Real human support · No lock-in contracts · PCI DSS & GDPR compliant
Security & trust

How we hold your data, in plain words.

You’re trusting us with your bookings, your guests’ details and their card data. Here is exactly how we protect all three — no jargon, no over-claiming.

Security at a small hotel isn’t about slogans — it’s about the card that must never leak, the guest record that must stay private, and the certainty that your data is still there tomorrow. We’ve built for those specifics. Below is what that means in practice, told straight.

Card data

A PCI DSS card vault, so you never hold the card

When a guest’s card is taken — at booking, from a channel, or at the desk — it goes straight into our PCI DSS card vault and is replaced with a token. Your property works with the token, not the number. The raw card details are never stored on your account, never shown back to your staff in full, and never sit in a spreadsheet or an inbox. Charges, deposits and refunds all run against the token, so you can bill a guest without ever touching the underlying card.

Data protection

UK-GDPR and the Data Protection Act 2018

Your guests’ personal data belongs to your property, and we handle it as your processor under UK-GDPR and the DPA 2018. We collect what running the booking needs and no more, we don’t sell it, and we honour access, correction and deletion requests. Guest records stay within your account so you stay in control of your own data.

Encryption

Encrypted in transit and at rest

Everything travels over HTTPS/TLS, so data is encrypted between your browser, our servers and the channels we connect to. Stored data is encrypted at rest, and the sensitive fields we hold — card tokens and secrets among them — are encrypted with keys kept out of the database and out of the application code.

Isolation

One property can never see another

Stayvieo is multi-tenant, but every property’s data is isolated. Requests are scoped to your account at the data layer, so there is no path for one property to read or write another’s bookings, guests or reports — even by accident. Portfolios that run several properties see only the ones they own.

Access control

Roles that fit how your team works

Not everyone needs to see everything. Role-based access lets you decide who can take payments, change rates, edit bookings or view reports, and you can scope a person to a single property or the whole portfolio. Owners keep the keys; staff get exactly what their job needs and nothing more.

Continuity

Backups, recovery and uptime

Your data is backed up regularly so it can be restored if something goes wrong, and we keep the service running through routine maintenance without losing your work. We watch availability closely, and when there is an incident we tell you plainly rather than hide it.

Have a specific compliance question, or need this for a supplier review? We’re happy to answer directly rather than point you at a PDF.

Talk to us about security →