hardware and software information about your device;
- payment transaction information;
- cookies, as described in the Cookie section of this Policy;
- clicked links;
- the content you have viewed.
2.4 Personal Information We Collect from Third Parties.
We collect personal information from other sources, such as:
- Background Information. To the extent permitted by applicable law, and with your consent where required, we may obtain information from public records related to criminal history or sex offender registrations. To obtain such information, we may provide your full name and date of birth.
- Referrals. Through our referral program, a current Guest or Host may submit to us personal information about you such as name and email address.
- Other Sources. Where permissible under applicable law, we may receive information from other resource sources such as related to identity verification or health information, and we may use that information, combined with information we currently have, to help us prevent fraud or address other safety concerns.
3. HOW WE USE PERSONAL INFORMATION AND OTHER DATA.
We use the personal information that you provide or that we collect for legal and regulatory purposes, to manage business risks, to provide our services to you, and to establish and enhance our relationship with you.
The Personal Information and data we collect is used for the following purposes:
- To improve and add to the services we provide to you;
- To provide support services to you;
- To provide you with account related notifications and additional information that you have opted to receive;
- For investigation purposes and fraud prevention;
- To enable your participation in promotions, such as the Stay Referral Program;
- To customize aspects of your use of the Stay Platform;
- For research and analysis, and product development;
- To assist with regulatory compliance;
- To enforce our Terms and Policies;
- To comply with our legal obligations.
4. SHARING YOUR PERSONAL INFORMATION
4.1 Sharing With Your Consent or at Your Direction.
We may disclose your personal information where you have authorized us to do so. Where permissible under applicable law, we may use certain anonymized information about you to promote our products and services.
4.2 Sharing Between Users.
Reviews and cancellation history may be shared between Guest(s) and Host(s). Certain information related to your profile and activity may need to be shared with other Users. For example, when you book a stay, your information is shared with the Host.
4.3 Information You Publish.
You can choose to make certain information public, such as:
- information on your public profile page
- Information included in social media posts or discussion forums and blogs
- Ratings and feedback
- Pages that include information about your Property or Experience such as photos, availability, and location information.
We reserve the right to display content that you have made publicly available on the Stay Platform, on third-party sites, platforms and apps. Additionally, your public content may be indexed by third-party search engines, unless you have opted out of that feature where that option is available. If you make any content publicly available on the Stay Platform, Stay will own all right, title and interest in, and shall have all rights to use such content for any purpose whatsoever. You hereby irrevocably assign to Stay all right, title and interest in and to any content you make publicly available on the Stay Platform, and agree to provide Stay any assistance we may require to document, perfect and maintain our rights in such content.
4.4 Information Used by Hosts to Provide Third-Party Services.
Services provided by Hosts may require the sharing of certain information about Guests such as name, contact information, and dates of booking.
4.5 Legal Compliance, Protection and Safety.
As permitted or required by applicable law, we may disclose your information to any authorized third parties, such as courts, law enforcement, governmental or public authorities, to comply with legal obligations, enforce our User agreements, and protect the rights and safety of Stay, its employees and Users, as well as the general public. We may store or process your personal information outside of your jurisdiction, and physical storage of your personal information may span multiple jurisdictions or countries and we may disclose your personal information in response to valid demands or requests from governments, regulators, courts or law enforcement authorities in those jurisdictions or countries.
Where appropriate, permissible and advisable we may notify Users about legal requests.
Where required under local law, Stay may share Host details such as full name, tax identification number and contact information, the address of the Property, listing information and number of nights booked.
4.6 Special Programs.
In the event that Stay has entered into an agreement with the landlord, property owner, or management company, as permissible by applicable law, we may share personal information about Hosts and Guests related to bookings to facilitate hosting and other services, and compliance with applicable laws.
4.7 Sharing with Third Parties.
We may share your personal and payment information with our business partners, suppliers, agents, advertisers and other third party organizations that perform services for us, or on our behalf (“Third Parties”) to the extent necessary to provide and administer the services that you have requested from us, or to offer you certain products, services, advertisements or promotions where applicable.
Stay does not share your data with Third Parties beyond what is reasonably necessary to achieve the given purpose. Third Parties may perform activities outside of your jurisdiction, and as a result, your personal information may be securely used, stored or accessed in another country than our own, and may be subject to the laws of those jurisdictions. Third Parties may be required to disclose your personal information in response to valid demands or requests from governments, regulators, courts and law enforcement authorities in those jurisdictions or countries.
4.8 Business Transfers.
We may share your personal information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by a third party. In the event that we are acquired by or merged with a third party entity, or if we sell a part of our business, we reserve the right to transfer or assign the Personal Information that we have collected from you as part of such merger, sale or other change of control
4.9 The Stay Group.
We may share your Personal Information with our subsidiaries or affiliates (the “Group”) for: fraud or crime prevention, suppression or detection; for legal and regulatory purposes and to meet regulatory, legal or reporting requirements; to manage business risks; to perform analytics; to ensure that we have correct and up to date information about you; and to the extent necessary if you have requested a Service that is jointly offered by more than one member of the Group. We may also share your Personal Information to better manage your total relationship with the Group and enable other members of the Group to bring suitable Services to your attention.
5. OTHER IMPORTANT INFORMATION
5.1 Aggregate Information
We may actively and/or passively monitor and analyze your activity and communications on the Stay Platform, automatically or manually as we determine in our sole discretion. In connection with the foregoing, we may generate non-identifying and aggregate profiles based off the information you provide to us, and through your activity, communications and use of the Stay Platform. These non-identifying and aggregate profiles are used by Stay (and may be shared with its Third Party partners) to provide additional services to you, to improve the quality of our services, and to develop new services to enhance the Stay Platform.
5.3 Connecting to or Using Third-Parties.
When you connect to or use certain unaffiliated third-party services which may be available on the Stay Platform, such as Google Maps and Facebook, you are providing your information to them, or authorizing them to provide information to us. These third parties have their own privacy policies which may be different from our privacy policies.
6. YOUR RIGHTS
Under applicable law, you have certain rights regarding our collection and use of your data as described in this section 6.
6.1 How to Access, Modify, Delete, or Challenge the Data Collected
We make good faith efforts to provide you with access to your Personal Information and to delete such data at your request if it is not otherwise required to be retained by law or for legitimate business purposes. We ask individual users to identify themselves and the information requested to be accessed, corrected or removed before processing such requests, and we may decline to process requests that are unreasonably repetitive or systematic, require disproportionate technical effort, jeopardize the privacy of others, or would be extremely impractical (for instance, requests concerning information residing on backup records), or for which access is not otherwise required. In any case where we provide information access and correction, we perform this service free of charge, except if doing so would require a disproportionate effort. We will advise you of any applicable fee prior to proceeding with your request. Upon your request, we will make reasonable efforts to delete your Personal Information from our database, however, it may be impossible to delete your information without retaining some residual information for a period of time due to backups and records of deletion.
We retain your Personal Information only for as long as it is necessary for the purpose(s) for which it was collected. This length of time will vary depending on the Service and the nature of the information and may extend beyond the end of your relationship with us. When your information is no longer needed for the purpose for which it was collected, we will destroy, delete, erase or convert it to an anonymous form. We will retain and use your Personal Information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your information to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
- to know if we have collected your personal data;
- to know how we have used your personal data;
- to know if we have disclosed your personal data and to whom we disclosed your personal data;
- copies of your data;
- for your data to be deleted or modified in any way.
We may require that you verify your identity prior to acting on any request. Our approval and handling of any request will be based on applicable law.
The security of your Personal Information is important to us, but remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security. We follow generally accepted industry standards to safeguard your Personal Information from loss or theft, unauthorized access, disclosure, duplication, use or modification through security measures appropriate to the sensitivity of the information. These measures include internal reviews of our data collection, storage and processing practices and security measures which include appropriate encryption and physical security measures to guard against unauthorized access to systems where we store Personal Information
8. PROVIDING OR WITHDRAWING YOUR CONSENT
You may withdraw your consent provided that: you provide reasonable notice; we are not legally required to collect, use or disclose your Personal Information; and withdrawing your consent does not impede our ability to fulfill our obligations to you. You may withdraw your consent by contacting our privacy officer at:
Our privacy officer will be pleased to explain your options and any consequences of refusing or withdrawing your consent, and record your choices.
9. INDIVIDUALS RESIDING IN THE EUROPEAN ECONOMIC AREA
If you are an individual from the EEA, please note that our legal basis for collecting and using your Personal Information will depend on the Personal Information collected and the specific context in which we collect it. We normally will collect Personal Information from you only where: (a) we have your consent to do so, (b) where we need your Personal Information to perform the services, or (c) where the processing is in our legitimate interests. Please note that in most cases, if you do not provide the requested information, we will not be able to provide the requested service to you. In some cases, we may also have a legal obligation to collect Personal Information from you, or may otherwise need the Personal Information to protect your vital interests or those of another person. Where we rely on your consent to process your Personal Information, you have the right to withdraw or decline consent at any time. Such withdrawal of your consent will not affect the lawfulness of our processing of your Personal Information before such withdrawal. Where we rely on our legitimate interests to process your personal data, you have the right to contact our Privacy Officer to object.
We use service providers or other third parties to help us provide our products or services to you. Such service providers may have access to your Personal Information. Regardless of where these service providers or other third parties are located, we require that they also comply with the GDPR and the applicable data protection laws.
If you are located in the EEA, you have certain rights under the GDPR with respect to your personal data, including the right to request access to, correct, amend, delete, port to another service provider, or object to certain uses of your personal data.
- Right of Access. You may access your Personal Information in order to verify that it is being processed in accordance with law.
- Right to Rectification. You may request the correction of inaccurate or incomplete Personal Information.
- Right to Erasure (“Right to be Forgotten”). You have the right to request the deletion of your Personal Information from our systems without undue delay where there is no compelling reason for its continued processing (if, for example, your Personal Information is no longer needed for the purposes for which it was collected or if you withdraw consent on which processing is based and where there is no other legal ground for processing). In such circumstances, we will take reasonable steps to inform other controllers who have had access to your Personal Information of your request.
- Right to Restriction of Processing. If you dispute the accuracy of your Personal Information or object to its processing you have the right to request us to restrict the processing of your Personal Information until your complaint has been resolved.
- Right to Data Portability. You have the right to receive your Personal Information that you have provided us in a structured, commonly used and machine-readable format and you have the right to transmit that information to another controller.
- Right to Object. You have the right to object to the processing of your Personal Information under certain circumstances, in particular if we process your Personal Information on the basis of legitimate interest or if we use your Personal Information for marketing purposes.
You can assert your above mentioned rights by contacting our Privacy Officer at:
Our products and services are mainly provided from our offices in Canada. We use third party service providers to provide our products and services. These third party providers may process, or store, Personal Information on servers outside of the EEA, including in Canada or the US. Whenever we transfer Personal Information from individuals residing in the EEA to a third-party service provider located in a country that has been deemed inadequate we do so with an approved legal adequacy mechanisms in place. For any transfers of Personal Information to the US, we rely on either the third-party’s registration in the EU-US Privacy Shield or on the implementation of the European Union’s Standard Contractual Clauses. By accessing or using our websites or services or otherwise providing information to us, you are agreeing to the transfer of your Personal Information to Canada and other jurisdictions in which we and our third party service providers operate. If you have concerns or complaints about this policy or our privacy practices that you do not feel you can resolve through contacting us you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction at any time.
11. THIRD PARTY SITES
12. OTHER INTERNATIONAL USERS
Please note that we use cloud storage services to store and process your Personal Information. In some cases, we store and process your Personal Information outside your own country. As a result, the physical storage of your Personal Information may span multiple jurisdictions or countries and the governments, regulators, courts or law enforcement authorities in those jurisdictions or countries may be able to obtain disclosure of your information through applicable laws. Your use of the Services or your submission of any Personal Information to us will constitute your consent to the transfer of your Personal Information outside of your home country, which may provide for different data protection rules than those in your own country.
We do not knowingly collect any Personal Information of minors. If you are an individual, by accessing or using the Services you represent and warrant that you are of legal age to form a binding contract. If we learn that Personal Information of a minor has been inadvertently collected without parental or guardian consent, we will take the appropriate steps to delete this information. If you are a parent or guardian and discover that a minor for which you are responsible has provided his or her Personal Information to us without your consent, then you may alert us by contacting our privacy officer at us at:
14. Complaints and Questions
- If you are located in Canada and are not satisfied with our response to your inquiries, you may contact the Office of the Privacy Commissioner of Canada by mail at 30 Victoria Street Gatineau, Quebec K1A 1H3 or by calling 1 800 282 1376.