Who we are
stay.cx is operated by Brunel Holdings Ltd (“we”, “us”, “our”), a company registered in England and Wales.
Registered address: 124 City Road, London, EC1V 2NX
Company number: 17108487
Data protection contact: privacy@stay.cx
Brunel Holdings Ltd is the data controller for the personal data collected through stay.cx. We are responsible for deciding how your personal data is used and for keeping it safe.
What this policy covers
This policy explains what personal data we collect when you visit stay.cx, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have. It also covers our use of cookies and similar technologies.
stay.cx is an accommodation booking platform. We display vacation rental properties sourced from third-party property management companies and enable you to book them. We act as an agent — the property manager is the provider of the accommodation, and your booking contract is with them, not with us.
What personal data we collect
3.1Data you provide to us
- Account registration: Name, email address, and authentication credentials (or third-party sign-in tokens from Microsoft, Google, or Apple).
- Booking details: Guest names, contact details, arrival and departure dates, party size, and any special requests you include when making a booking.
- Saved preferences: Favourite properties, saved searches, and destination preferences you choose to save to your account.
- Communications: Messages you send to us via the contact form or AI chat widget, and any email correspondence.
- Newsletter signup: Email address, if you opt in to our editorial newsletter.
3.2Data we collect automatically
- Usage analytics: Pages visited, search queries, property views, and booking funnel steps. This is collected by PostHog, hosted in the EU and reached through our own e.stay.cx domain. It uses no cookies and sets nothing on your device; visitors are counted by a privacy-preserving hash that changes every day, so we cannot recognise you on a later visit, and your IP address is discarded before anything is stored. We also log anonymised search and browse events in our own database to improve the service.
- Authentication session: When you sign in, a session token is stored in your browser to keep you logged in. This is strictly necessary for the service.
- Device and browser information: Basic technical data (browser type, operating system, screen size) transmitted automatically in HTTP requests. We do not fingerprint devices or create persistent profiles from this data.
3.3Data we do not collect
- We do not collect or store payment card details. All payment processing is handled directly by the property manager’s payment service provider via an embedded payment form. Card data is transmitted directly to the payment provider and never passes through stay.cx servers.
- We do not use advertising cookies, tracking pixels, retargeting scripts, or advertising analytics such as Google Analytics or Facebook Pixel. Our only analytics service is PostHog, described in section 7.4: it uses no cookies and does not identify you.
- We do not sell, rent, or trade your personal data to any third party for marketing purposes.
- We do not collect biometric data, facial recognition data, or government identity documents.
- We do not create profiles about you for the purpose of targeted advertising or behavioural tracking across websites.
3.4Data provided by third parties
If you sign in using Microsoft, Google, or Apple, we receive your name and email address from that provider. We do not receive your password and we do not access your contacts, calendar, or other data from these providers. We receive only the minimum information needed to create your stay.cx account.
If a booking is made on your behalf by another person (for example, a travelling companion who holds the account), the account holder provides your name and any special requests to us. The account holder is responsible for having your permission to share this information.
Why we process your data and our legal basis
Where the law of your country requires us to state a specific purpose of use rather than a legal basis, the purposes set out in this section are that statement.
4.1Contract performance
We process your booking details, account information, and communications to fulfil your booking request, manage your account, and provide the services you have requested. This processing is necessary for the performance of a contract with you.
4.2Legitimate interests
We process usage analytics, search queries, and browsing patterns to improve the stay.cx service, maintain platform security, detect errors, and develop new features. Our legitimate interest is operating and improving the platform. We have assessed that this processing does not override your rights because the data is anonymised or pseudonymised and is never used for profiling or targeted advertising.
We process AI chat interactions to provide real-time pre-booking support. Our legitimate interest is offering a responsive, multilingual customer service experience.
4.3Consent
We process your email address for newsletter distribution only if you have given explicit, informed consent. Signing up is a two-step process: you enter your address, we send a confirmation email, and we add you to the list only when you open the link in it. You can withdraw consent at any time by clicking the unsubscribe link in any newsletter or by contacting privacy@stay.cx.
4.4Legal obligation
We may process and retain certain data (such as booking records and commission data) to comply with tax, accounting, and regulatory obligations.
International data transfers
Your personal data is stored in the United Kingdom and in Cloudflare's EU-resident D1 database. Depending on the property you book and the services you use, your data may also be transferred to and processed in the United States, Switzerland, and the country in which your property manager is established. Section 5 identifies where each recipient processes data.
Where personal data is transferred outside the UK or EU, we rely on:
- EU-US Data Privacy Framework certification (Cloudflare, Anthropic);
- Standard Contractual Clauses (SCCs) approved by the European Commission (where DPF is not available);
- The UK International Data Transfer Agreement or Addendum, as applicable.
Where you are located outside the UK or EU, we transfer your personal data to another country only where that country is recognised as providing comparable protection, or where we have taken reasonable steps to ensure the recipient protects your data to a comparable standard, or where you have agreed to the transfer having been told where your data is going. On request we will tell you which basis applies to a particular transfer and how we verify it.
Some countries to which we transfer data may not provide the same level of legal protection as your own, and a recipient may be required to disclose personal data under the law of the country in which it operates. If you are in Japan, the United Kingdom and the European Economic Area are recognised by Japan as providing an equivalent level of protection.
Cloudflare's edge network processes data in the nearest geographic location to the visitor. For a visitor in Europe, data is processed at European edge nodes.
7.1Our approach
stay.cx is designed to minimise cookie usage. We do not use advertising cookies, third-party tracking cookies, or analytics cookies that require consent. The only cookies and local storage items used on stay.cx are strictly necessary for the service to function.
7.3What we do not use
- No Google Analytics or similar third-party analytics cookies.
- No advertising or retargeting cookies (no Google Ads, Facebook Pixel, etc.).
- No social media tracking cookies or embedded social widgets.
- No third-party session replay or heat-mapping tools.
- No cross-site tracking of any kind. Because we set nothing that requires your permission, we do not show a cookie banner and we do not ask you to consent to anything. Full detail is on our Cookies page.
Automated decision-making and profiling
stay.cx does not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. Search results are ordered by relevance to your query (destination, dates, party size) and are not personalised based on a profile of your behaviour. Property recommendations on editorial pages are curated by our editorial team, not by an algorithm tracking your activity.
The AI chat widget uses a large language model to generate responses to your questions. This is a conversational tool, not a decision-making system — it does not make booking decisions, set prices, or determine your eligibility for any service.
How long we keep your data
- Account data: Retained for the duration of your account. Deleted when you delete your account, subject to the legal retention periods below.
- Booking records: Retained for 7 years after the booking date to comply with UK tax and accounting obligations. After this period, records are permanently deleted.
- Commission records: Retained for 7 years (anonymised — linked to the booking, not to you personally, after you delete your account).
- Favourites and saved searches: Deleted immediately when you remove them, or when you delete your account.
- Event data (analytics): Retained for 2 years, then permanently deleted.
- AI chat messages: Not stored by stay.cx after the chat session ends. Your messages are processed by Anthropic as a sub-processor under its API terms and are not used to train its models.
- Newsletter subscription: Your email address is kept until you unsubscribe. When you unsubscribe we delete the address and keep only a salted, one-way hash of it, so that the address cannot be added again by mistake. The hash cannot be turned back into your address. An address that never completed the confirmation step is never emailed beyond that single confirmation message, and is removed when the list is next reviewed.
Your rights
Under the UK GDPR and EU GDPR, you have the following rights. These apply regardless of where you are located.
- Access: You can request a copy of the personal data we hold about you. If you have an account you can view most of this directly in your account (bookings, favourites, saved searches, profile), and download a copy using the Download my data option.
- Rectification: You can correct inaccurate personal data via your account settings, or by contacting us.
- Erasure: You can delete your account at any time. This will permanently delete your profile, favourites, and saved searches. Some records are anonymised rather than deleted: booking records, because we must keep commission and accounting records; and any reviews you have written, so that the property's overall rating remains accurate for other guests. Once anonymised, these records can no longer be linked to you.
- Restriction: You can request that we restrict processing of your data in certain circumstances.
- Portability: You can request your personal data in a structured, machine-readable format (JSON).
- Objection: You can object to processing based on our legitimate interests. We will cease processing unless we have compelling legitimate grounds.
- Withdraw consent: Where processing is based on consent (newsletter), you can withdraw at any time.
To exercise any of these rights, contact privacy@stay.cx. We will respond within one month.
If you believe we have not handled your personal data in accordance with data protection law, you have the right to complain to us directly. You can do this by emailing privacy@stay.cx or by writing to us at Data Protection, Brunel Holdings Ltd, 124 City Road, London, EC1V 2NX. We will acknowledge your complaint within 30 days and tell you how we intend to deal with it. You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. If you are outside the UK, you may instead contact the data protection authority in your own country.
Children
stay.cx is intended for users aged 18 and over. You must be at least 18 to make a booking, and the service is not directed at anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a person under 18, please contact privacy@stay.cx and we will delete it promptly.
Our editorial team
Our guides and editorial pages carry author credits. Where an author is named, we publish their name, a photograph and a short professional biography. This is personal data about our own editorial staff and contributors rather than about you as a user, and it is published with their agreement so that readers can see who wrote what they are reading. Authors can ask us to update or remove their details at any time by contacting privacy@stay.cx.
Security
We take appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (HTTPS/TLS 1.2+ on all connections) and encryption at rest for database storage.
- Row-level security (RLS) on all database tables, ensuring users can only access their own data.
- No storage of payment card data — all payment processing is handled by the supplier’s payment service provider.
- API keys and secrets stored as encrypted environment variables, never in source code or version control.
- Rate limiting on authentication, search, and booking endpoints to prevent abuse.
- Regular dependency audits and security updates.
- Access to personal data restricted to authorised personnel on a need-to-know basis.
- Automated monitoring of infrastructure health and security events.
No system is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and will notify you without undue delay if the breach is likely to result in a high risk to you, in accordance with Articles 33 and 34 of the UK GDPR, and within any shorter or additional timescale required by the law of your own country.
Governing law
This privacy policy is governed by the laws of England and Wales. The primary data protection framework applicable to stay.cx is the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For users in the European Economic Area, the EU General Data Protection Regulation (EU GDPR) also applies.
For users in other jurisdictions, we comply with applicable local data protection laws to the extent they apply to our processing of your personal data. If there is a conflict between this policy and mandatory local law, local law prevails.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email (if you have an account) or by a prominent notice on stay.cx at least 30 days before the changes take effect. The “Last updated” date at the top of this policy indicates when it was most recently revised. Your continued use of stay.cx after the effective date of a revised policy constitutes your acceptance of the changes.
Contact us
If you have any questions about this policy or our data practices, or if you wish to exercise any of your rights, please contact:
Email: privacy@stay.cx
Post: Data Protection, Brunel Holdings Ltd, 124 City Road, London, EC1V 2NX
We aim to respond to all enquiries within one month. If you are not satisfied with our response, you may escalate your complaint to the Information Commissioner’s Office (ICO) in the UK, or to the supervisory authority in your country of residence.
Questions about these terms?
Our team is happy to walk you through anything here in plain language.