Skip to main content
StayToEnjoy

Data protection and privacy

Privacy Policy

This privacy statement informs you about how StayToEnjoy processes personal data when you use our website, app, social, commercial, booking, live and business functions.

Last updated: July 2026·GDPR compliant·EU hosting

1. Protection of data at a glance

The protection of your personal data is an important concern for us. We only process your data within the framework of applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and additional national data protection regulations.

What this privacy statement is about

This Privacy Statement applies to the use of StayToEnjoy including website, app, user account, profiles, social and community features, messaging, marketplace, booking, live streaming, live shopping, business dashboards, and support and security-related processes.

Briefly summarised

  • We process data to provide, secure and develop our platform.
  • Depending on the use, we process, for example, account, profile, communication, transaction, device and usage data.
  • Certain data are processed for the purpose of contract fulfillment, others are processed on the basis of legal obligations, legitimate interests or your consent.
  • You have extensive rights, including information, rectification, deletion, objection and data portability.

2. responsible body

Responsible

Responsible for data processing within the meaning of data protection laws is:

StayToEnjoy UG (haftungsbeschränkt)

Brökerei 6

26129 Oldenburg, Deutschland

E-Mail: datenschutz@staytoenjoy.com

Contact with data protection

If you have questions about data protection, the exercise of your rights or data protection concerns, you can contact us at any time using the contact details mentioned above.

3. Hosting, Infrastructure & Security

StayToEnjoy uses technical infrastructure, hosting and cloud services to provide the platform securely, efficiently and reliably.

We shall take appropriate technical and organisational measures to protect personal data, in particular to ensure the confidentiality, integrity, availability and resilience of our systems.

Hosting and system operation

In particular, server logs, technical metadata, usage data, security events and communication data may be processed in the context of hosting and platform operation.

Security measures

  • Access restrictions and role/rights management
  • Transport encryption and technical securing of connections
  • Monitoring, error analysis and protection against abuse
  • Backups, recovery and security processes

4. What data we process

Depending on the use of StayToEnjoy, we may in particular process the following categories of personal data:

  • Stock data such as name, e-mail address, telephone number, account data
  • Profile data such as username, profile picture, bio, preferences, settings
  • Authentication data, such as login information, security and verification data
  • Communication data such as messages, support requests, messages and interactions
  • Use data, such as content called up, clicks, ranges, interactions, session data
  • Device and technical data such as IP address, browser type, operating system, language, time zone
  • Transaction and booking data, e.g. orders, reservations, booking status, refund reference
  • Supplier data, such as business statements, listings, performance data, verification documents
  • Content data, such as posts, comments, reviews, uploads, content related to livestreams

5. Purposes and legal bases

Contract performance and implementation of pre-contractual measures

We process data to the extent necessary to provide user accounts, perform functions of the platform, make purchases, bookings, communications or business functions technically possible.

Consent given

Insofar as we obtain your consent for certain processing operations, the processing takes place on the basis of that consent.

Legitimate interests

Where permitted, we process data to protect legitimate interests, in particular for:

  • Operation, security and stability of the platform
  • Abuse, fraud and risk detection
  • Product improvement, analysis and further development
  • Moderation, Trust & Safety and enforcement of platform rules
  • Internal administration, documentation and legal protection

Abuse and fraud prevention of assessments

In order to detect false reviews, automated bot reviews, multiple accounts and coordinated spam, and to protect the integrity of reviews, we only process data-minimized behavioral signals when submitting a review:

  • your IP address is only shortened (on the subnet /24 for IPv4 or /48 for IPv6) never in plain text
  • your browser and operating system type (buried, no complete device fingerprint)
  • a device-specific identification if your device is already using it for registration
  • Date, valuation and accounting reference for the assignment

The legal basis is our legitimate interest in fraud and abuse prevention (Art. 6 (1) (f) DSGVO).90 days automatically deleted and are intended exclusively for the purpose of preventing abuse.

Objection (Article 21 of the GDPR): You can object to this behavior-based assessment, in which case we will no longer record such signals for you; your reputation will be based solely on objective facts (e.g. verified visits, helpful reviews).

Legal obligations

Processing may also take place insofar as it is necessary to comply with legal obligations, such as commercial, tax, supervisory or data protection requirements.

Data collection by website and app

Server log files

When visiting our website or app, technical information is automatically collected to deliver the platform, ensure security and analyze errors.

  • IP address
  • Date and time of access
  • Used pages or resources
  • Browser type and browser version
  • Operating system
  • Referrer URLs
  • Technical status and log data

Fault analysis and stability

Technical data may be processed to detect and correct performance problems, crashes, charging problems, safety events or malfunctions.

7 Account, profile and authentication

Registration and login

When you create an account or sign in, we process the data necessary to set up your user account, manage access and implement security measures.

Profile and settings

As part of your profile and settings, we process the information you provide to provide personalized features and to store your preferences.

Safety and verification

To secure accounts and platform features, we may process security-related information, login metadata, verification status, or abuse indicators.

8. social, community and interactions

If you use StayToEnjoy's social and community features, we process the content and interactions you create or trigger.

  • Posts, comments, reactions, likes, saves and shares
  • Followers, profile and community relations
  • Reports of content or users
  • Interaction and scope data
  • Moderation and security information
Content and interactions may be visible to other users insofar as this corresponds to the platform's function or depends on your settings.

9 Providers, listings and business tools

If you use StayToEnjoy as a supplier, retailer or service provider, we also process business-related data to provide the platform functionality to business users.

  • Business and enterprise data
  • Contact and verification data
  • Listing, product, service and booking information
  • Dashboard, performance and analytical values
  • Communication and support data in the business context

10. Purchases, bookings and payments

Transactions and bookings

In connection with purchases, orders, reservations, appointments or bookings, we process the necessary data for technical handling, documentation, communication and abuse prevention.

Payments by third parties

Where payment functions are available on StayToEnjoy, payment data may be processed by external payment service providers.

Close to transaction data

Regardless of the actual payment process, we may process transaction-related information, such as order status, booking references, cancellation or refund references, communication data and abuse-relevant signals.

11. live streaming and live shopping

When using live functions, additional data may be processed, such as in relation to stream participation, interactions, comments, moderation, technical quality and security.

  • Live comments, reactions and interactions
  • technical streaming and connection data
  • Moderation, reporting and security data
  • Live purchasing or booking interactions

12. Communication and support

Contacts

If you contact us, for example by e-mail, form, support centre or as part of enquiries, we process your information for processing your request and for enquiries.

Support and case management

In support, complaint, security or trust and safety cases, we may also process case-related information, content, communications and evidence.

13. Cookies, consent and similar technologies

Common

We use cookies and similar technologies insofar as this is necessary or agreed by you for the operation, security, ease of use, analysis or optional functions of the platform.

Categories

  • Cookies required for basic functions, security and session management
  • Functional cookies for preferences, language and comfort functions
  • Analysis and performance technologies for measurement and improvement
  • Optional marketing or reach technologies, where used and permitted

Management of consent

Where required by law, we obtain your consent for unnecessary cookies or similar technologies. You can change or withdraw your consent at any time with effect for the future.

14. Analysis, scope and improvement

Current status: We do not use any analysis or range measurement. There's no Google Analytics, no Matomo, and no comparable service, and we don't create user profiles, and we don't evaluate your behavior on the platform for analytical purposes.

What we process is only the technically relevant server protocols (see Section 3) which are, for example, error messages, loading times and access data that every web server inevitably generates.

Should we introduce a range measurement in the future, we will complete this privacy statement beforehand and, where necessary, obtain your consent via our cookie banner.

15. Recipients and processors

These are the service providers that we actually use. They process data exclusively on our behalf and on our instructions (processing orders under Art. 28 DSGVO), unless otherwise stated below:

  • Amazon Web Services EMEA SARL, Luxembourg hosting our servers, storing uploaded media and invoices and sending our system emails.
  • MongoDB Ltd. (MongoDB Atlas) Operating our database.The cluster is located in the AWS Frankfurt region (eu-central-1).
  • Host Europe GmbH, Cologne operation of our mail server and DNS management for staytoenjoy.com.
  • Stripe Payments Europe Ltd., Ireland processing payments if you initiate a fee-based transaction. Stripe processes payment data partly on its own responsibility as its own controller.
  • Authorities or courts, insofar as we are required by law to provide information.
In addition, we areof which:In particular, we are making use of other service providers. No analytical, tracking or advertising services In addition, the Commission considers that, in the light of the above, it is necessary to ensure that the information provided by the Member States is kept up to date in order to ensure that the information provided is kept up to date and that no third party content, fonts or images are attached everything is delivered from our own servers.

16. transfers to third countries

All our infrastructure is in the European Union. Servers, database, media storage, mail and mail servers operate exclusively in Germany (AWS-Region Frankfurt and Host Europe in Cologne).No transmission to third countries It's not.

The only possible exception concernsPayments: Our contractual partner is Stripe Payments Europe Ltd. based in Ireland (EU). Access by the US parent company Stripe, Inc. cannot be excluded. This transmission is made on the basis of the guarantees provided by Stripe (Standard Contractual Clauses of the EU Commission or EU-US Data Privacy Framework).

In addition to the aforementioned payment processing, we do not currently use any service outside the EU/EEA. Should there be further additions in the future, we will supplement this privacy statement in advance and specify the basis for the transfer.

17. Duration of storage and deletion

We only store personal data for as long as this is necessary for the respective purposes or as long as there are statutory retention or verification obligations.

Delete your account this is how it runs

  • Stage 1 (Deactivation): After requesting deletion, your account will be activated immediately invisibly. Within 30 days, you can revoke the deletion by simply logging in.
  • Phase 2 (Final deletion): At the end of the 30 days, your data will be irrevocably deleted from the active systems within another 14 days including profile, settings, addresses, contributions and searches.
  • Stage 3 (security copies): Data for system security reasons shall remain in backups for a maximum of three months until they are overwritten in turn.

What cannot be deleted for legal reasons remains limited (Article 18 GDPR): invoices and proofs of payment are subject to a 10-year retention obligation (Article 147 AO). Reviews written by you remain anonymous; messages you have sent to others remain visible to the recipient then only appears as the sender Deleted account".

  • Account data, in principle, for the duration of the user relationship
  • Transaction, accounting and billing data in accordance with statutory obligations
  • Security and log data, in principle, only for as long as necessary for security and detection purposes
  • Support and case information in accordance with its factual need and legal requirements

18. Your Rights

You have, in particular, the following rights under the law:

  • Information about the personal data we process
  • Correction of incorrect or incomplete data
  • Deletion of personal data
  • Restriction of processing
  • Objection to certain processes
  • Transferability of data
  • Withdrawal of consent granted with effect for the future
  • Complaint to a data protection authority
To exercise your rights, you can contact us at any time via data protection@staytoenjoy.com.
The supervisory authority responsible for us is Oldenburg (Niedersachsen) Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.

19. Protection of minors

Insofar as individual functions or areas of StayToEnjoy are intended only for adult or specially authorised users, we may take appropriate measures to restrict, review or enforce such conditions of use.

20. Amendments to this Privacy Statement

We may modify this Privacy Statement with effect for the future, in particular in the event of changes to legal requirements, technical processes, platform functions or new services.

The current version will be published on StayToEnjoy.