Privacy Policy
Checkinea ("we", "us") provides property-management software that helps accommodation hosts manage bookings, collect guest check-in data, generate rental contracts, and file the mandatory traveller report with the Spanish authorities (SES Hospedajes, under Real Decreto 933/2021).
Who controls what (important)
- If you are a host using Checkinea to manage your property, you are the data controller for your guests' personal data, and Checkinea is your processor: we process guest data only on your documented instructions, under our Data Processing Agreement (DPA).
- If you are a guest completing a check-in, the host you booked with is the controller of your data; Checkinea processes it on their behalf. This policy explains how we handle it; for controller-level requests, you may contact your host or us and we will route it.
- For our own host accounts and billing, Checkinea is the controller.
What data we process
Host / account data: name, email, password (managed by our auth provider; we never see it), business name, locale, and billing identifiers (your card is handled by a PCI-DSS-certified third-party payment provider; we do not store card numbers).
Booking data: guest contact name, email, phone, reservation code, stay dates, channel; received from you or from your connected booking platforms (Airbnb, Booking.com) by email.
Guest check-in / traveller data (special-category and identity data): as required by Spanish law (RD 933/2021): name and surnames, identity-document type and number, date of birth, nationality, sex, home address, contact details, and (for accompanied minors) kinship to the lead guest.
Contracts: rental contracts you generate, including signer name, signature, and the IP address at the time of signing.
Why we process it, and our lawful basis
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Provide the service / your account | Performance of a contract |
| Billing | Performance of a contract |
| Detect bookings from platform emails; deliver check-in links | Legitimate interests (managing your bookings) |
| Collect guest identity data and file it with SES Hospedajes | Legal obligation (RD 933/2021) |
| Generate and retain rental contracts | Legitimate interests + Spanish civil-law obligations |
| Send transactional emails (invites, arrival info, confirmations) | Legitimate interests / contract |
| Error monitoring to keep the service reliable | Legitimate interests |
We do not use your or your guests' data for advertising, profiling, or automated decisions.
Who we share it with (sub-processors and recipients)
We use a small set of vetted service providers (sub-processors) to run the service, covering areas such as cloud hosting and database, transactional email, error monitoring, and payment processing. Our core systems are hosted in the EU. A current, named list of our sub-processors is available to customers on request.
We also transmit the mandatory traveller report to SES Hospedajes (Spanish Ministry of the Interior): this is a legal obligation, not an optional sharing. Where a provider is outside the EEA, we rely on appropriate safeguards (e.g. Standard Contractual Clauses). We never sell personal data.
How long we keep it
- Police-filing records (and the guest identity data they contain): 3 years, as required by RD 933/2021, then deleted automatically.
- Signed contracts: 5 years (Spanish civil-law limitation period), then deleted automatically.
- Account data: until you delete your account; on deletion we cancel billing, remove or irreversibly scrub account-level personal data, and delete your login.
- Some guest/filing records are kept for the legal-retention windows above even after account deletion, because the law requires it; they are deleted when the window expires.
Your rights
You can ask us (or, as a guest, the host) to access, correct, or delete your data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority (in Spain, the AEPD). Contact: [email protected].
Important limit: while a filing obligation is live, we may be unable to erase guest identity data that the law requires us to keep for the retention window above (GDPR Art. 17(3)(b)). We will erase it when the window expires. Guest check-in data can be corrected up until the report is filed with SES; after filing it is locked.
Cookies
We use only essential cookies (login/session and language preference). We do not use advertising, analytics, or tracking cookies, and our error monitoring is configured to exclude personal data, so no consent banner is required. This will change (and we will add a consent mechanism) only if we ever introduce analytics or marketing cookies. During payment operations, our payment provider sets strictly necessary cookies, used solely for fraud prevention and security, which do not require consent.
Security
We protect data with encryption in transit and at rest, application-level encryption of the most sensitive secrets, appropriate technical and organizational measures, such as strict access controls, and personal-data scrubbing in our error logs. No system is perfectly secure; we maintain a breach-response process and will notify as required by law.
Changes
We may update this policy; material changes will be notified to hosts. The "last updated" date above reflects the current version.