How SERAVIE collects, uses, and protects your personal data — applies to hosts, guests, and property managers.
This Privacy Policy explains how SERAVIE ("we", "us") collects, uses, discloses, and safeguards personal data when you use our website, marketplace, and Hospitality OS platform, whether as a host, guest, property manager, or visitor.
Account data (name, email, phone, password hash); identity verification data when required by law; booking data (stays, dates, payment metadata — we do not store full card numbers, these are handled by our payment processor); property data submitted by hosts; messages exchanged through the guest communication hub; device and usage data (IP address, browser, pages visited) collected automatically.
To operate the marketplace and booking flow; to process payments and payouts; to provide customer support; to send transactional notifications (booking confirmations, reservation updates); to improve and secure the platform; to comply with legal and tax obligations; with your consent, to send product updates and marketing communications, which you can opt out of at any time.
We process personal data under one or more of the following bases: performance of a contract (fulfilling a booking or host agreement), legal obligation (tax, identity verification), legitimate interest (fraud prevention, platform security, service improvement), and consent (marketing communications, optional cookies).
We share data with: payment processors to complete transactions; channel manager providers (e.g. Channex, Beds24, Hostex) when a host connects external booking channels; cloud infrastructure providers that host our systems; and law enforcement or regulators when legally required. We do not sell personal data to third parties.
We retain personal data for as long as your account is active and as needed to comply with legal, accounting, or reporting obligations. You may request deletion of your account data at any time, subject to retention periods required by law (e.g. financial records).
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us through your account settings or support channel.
We use industry-standard encryption in transit and at rest, role-based access controls, and regular security reviews to protect personal data. No system is completely secure, and we encourage users to use strong, unique passwords and enable two-factor authentication where available.
Where personal data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms required by applicable data protection law. EU-originating data is stored in EU-based infrastructure where required.
We may update this Privacy Policy from time to time. Material changes will be communicated with reasonable notice, and continued use of the platform after changes take effect constitutes acceptance of the updated policy.