Last updated · 2026-06-10
Privacy Policy
This Privacy Policy explains what data SyncStay collects, why we collect it, how we use it, and the rights you have over it. We try to keep this document short and plain — if anything is unclear, email privacy@syncstay.co.
1. Who we are
"SyncStay" is the channel-management service operated as a sole proprietorship from Kosovo. For the purposes of the General Data Protection Regulation (GDPR), SyncStay is the data controller for the personal data described below.
2. What we collect
- Account data: your name, email address and (if you set one) a hashed password. If you sign in with Google, we receive your email and name from Google.
- Property data: details you enter about each rental — name, address, timezone — and the iCal links you connect for Airbnb, Booking.com or other calendars.
- Booking data: booking dates pulled from the iCal feeds you connect, plus any direct bookings you add manually (guest name, contact, price note and free-text notes — all optional).
- Operational data: sync events, conflict records, notifications and an audit trail of sensitive actions (export, deletion).
- Billing data: if you subscribe, our payment processor (Paddle, acting as Merchant of Record) collects payment information. We receive only the subscription status and the last four digits of your card — never your full card number.
- Technical data: IP address and basic request information for security and abuse prevention, and minimal product analytics (page visits, no tracking of you across other sites).
3. Why we use your data
- To operate the service you signed up for (legitimate interest, contract).
- To prevent double bookings — by polling the calendar URLs you provided, generating an export feed, and emailing you when conflicts or sync failures are detected.
- To handle billing through our payment processor.
- To detect and prevent abuse and to meet our legal obligations.
We do not sell your data, share it with advertisers, or use it to train AI models.
4. Where your data lives
Application data is stored in PostgreSQL on Neon, hosted in the EU (eu-central-1, Frankfurt). Transactional email is processed by Resend. Authentication is handled by Better Auth (running on our servers). Payment processing is handled by Paddle.com Market Ltd as Merchant of Record. The marketing site and dashboard are served from Vercel.
5. Cookies
SyncStay uses a small number of strictly necessary cookies — chiefly the session cookie that keeps you signed in. We do not use third-party advertising or cross-site tracking cookies.
6. Your rights
Under GDPR you have the right to access, correct, export and delete your data, and to object to or restrict processing. SyncStay gives you self-serve buttons for the two most common operations:
- Export— Settings → "Export my data" downloads everything we hold for you as a JSON file.
- Delete— Settings → "Delete my account" permanently erases your account and every record linked to it.
For any other request, email privacy@syncstay.co. You also have the right to lodge a complaint with your national supervisory authority.
7. Retention
Active accounts: we keep your data for as long as your account exists. Cancelled/inactive: if you stop paying and don't reactivate, we keep your data for up to 90 days before deletion, so reactivation is easy. Backups: rolling encrypted backups are retained for up to 30 days. Audit logs survive account deletion (with your identifier removed) for fraud-prevention purposes for up to 12 months.
8. Children
SyncStay is not intended for use by anyone under 16. We do not knowingly collect data from children.
9. Changes
If we make material changes to this policy we will email you in advance and update the "Last updated" date above.