Privacy Policy

Version 1.6 · effective 22 October 2026

Izvornik na bosanskom jeziku

This is an English translation of the Privacy Policy, provided for convenience. The original is in Bosnian (at /privatnost), and in case of any discrepancy the Bosnian version prevails.

This Privacy Policy (the Policy) explains what personal data the Aura Stay platform processes, for what purposes, on what legal basis, how long it keeps the data, who it shares the data with and what rights you have. It applies to Hosts, their Staff, Partners and Guests, to the Platform’s web pages and to the Android app “Aura Stay”. Capitalised terms have the meaning given to them in the Terms of Use.

The Policy applies in accordance with the Law on Personal Data Protection of Bosnia and Herzegovina and, towards Guests and Users from the European Union to the extent it applies to them, with the General Data Protection Regulation (GDPR).

Article 1

Controller and roles

(1)The controller of the data processed on the Platform is the Provider: the founder and owner of the Aura Stay platform, a natural person from Sarajevo, Bosnia and Herzegovina. Contact for data protection questions: info@aurastay.ba.

(2)The Provider is the controller of the data of Hosts, Staff and Partners, of the Platform’s technical data, and of Guests’ data to the extent it concerns the operation, security and retention periods of the Platform.

(3)The Host is an independent controller for their own relationship with the Guest: the Host decides which services and rules to offer the Guest, reads and uses the Guest’s messages, requests and orders to provide accommodation and services, and keeps their own guest records outside the Platform (e.g. guest registration required by law). The Host must inform the Guest about the processing of data and may refer the Guest to this Policy.

(4)In the same way, a Partner is an independent controller for orders of its offers: it uses the order data only to fulfil the order and to communicate with the Guest about it.

(5)Until the Provider registers a sole trade (obrt) or founds a legal entity, the Provider processes data as a natural person. When it does so, that entity takes over the role of controller for all data in this Policy and processes them for the same purposes, on the same legal bases and with the same retention periods (Terms of Use, Article 2(6)). The Provider informs Hosts of this by e-mail to the Account’s address and publishes a new version of the Policy with the details of the new controller.

Article 2

Host data

(1)

About the Host we process:

  1. a)identification and contact data: first and last name, e-mail address and mobile phone number (permanently linked to the Account, in international format). The Platform also enters the number from registration as the Host’s contact (phone and WhatsApp) that Guests see on the Guest Page and on the pre-arrival page; the Host can change or remove that contact in the Console, while the Account number stays;
  2. b)access data: the password, only in hashed form (a one-way digest from which the password cannot be read; not even the Provider can see it), session cookies and login time;
  3. c)e-mail address confirmation on self-registration: the six-digit code the Platform sends by e-mail is stored only as a hash, together with the address it was sent to, the number of attempts and the time it was sent, and is valid for 15 minutes. Confirmation deletes this record and only the time of confirmation remains, and entries in the log of sent codes (hash of the address and time) older than two days are deleted the next time a code is sent;
  4. d)registration data: the time at which the Host, on self-registration, accepted the Terms of Use and confirmed having read this Policy, with the version of those documents, and, to prevent abuse, a hash of the IP address from which the Account was opened (Article 9), the time of registration, a flag that the Account was self-registered, administrative review flags (e.g. same address, same location, same Wi-Fi, same network) and the time of review;
  5. e)Apartment data: name, address, city, location on the map (coordinates), Wi-Fi network name and password, key safe code if the Host enters it, house rules, guide, arrival directions, contact details for Guests, services and prices, recommendations and photos. Guests see the Wi-Fi password on that Apartment’s Guest Page and on the pre-arrival page, and the key safe code only on the pre-arrival page, on the Pro plan (Article 16(2));
  6. f)Plan and payment data: the Plan selected per Apartment, the paid period, records of agreements and payments (date, amount, pro-forma invoice and invoice, payer details from the bank statement) and records of Plan changes with the reason entered by the administrator. We also record the Pro plan expiry notice: when the expiry e-mail was sent or why it was not, the number of sending attempts and when the Host closed the notice in the Console. We do not process payment card data, because the Platform has no payment intermediary;
  7. g)records of the relationship with the Provider: contact (phone, WhatsApp, e-mail), the source through which the Host came, relationship status, agreed price, cycle and plan, next step and administrator notes, as well as records of calls, meetings, agreements, stand installation and administrator visits to the Host’s Console. These records are kept and seen only by the Provider’s administrator;
  8. h)the Host’s photo, if the Host adds it in the Console; it is shown to Guests next to the Host’s phone number, on the pre-arrival page and on the Guest Page, until the Host removes it;
  9. i)communication with the Provider: enquiries, complaints and app problem reports (text, a screenshot if the Host attaches one, the name under which the Host is signed in, a description of the device and the app version);
  10. j)notification data: web push subscriptions (the subscription address and keys issued by the browser, at most five per Account) and, in the Android app, the device notification token with the platform type and the time it last checked in (at most ten devices per Account). Signing out on a device deletes its subscription and token (Article 7);
  11. k)Console usage data needed for it to work: notifications, time of last activity and settings;
  12. l)a log of automatic translation of Content and chat messages: when and for which Apartment a translation was started, how much text and how many languages were translated, the service usage and the outcome, without the text of the messages. Entries older than 90 days are deleted at the manual clean-up in Article 10;
  13. m)Referral Programme data (Terms of Use, Article 8): the Host’s personal referral code and link, which Host referred whom and with which code, the time the referral was recorded, review flags (e.g. same contact number, same network or a network that cannot be compared, Trial Period not granted, many referrals on the same day), the status of the referral (under verification, approved or rejected), the time of the decision, the administrator who decided, their note or reason, and the reward granted. When recording a referral, the Platform compares the new Host’s e-mail address, mobile number and IP address hash with the data of the referring Host (Article 18(3)). To verify that the new Host is real and new, the Provider’s administrator reviews the data of the new Host’s Account and Apartments (name, e-mail address, mobile number and WhatsApp, city, time of registration, e-mail confirmation, registration review flags, the Plan, and the Apartments’ name, address and location), compares them with the data of the referring Host and with the registration record in Article 9, and may contact the new Host by phone or e-mail.

(2)The Host enters the data in paragraph 1, points a), b) and e), personally at registration or in the Console. Without them the Account and the Guest Page cannot work.

Article 3

Staff data

(1)For Staff, the Host enters a name and e-mail address and personally forwards to them the link for setting a password. Staff set the password themselves, and the Platform stores it only in hashed form.

(2)We also process the assigned rights, the Apartments the Staff member may access, the shift status (who is currently on shift) and the actions the Staff member performs in the Console (messages to Guests, handling of requests and orders), because they are carried out under the Host’s Account. Article 2(1), point j), applies to notifications for Staff.

(3)When the Host removes a person from Staff, that person’s login account is deleted.

(4)The Host must familiarise Staff with this Policy before granting them rights.

Article 4

Partner data

(1)A Partner is a service provider (e.g. a restaurant, transport or excursion) whose offers the Guest sees in the “Explore more” section of the Guest Page when the Provider enables them for the Host. A Partner’s account is opened by the Provider.

(2)

About the Partner we process:

  1. a)name, category, opening hours and cover photo;
  2. b)the name and e-mail address of the person who signs in, the password only in hashed form, and session cookies;
  3. c)offers with descriptions, prices and photos, the commission rate and turnover;
  4. d)orders of its offers, the messages attached to them and the ratings Guests give it;
  5. e)app problem reports and notification data, as for Hosts (Article 2(1), points i) and j)).

Article 5

Guest data

(1)The Guest does not create an account or install an app. When the Guest enters a name on the Guest Page, the Platform creates an anonymous session (without e-mail or password) which lets the Guest see their own messages and orders and by which each of the Guest’s entries is labelled with the Apartment and the name the Guest entered.

(2)

About the Guest we process:

  1. a)the name or nickname the Guest enters and the language the Guest chooses;
  2. b)the browser description the device sends by itself (e.g. phone type, operating system and browser), recorded on entering the stay;
  3. c)a random visit identifier: the browser creates a separate random number for each Apartment, without a name, IP address or link to other Apartments, and keeps it until the browser data are cleared; it prevents the same device from being counted as several visits on the same day. The day and time of the visit and the browser language are recorded with it;
  4. d)recognition of a returning device: when the same device signs in to the same Apartment again, the Platform recognises it by the earlier anonymous session and shows the Host, with the order, when that device first entered the Apartment;
  5. e)chat messages with the Host, including photos the Guest attaches. These photos, like photos attached to quick requests, are stored in private storage and shown only to the Host and to Staff with the “poruke” (messages) right (chat photos) or Staff on shift (photos with requests), to the Guest who sent them or to whom the Host sent them in the chat, and, where necessary for support, to the Provider’s administrator. A link to a photo is valid for one hour;
  6. f)quick requests (towels, bed linen, fault reports and other things the Guest asks for, with quantity, note and a photo of the fault) and their status;
  7. g)orders of the Host’s services and Partners’ offers: items, quantities, date and time slot, note, delivery address (the Apartment’s address and name, recorded with every order), total amount, status, the reason for rejection if the Host or Partner enters one, and messages attached to the order. The state of the stay at that moment is also recorded with the order (e.g. whether the Guest is the holder of the stay, since when the Guest has been in the stay, until when the Guest is staying and how many devices are in the stay);
  8. h)requests for late check-out and an extra night, with the price set by the Host and the Host’s answer;
  9. i)the departure date the Guest enters, ratings of the stay and of Partners, and comments; the rating of the Host with its comment is the public review in paragraph 8;
  10. j)location, only if the Guest expressly allows access to location in the browser when sending an order. The coordinates are sent to the database only for the calculation and are not stored: only the distance from the Apartment and the accuracy of the measurement remain with the order, so that the Host can see how far away the Guest was when ordering. Once the Guest has allowed location in the browser, it is measured on later orders without asking again, until the Guest withdraws the permission in the browser settings. Location is not tracked continuously. Refusing does not prevent the order, and the choice “not now” is remembered only for that stay;
  11. k)a push notification subscription (technical keys and the subscription address issued by the browser), only with the Guest’s consent in the browser. A notification contains our own sentence in the Guest’s language and, depending on the event, the beginning of the Host’s message, the name of an order or the reason for rejection entered by the Host or Partner;
  12. l)app problem reports the Guest sends: text, a screenshot if attached, the label “Name - Apartment”, the browser description and the app version. The report goes to the Provider’s support, not to the Host;
  13. m)pre-arrival page data: when the Host sends the Guest a pre-arrival link, the arrival date and the label the Host entered (e.g. the guest’s name or a booking reference) are stored with the link. The Platform records when the link was first opened and how many times, and the Host sees this on the Pro plan;
  14. n)a log of entries into the stay: name, time and type of event (new stay, joining, takeover of the stay, removal of a device), for the security of the stay and for support.

(3)The Platform automatically translates chat messages into the recipient’s language: the Host reads the Guest’s message in the Host’s language, and the Guest reads the Host’s reply in the Guest’s language. The original is kept with the translation, and the recipient can always view it. For translation, the message text and the sender’s and recipient’s languages are sent to a machine translation service (Article 12); the Platform does not send the Guest’s name, label or photos. The Guest sees automatic messages for quick requests in their own language from our dictionary, not from a translation service.

(4)We do not collect Guests’ e-mail addresses, phone numbers, documents or payment data; orders are paid to the Host or Partner directly. The exception is the app enquiry in paragraph 5, which the Guest sends personally and voluntarily.

(5)

App enquiry. A Guest who also rents out accommodation may leave an enquiry about the Platform on the pre-arrival page or on the Guest Page. In that case we process:

  1. a)the country, phone number and/or e-mail address and type of accommodation the Guest enters;
  2. b)the language of the page from which the enquiry was sent and the Apartment through which it arrived;
  3. c)the time of the enquiry and a flag that it has been handled.

(6)Only the Provider’s administrator sees the enquiry, not the Host. It is used solely to reply to the Guest and present the Platform; it is not sent to third parties or used for advertising. The legal basis is the Guest’s request (Article 8), and the entry is made only through the Platform’s server.

(7)On the entry screen, next to the name field, the Guest reads that the name, messages and orders are seen by the Host and the Host’s Staff, the name and orders also by the other Guests of that stay, and orders of a Partner’s offers by that Partner, with a link to this Policy.

(8)Public review. On the day of departure, and up to 14 days after it, the Guest may rate the Host with one to five stars and, if they wish, a comment. A stay has one review, and only a Guest who spent at least one night in the Apartment can rate. Before sending, the Guest reads that the rating and comment may be shown on the Apartment’s public page and under which signature. The following are shown publicly: the rating, the comment, the date of publication, the language of the comment and a signature made of the first name and the initial of the last name the Guest entered (e.g. “Amra K.”); the full name, device, dates of the stay and other Guest data are not published. The Host may publish one public reply under the review. The Provider hides from the public page a review that contains personal data, insults or advertising or is unrelated to the stay, with a reason the Host sees. The same rating with its comment also reaches the Host as a notification.

Article 6

Technical data

(1)On every access to the Platform, the hosting provider (Vercel) and the database provider (Supabase) record in their logs the IP address, time, requested address, browser type and any error. We use these logs solely for security, troubleshooting and abuse prevention; they are kept briefly, according to those providers’ rules.

(2)To protect sign-in against password guessing, the Platform records sign-in attempts: a hash of the network the attempt comes from (the IP address, for IPv6 the /64 network) and a hash of the e-mail address or Account, with the time. A successful sign-in deletes its own attempts, and attempts older than one day are deleted at the next sign-in attempt.

(3)To limit the number of registrations, the Platform temporarily keeps a counter of registration attempts per IP address hash and day, and in the same way, per network hash and day, a counter of app enquiries. Counters older than two days are deleted at the next entry of the same kind.

(4)We do not use third-party tools for analytics, tracking or advertising, neither on the web pages nor in the Android app. The statistics the Host sees (e.g. the number of openings, requests and messages) are calculated from the Platform’s own database.

Article 7

The Android app “Aura Stay”

(1)The Android app “Aura Stay” (package ba.aurastay.app) is intended for Hosts, Staff, Partners and the Provider’s administrator. The app loads the same pages as the web (www.aurastay.ba), so it processes the same data described in this Policy. Guests do not use it: the Guest Page and the pre-arrival page open in the browser.

(2)

The app requests or uses only the following on the device:

  1. a)notifications: only once you allow them does the device receive a notification token from the Google Firebase Cloud Messaging service. The token is stored with your account until you sign out on that device or turn notifications off in the phone settings (it is then deleted the next time the app is opened); at most ten devices are kept per account;
  2. b)location, only when you tap “Moja lokacija” (My location) during registration: it is used only to place the Apartment pin on the map, is sent with the form as the Apartment’s location and is not tracked;
  3. c)the camera, through the system camera app and only when you choose to take a photo while adding one; the app has no camera permission of its own, and the photo is sent only when you add it;
  4. d)storage: QR codes, labels, PDFs and other files you download are kept only on the device (images in the Gallery, album Aura Stay; everything else in Downloads, folder Aura Stay). On Android 9 and older the app asks for permission to write to storage for this;
  5. e)internet access and network state, to show the “Nema veze” (No connection) page and continue when the connection returns.

(3)The app does not back up its data: login cookies and the notification token are not transferred through a cloud backup or to a new phone. Uninstalling the app deletes its data from the device but does not delete the account (Article 11).

(4)In its browser description the app carries the label “AuraStay”, by which the server recognises that a request came from the app (e.g. so that it does not show the public pricing page in it).

Article 8

Purposes and legal basis

(1)

We process data for the following purposes and on the following bases:

  1. a)registering and managing the Account (including e-mail confirmation by code), operating the Console, the Guest Page, the pre-arrival page and the Android app, notifications, support: performance of the contract (Terms of Use), and for the Partner its contract with the Provider;
  2. b)issuing pro-forma invoices and invoices, recording payments and activating the Plan: performance of the contract and legal obligation (accounting and tax regulations);
  3. c)preventing fake and automated registrations, granting the Trial Period only once, the Apartment fingerprint, limits on the number of requests, sign-in attempts and codes, the IP address hash, administrative review and deactivation of suspicious Accounts: the Provider’s legitimate interest in protecting the Platform, other Users and Guests from abuse and harm;
  4. d)records of the relationship with the Host (contact, agreements, notes): the Provider’s legitimate interest in managing the business relationship and answering enquiries;
  5. e)automatic translation of the Host’s Content: performance of the contract (a Pro plan feature); Content as a rule does not contain personal data, and the Host does not enter personal data of third parties into it;
  6. f)automatic translation of chat messages: performance of the service the Guest and the Host use (chat, a Pro plan feature), because a conversation in different languages is hard to hold without translation;
  7. g)processing Guests’ data (name, language, browser description, messages, requests, orders, departure date, rating, entry log, device recognition and visit identifier): performance of the service the Guest personally requests and the legitimate interest of the Host, Partners and the Provider in making the stay, orders and communication work and in preventing abuse;
  8. h)location with an order and push notifications to the Guest: the Guest’s consent, which may be withdrawn at any time (Article 14); notifications in the Android app: consent given through the permission on the phone;
  9. i)security, access logs, troubleshooting, problem reports and abuse prevention: the Provider’s legitimate interest;
  10. j)responding to requests from competent authorities and establishing or defending legal claims: legal obligation and legitimate interest;
  11. k)replying to an app enquiry the Guest personally sends (Article 5): steps taken at the Guest’s request before a possible contract; the enquiry counter per network hash: the Provider’s legitimate interest in preventing abuse;
  12. l)the Referral Programme (recording the referral, verifying that the new Host is real and new, granting and revoking the reward): towards the referring Host, performance of the contract (Terms of Use, Article 8), and towards the new Host, the Provider’s legitimate interest in ensuring that only a genuine referral is rewarded and in preventing abuse. Registering through a link imposes no obligation on the new Host and does not affect the new Host’s rights.
  13. m)the Host’s public review (Article 5(8)): the Guest’s consent, which the Guest gives by sending the rating after reading that it may be published and under which signature, and the legitimate interest of future Guests in seeing the experiences of real Guests before their stay; the Guest may request removal of the review at any time (Article 14), and the Host’s public reply is part of the Host’s Content.

(2)Where processing is based on legitimate interest, the Provider has assessed that this interest is not overridden by the interests and rights of the person: only the data necessary for that purpose are processed, and in hashed form where possible.

Article 9

Permanent registration record

(1)So that the free Trial Period is granted only once per person and per Apartment, on every self-registration the Provider permanently enters into the registration record: a hash of the e-mail address, a hash of the mobile number, a hash of the IP address, the Apartment fingerprint and the time of registration.

(2)The hash is a SHA-256 digest without a secret addition (salt). The e-mail address, number or IP address cannot be read from it directly, but anyone who knows a particular value can calculate its hash and compare it with the record; phone numbers and IP addresses have a limited number of possible values, so they can also be guessed. That is why the record is seen only by the Provider’s administrator and by the Platform functions that check registrations.

(3)The Apartment fingerprint is stored in readable form: the address in simplified form (lower case, without diacritics and punctuation), the coordinates of the location and the Wi-Fi network name in simplified form. The Platform also keeps the same fingerprint with the Apartment, to check for repeated registrations. The record does not contain the name, the Wi-Fi password or other Host data.

(4)The record and the fingerprints are kept permanently and are not deleted when the Account is deactivated or upon a deletion request, because this is the only way to ensure that the Trial Period is granted once. The legal basis is the legitimate interest in Article 8(1), point c). Other Host data are deleted in accordance with Articles 10 and 11.

Article 10

Retention periods

(1)The Provider deletes Guests’ data manually, using a procedure in the Platform’s administration; there is no automatic deletion. The retention period is 90 days from the closing of the stay, or the period the Provider sets between 30 and 3650 days. The Provider runs the deletion regularly, so that the data are deleted no later than 30 days after the retention period expires.

(2)A stay is closed when the Host ends it, when the next guest enters the Apartment or, if no device of the stay checks in for 30 days, at the next deletion run.

(3)

The deletion removes:

  1. a)the Guests of that stay (name, language, browser description) and their anonymous sessions;
  2. b)chat messages and quick requests, with the photos the Guest attached;
  3. c)notifications to the Host about that stay and the state of the stay recorded with orders, including the distance from the Apartment;
  4. d)the Guests’ push subscriptions;
  5. e)the name in the entry log;
  6. f)individual visits (with the visit identifier), the translation cache and resolved problem reports older than the retention period, with their screenshots.

(4)The following remain, without the Guest’s name: orders (the Apartment name replaces the name, the note and delivery address are deleted, and items, amount and date remain for accounting, commissions and reports), ratings (stars and text) and the daily visit total, which contains no personal data.

(5)Requests for late check-out and an extra night remain with the Apartment with the Guest’s name until the Apartment is deleted. A pre-arrival link with the label the Host entered is deleted when the Host creates a new link and more than 90 days have passed since the arrival date, and at the latest when the Apartment is deleted. The Host can switch a pre-arrival link off and does not have to enter a label.

(6)Data of Hosts, Staff and Partners are kept for as long as their account exists. A deactivated Account remains stored until it is deleted upon request (Article 11). A Staff member’s account is deleted when the Host removes them.

(7)Records of pro-forma invoices, invoices and payments are kept for the periods prescribed by accounting and tax regulations.

(8)The registration record and the Apartment fingerprints in Article 9 are kept permanently, even when the Apartment or the Account is deleted.

(9)An app enquiry is kept for as long as it is needed to reply to and agree with the Guest. The Guest may request its deletion at any time, and the Provider then deletes it without delay.

(10)Access logs of the hosting and database providers are kept briefly, according to those providers’ rules. Protection records are deleted at the next entry of the same kind: sign-in attempts older than one day, and the log of sent e-mail confirmation codes and the counters of registration attempts and app enquiries older than two days. The translation log older than 90 days is deleted at the manual clean-up in paragraph 1.

(11)Data of a deactivated Account for which abuse has been established may be kept longer in hashed form, to the extent necessary to prevent repeated abuse.

(12)A Referral Programme record (Article 2(1), point m)) is kept for as long as the Accounts of both Hosts it concerns exist; when one of them is deleted, the record is deleted too. A reward already granted remains in the referring Host’s Plan data, with the record of the Plan change in which only a referral reference is stated as the reason, without the new Host’s name or other data (Article 2(1), point f)), until the referring Host’s Account is deleted.

(13)A public review (Article 5(8)) remains published after the Guest’s data are deleted under paragraph 1, without any link to the Guest, with the signature made of the first name and the initial of the last name, until the Apartment is deleted or the Provider removes or hides it - at the Guest’s request, or for the reasons in Article 5(8).

Article 11

Deleting the Account and data

(1)The Host deletes the Account themselves, in the console: Meni (Menu) → Moj nalog (My account) → Obriši nalog (Delete account), with the Account password. The same button is also on the e-mail confirmation screen. The deletion takes effect immediately and cannot be undone. While login to the Account is deactivated, the Account cannot be deleted in the console; deletion is then requested by e-mail (paragraph 2).

(2)The Host may also request deletion of the Account by an e-mail sent from the Account’s e-mail address to info@aurastay.ba. The Provider carries out such a request within 30 days of receiving it and informs the Host by e-mail; a request sent from another address is carried out only after the Provider has verified that it comes from the Account owner.

(3)Deletion removes the login account and the Host’s data (Article 2), the Host’s Apartments with their Content and photos, the data of the Host’s Staff and the accounts of Staff members who have no other role (who are not also a Host, a Partner, an administrator or Staff of another Host), the data of Guests of the Host’s Apartments and their anonymous sessions older than one day (younger ones are removed at the next manual clean-up under Article 10), the orders and reviews of those Apartments (including Partner orders placed in them), notification subscriptions, device tokens and the problem reports sent by the Host, the Host’s Staff and the Guests of those Apartments. Partner reviews from stays in those Apartments remain with the Partner, without the Guest’s label. In the administrator’s activity log entries about the Host, the Host’s name is replaced by the label “[obrisan nalog]” (deleted account). The QR codes in the Apartments stop working and the stands are withdrawn from use.

(4)If the same login account is also used by a Partner or by an administrator of the Provider, the account remains for that role and only the Host part described in paragraph 3 is deleted.

(5)Only the following remain: data the Provider must keep by law (e.g. pro-forma invoices, invoices and records of agreements and payments: the payer’s name and e-mail address, dates, amounts, paid periods, Apartment names and the administrator’s notes on those entries, for the periods prescribed by accounting and tax regulations), the registration record in Article 9, and data needed to establish or defend legal claims, until those claims are concluded. Copies of Content texts in the translation cache, with no link to the Account, are deleted after the period in Article 10.

(6)Staff and Partners request deletion of their account by e-mail, in the same way. The Host can also remove a Staff member, which deletes that person’s account immediately; deleting the Host’s Account also deletes the accounts of the Host’s Staff.

(7)The Guest has no account. The Guest requests deletion of their data before the period in Article 10 expires from the Host or from the Provider at info@aurastay.ba, stating the Apartment name, the name used to enter and the approximate time of the stay; the Provider then deletes the data within 30 days.

(8)In the Android app the Account is deleted the same way: Meni (Menu) → Moj nalog (My account) → Obriši nalog (Delete account). Uninstalling the app deletes its data from the device but does not delete the account.

Article 12

Processors, external services and data transfers

(1)

To operate the Platform, the Provider uses the following service providers (processors), which process data on the Provider’s behalf and according to its instructions:

  1. a)Vercel Inc. (USA): hosting and running the Platform’s code; the code runs in the European Union (Frankfurt), while requests and static files are received by Vercel’s global content delivery network (CDN) at the location nearest to the user;
  2. b)Supabase Inc. (USA): database, user sign-in and photo storage; the data are stored in the European Union (Frankfurt);
  3. c)Sendinblue SAS (Brevo, France): sending the Platform’s automatic e-mails, of which there are only two: the address confirmation code on self-registration and the notice to the Account owner when their Pro plan expires; it receives the e-mail address, the name when entered and the text of the message (the code, or the names of the Apartments that have moved to the Basic plan);
  4. d)Google Ireland Ltd. and Google LLC (Firebase Cloud Messaging): delivering notifications to the Android app; it receives the device token and the title and text of the notification, which may contain the Guest’s label, the beginning of the Guest’s message or of the note with a request, the name and amount of an order, the Apartment’s address and the departure date;
  5. e)Google LLC (Gemini API, USA): machine translation; it receives the text the Host writes for the Guest Page and the pre-arrival page and the text of chat messages between the Guest and the Host with the language codes, and the Platform does not send the Guest’s name, label or photos. The Platform uses paid access, under which Google does not use these texts to improve its models;
  6. f)the Provider’s bank: payment details.
(2)

The Platform also uses the following external services, which process data under their own terms:

  1. a)OpenStreetMap Foundation (United Kingdom): the browser loads the map (the sketch of the way to the Apartment on the Guest Page and on the pre-arrival page, the map during registration, in the Console and in the administration, and the map with the Apartment’s location on its public page) directly from OpenStreetMap’s servers, which thereby see the IP address and the browser description. The Apartment address is converted into a point on the map by their Nominatim service, to which the Platform’s server sends only the street, number, city and country, without data about the Host;
  2. b)Open-Meteo (weather forecast) and Frankfurter (exchange rates): the Platform’s server sends them only rounded coordinates of the Apartment, or a request for exchange rates, without data about the Guest, and caches the response;
  3. c)Unsplash and Picsum: the browser loads the photos of the public demo page and of sample data directly from those services, which thereby see the IP address and the browser description;
  4. d)the web push notification services of browser makers (e.g. Google, Apple, Mozilla, Microsoft): they receive an encrypted notification and the subscription address issued by the browser of the Guest, Host, Staff member or Partner; they cannot read the content of the notification.

(3)Fonts are downloaded only when the Platform is built and are served from our own address, so the browser does not contact Google for fonts.

(4)The database and photo storage are located in the European Union (Frankfurt). Under the law of Bosnia and Herzegovina, the EU member states ensure an adequate level of data protection. Data leave the EU with the following services: Firebase Cloud Messaging and Gemini (Google LLC, USA), OpenStreetMap and Nominatim (United Kingdom), web push notification services, Unsplash and Picsum (demo page), the hosting provider’s global content delivery network, and support of the hosting and database providers (USA). Such transfers take place under those providers’ terms and the mechanisms they provide for this, such as the European Commission’s standard contractual clauses.

(5)We do not sell data, share it with advertisers or use it for profiling. We disclose data to competent authorities only when the law requires it, on the basis of a valid request.

Article 13

Who has access to the data

(1)The Host sees the data of Guests of the Host’s Apartments: name, language, browser description, time of entry and of last activity, messages and photos, requests, orders with the state of the stay at the time of the order (e.g. whether the Guest is the holder of the stay, how many devices are in the stay and whether that device has been in the Apartment before), requests for late check-out and an extra night, departure date, ratings, the log of entries into the stay and, if the Guest allowed location with an order, the distance from the Apartment, or the fact that location was not allowed.

(2)Staff see only the Apartments the Host assigns to them (individual ones or all) and only while on shift. In those Apartments they see the Guests and their stays, requests, orders with the state of the stay and requests for late check-out and an extra night; they see chat messages only with the “poruke” (messages) right, and pre-arrival links with the “boravak” (stay) right. The rights the Host assigns also determine what Staff may do (reply to Guests, resolve requests, handle orders, manage the stay). Staff do not see ratings, the entry log or statistics.

(3)A Partner sees the orders of its offers: the Guest’s label (Apartment and name), items, date and time slot, note, delivery address (the Apartment’s address and name), messages attached to that order, as well as the ratings Guests give it. A Partner does not see the Guest’s chat with the Host, other orders, or the Host’s contact and other data.

(4)The Guest sees the Apartment’s Content, the Host’s contact details to the extent the Host has chosen, and their own messages, requests and orders. Guests who have entered the same stay (travel companions) see each other’s names in the group, browser descriptions, the shared orders and the messages attached to them, the quick requests of the stay, requests for late check-out and an extra night, ratings of the stay and the departure date; each Guest’s chat with the Host is visible only to that Guest. A Guest does not see the data of other stays, but anyone who has the Apartment’s link or QR code can enter a stay that is in progress and then sees the same as the travel companions; the Host sees that entry in the entry log and can remove the device.

(5)The Provider’s administrator sees the data of Hosts, Staff and Partners, records of Plans, payments and the relationship, registration review flags and the Platform’s technical data; the administrator accesses Guests’ data only to the extent necessary for support, security and troubleshooting. For support, the administrator can open a Host’s Console in the administrator’s own account; entry and exit are recorded, with the administrator’s name, in the Provider’s records about that Host, and the access expires by itself after eight hours. Individual changes the administrator makes during that time are not marked separately.

(6)The database applies row-level isolation (Row Level Security): every request sees only the rows it is entitled to, so a Host cannot see other Hosts’ Apartments or Guests, a Partner cannot see other Partners’ orders, and a Guest sees only the stay they have entered.

(7)In the Referral Programme, the referring Host sees only the new Host’s first name, the initial of the new Host’s last name and the status of the referral, and the notification of the decision contains no data of the new Host. When registering, the new Host only sees that they are registering through a referral. Neither sees the other’s contact details, Apartments, Guests or other data. The data from verifying a referral are seen only by the Provider’s administrator.

(8)The Apartment’s public page (showcase). When the Provider’s administrator includes an Apartment in the public showcase, anyone who opens its public page or the catalogue of Apartments sees: the Apartment’s photos, name, city and capacity, amenities, the Host’s welcome text and introduction, the Host’s name, photo and phone number, recommendations, the Apartment’s location on the map (the point of the building, without the street, number, floor or entrance), the type, access and price of parking, starting points and transport to the Apartment, and Guests’ public reviews with the Host’s replies (Article 5(8)). Wi-Fi and other access codes, entry instructions, the parking description and Guest data other than the review signature are never shown publicly. In the Console the Host sees that the Apartment is in the showcase and sees all reviews of the Host’s Apartments, including hidden ones, with the reason; the Guest sees their own review and the Host’s reply on the Guest Page.

Article 14

Your rights

(1)

Every person whose data we process has the right:

  1. a)of access: to find out which data about them we process and to receive a copy;
  2. b)to rectification of inaccurate or completion of incomplete data (the Host corrects most of their data personally in the Console);
  3. c)to erasure, when the data are no longer needed for the purpose, when consent has been withdrawn or when the data are processed unlawfully, subject to the exceptions in paragraph 4; the procedure for deleting an Account is described in Article 11;
  4. d)to restriction of processing while the accuracy of the data or the merits of an objection are being checked;
  5. e)to object to processing based on legitimate interest, on grounds relating to their particular situation;
  6. f)to portability of the data they have provided, in a structured, commonly used format;
  7. g)to withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal: consent to location and notifications is withdrawn in the browser or phone settings;
  8. h)to lodge a complaint with a supervisory authority: the Personal Data Protection Agency in Bosnia and Herzegovina, based in Sarajevo, and persons from the European Union also with the supervisory authority of their country.

(2)Requests are submitted to the contact in Article 1. The Provider replies without undue delay and at the latest within 30 days, and may extend this period when the request is complex, in which case it informs the requester. To protect the data, the Provider may ask the requester to confirm their identity (e.g. by replying from the Account’s e-mail address).

(3)The Guest exercises their rights with the Host (for the relationship with the Host) or with the Provider; to find the data, the Guest should state the Apartment, the name used to enter and the approximate time of the stay.

(4)The right to erasure does not apply to data the Provider must keep by law (e.g. invoices), to data needed to defend legal claims or to the registration record in Article 9.

Article 15

Cookies and local storage

(1)The Platform uses only technically necessary cookies: sign-in session cookies (Supabase Auth) for Hosts, Staff, Partners and administrators, and anonymous sessions for Guests. The administrator also has the cookie “aura-master”, which remembers whose Console the administrator opens for support, is read only when an administrator account is signed in and expires after eight hours. When a password is set from a link, the browser keeps the cookie “pw_setup_uid” with the account identifier for 15 minutes, only for the password-setting page, so that the password is set for exactly the account from the link. The referral link (Terms of Use, Article 8) uses no cookie: the referral code is passed only in the address of the registration page (the parameter “r”) and in the registration form, serves only to record the referral when the Account is opened, and contains no data about the visitor. Without these cookies sign-in and the Guest Page cannot work. We do not use marketing, analytics or third-party cookies, so we do not ask for separate consent to cookies.

(2)The browser’s local storage (localStorage) keeps settings and working data that stay on the device: the order basket before sending, the “not now” choice for location, a mark that the introduction has been viewed and that the device has left the group, the chosen currency and the latest exchange rates, the language of the pre-arrival page, the theme of the public page, the choice made on offers of notifications and installation, and the time the notification subscription was last synchronised.

(3)Some local storage entries are sent to the Provider together with the action they serve: the random visit identifier (when the Guest Page is opened, Article 5), the identifier of an order sending attempt, by which the database recognises a repeated sending of the same basket and does not record the order twice, and, in the Android app, the notification token (when the device is registered and on sign-out, Article 7).

(4)To work without a network connection, the Guest Page keeps on the device the latest stay data the device has already received: the Wi-Fi password, the Guest’s name and language, the group members and the holder of the stay, the departure date and check-out time, the stay’s requests for late check-out and an extra night with price, status and reason for rejection, and the stay’s fault reports. They are deleted when the Guest leaves the group, when the Guest opens the page of an archived Apartment, and the first time the page is opened after the Guest’s access has ended (stay closed or device removed); otherwise they remain until the browser data are cleared.

(5)In the browser (but not in the Android app) the Platform registers a service worker so that the Guest Page can be shown offline and push notifications can be received. It keeps a copy of pages, static files and photos in the browser and does not collect data by itself.

Article 16

Security

(1)

The Provider applies technical and organisational measures appropriate to the risk:

  1. a)encrypted data transfer (HTTPS/TLS) between the browser, the app, the Platform and the database;
  2. b)passwords only in hashed form; the e-mail confirmation code only as a hash; IP addresses, e-mail addresses and numbers in protection records only as hashes (Article 9);
  3. c)row-level data isolation in the database (RLS), so that every User, Partner and Guest sees only the data they are entitled to;
  4. d)an unpredictable access token for the Guest Page and the pre-arrival page. The Apartment link does not change, but the Host can end the stay, remove devices and switch off a pre-arrival link, and the Provider can withdraw a stand QR code and replace it with a new one;
  5. e)photos from the chat, fault reports and problem reports in private storage, accessible only through a signed link valid for one hour;
  6. f)prices and order amounts are calculated in the database, not in the browser;
  7. g)limits on the number of requests, sign-in attempts, e-mail confirmation codes and registrations, and administrative review of new Accounts;
  8. h)administrator access limited to authorised persons of the Provider, with records of Plan changes and of entries into a Host’s Console.

(2)The Apartment’s Wi-Fi password is visible to anyone who enters the stay with the link or QR code, and to anyone who has the pre-arrival link while it is valid (until the end of the arrival day); a promo link does not show it. On the Pro plan, from 48 hours before check-in time until the end of the arrival day, the pre-arrival link also shows the key safe code. The Host is responsible for sharing the link, the QR code and the pre-arrival link only with Guests.

(3)In the event of a personal data breach that may endanger the rights of individuals, the Provider informs the affected persons and the competent authority without delay, in accordance with the regulations.

Article 17

Children

(1)Only persons aged 18 or over may hold a Host Account, Staff rights or a Partner account. If we learn that an account was opened by a younger person, we deactivate it and delete the data.

(2)The Guest Page is intended for adult guests. A child staying in the Apartment uses it under the supervision of the adult guest responsible for the stay; we do not knowingly collect children’s data beyond the name the guest enters.

Article 18

Automated checks

(1)The Platform automatically checks registrations (matching of the Apartment fingerprint, hashed data and the number of attempts from the same network) and may reject a registration, flag it for review or not grant it the Trial Period. The decision on permanent deactivation of an Account is made by the Provider’s administrator, and the User may object to it at the contact in Article 1.

(2)The Platform makes no automated decisions with legal effect about Guests and does not profile them.

(3)In the Referral Programme (Terms of Use, Article 8), the Platform automatically does not record a referral when the new Host has the same Account or e-mail address as the referring Host, when the new Host’s Account was not self-registered within the last 24 hours, or when the new Host has already been referred, and it may flag a recorded referral for closer verification (e.g. same contact number, same network or a network that cannot be compared, Trial Period not granted, many referrals on the same day). A flag by itself does not reject the referral. A recorded referral is approved or rejected manually by the Provider’s administrator, after verification; the Platform does not do this by itself.

Article 19

Changes to the Policy

(1)The Provider may change the Policy due to changes in regulations, the Platform, processors or the manner of processing. Each new version carries a number and an effective date and is published at this address.

(2)We inform Hosts of material changes by e-mail to the Account’s address before they take effect; the Host must pass the changes on to Guests where necessary.

Article 20

Contact

(1)Controller: the founder and owner of the Aura Stay platform, a natural person from Sarajevo, Bosnia and Herzegovina.

(2)Send questions about data protection, requests to exercise your rights and requests to delete an Account to: info@aurastay.ba.

Article 21

Entry into force

(1)This Policy, version 1.6, enters into force on 22 October 2026.