Privacy Policy
Last updated: 25 July 2026
Legal review required before shipping
This page is baseline drafting only — engineering copy, not legal advice. It has not been reviewed by a solicitor and must not be treated as final before Stripe payments go live. See the TODO comment in this page's source for the specific open questions, including whether the EU 14-day distance-selling withdrawal right applies to our bookings — that answer changes our refund policy and is blocking for payments.
Who we are
Fun-Stay is based in Ireland. For the purposes of GDPR, Fun-Stay is the data controller for the personal data described on this page. You can reach us at info@fun-stay.com for any privacy question, including the requests described below.
What we collect
We collect personal data only where you give it to us directly, specifically:
- Account data— name, email, phone, and university, when you sign in or create an account (passwordless email link, or Google Sign-In). If you use Google Sign-In we receive your name, email, and profile photo from Google, and store Google's account identifier ("sub") so we can recognise you on future sign-ins.
- Listing enquiries — name, email, phone, university, move-in date, stay duration, student/intern status, and any message you add, when you request to book a room.
- General enquiries and group/partner enquiries — name, email, WhatsApp number, and the accommodation details you provide (city, dates, budget, group size, and similar), when you submit our enquiry or partner forms.
- Property submissions— if you list a property with us, we collect the host's name, email, phone, property details, and any verification documents or photos you upload.
- Technical data — standard request metadata (such as IP address) is processed transiently by our hosting and rate-limiting infrastructure to keep the service secure and prevent abuse.
We do not collect payment card data ourselves — see "Payments" below.
Lawful basis for processing
- Performance of a contract / steps prior to entering one — creating your account, matching you with accommodation, and responding to enquiries and partner requests.
- Legitimate interests — securing the platform against fraud and abuse (for example, rate-limiting sign-in and admin login attempts), and improving the service.
- Consent — any non-essential cookie, described in the Cookies section below.
- Legal obligation — once payments launch, retaining transaction records as required by Irish tax and accounting law.
How long we keep it
We keep personal data for as long as needed to provide the service to you, respond to your enquiry, and meet our legal obligations, and we delete or anonymise it once it is no longer needed for those purposes. Once payments launch, transaction records will be retained for the period required by Irish tax and accounting law.
Exact retention periods per data category have not yet been finalised with legal — see the TODO comment in this page's source.
Your rights
Under GDPR, you have the right to access, correct, or request erasure of your personal data, to restrict or object to certain processing, and to receive your data in a portable format. To exercise any of these rights, email info@fun-stay.com. You also have the right to complain to Ireland's Data Protection Commission (dataprotection.ie) if you believe your data has been mishandled.
Who we share data with
We use the following processors to run the service:
- Neon — our database host, where account and enquiry data is stored.
- Resend — sends transactional emails (sign-in links, enquiry confirmations).
- Vercel — hosts the application.
- Cloudflare R2 — stores uploaded images and property verification documents.
- Upstash — supports rate-limiting to keep sign-in and the service secure.
- Google — provides Google Sign-In (Google Identity Services), and Google Analytics for site usage statistics (see Cookies below).
- Stripe — will process payments once our payment flow launches. Stripe is not yet processing any data — this is listed in advance so this page does not need to be rewritten when payments go live.
Payments
Payments (not yet live) will be handled through Stripe's hosted checkout, in euro. Your card details are entered directly into Stripe's own checkout page and are sent straight to Stripe — they never touch Fun-Stay's servers or database. We do not store card numbers, expiry dates, or CVCs anywhere in our systems.
Cookies
We use a small number of cookies:
- fs_session — keeps you signed in. This cookie is strictly essential to the service (there is no way to offer an account without it), so it is set automatically and is not subject to cookie consent.
- Admin session cookie — used only by our own staff to access the admin dashboard. Also strictly essential and not subject to consent.
- Google Sign-In— when you use the "Sign in with Google" button, Google's own script may set its own cookie to support that feature. This is set by Google, not by Fun-Stay, and only runs when you interact with that button.
- Google Analytics — we use Google Analytics to understand site usage. These cookies are non-essential.
Known gap, flagged for legal/product review rather than silently fixed: Google Analytics currently loads on every page load without a consent banner or opt-out gate. We have not built a cookie-consent mechanism yet. Until one exists, this section is a disclosure of current behaviour, not a claim that non-essential cookies are gated behind consent. See the TODO comment in this page's source.
We do not use advertising or cross-site tracking cookies.