CortoCasa
  • Home
  • Features
  • Pricing
  • STR management
  • FAQ
  • Contact
  • Sign in
EN
English EN Español ES Українська UK
Sign in

Privacy Policy

Last updated: 19 July 2026 · Version 1.0 (draft)

Draft — pending legal review. Operational draft prepared for launch. All placeholders are now filled; what remains is review by a qualified data-protection adviser for GDPR (Spain/EU) and Ukrainian law before it is relied upon. Not legal advice.

CortoCasa is a product developed, owned and operated by Teleport Dynamix SL, a company based in València, Spain. This Privacy Policy explains how Teleport Dynamix SL (“CortoCasa”, “we”, “us”) collects, uses, shares and protects personal data. It applies to two connected surfaces:

  • the marketing website at cortocasa.com; and
  • the application at app.cortocasa.com (the “Service”).

1. Who we are (controller)

The data controller for this website and for our own business data is Teleport Dynamix SL, the company that develops and operates CortoCasa, with registered office at Plaza Sant Felip Neri núm. 2, Pta. 5, 46021 València, Spain, Spanish tax ID (NIF) B21782743. Contact: support@cortocasa.com.

Our roles differ depending on the data:

  • We are a controller for data about visitors, prospects and account holders (e.g. the person who signs up, billing contacts, support correspondence).
  • We are a processor for the operational data that our customers enter into the Service about their own guests, properties and staff. In that case the customer (the rental operator / management company) is the controller, and we process that data on their instructions under our Data Processing Agreement (see section 9).

2. What data we collect

2.1 Website (cortocasa.com)

  • Contact-form data you submit (name, email, message). These submissions are delivered to us by email over an encrypted SMTP connection and are not shared with third parties.
  • Technical data: IP address, device/browser, and — only with consent — analytics and cookie data (see section 8).

2.2 Application (app.cortocasa.com) — account data (we are controller)

  • Account and profile: name, email, password (hashed), language, role, company.
  • Billing: plan, subscription status and payment references. Card details are collected and held by Paddle, not by us — see section 4.1.
  • Usage and log data needed to operate and secure the Service.

2.3 Application — customer operational data (we are processor)

Our customers use the Service to run short-term rental operations. On their behalf we process, among other things:

  • guest details: name, phone, email, nationality, and identity/travel documents (e.g. passport or ID) uploaded by the operator;
  • booking, payment-schedule, cash-ledger, key-handover, cleaning and maintenance-ticket records;
  • property information and guest-communication content (e.g. WhatsApp message templates and guest-kit links).
Special note on identity documents. Passport/ID data is sensitive and attracts heightened obligations. Operators (controllers) are responsible for having a lawful basis to collect it and for limiting what they upload. CortoCasa applies access controls, encryption in transit and at rest, private storage and retention limits — but customers must configure their own retention and lawful basis. This section in particular should be confirmed in legal review.

3. Why we use data and our legal bases (GDPR Art. 6)

PurposeLegal basis
Provide and operate the Service / websitePerformance of a contract
Account security, fraud and abuse preventionLegitimate interests
Billing and tax recordsLegal obligation / contract
Support and service communicationsContract / legitimate interests
Analytics and marketing cookiesConsent
Processing guest operational dataOn behalf of the customer-controller (their legal basis; our basis is the DPA)

4. Sharing and sub-processors

We share data only as needed to run the Service, with vetted providers under contract. Current sub-processors:

ProviderPurposeRegion
Supabase (via Lovable Cloud)Database, authentication and file storage for the applicationAWS eu-west-1 (Ireland)
LovableApplication hosting, platform error reporting, and the AI gateway that routes assistant requestsEU / United States
HostingerMarketing website hosting; backups held in BostonUnited States (Massachusetts)
ResendTransactional email (invitations, notifications); authentication email is sent by SupabaseUnited States
OpenAIAI assistant and guest-feedback analysis (gpt-5.4-mini) and voice transcription (gpt-4o-transcribe), reached through the Lovable AI gatewayUnited States

An up-to-date sub-processor list is maintained and provided to customers under the DPA. We do not sell personal data.

WhatsApp is not on this list, and that is deliberate. Guest-kit links are shared by opening WhatsApp on your own device with the message already written; you send it from your own number. We do not connect to the WhatsApp Business API, and no guest data passes from us to Meta.

4.1 Payments — Paddle acts as a separate controller

We do not sell subscriptions directly. Our order process is conducted by our online reseller Paddle.com, which is the Merchant of Record for all our orders and handles invoicing, tax compliance, subscription management and refunds.

Paddle is not our sub-processor. It decides for itself how and why it processes the payment data it collects, and so acts as a data controller in its own right. It holds data we never see — full card details, cardholder name, billing address and payment identifiers. What reaches us is limited to your plan, subscription status and a payment reference.

Paddle's handling of that data is governed by Paddle's privacy policy and its Buyer Terms. Requests to access, correct or delete payment data should go to Paddle directly; we can only act on the limited subscription data we hold.

5. International transfers

Application data stays in the EU. All customer and guest records in the Service — bookings, guests, uploaded identity documents, cash and ticket history — are held in Ireland (AWS eu-west-1).

Some providers are outside the EU/EEA and Ukraine: OpenAI and Resend in the United States, and this marketing website is hosted by Hostinger in Massachusetts, with its backups in Boston. That means data you submit through the website — your contact-form message and the technical data in section 2.1 — is processed in the United States.

Where data is transferred internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. Details available on request. [Confirm mechanisms in legal review.]

6. Retention

We keep account and billing data for the life of the account and as required by law thereafter. Customer operational data is retained per the customer’s configuration and deleted or returned on termination in line with the DPA.

When you delete a record or an account, it is permanently deleted — the delete cascades through related records and removes the associated files from storage. It is not a hidden soft-delete. (Properties are the one exception: they can be archived, which keeps them visible but inactive, and archiving is not deletion.)

Encrypted backups are taken daily and held in the same region on a rolling 7-day window, so deleted data can persist in backups for up to seven days before ageing out.

7. Your rights

Under GDPR and Ukrainian data-protection law you may have the right to access, rectify, erase, restrict or object to processing, and to data portability, plus the right to withdraw consent at any time. For account/website data contact support@cortocasa.com. For guest data held on a customer’s account, please contact that operator (the controller); we will assist them as processor.

EU/Spain users may lodge a complaint with the Spanish Data Protection Agency (AEPD). Ukrainian users may contact the relevant Ukrainian supervisory authority. [Confirm authorities in review.]

8. Cookies

Essential cookies are used to run the site. With your consent we use Google Analytics 4 (GA4) for analytics only — to measure how the site is used so we can improve it — via Google Consent Mode v2, which keeps analytics and advertising storage denied by default. GA4 sets the _ga cookie to distinguish visitors; nothing is set until you choose Accept in our cookie banner. You can withdraw or change your consent at any time using the “Cookie settings” link in the footer.

9. Data Processing Agreement

Customers acting as controllers can enter into our Data Processing Agreement, which governs how we process guest and operational data on their behalf, including security measures and the sub-processor list. Request it at support@cortocasa.com.

10. Security

We apply row-level tenant isolation, encryption in transit and at rest, role-based access, private document storage and least-privilege access controls. No system is perfectly secure; we work to protect data using industry-standard measures.

11. Changes

We may update this policy. Material changes will be notified via the Service or by email. The “last updated” date shows the current version.

12. Contact

Questions or requests: support@cortocasa.com.

CortoCasa

Operations software for short-term rental teams. Bookings, keys, cleaning, cash, guests — one mobile-first app.

Product

Features Pricing STR management

Resources

Blog FAQ Contact

Get started

Sign in Create account
© 2026 Teleport Dynamix SL. CortoCasa is a product of Teleport Dynamix. Privacy · Terms · Refunds · FAQ · Contact ·