Legal

Privacy Policy

Last updated 2026-09-25

What we collect, and why

When you join the waitlist we ask for your email address, which side of the market you are on, the city you are interested in, roughly how long you want or how many places you rent out, and — optionally — what has gone wrong for you before. The last one is the most useful thing on the form and it is the reason we read the list at all.

We also ask for your date of birth, and for one reason only: a member must be 18 or older, and the form refuses to create an account for anyone younger on the day they join. We do not check it against a document, nobody else on the site sees it, and it is not used for anything else. It is kept for as long as your account exists and erased with the account.

We record the address you signed up from and the browser you used, so that a stolen session can be recognised and ended. If you use the site we store what you save, which area you vote for, and the notifications we have shown you.

We do not use analytics, advertising or tracking cookies. Five cookies exist, and each is named for what it does. One keeps you signed in — __Host-rl_session if your connection is HTTPS, or rl_session over plain HTTP in local development, never both at once. One, rl_just_joined, is a one-shot flag lasting sixty seconds that tells the home page you just joined, so it shows you the member view instead of the signup form you already filled in. One, rl_lang, remembers the language you last chose to read the site in. One, rl_lang_prompt, records only that we offered you the site in another language and you said no, so that the offer is not made again; it holds a fixed word and nothing about you. And one, rl_consent, holds your answer to the one question on this site that has to be asked before something happens: whether the search map may load. It records the answer you gave and the version of the question you were asked, for a year, and it holds nothing else. You can change that answer, or take an allowance back, in the section on consent below.

Filming a walkthrough

Listing a place means filming the inside of it in one take, from the front door to the electricity meter. That video is the product, so it is worth being exact about what it is.

The microphone is on for all of it. The recorder asks your browser for the camera and the microphone together, so whatever is said or playing while you film is in the file we keep — by you, and by anybody else who is home. One of the prompts asks you to say the date out loud, which is part of why. If someone else is in the rooms, they are being recorded too, and telling them is something only you can do.

The recording goes to our own server and onto a disk that only the application can read. It is not on a video platform and not on anybody else’s account. Beside it we write a small record of its size, a checksum, when it arrived, the checkpoints you marked and the verdict of the check that decides whether it was filmed in one go. Your browser also cuts a still out of the video at each checkpoint and sends those the same way.

A take that fails the check is kept rather than deleted. It is evidence either way, and somebody arguing with the verdict deserves to have the file looked at.

Who can watch it: you, and our reviewers. Once the listing is published, anybody can — that is what publishing it means, and it is worth knowing before you film. There is no other route to the bytes; the one place that serves them asks the same question the listing page asks before it shows anyone anything. If the listing is later paused they stop being served, though a copy already fetched can sit in a browser or a cache for up to an hour after that.

Where the recording was filmed

When the camera opens, the recorder also asks your browser where you are. Answering is yours to refuse. If you decline the prompt, or your device has no way to answer it, the listing goes through exactly as it would have — what we record then is which of those happened, and no position at all.

If you do allow it, the position we store is a precise one. We ask for the best fix the device can give and refuse a cached one, and the column holds six decimal places. Taken standing at your own front door, that is your exact address written in another notation, so it is handled as one: it is never on the public listing page, and it is not in the record written beside the video. Our reviewers are the only people who see it, and the only reason it is taken is so a reviewer can hold it against the address you typed.

We keep the radius your device claimed for that fix alongside it, because a position good to a few metres and one good to a few kilometres look identical without it. And we do not treat any of it as proof: it is a number your browser reported, and a browser can be told what to report.

The address of a place you list

The exact address is required, and it is encrypted before it is written down — sealed against the one property it belongs to, so the same ciphertext cannot be lifted onto another row. It is unsealed on our server for you, for a reviewer, and for whoever is travelling on a confirmed booking of yours — nobody else, and not before that booking is confirmed. The query behind the public listing page does not read that column at all.

What a stranger sees instead is a second pair of coordinates rounded to three decimal places, which is roughly a hundred metres. They live in their own columns and the database itself refuses to hold anything more precise there.

If you fill it in, we also store the registration number for the property. It identifies one building to a government, which is why a reviewer sees it beside the address rather than on its own: each is the check on the other.

Paperwork, and who you are

A listing can carry a document showing you are allowed to rent the place out. It has to be a PDF, it is attached to that one listing, and it is stored the way the video is: our own disk, nothing readable from the web. We record who uploaded it, which listing it belongs to, its size, a checksum, and whether a reviewer accepted or rejected it and why. Only you and our reviewers can open it, it is never served by the same place that serves listing video, and every time a member of staff opens one we write down that they did.

Before a home can go live, we ask its host for an identity document. You send a scan of your passport or national identity card, as a PDF, from your listing page. It is attached to you rather than to a listing, and it is stored the way the paperwork above is: our own disk, nothing readable from the web, nothing served by the same place that serves listing video. Sending it opens an identity check; a reviewer opens the scan and decides by hand. Only you and our reviewers can open it, and every time a member of staff opens one we write down that they did. There is no automated check and no third party sees it. What the decision leaves behind is a row saying it was checked, when, by whom, and a short note the reviewer wrote — which can be about you, and which is not in the export you can download.

The scan itself is kept for 30 days after the check closes, then the file is removed and the row recording that it existed stays. Closing your account removes it sooner, with everything else.

Messages about a booking

A guest and a host can write to each other on a booking. We store what is sent, and until a first payment on that booking has cleared we take the contact details out of it first: email addresses, phone numbers, messaging links and social handles. What is kept is the stripped version — we do not hold the original as well, because keeping it would put back the thing we just removed. The same stripping is applied to the sentence a guest writes when they first ask about a place. It applies to what a host and a guest write to each other, and not to what you write to us: a conversation with RemoteStay support is stored as written, so that you can give us a number to reach you on.

One more thing you can write about a booking is not a message and is not handled as one. Declining a request, and cancelling a booking, each offer you a box headed why, for our record. Filling it in is optional, and what you write goes into our own record of what happened to that booking and stops there. The other person is not shown it, it is not in the email or the notification that tells them what happened, and no page on this site displays it — the only people who can read it are the people who run RemoteStay, in that record. The stripping described above is not applied to it, which is another way of saying it is a note to us rather than a message to them. It is not in the download you can take, closing your account does not remove it, and none of the windows below covers it: it lasts as long as the record of the booking does, and nothing deletes that.

Consent, and what it covers

Joining the waitlist is one decision and being emailed about it is another, so they are asked separately. We record the exact sentence you agreed to and the day you agreed to it, so that a later change of wording cannot be presented as something you accepted. You can withdraw at any time from your account or from the unsubscribe link at the foot of every marketing email we send. Withdrawing never stops the messages you need — a sign-in link, or an answer about a place you asked about. Those carry no unsubscribe link, because there is nothing about them to unsubscribe from. Marketing is one of the two things this site asks your permission for. The other is not about email and is not held in your account: whether the search page may load its map from CARTO. That answer lives in a cookie in the browser you gave it in, it lasts a year, and the control at the foot of this section is where it is changed. Allowing the map there does what the banner does; taking an allowance back deletes the answer rather than recording a refusal, so the map goes off and the question is asked again the next time you meet it.

That unsubscribe link never expires. It carries no timestamp and we set no age limit on it, so a letter found in an archive folder two years from now still works. That is on purpose: “this link has expired” is a worse answer than no link at all.

Your answer about the search mapYour answer is kept in this browser, so it is read here rather than on our server. It appears once this page has loaded.Whichever answer is recorded is kept for a year, in this browser only, and is not attached to your account. Withdrawing deletes the answer rather than storing a refusal, so the question is asked again the next time you meet it.

Third parties your browser contacts directly

Everything else on this page describes what reaches our own server. Two things do not — each runs from inside your browser, to somebody else’s server. One of them waits for you to say yes; the other waits for you to authorise a payment.

The map on the search page is CARTO’s, not ours, and it is off until you allow it. Nothing is fetched from {a-d}.basemaps.cartocdn.com until you choose “Allow the map” in the banner or “Show the map” on the search page itself — before that, what you see in place of the map is drawn from coordinates the page already holds, and no request leaves your browser for CARTO at all. Once you have allowed it, every pan and zoom fetches image tiles straight from your browser to that host, which sees your IP address and the coordinates of whatever part of the map is on screen. “Not now” is recorded just as an allowance is, so that we stop asking rather than putting the question in front of you again on the next page. Either answer is kept for a year, in rl_consent.

Authorising a deposit loads a script from js.stripe.com into your browser, so the card field it draws can talk to Stripe directly and the card number never passes through our own server at all. That is separate from the Stripe customer record described under “Who else sees it” below: that record is us telling Stripe your email address; this script is Stripe seeing that your browser asked for it.

Nothing on this site loads Google reCAPTCHA, and this page said otherwise until 2026-09-06. There is a reCAPTCHA check in our code and it is inert: no reCAPTCHA script is served to your browser, the signup form posts an empty token, and the check on our own server treats an empty token as no answer and accepts the signup without asking Google anything. So no request reaches Google, from your browser or from us. What actually stands between the signup form and a bot is a hidden field a person never fills in, how fast the form came back, and two limits — one on how often signups may come from a single network address, one on how often a single email address may be tried. All of them run on our own server.

How long we keep things

  • Unused sign-in links: 30 days after they expire.
  • Ended sessions: 90 days after they expire, and the whole record goes — the address it was opened from with it. There is a second, longer limit of 365 days on that address on its own. It is a backstop for the case where the nightly clean-up has stopped running, not the window you should expect: in normal operation the record is gone long before it.
  • Emails we have queued for you: 365 days from that outcome, whether we delivered them or gave up on them — a letter abandoned because you withdrew consent before it went out is erased on the same clock as one we sent.
  • Notifications you have read: 365 days. Unread ones are kept until you read them.
  • The counters behind our rate limits, which record that a request was made rather than what was in it: 7 days.
  • The messages Stripe sends us when a payment goes through or fails, which carry the email address on the payment and some detail about the card: 90 days, whether we managed to act on them or not.
  • A request to move your account to a new email address, which records the new address and where the request came from: 90 days after it is confirmed, cancelled or lapses. A request that is still open is kept until it lapses.
  • An invitation to join a booking as a co-guest, which records the address it was sent to: 30 days after it is accepted, taken back by the person who sent it, or lapses. One that is still live is kept until it lapses. The address on it may belong to somebody who has no account here, which is why it has a window of its own rather than waiting for an account to close; closing yours removes any invitation addressed to you, accepted or not. A guest who names you on their booking gives us your address for that one invitation, and we send nothing else to it. If you join, the host of that booking is told your display name.
  • What you attach to a report about another member — your notes, and the messages from the booking thread you point us at: kept for 365 days after the report is closed with no action taken, and for 1825 days after one that ended in a note, a warning, a restriction, a suspension or a removal. The report itself — who filed it, about whom, and what we decided — is kept longer than what was attached to it, because a pattern across reports is evidence even when one report is not. Nothing is removed while a report is still open.
  • A conversation with RemoteStay support, and everything said in it, stored as written rather than stripped of contact details: 730 days after the last message in it, whether or not it was closed. Closing your account removes your support conversations with it.
  • Our web server’s access log, which records the address of every page requested. It is kept for as long as the server keeps its logs and is not covered by the windows above.
  • Walkthrough recordings, the stills cut from them and any photo on a listing: 183 days after the listing they belong to is retired. A retired listing is one that is never published again — the host closed it, or closed their account — and a listing that is merely paused or lapsed keeps its recording, because it can come back. The file is removed; the record written beside it stays, noting the file existed and when it went.
  • An identity document you send: 30 days after the identity check it was sent for is decided, and not while a newer check on you is still open. The file is removed and the record stays, as with a recording.
  • Documents you upload to show a place may be let: 730 days after the listing they back stops being published, and not while it is published again. The file is removed and the record stays, as with a recording. A document attached to no listing is kept until you close your account.
  • The exact address of a place you list, its coordinates and its registration number: kept as long as the property record, which nothing deletes.

Damage claims include the amount requested, each party’s written account and uploaded evidence. The booking host, lead guest and our reviewers can read them. Claim records and written accounts have no automatic retention window and remain after account closure. Uploaded claim evidence also has no age-based deletion window; we remove files when the uploader’s account is erased. Avoid including identity documents or unrelated personal information in evidence.

Your account itself is kept until you close it, and your date of birth lives exactly as long: it has no window of its own and goes when the account does.

None of those windows describes our backups. The server takes a copy of the database and of the uploaded files every night and keeps the recent ones, and it keeps a rolling log of database changes beside them, so a row erased today is still in last night’s copy until that copy rotates out. How long that takes is set on the server rather than by this application, which is why no figure for it appears above.

Taking it back, and being forgotten

Four things you can do from your account, none of which needs you to ask us: download everything we hold about you as a file, withdraw marketing consent, change the currency prices are shown in, and close your account. The answer you gave about the search map is not one of the four and is not in your account at all: it is a cookie in one browser, kept for a year, and the section on consent above is where that one is changed or taken back. Closing your account does not clear it, and signing out does not either.

There is no screen for correcting your details, because there is no screen for entering most of them — what a member types is an email address, a date of birth, a city, a length of stay and an optional note. If something we hold about you is wrong, tell us — the last section is how — and we will correct it.

Closing the account is the part worth reading twice. If you have never listed a place, booked a stay, referred anybody, or filed or been named in a report, closing it removes your account entirely. If you have, we erase your name, your address and everything you wrote about yourself, and the records those things left behind stay without naming you — we cannot delete our own record that a listing was approved or a booking was cancelled, and we do not pretend otherwise.

Closing the account also takes every place you have listed off the site, in the same step, and that one cannot be undone — a retired listing has no way back to being published.

Closing the account also removes every recording, still and photo on a place you have listed, and every document you uploaded, including the paperwork behind a listing that was published: the files and the records describing them go in the same step as the listing is retired, and nothing keeps a copy other than the backups described above until those rotate out.

Two things neither button reaches, and you should hear it here rather than discover it. A place you have listed keeps its encrypted address and its registration number: those hang off a property rather than off your account, and closing the account does not touch them. And the download is an export of your account — your details, your consents, your saved homes, the area you voted for, your notifications, any offer attached to you, your sessions, and a list of every video, still and photo on a place you have listed and every document you uploaded: for each one, what it is, its size, its checksum, when it was recorded or uploaded, the position recorded with a video, and the address on this site that serves the file to you while you are signed in. The files themselves are not inside the download; the links do not expire and work for nobody else. The list does not carry the note a reviewer wrote on a document, or who reviewed it. It does not carry the address you typed, your bookings or your messages.

Closing an account cannot be undone, whichever of those two outcomes it takes, and the screen says so before you press the button.

Who else sees it

We do not sell, rent or share your details, and we have no advertising partners. Two companies handle things on our behalf and necessarily see part of what you give us. Email is delivered by Brevo, which sees the address a message is going to and the message itself while it is being sent. Payments are handled by Stripe: if you book, we create a customer record there holding your email address, and Stripe sees the card details you enter, which never reach us.

Closing your account does not remove the Stripe record, and we would rather say so than promise otherwise. A payment is a financial record with its own retention rules, so it outlives the account it belonged to. What we delete on closure is our own pointer at it, along with everything listed under closing your account above.

One thing that is not sharing but is worth saying in the same breath: a published listing is a public page, so the walkthrough on it is public with it — sound included. The recording itself stays on our server; what does travel is a single still from it, used as the preview card when the page is linked anywhere, so a chat app or a mail scanner that draws that card keeps its own copy of that frame for as long as it likes. Nothing is emitted at all until you publish. What that means for the recording is set out above.

Getting in touch

The company that holds your data is Momentum Minds LLC, a limited liability company formed in the State of New Mexico, United States of America. Its address is 8206 Louisiana Blvd NE, Ste A #7489, Albuquerque, New Mexico 87113, United States. The terms you use the site under are governed by the law of the State of New Mexico, and so is this policy.

Write to hello@remotestay.net, or reply to any email we have sent you. Either reaches a person, and either is the route for a question about this policy, a correction, a complaint about how we have handled your data, or anything you want done with it that the buttons above do not do.

The supervisory authority you can take a complaint to is not yet named on this page. Which one applies depends on questions about the company that are still being answered with a lawyer, and we would rather leave the line blank until then than print a name we have no basis to choose. That is a statement about this page, not about your rights: it does not say where you may or may not complain under the law of the place you live, and it does not narrow that. A complaint to us comes to the address above, and a person answers it.