Privacy Policy
Last updated: 19 July 2026 · Version 1.0 (draft)
[REGION] values, [PAYMENT PROVIDER] and specific retention periods — should be completed, and the text reviewed by a qualified data-protection adviser for GDPR (Spain/EU) and Ukrainian law before it is relied upon. Not legal advice.
CortoCasa is a product developed, owned and operated by Teleport Dynamix SL, a company based in València, Spain. This Privacy Policy explains how Teleport Dynamix SL (“CortoCasa”, “we”, “us”) collects, uses, shares and protects personal data. It applies to two connected surfaces:
- the marketing website at cortocasa.com; and
- the application at app.cortocasa.com (the “Service”).
1. Who we are (controller)
The data controller for this website and for our own business data is Teleport Dynamix SL, the company that develops and operates CortoCasa, with registered office at Plaza Sant Felip Neri núm. 2, Pta. 5, 46021 València, Spain, Spanish tax ID (NIF) B21782743. Contact: privacy@cortocasa.com.
Our roles differ depending on the data:
- We are a controller for data about visitors, prospects and account holders (e.g. the person who signs up, billing contacts, support correspondence).
- We are a processor for the operational data that our customers enter into the Service about their own guests, properties and staff. In that case the customer (the rental operator / management company) is the controller, and we process that data on their instructions under our Data Processing Agreement (see section 9).
2. What data we collect
2.1 Website (cortocasa.com)
- Contact-form data you submit (name, email, message).
- Technical data: IP address, device/browser, and — only with consent — analytics and cookie data (see section 8).
2.2 Application (app.cortocasa.com) — account data (we are controller)
- Account and profile: name, email, password (hashed), language, role, company.
- Billing: plan, subscription status and payment references handled by our payment provider (we do not store full card numbers).
- Usage and log data needed to operate and secure the Service.
2.3 Application — customer operational data (we are processor)
Our customers use the Service to run short-term rental operations. On their behalf we process, among other things:
- guest details: name, phone, email, nationality, and identity/travel documents (e.g. passport or ID) uploaded by the operator;
- booking, payment-schedule, cash-ledger, key-handover, cleaning and maintenance-ticket records;
- property information and guest-communication content (e.g. WhatsApp message templates and guest-kit links).
3. Why we use data and our legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide and operate the Service / website | Performance of a contract |
| Account security, fraud and abuse prevention | Legitimate interests |
| Billing and tax records | Legal obligation / contract |
| Support and service communications | Contract / legitimate interests |
| Analytics and marketing cookies | Consent |
| Processing guest operational data | On behalf of the customer-controller (their legal basis; our basis is the DPA) |
4. Sharing and sub-processors
We share data only as needed to run the Service, with vetted providers under contract. Current sub-processors:
| Provider | Purpose | Region |
|---|---|---|
| Supabase / Lovable Cloud | Database, authentication, file storage, hosting | [REGION] |
| Hostinger | Website hosting | [REGION] |
| WhatsApp (Meta) | Guest messaging via user-initiated links | [REGION] |
| OpenAI | AI assistant features (processes text you route through the assistant) | United States |
| [PAYMENT PROVIDER] | Subscription billing | [REGION] |
An up-to-date sub-processor list is maintained and provided to customers under the DPA. We do not sell personal data.
5. International transfers
Some providers (e.g. OpenAI) are located outside the EU/EEA and Ukraine. Where data is transferred internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. Details available on request. [Confirm mechanisms in legal review.]
6. Retention
We keep account and billing data for the life of the account and as required by law thereafter. Customer operational data is retained per the customer’s configuration and deleted or returned on termination in line with the DPA. [Insert specific retention periods after review.]
7. Your rights
Under GDPR and Ukrainian data-protection law you may have the right to access, rectify, erase, restrict or object to processing, and to data portability, plus the right to withdraw consent at any time. For account/website data contact privacy@cortocasa.com. For guest data held on a customer’s account, please contact that operator (the controller); we will assist them as processor.
EU/Spain users may lodge a complaint with the Spanish Data Protection Agency (AEPD). Ukrainian users may contact the relevant Ukrainian supervisory authority. [Confirm authorities in review.]
8. Cookies
Essential cookies are used to run the site and keep you signed in. Analytics or marketing cookies are set only with your consent via our cookie banner, and you can change your choice at any time. [Link cookie settings once the banner is live.]
9. Data Processing Agreement
Customers acting as controllers can enter into our Data Processing Agreement, which governs how we process guest and operational data on their behalf, including security measures and the sub-processor list. Request it at privacy@cortocasa.com.
10. Security
We apply row-level tenant isolation, encryption in transit and at rest, role-based access, private document storage and least-privilege access controls. No system is perfectly secure; we work to protect data using industry-standard measures.
11. Changes
We may update this policy. Material changes will be notified via the Service or by email. The “last updated” date shows the current version.
12. Contact
Questions or requests: privacy@cortocasa.com.