Privacy policy
Draft for launch review. This policy accurately describes what the WatchMyStay service does today. Replace the bracketed company details below and have a solicitor review this page, the cookie policy and the terms before public launch.
Last updated 23 September 2026 · Policy version privacy-2026-09
Who we are
WatchMyStay is operated by [Company legal name], a company registered in England and Wales under company number [00000000], registered office [registered address] (“WatchMyStay”, “we”, “us”). We are the data controller for the personal data described below. You can contact us at hello@watchmystay.com. ICO registration: [number, once registered].
What WatchMyStay does, in plain terms
You tell us which hotel you are staying at and your dates. We watch that property using public sources – not your booking – and email you only if credible evidence suggests something important has changed. See how it works for the full picture. This policy explains the personal data that involves.
The personal data we collect
| Data | Where it comes from | Why we need it |
|---|---|---|
| Email address | You, when you create a watch or sign in | To verify it’s really you (magic link), let you sign in, and send the alerts you asked for |
| Hotel and travel dates | You, when you create or edit a watch | To know what to monitor and until when |
| Alert & delivery history | Generated by our monitoring and email systems | To avoid sending you a duplicate alert, show you your alert history, and prove delivery if something goes wrong |
| A hashed fragment of your IP address | Your browser, automatically, on API requests | To rate-limit abusive traffic (e.g. someone trying to spam an email address with verification links). We never store your IP address itself – only a one-way hash of it, and only for up to 2 days. |
| Whether you opened an alert’s evidence page | Generated automatically | To measure whether alerts are useful, so we can improve them |
| Clicks on a labelled “compare alternatives” link | Generated automatically when you click one | To measure whether the referral link is useful. Stored against the watch, not your email, and kept separate from any assessment of a hotel. |
| A single sign-in cookie | Set by us after you confirm a magic link | To keep you signed in. See the cookie policy – it’s the only cookie we use. |
We deliberately do not collect: your name, a booking reference or confirmation number, payment card details, your passport, who else is travelling with you, or any access to your email inbox. We never see your booking – only the hotel and dates you tell us.
Our lawful basis for using it
- Performance of a contract (UK GDPR Art. 6(1)(b)): collecting your email, the hotel and your dates, and sending you the monitoring emails you asked for, is how we provide the service you signed up to.
- Legitimate interests (Art. 6(1)(f)): keeping delivery and audit records, rate-limiting abusive requests, and measuring whether alerts and the alternatives link are useful, so we can run a reliable, non-abusable service and decide whether it’s worth continuing. We’ve balanced this against your privacy by minimising what we keep (hashing IPs, no analytics cookies, short retention windows – see below).
- Legal obligation (Art. 6(1)(c)): keeping a minimal record of email addresses that have bounced or complained, even after you delete your account, so we do not email that address again – this is standard anti-spam practice under UK PECR.
We do not use your data for marketing. We currently send no marketing emails at all, so there is nothing to opt out of; if that changes, it will require your separate, explicit consent and will never be mixed into service emails.
Automated decisions
Whether an alert is sent is decided by an automated set of rules that compare fresh evidence against what we already know about a hotel (see how it works). This affects what email you receive, not any right, benefit or legal status, and during our pilot phase every “likely” or “confirmed” alert is checked by a person before it is sent. You can query or dispute anything we send you via the correction form.
Who we share it with
We use a small number of processors to run the service. None of them may use your data for their own purposes.
| Processor | What they process | Purpose |
|---|---|---|
| Resend (email delivery) | Your email address and the content of the email we send you | Delivering verification, sign-in and alert emails |
| Neon (database hosting) | All the data in the table above | Storing it securely |
| Our application host | The same data, while the app is running | Running the website and the monitoring worker |
| Google (Places API) | The hotel name/destination you search for, and the hotel’s own public details (name, address, status). Not your email or dates. | Finding and checking the status of the hotel property |
If you click a labelled “compare alternatives” link, you leave our site and go to Booking.com, which then applies its own privacy policy to whatever you do there. We only pass the destination and your dates in that link – never your email address.
We do not sell your data, and we do not share it with data brokers, advertisers, or for any purpose other than running the service described above.
International transfers
Our processors may process data outside the UK (for example, on infrastructure located in the EU or the US). Where they do, we rely on their UK/EU GDPR–compliant safeguards (such as the UK International Data Transfer Addendum or an adequacy decision) – check each processor’s own policy for specifics.
How long we keep it
- An active watch: for as long as you keep it running.
- A completed or stopped watch: deleted automatically 30 days after check-out, or 30 days after you stop it.
- An unconfirmed sign-up: deleted automatically after 7 days if you never open the confirmation link.
- Sign-in links and sessions: a magic link expires in 20–60 minutes and is deleted shortly after use or expiry; a session lasts 30 days.
- Rate-limit records (hashed IP only): deleted after 2 days.
- Email delivery logs: deleted after 30 days.
- A deleted account: your email address and travel dates are removed immediately. A minimal, anonymised operational record (with no email address) may remain briefly for security and fraud-prevention purposes.
- Bounced, complained or unsubscribed email addresses: kept indefinitely on a do-not-email list, even after account deletion, so we never email that address again. This is the one exception to immediate deletion, and it exists only to protect you from receiving further mail.
- Hotel observations and assessments (what a hotel’s website said, its status, etc.) are not personal data about you and are kept to improve accuracy for everyone watching that property.
Keeping your data safe
Passwordless sign-in means we never store a password to lose. Sign-in links are single-use, hashed before storage, and expire quickly. Your email address is never guessable from our sign-in flow (asking to sign in always gives the same response, whether or not an account exists). Traffic to the site is encrypted, and access to the database and hosting is restricted to the people who run the service.
Your rights
Under UK GDPR you have the right to:
- Access your data – download it any time from your account page.
- Rectify it – correct your dates or hotel from your watches, or email us for anything else.
- Erase it – delete your account and all personal data instantly from your account page.
- Restrict or object to our processing, including the legitimate-interest uses above – email us and we will action it.
- Port your data – the account export is provided as machine-readable JSON.
- Complain to the Information Commissioner’s Office (ICO), though we’d appreciate the chance to put things right first – hello@watchmystay.com.
Cookies
We use exactly one cookie: the one that keeps you signed in. No analytics, advertising or third-party tracking cookies. Full details, including how to control it, are in our cookie policy.
Children
WatchMyStay is not directed at children, and we do not knowingly collect data from anyone under 16.
Changes to this policy
If we make a material change, we’ll update the date at the top of this page and, where the change is significant, tell active users by email.
