Privacy policy
Effective 18 August 2026
Airbtc Ltd, trading as Hodlstay | Cayman Islands | hodlstay.com/legal/privacy Effective date: 18 August 2026 | Version 1.0
YOUR PRIVACY IN PLAIN ENGLISH
We collect the minimum data needed to run the platform and process bookings. We do not sell your data. We do not share it with advertisers. We do not share it with governments unless legally compelled. Bitcoin payments are processed pseudonymously. This document explains exactly what we collect, why, who sees it, and how long we keep it.
1. Who we are
1.1 This Privacy Policy is issued by Airbtc Ltd, a company incorporated in the Cayman Islands, trading as Hodlstay ("Hodlstay", "we", "us", "our"). We operate the travel booking platform at hodlstay.com.
1.2 Hodlstay is the data controller for personal data collected and processed through the Platform.
1.3 For all privacy enquiries, requests and complaints, contact hello@hodlstay.com.
1.4 This Policy applies to everyone who uses the Platform: guests, hosts, and visitors.
2. Legal framework
2.1 Hodlstay processes personal data in accordance with the Cayman Islands Data Protection Act, as amended, and, where applicable to EU residents, the General Data Protection Regulation (EU) 2016/679.
2.2 The GDPR applies to our processing where: (a) you are resident in the European Union or European Economic Area; or (b) your personal data is processed in connection with offering services to EU/EEA residents or monitoring their behaviour.
2.3 Where the GDPR applies, any reference in this Policy to "applicable data protection law" includes the GDPR and its implementing legislation in relevant member states.
3. Data we collect
3A. Data you give us directly
| Category | Data points | Who provides it |
|---|---|---|
| Identity | Display name | Guests and hosts |
| Contact | Email address; phone number (hosts) | Guests and hosts |
| Payout (hosts) | Bitcoin wallet address | Hosts only |
| Business (hosts) | Property details, listing content, pricing, availability | Hosts only |
| Booking | Travel dates, number of guests, any message you send with a request | Guests only |
| Enquiries | Name, email, and the message you send us through the contact, conference-partner or property-sales forms | Anyone who uses those forms |
3B. Data we collect automatically
| Category | Data points | Purpose |
|---|---|---|
| Usage data | Pages visited, searches, booking-flow steps | Operating and improving the Platform |
| Technical data | IP address, browser and device type, user-agent string | Security |
| Log data | Server logs including timestamps and IP addresses | Security monitoring |
| Cookie data | Session and authentication tokens | See Section 8 |
3C. Data we do not collect
- Government-issued identity documents. We do not ask for or store passports, ID cards or any identity document.
- Payment card numbers. There is no card payment on the Platform.
- Bitcoin private keys. Your wallet is yours. We never request or store private keys.
- Device fingerprints. We do not use fingerprinting of any kind.
- Sensitive personal data. We do not collect health, racial, political, religious or biometric data.
- Children's data. The Platform is for adults. We do not knowingly collect data from anyone under 18.
4. Why we process your data, and our legal basis
| Purpose | Legal basis | Applies to |
|---|---|---|
| Account creation and sign-in | Performance of contract | Guests and hosts |
| Processing bookings and payments | Performance of contract | Guests and hosts |
| Host phone verification | Performance of contract | Hosts |
| Sending booking confirmations, receipts and account notifications | Performance of contract | Guests and hosts |
| Host payouts | Performance of contract | Hosts |
| Platform security and fraud prevention | Legitimate interests | Guests and hosts |
| Improving the Platform | Legitimate interests | All users |
| Compliance with tax and financial record-keeping | Legal obligation | Guests and hosts |
| Responding to your enquiries | Legitimate interests | Anyone who contacts us |
We do not currently run a marketing email programme, and we do not process anyone's data for advertising. If that changes, this Policy will be updated and your consent obtained first where the law requires it.
5. Who we share your data with
5.1 We do not sell your personal data. We do not share it with advertisers. We share it only as described in this section.
5A. Service providers acting as our processors
| Provider | Role | Data shared |
|---|---|---|
| Supabase | Database, authentication and file storage | All account, listing and booking data; sign-in and phone verification |
| Vercel | Platform hosting and edge network | Server logs including IP addresses and request metadata |
| Cloudflare | DNS and traffic proxy | IP address, request headers, traffic metadata |
| Resend | Transactional email delivery | Email address, name, and the contents of the email sent to you |
| BTCPay Server | Bitcoin payment processing | Bitcoin transaction data and the booking reference |
| Google Maps Platform | Address search, place suggestions and geocoding | The text you type into a location search, and your approximate location if you use "use my location" |
| HotelPlanner | Hotel inventory partner | The booking details needed to confirm a hotel reservation |
| Dtravel | Inventory partner | The booking details needed to confirm a reservation |
5B. Hosts
5.2 When you book a listing owned by a host, we share your name, contact details and booking details with that host so they can fulfil your stay. Hosts are required under our Host Terms to use your data only for that purpose.
5C. Content embedded from other sites
5.3 Some pages can embed a timeline from X (formerly Twitter). That embed is loaded only if you have accepted non-essential cookies. If you have not, it is not loaded and X receives nothing. We do not use advertising pixels, analytics tags or retargeting tools of any kind.
5D. Calendars you connect
5.4 If you are a host and you connect an external calendar, availability data is exchanged with the iCalendar URL you provide. We do not control who operates that URL, and what they receive is determined by them, not by us.
5E. Legal and regulatory disclosure
5.5 We will disclose your personal data to government authorities or law enforcement only where we are legally compelled to do so by a valid legal order under Cayman Islands law or, for EU users, under applicable EU law.
5.6 We do not voluntarily disclose user data to governments or law enforcement, and we will not comply with informal requests or requests unsupported by a valid legal order in our jurisdiction.
5.7 Where legally permitted, we will tell you before disclosing your data in response to a legal order.
6. International data transfers
Multiple-region storage. Our infrastructure spans more than one region, which may include servers outside the European Economic Area. For EU/EEA residents this means your personal data may be transferred to countries without an equivalent level of data protection to the EU.
6.1 Your personal data is processed in the Cayman Islands and in the regions where our infrastructure providers operate, which may include the United States, the European Union and other jurisdictions.
6.2 For transfers of EU/EEA personal data to countries not covered by an EU adequacy decision, we rely on Standard Contractual Clauses approved by the European Commission. We have executed or are executing SCCs with the relevant processors, including Supabase, Vercel and Resend.
6.3 You may request a copy of the relevant clauses by contacting hello@hodlstay.com.
7. Data retention
7.1 We retain your personal data for as long as you have an account with us. You may ask us to delete your account at any time, and we act on that request rather than waiting for a fixed period to elapse.
7.2 We retain booking records and financial transaction data for 7 years from the date of the transaction, to meet tax, accounting and financial record-keeping obligations. Where you have asked us to delete your account, those records are kept in anonymised form with personal identifiers removed.
7.3 Enquiries sent through our contact, conference-partner and property-sales forms are retained while we deal with them and for as long as we may reasonably need them afterwards. Ask us and we will delete yours.
7.4 Server logs and technical data are retained by our hosting providers according to their standard periods.
7.5 We do not currently run an automated deletion schedule. Retention beyond an active account is managed by us on request, so if you want your data removed, the fastest route is to ask at hello@hodlstay.com.
8. Cookies and tracking
8.1 We use cookies and similar storage on the Platform. Cookies are small files stored on your device that help us operate the Platform.
| Category | Consent required | Purpose |
|---|---|---|
| Strictly necessary | No — always active | Session management and sign-in. Cannot be disabled without breaking the Platform |
| Functional | Yes — opt-in | Remembering preferences such as recent searches |
| Analytics | Yes — opt-in | Understanding how the Platform is used. Not currently in use |
| Marketing | Yes — opt-in | Not in use. We run no advertising or retargeting of any kind |
8.2 When you first visit, our consent tool asks for your choice before anything non-essential is stored. You can change your preferences at any time from the cookie settings link in the footer.
8.3 Today the only non-essential thing your consent enables is the embedded X timeline described at clause 5.3. The analytics and marketing categories exist in the consent tool so that your choice is recorded, but nothing is loaded under either of them. We will not activate anything in those categories without updating this Policy first.
9. Emails we send
9.1 We send transactional email only: booking requests and confirmations, payment receipts, sign-in links, account notifications, and operational messages about your listings. These are part of providing the service and cannot be switched off while your account is active.
9.2 We do not currently send marketing email. If we start, it will be on an opt-in basis with an unsubscribe link in every message, and for EU/EEA residents only on the basis of freely given, specific, informed and unambiguous consent.
9.3 We do not share your email address with third-party marketers. Our email is sent through Resend, which acts as our processor.
10. Automated decision-making
10.1 We do not carry out automated decision-making or profiling. We have no automated fraud screening, no behavioural scoring and no automated system that makes decisions about you.
10.2 Decisions that affect you — approving a listing, assessing a refund, reviewing a non-delivery claim — are made by a person.
10.3 If you believe a decision about your account or a booking is wrong, contact hello@hodlstay.com. We will review it and respond within 5 business days.
11. Your privacy rights
11.1 You have the following rights over the personal data we hold about you. To exercise any of them, contact hello@hodlstay.com. We will respond within 30 days.
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Ask us to correct inaccurate or incomplete data |
| Erasure | Request deletion of your account and personal data |
| Restriction | Ask us to pause processing while a dispute is resolved |
| Portability | Receive your personal data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interests |
| Withdraw consent | Withdraw consent for non-essential cookies at any time |
11.2 How deletion actually works. When you ask us to delete your account we do one of three things. If you have no bookings or obligations outstanding, we delete your profile and your sign-in record outright. If you have historical bookings we are required to keep for financial records, we anonymise your profile instead — your name and email are replaced and the booking history remains without you attached to it. If you have a live booking, an open cancellation case or an unpaid payout, we cannot delete the account until those are closed, and we will tell you which one is blocking it.
11.3 EU/EEA residents — right to complain. If you are not satisfied with our response, you may lodge a complaint with your national data protection supervisory authority. The list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
11.4 EU Representative. Hodlstay is in the process of appointing an EU Representative as required by GDPR Article 27. Details will be published on this page on appointment. In the meantime, direct all GDPR enquiries to hello@hodlstay.com.
12. Data security
12.1 Our security measures include encryption in transit using TLS, access controls limiting data access to authorised people, row-level security policies on our database, and regular security review.
12.2 In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authorities within 72 hours of becoming aware of it.
12.3 If you believe your account has been compromised, contact us immediately at hello@hodlstay.com.
13. Bitcoin payments and pseudonymity
13.1 Bitcoin transactions are recorded on a public blockchain. Bitcoin addresses are pseudonymous, but our own records link your payment to your account and booking so that we can confirm and support it.
13.2 We do not store your Bitcoin private keys. For each payment we record the transaction reference, the sats amount, the USD equivalent at the time of payment, the booking reference, and the invoice identifier, checkout link, status and event timestamps supplied by our payment provider.
13.3 On-chain transactions are permanently recorded on the public blockchain. Your right to erasure applies to the data we hold in our own systems; it cannot extend to the blockchain.
13.4 Lightning Network payments are not publicly recorded on the Bitcoin base layer, which gives them more privacy. We still record the payment internally to confirm and support your booking.
14. Children
14.1 The Platform is for users aged 18 and over. We do not knowingly collect personal data from anyone under 18.
14.2 If you believe someone under 18 has given us personal data, contact hello@hodlstay.com. We will delete it promptly on verification.
15. Third-party links
15.1 The Platform contains links to third-party websites, including our inventory partners, where some bookings are completed. This Policy does not apply to those sites and we recommend reading theirs.
16. Changes to this policy
16.1 We may update this Policy. Material changes will be communicated by email to your registered address and by notice on the Platform at least 14 days before taking effect.
16.2 The current version is always at hodlstay.com/legal/privacy.
17. Contact and complaints
Privacy enquiries and legal notices: hello@hodlstay.com
Airbtc Ltd, trading as Hodlstay, Cayman Islands.
EU supervisory authority. EU/EEA residents unsatisfied with our response may escalate to their national data protection authority. Full list: https://edpb.europa.eu/about-edpb/about-edpb/members_en. EU ODR platform: https://ec.europa.eu/consumers/odr.

