Privacy Policy
Last updated 19 August 2026
1. Who we are
Guestly (“we”, “us”) provides a service that helps operators of licensed short-term rental accommodation in Malta (“owners”) calculate and collect the Maltese environmental contribution (“eco tax”) from their guests. For any privacy question or request, contact us at info@guestly.mt.
For the data in an owner's Guestly account, we act as a data controller. For guest booking data that owners share with us through their property management system, the owner remains the controller of that data and we process it on the owner's behalf in order to collect the eco tax, as well as for our own limited operational purposes described below.
2. What data we process
Owner account data. Your name and email address, a hashed password (we never store passwords in plain text) or your Google sign-in profile, your property and listing details imported from your property management system, your payment account identifiers, and the API credentials you connect. Connected credentials are stored encrypted.
Guest booking data.When a booking is made at a connected property we receive, via the owner's property management system (Hostaway), the guest's name, email address, phone number, booking channel, arrival and departure dates, length of stay, and party size, together with the payment status and amounts of the eco-tax request.
Payment data. Card payments are processed entirely by Stripe on Stripe-hosted, PCI-compliant infrastructure. We never receive, store, or transmit card numbers. We record only the outcome of a payment (paid, pending, refunded) and its amounts.
3. Why we process it
- To provide the service to owners under our contract with them: calculating the eco tax due for each booking, sending the guest a payment request, collecting payment, and reporting.
- To contact guests with an eco-tax payment request by email or, where no usable email is available, through the booking channel's messaging system. This is done in support of the owner's legal obligation to collect the environmental contribution under Maltese law.
- To send owners transactional email about their account (verification, password reset, payment notifications).
- To keep records of collected amounts for tax-reporting and audit purposes.
- To secure, maintain, and improve the service.
We do not sell personal data, we do not use it for advertising, and we do not use guest contact details for marketing of any kind.
4. Where data is stored
All personal data is stored in the European Union. Our database is hosted in an EU region and our application runs on EU infrastructure. Where a service provider processes data outside the EU, we rely on the safeguards required by the GDPR, such as adequacy decisions or standard contractual clauses.
5. Who we share data with
We share personal data only with the service providers needed to run Guestly:
- Hostaway — the property management system from which booking data is received and through which channel messages are sent.
- Stripe— payment processing. Guest payments are made directly to the owner's connected Stripe account; Stripe's own privacy policy applies to the payment transaction.
- Resend — delivery of transactional email to guests and owners.
- Vercel and Neon — application hosting and database hosting, in the EU.
- Google — only if an owner chooses to sign in with Google.
We may also disclose data where required by law, for example to Maltese tax or regulatory authorities.
6. How long we keep it
Booking and payment records are retained for as long as needed to support the owner's tax records and any statutory retention periods that apply to them, after which they are deleted or anonymised. Owner account data is retained while the account is active and deleted within a reasonable period after account closure, except where we must keep records to comply with law.
7. Cookies
We use only essential cookies: a session cookie to keep owners signed in to the dashboard, and short-lived tokens to secure guest payment pages. We do not use advertising or cross-site tracking cookies.
8. Security
All traffic is encrypted in transit (TLS). Data is encrypted at rest, connected API credentials are additionally encrypted at the application level, passwords are hashed, and access to production systems is restricted. No card data ever touches our systems.
9. Your rights
Under the GDPR you may request access to, rectification of, or erasure of your personal data, restriction of or objection to its processing, and a portable copy of data you have provided. To exercise any of these rights, email info@guestly.mt. If you are a guest, we may refer your request to the property owner where they are the controller of the data concerned. You also have the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC) in Malta or your local supervisory authority.
10. Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last revised; material changes will be notified to account holders by email.