Privacy Policy

Last updated: 6 August 2026

This Privacy Policy explains how TeamStays Limited uses personal data relating to Hosts, Customers, bookers, Guests, and website users. It is written for the UK legal framework, including the UK GDPR and Data Protection Act 2018.

1. Who we are

TeamStays Limited (company number 17251592) of 128 City Road, London, United Kingdom, EC1V 2NX is the controller of personal data described in this policy when we decide how and why it is processed for our platform, payment administration, compliance, and support activities. Contact: info@teamstays.co.uk.

2. Categories of personal data

  • Identity and contact data, including name, job title, company name, email address, telephone number, billing address, and emergency contact details.
  • Booking data, including property, stay dates, Guest names, occupancy, access details, communication records, complaint records, and booking history.
  • Payment and finance data, including bank details, payment status, transaction references, billing data, refunds, chargebacks, and tax/VAT information.
  • Verification and compliance data, including ID documents, company registration details, sanctions screening information, fraud prevention signals, device/browser information, and audit logs.
  • Property and host compliance data, including ownership or authority documents, insurance details, licences, safety certificates, and listing content.
  • Support and call data, including emails, tickets, call recordings, chat transcripts, and complaint handling notes.

3. Purposes and lawful bases

PurposeExamplesLawful basis
Operate bookings and accountsCreate accounts, arrange bookings, send confirmations, manage stay changes, support check-in and check-outContract or steps prior to contract
Payment administrationCollect, hold, release, refund, reconcile, and recover booking fundsContract; legitimate interests
Fraud, sanctions, and identity checksVerify parties, screen risk, prevent misuse, manage suspicious activityLegal obligation; legitimate interests
Customer and host supportHandle enquiries, incidents, complaints, and service quality reviewsContract; legitimate interests
Legal and tax complianceMaintain records, respond to authorities, keep accounting and audit recordsLegal obligation
Platform improvement and securityAnalyse performance, maintain logs, defend systems, investigate abuseLegitimate interests
Marketing to business contactsSend relevant B2B updates where permitted by lawLegitimate interests or consent, depending on channel and circumstances

4. Who we share data with

  • Hosts and Customers, where sharing is necessary to arrange and perform bookings.
  • Payment processors, banking partners, fraud tools, sanctions screening providers, and identity verification providers.
  • Professional advisers, auditors, insurers, debt recovery providers, and legal representatives where reasonably necessary.
  • IT, cloud, communications, customer support, and analytics service providers acting on our instructions.
  • Courts, regulators, law enforcement, tax authorities, or other bodies where disclosure is required or reasonably necessary.

5. Identity checks and compliance monitoring

We may require Hosts, Customers, bookers, or Guests to complete identity, business verification, sanctions, fraud, or payment-risk checks before or after booking. If a required check is not completed or raises a material concern, we may suspend the account, withhold payout, decline the booking, or request further information.

6. Data relating to Guests

Customers and bookers must ensure they have a lawful basis to provide Guest data to TeamStays and the Host. Hosts must use Guest data only as necessary to perform the stay, comply with law, handle incidents, or defend legal claims, and must not use it for unrelated marketing or profiling.

7. International transfers

Where personal data is transferred outside the UK, TeamStays will use appropriate safeguards required by applicable law, such as adequacy regulations, approved contract terms, or other lawful transfer mechanisms.

8. Retention

  • Account and booking records: retained for as long as needed for the account relationship and then for a reasonable period to manage legal, tax, and audit obligations.
  • Payment and tax records: retained for the period required by accounting and tax law.
  • Complaint, incident, and claim records: retained for as long as reasonably necessary to manage the issue and limitation periods.
  • Call recordings and support logs: retained for quality, training, dispute resolution, and legal defence purposes for a limited retention period set by internal policy.

9. Data subject rights

  • Depending on the circumstances, individuals may have rights of access, rectification, erasure, restriction, objection, data portability, and complaint to the Information Commissioner’s Office.
  • Requests should be sent to the contact email in this policy. We may need to verify identity before acting on a request.

10. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or disclosure. No online service is completely secure, and users should also protect their account credentials and devices.

11. Cookies and analytics

The TeamStays website may use cookies and similar technologies for login, site functionality, security, and analytics. Non-essential cookies should be controlled through an appropriate consent mechanism where required by law.

12. Changes to this policy

We may update this Privacy Policy from time to time. The current version date will be shown on the document or website publication page.