The Site is operated by Coolstays, a trading name of Coolstays Ltd, a company registered in England and Wales. Our company registration number is 7804381. Our registered office is at Nile House, Nile St, Brighton, BN1 1HW, UK. When this Privacy Policy mentions "Coolstays," "we," "us," "our," or "Data Controller" it refers to the Coolstays Ltd trading as Coolstays.
We are registered with the Information Commissioner’s Office as a data controller under number Z3404833.
This Privacy Policy sets out how we collect, process and protect any information (including personal data) that you give when you use this website, or communicate with us in any way.
This Privacy Policy applies to all users of our website and service, including property Owners or agents who advertise with us ("Owners"), website visitors who have registered for an account ("Webusers") and website visitors who have not registered for an account ("Visitors").
Use of this website is in accordance with our Terms of Use. By using our site you indicate that you agree to our Terms of Use and this Privacy Policy.
You must be over 18 years old to use our site and to make booking enquiries with Owners. By using our site you confirm that you are over 18 years of age.
If you have any questions about your personal data and this Privacy Policy you can contact us for more information any time by emailing privacy@coolstays.com.
We promise to keep your personal data safe and private, not to sell your personal data, and to give you a simple way to view and manage your marketing and communication choices at any time.
The UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 set out how personal data must be handled in the United Kingdom. This Privacy Policy is designed to comply with these laws.
Personal data includes information commonly considered personal (e.g. names, physical addresses, email addresses), and also data such as IP addresses, behavioural data, location data, financial information, and more.
This Privacy Policy informs you about what kind of information we may collect, how we collect it, why we collect it, the legal basis for collecting it and your rights under the UK GDPR.
We may change this Privacy Policy from time to time by updating this page. Any changes will be effective immediately upon notice which we may give by any means, including updating this page. You should revisit this page regularly to stay informed of the most up-to-date Privacy Policy.
This Privacy Policy was last updated 7th November 2025.
There are three categories of information we collect:
a) Information necessary for use of the site.
We ask for this information when you use the site as it is required for proper performance of our contract with you and/or to comply with our legal obligations.
b) Information you choose to give us.
You can choose to give us additional information that is not essential for use of the site but will enhance your experience and help us provide a better service to you. This information is processed based on your consent (which you may withdraw at any time).
(Lawful basis (i–iv): Consent; legitimate interests in improving our services.)
When you use the website we automatically collect information, including personal data. This information is necessary for the performance of the contract between you and us, and given our legitimate interest to improve the functionality and security of the site and provide you with a good service.
We may collect personal data that other site users may submit to us when they use the website and communicate with us, or we may obtain information from other third parties as detailed below. We have no control over how these third parties may themselves control or process this information and any information request relating to the data they might provide to us must be directed to that third party.
We may use and disclose personal data only for the following purposes:
| Processing Purpose | Example Activities | Lawful Basis under UK GDPR | Typical Data Categories |
|---|---|---|---|
| Account creation & management | Registration, login, profile updates | Performance of a contract | Name, email, login details |
| Property listing & promotion | Owner registration, listing uploads | Performance of a contract | Owner contact details, property info |
| Guest enquiries & bookings | Messaging, confirmation | Performance of a contract | Guest name, contact, booking details |
| Payments & invoicing | Stripe/Revolut transactions, Accounting | Contract / Legal obligation | Billing info, payment details |
| Marketing communications | Newsletters, promotions | Consent | Contact info, preferences |
| Analytics & improvement | Site analytics (Hotjar, GA) | Legitimate interests | IP, device, session data |
| Customer support | Helpdesk interactions | Legitimate interests | Email, ticket content |
| Legal compliance | Record-keeping, regulatory requests | Legal obligation | Various |
| Security & fraud prevention | Monitoring, logs | Legitimate interests / Legal obligation | IP, device data |
(This table supplements the detailed explanations above.)
Coolstays includes links to third party websites including property Owner websites, affiliate partner websites (such as Booking.com), social media sites (such as Facebook or Instagram) and other websites. We do not control these sites and when you visit them you may be providing personal data to the third party. The third party’s use of your information will be governed by their own Privacy Policy which we recommend you review. We do not accept any responsibility or liability for their policies whatsoever.
a) Third Party Processors (TTPs) – We use a variety of third party data processors to help us provide and support our services. We need to share information with them in order to ensure the adequate performance of our contract with you. These would be classed as “data processors” under UK GDPR. Examples include payment processors, hosting providers, email delivery systems, site usage analysis services, helpdesk systems and content delivery services. All third party processors we use enter into a contract that requires them to use your personal data only for the provision of services to us and in a manner that is consistent with this Privacy Policy. A full list of TPPs we use can be found at https://www.coolstays.com/data-processors/
b) Review platforms – If you use the site to make an enquiry we may share your name, email address and the property you made an enquiry at with Feefo, who will send you an email on our behalf asking you to complete a review. Our legal basis for doing this is our legitimate interest in asking for feedback in order to improve our products and services. If you choose to leave a review on the Feefo platform, Feefo would be the “data controller” of the feedback they receive from you and that data would be held in accordance with their own Privacy Policy.
Data Processing Agreement with Owners
Where personal data is shared between Coolstays and property Owners or agents for the purposes of advertising, enquiries, and bookings, that processing is governed by our Data Processing Agreement for Owners, which forms part of the Coolstays Owner Terms. This agreement sets out the respective roles and responsibilities of each party under the UK GDPR, including how Owners must safeguard guest information and respond to data-subject rights.
We are a UK registered company, operating in the UK and our website and service is available to anyone worldwide. We use a number of Third Party Processors (TPPs) to enable us to provide and support the website and service to our Owners, Webusers and Visitors. Some of these TPPs are based outside the United Kingdom and/or the European Economic Area (EEA) and data may be processed on servers located internationally. We only use TPPs who we are confident have the appropriate safeguards in place and they are contractually bound to protect and use it only for the purposes for which it was transferred, consistent with this Privacy Policy.
A full list of TPPs we use can be found at https://www.coolstays.com/data-processors/
International transfer safeguards: Where personal data is transferred outside the UK/EEA, we rely on one or more of the following: UK Government adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or other ICO-approved safeguards.
The UK GDPR provides the following rights for individuals:
You also have the right to complain to the Information Commissioner’s Office (ICO): www.ico.org.uk | 0303 123 1113.
We generally retain your information for as long as your account is active or as long as necessary to provide you with our service. We may also retain and use your information in order to comply with our legal obligations, resolve disputes, prevent abuse, and enforce our Agreements.
Typical retention periods:
When data is no longer required it will be securely deleted or anonymised.
| Data Category | Typical Retention Period | Deletion / Anonymisation Method | Legal / Business Reason |
|---|---|---|---|
| Website Accounts (Guests & Owners) | While account is active, then up to 6 years after closure | Account and personal details deleted or anonymised after 6 years | Contract and legitimate interests – manage accounts, prevent fraud, legal claims limitation |
| Guest Enquiry Data | Up to 6 years from enquiry date | Personal details deleted or anonymised after 6 years; anonymised metadata retained for statistics | Legitimate interests – dispute handling, fraud prevention, and record keeping (UK Limitation Act 1980) |
| Booking Data | Up to 6 years from booking date | Deleted or anonymised after 6 years | Contract and legal obligation – accounting, tax and legal compliance |
| Owner Listing and Payment Records | Up to 6 years after termination of listing or final payment | Deleted or anonymised after 6 years | Contract and legal obligation – financial record keeping, audit, and compliance |
| Customer Support and Complaint Records | Up to 6 years from resolution | Deleted or anonymised after 6 years | Legitimate interests – resolve disputes, monitor service quality, defend legal claims |
| Marketing and Newsletter Subscribers | Until consent withdrawn or inactivity for 2 years | Deleted from mailing lists or anonymised upon unsubscribe | Consent – marketing communications; legitimate interests – record of consent |
| Analytics and Website Usage Data | Retained in anonymised or aggregated form | Anonymised immediately or after session ends | Legitimate interests – improve website and service performance |
| Cookies and Tracking Data | Duration set per cookie (typically up to 2 years) | Automatically deleted or user-controlled | Consent and legitimate interests – functionality, analytics, advertising |
| Financial and Transaction Data | Up to 6 years from transaction | Deleted or anonymised after 6 years | Legal obligation – accounting and HMRC compliance |
| Employee or Contractor Data | During engagement and up to 6 years after leaving | Deleted or anonymised after 6 years | Legal obligation – employment and tax record retention |
(Where immediate deletion is not technically possible, data is securely archived until automatic purge schedules apply.)
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online, including encrypted connections (HTTPS/TLS), access controls, monitoring and regular reviews.
We maintain procedures to detect, investigate and report personal-data breaches. If a breach is likely to result in a risk to your rights and freedoms, we will notify the ICO and affected individuals without undue delay, in accordance with Articles 33–34 of the UK GDPR.
We do not perform automated decision-making that has legal or similarly significant effects on individuals. If this changes, we will update this Privacy Policy and provide you with information about the logic involved and the potential consequences.
If you have any questions about this Privacy Policy or our data-protection practices, please contact us via email - privacy@coolstays.com