Privacy Policy
Last updated: June 2026
Hostmizer® ("Hostmizer", "we", "us", "our") respects your privacy. This policy explains what personal data we collect, why, the legal grounds we rely on, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Belgian data-protection law.
This policy covers hosts, prospective hosts and website visitors (including people who use our free tools), and guests whose data we process on a host's behalf.
1. Who is responsible for your data (controller)
The data controller is:
[REGISTERED LEGAL NAME], [STREET + NUMBER], [POSTAL CODE] [CITY], Belgium — enterprise number BE [0XXX.XXX.XXX].
Privacy contact: [privacy@hostmizer.com — recommended dedicated address; fallback team@hostmizer.com]
Guest data — controller vs processor. For personal data about guests, the host is generally the data controller and Hostmizer® acts as a processor (and/or, where we determine certain purposes ourselves, a joint controller). The arrangement between us and the host is governed by a data processing agreement (see section 7).
2. What data we collect, and where it comes from
From hosts and prospective hosts (provided by you):
- Identity & contact: name, email, phone, language, country.
- Account credentials: username and a securely hashed password.
- Property/listing data: address, property type, number of bedrooms, photos, descriptions, availability, pricing, house rules, reviews (including data imported from Airbnb or other platforms at your request).
- Free-tool inputs: for the revenue estimate, listing audit and regulations checker — property location, property type, bedrooms, current nightly rate (optional) and your email.
- Financial/payout data: bank/IBAN or payout details, invoices, transaction history.
- Communications: emails, support messages, and notes from calls with your listing manager.
From guests (processed on the host's behalf):
- Booking details, contact information, and verification/screening data used to confirm and protect reservations.
Collected automatically when you use the Site:
- Device and usage data: IP address, browser, device type, pages viewed, referring URL, and analytics events.
- Cookies and similar technologies — see our Cookie Policy.
3. Why we use your data and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and manage your account; deliver the co-hosting service | Performance of a contract (6(1)(b)) |
| Process and protect bookings, payouts and deposits | Performance of a contract (6(1)(b)) |
| Respond to free-tool requests (e.g. send your earnings estimate) | Steps taken at your request prior to contract (6(1)(b)) / consent (6(1)(a)) |
| Customer support and account management | Performance of a contract / legitimate interests (6(1)(f)) |
| Marketing emails and remarketing to prospects | Consent (6(1)(a)), withdrawable at any time |
| Security, fraud prevention, service improvement, analytics | Legitimate interests (6(1)(f)) |
| Accounting, tax and legal compliance | Legal obligation (6(1)(c)) |
4. Automated processing and profiling
We use tools that score and prioritise leads and that suggest dynamic pricing. These support human decisions; [we do not / we do] make decisions producing legal or similarly significant effects about you solely by automated means within the meaning of Article 22 GDPR.
5. Who we share data with
We share data only as needed to run the service:
- Service providers (processors) acting on our instructions under data processing agreements, for example: [CRM — e.g. HubSpot], [website/hosting platform — e.g. Lovable], [email/transactional email provider], [analytics provider], [payment processor — see below], [workflow/automation tooling — e.g. n8n]. [List the actual providers.]
- Booking platforms / OTAs (e.g. Airbnb, Booking.com, Vrbo, Expedia) strictly to publish listings and fulfil reservations you have authorised.
- Authorities and advisers where required by law, or to establish, exercise or defend legal claims.
We do not sell personal data.
6. International transfers
Some providers may process data outside the European Economic Area (e.g. in the United States). Where they do, we rely on an adequacy decision or on appropriate safeguards such as the EU Standard Contractual Clauses [and supplementary measures]. You can request a copy of the relevant safeguards from [privacy contact].
7. Data processing on behalf of hosts
When we process guest data on a host's behalf, we do so under a data processing agreement that limits us to the host's instructions, requires confidentiality and security, governs sub-processors, and provides for assistance with data-subject requests and breach notification, in line with Article 28 GDPR.
8. How long we keep data
- Account and listing data: for as long as your account is active, then deleted or anonymised after [RETENTION PERIOD] following closure, unless a longer period is legally required.
- Accounting and invoicing records: kept for the statutory period (in Belgium, generally 7 years).
- Free-tool / prospect data: kept for [RETENTION PERIOD] from last interaction, then deleted.
- Marketing data: kept until you unsubscribe or withdraw consent.
- Guest data: retained only as long as needed to fulfil the reservation and meet legal obligations, then deleted per the host agreement.
9. How we protect your data
We use technical and organisational measures appropriate to the risk, including access controls, encryption in transit, hashed passwords, and vetting of processors. No system is perfectly secure, but we work to protect your data and will notify you and the supervisory authority of a personal-data breach where the law requires.
10. Your rights
Under the GDPR you have the right to: access your data; request correction or erasure; request restriction of, or object to, processing; data portability; and withdraw consent at any time (without affecting prior processing). Where Hostmizer® acts as a processor for guest data, guests should contact the host (controller) first; we will assist.
To exercise any right, contact [privacy contact]. We respond within one month, as required by law.
You also have the right to lodge a complaint with the Belgian Data Protection Authority: Autorité de protection des données / Gegevensbeschermingsautoriteit (APD/GBA), Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels — contact@apd-gba.be — www.autoriteprotectiondonnees.be.
11. Children
The Hostmizer® services are intended for adults (18+). We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy. Material changes will be communicated by email or in-app, and the "Last updated" date above will change. [Optionally: a version history is shown on this page.]
Questions about your privacy? Contact [privacy contact].