Skip to content
StayMission

PRIVACY

StayMission Privacy Notice

How personal data is used during the free StayMission pilot. Effective 16 September 2026.

Who is responsible

StayMission is operated by Lyuben Doykin, an individual based in Bulgaria. For account, website, support and service-administration data, Lyuben Doykin is the controller. Contact [email protected] for privacy questions. A customer organization normally acts as controller for property, owner, staff and operational information it enters; StayMission processes that information on its instructions.

Information collected

We process account names, email addresses, password hashes, organization membership, consent records, authentication and security events, support enquiries, property and owner information, work records, financial entries, comments and files supplied by users. For website measurement we also record an anonymous session identifier, page path, referring website domain, campaign labels, country code supplied by Cloudflare and time of visit. Full referring URLs and visitor IP addresses are not stored in the analytics table. Do not upload identity documents, payment-card data, health information or other special-category personal data.

Purposes and legal bases

Account and operational data are used to provide and secure the service, perform the free pilot agreement, support users, prevent abuse, maintain records and meet legal obligations. Limited first-party website measurement is used to understand launch traffic and improve the service. Necessary service messages are sent to verify accounts, reset passwords, deliver invitations and explain important account activity. Optional product marketing is based only on separate consent and may be withdrawn at any time.

Access and sharing

Access is restricted by organization, role, assignment and property-owner relationship. Service providers receive only the data needed for hosting, backups, domain operation and transactional email. We do not sell personal data. The current subprocessor list identifies Hetzner and Resend and explains GoDaddy and certificate services.

Retention and deletion

During the free pilot, active workspace information is kept while the account is used. Following cancellation or a verified deletion request, operational data is scheduled for deletion within 30 days unless retention is needed for security, disputes or law. Deleted live data may remain in rolling backups for up to a further seven days. Necessary tax or legal records may be retained for the period required by law.

Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. Contact [email protected]. We may verify identity before acting. You may complain to the Bulgarian Commission for Personal Data Protection or another competent EU supervisory authority.

Security and incidents

The service uses HTTPS, hashed passwords, expiring single-use links, secure cookies, server-side permissions, tenant-separated operational databases, firewall protection, SSH keys and rolling infrastructure backups. No system is risk-free. Report suspected unauthorized access immediately to [email protected].

Changes

Material changes will be dated and communicated through the service or email where appropriate. This notice covers the current free pilot and its limited first-party website measurement; it must be updated before paid billing, external analytics, new integrations or materially different processing begins.