Skip to content
See how Guestalizer looks before you create an account

A preview filled with sample data. No account and no card needed.

Legal

Privacy policy

How Guestalizer, run by Global Tech Develop, looks after the personal data of hosts and their guests.

Last updated: 8 October 2026

Who we are

Guestalizer is run by Global Tech Develop ("GTD", "we", "us"). We follow the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as set out in GTD’s own privacy policy at globaltechdevelop.com/privacypolicy.

For anything about your data, email support@guestalizer.io.

Two kinds of people use Guestalizer

  • Hosts: short let operators and their teams, who create an account, add properties and bookings, and check their guests.
  • Guests: people staying with a host, who open the link the host sends them to confirm their details, verify their ID, save a card for a deposit hold and sign the rental agreement.

For host accounts, GTD decides how the data is used: we are the controller. For guests, the host decides why guests are checked and what is asked: the host is the controller and GTD processes the data on the host’s behalf, under our data processing terms. If you are a guest and want to use your rights, you can contact the host or us; we will pass your request to the host and help them answer it.

What we collect

  • Host accounts: name, email, phone, company details, team members, properties, bookings and messages, billing details (cards are handled by Stripe, we never see full card numbers), and technical data such as IP address and device type.
  • Guests: name, email and phone; ID document photos or the result of an automatic ID check; the card brand and last four digits used for the deposit hold (the card itself is held by Stripe); the signed rental agreement with the time, IP address and a fingerprint of the text signed; messages with the host; and, where the host keeps the UK guest register, nationality and passport details required by the Immigration (Hotel Records) Order 1972.

Why we use it, and the legal basis

  • To provide Guestalizer to hosts and their guests (performance of a contract).
  • To keep accounts and payments secure, prevent fraud and fix problems (legitimate interests).
  • To keep records the law requires, such as invoices and the guest register (legal obligation).
  • To send product news to hosts, only if they agree (consent, which can be withdrawn at any time).

Guests are checked because the host needs to know who is staying and to protect the property. Hosts must have their own lawful basis for each check they switch on.

How long we keep it

  • ID document photos are deleted automatically after the stay, on the date the host sets (30 days after check out unless the host chooses otherwise). The guest sees the deletion date on their link.
  • Guest register entries are kept for 12 months, as the law requires, then deleted.
  • Signed agreements, bookings and messages are kept while the host’s account is open, so the host can show what was agreed.
  • When a host closes their account we delete their data within 30 days, apart from what the law requires us to keep (for example invoices for six years). Backups are kept for 30 days.

Who we share it with

We do not sell personal data. We use these providers to run Guestalizer, each bound by a data processing agreement:

  • Amazon Web Services (hosting, storage, backups and email), in London, United Kingdom.
  • Stripe (card deposit holds, automatic ID checks if the host uses them, and our own billing).
  • Text message providers, only if the host switches on SMS or WhatsApp.
  • Booking systems the host connects, such as Uplisting, which send us the host’s bookings.
  • Freedom Property Academy, if a host signs in from the academy (it confirms who the host is; it does not receive guest data).

Where a provider handles data outside the UK, the transfer is protected by UK adequacy regulations or the UK International Data Transfer Addendum.

How we protect it

  • Encryption in transit (TLS) and at rest, with keys and passwords for connected services stored encrypted.
  • ID photos and signatures kept in private storage, shown to the host’s team only through short lived links, with every view logged.
  • Each host only ever sees their own guests. Guest links use a long secret code, never a booking number.
  • Nightly encrypted backups, role based access for team members, and regular security reviews.

Your rights

  • To see the personal data we hold about you, and to get a copy.
  • To have it corrected, deleted or restricted, and to object to how it is used.
  • To move it to another service.
  • To withdraw consent where we rely on it.
  • To complain to the Information Commissioner’s Office (ico.org.uk) if you are unhappy with how we handle your data.

Email support@guestalizer.io to use any of these rights. We reply within one month.

Cookies

Guestalizer does not use advertising or tracking cookies. The website stores your sign in in your browser’s storage so you stay signed in, and the card form uses Stripe’s own cookies to prevent fraud.

Changes

If we change this policy we will update the date at the top, and tell hosts by email about any important change.