Privacy Policy
Effective date: 26 June 2026 · Last updated: 26 June 2026
This Privacy Policy explains how Ownia collects, uses, stores, and protects your personal data, and describes your rights under applicable data protection laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, and North American privacy laws including the California Consumer Privacy Act (CCPA) and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
At a Glance
- ✓ We are the data controller for your personal data.
- ✓ Our servers are located in the EU (Ireland). We do not sell your personal data.
- ✓ We collect only what is necessary to provide the Services.
- ✓ We do not handle financial data — payments are processed directly by Stripe.
- ✓ We use no third-party tracking or advertising cookies.
- ✓ You can request deletion, export, or correction of your data at any time.
1. Who We Are
Ownia is the data controller responsible for the personal data processed in connection with the Ownia platform and Services. Our primary place of business and the location of our data infrastructure is in the European Union (Ireland).
For data protection enquiries, please contact our privacy team at privacy@ownia.co.
2. Scope of This Policy
This Policy applies to personal data collected through:
- The Ownia website (ownia.co and subdomains);
- The Ownia web application (app.ownia.co);
- Any APIs or integrations we provide;
- Communications you initiate with us (e.g., support emails).
This Policy does not cover third-party websites, services, or applications that may link to or integrate with our Services. Those services have their own privacy policies.
Where Ownia customers (property owners) process their guests' personal data through the Platform,Ownia acts as a data processor on behalf of the customer (the data controller for that guest data). Customers are responsible for ensuring they have a lawful basis for processing their guests' data and for providing guests with appropriate notice.
3. Data We Collect and Why
3.1 Data You Provide Directly
| Category | Data | Purpose | Legal Basis (GDPR) |
|---|---|---|---|
| Account data | Full name, email address, hashed password | Creating and managing your account; authentication | Art. 6(1)(b) — contract performance |
| Property data | Property name, address, description, listing details, photos, pricing rules | Providing core platform features (listings, bookings, guest communications) | Art. 6(1)(b) — contract performance |
| Guest data | Guest full name, guest email address | Managing booking records and guest communications at the Customer's direction | Art. 6(1)(b) — contract performance; Art. 6(1)(f) — legitimate interest |
| Support communications | Name, email, message content | Responding to support requests; improving the Services | Art. 6(1)(b) — contract performance; Art. 6(1)(f) — legitimate interest |
We do not collect payment card numbers, bank account details, or other financial data. All payments are handled by Stripe, Inc. directly under Stripe's own privacy policy.
3.2 Data Collected Automatically
| Category | Data | Purpose | Legal Basis (GDPR) |
|---|---|---|---|
| Session data | Session tokens, authentication state | Maintaining logged-in sessions; security | Art. 6(1)(b) — contract performance |
| Technical logs | IP address, browser type, operating system, pages visited, timestamps, error logs | Platform security, debugging, abuse prevention | Art. 6(1)(f) — legitimate interest |
We use session cookies strictly necessary for authentication. We do not use analytics, advertising, or tracking cookies. See Section 6 for details.
3.3 Data from Third-Party Sources
We use ScraperAPI to retrieve publicly available information from the internet (e.g., publicly listed property data for competitive analysis or AI-assisted content suggestions). No personal data obtained via ScraperAPI is attributed to identifiable individuals beyond what is already publicly available.
4. How We Use Your Data
We use the personal data described above for the following purposes:
- Providing and improving the Services — operating the platform, processing bookings, enabling guest communications, and developing new features;
- Account management — creating and managing user accounts, authentication, and billing administration (billing handled via Stripe);
- AI-assisted features — passing relevant, minimised data to Anthropic's API to generate content suggestions (e.g., property descriptions). Data sent to Anthropic is governed by our data processing agreement with Anthropic;
- Transactional email — sending booking confirmations, account notifications, and service communications via Resend;
- Security and fraud prevention — detecting, investigating, and preventing security incidents, abuse, and fraudulent activity;
- Legal compliance — complying with applicable laws, responding to lawful requests from public authorities, and enforcing our Terms;
- Customer support — responding to your enquiries and resolving disputes.
We do not sell, rent, or share your personal data with third parties for their own marketing purposes. We do not use your personal data for profiling or automated decision-making that produces legal or similarly significant effects.
5. Legal Bases for Processing (GDPR)
For users in the EU/EEA and UK, we process personal data under the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR) — processing necessary to provide the Services you have subscribed to, including account management, property listings, and guest booking management.
- Legitimate interests (Art. 6(1)(f) GDPR) — processing necessary for our legitimate interests where these are not overridden by your rights. These interests include platform security, fraud prevention, service improvement, and internal analytics. We have conducted balancing tests to ensure our interests do not unduly impact your rights.
- Legal obligation (Art. 6(1)(c) GDPR) — processing required to comply with applicable law (e.g., tax and financial recordkeeping obligations).
- Consent (Art. 6(1)(a) GDPR) — where we rely on consent (e.g., optional marketing emails), you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
6. Cookies and Tracking
We use only strictly necessary session cookies — small data files stored on your browser that are essential for authentication and secure operation of the platform. These cookies do not track your activity across other websites and are deleted when you log out or close your browser session.
We do not use:
- Analytics or performance cookies (e.g., Google Analytics);
- Advertising or targeting cookies;
- Social media tracking pixels;
- Any third-party cookies for profiling or behavioural advertising.
Because we use only strictly necessary cookies, no cookie consent banner is required under EU law (ePrivacy Directive / Regulation). You may disable cookies in your browser settings; however, doing so will prevent you from logging in to the platform.
7. Sub-Processors and Third Parties
We engage the following sub-processors to help us deliver the Services. Each sub-processor is bound by a Data Processing Agreement (DPA) that requires them to protect your data in accordance with GDPR and equivalent standards:
| Sub-Processor | Purpose | Data Transferred | Location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, and infrastructure hosting | All user and property data stored on the platform | EU (Ireland / AWS eu-west-1) |
| Stripe, Inc. | Payment processing (via Stripe Connect) | Billing data only — no card data passes through Ownia | USA / EU (SCCs in place) |
| Resend, Inc. | Transactional email delivery | Name, email address, email content | USA (SCCs in place) |
| Anthropic, PBC | AI-assisted content generation features | Minimised property and content data (no guest PII) | USA (SCCs in place) |
| ScraperAPI | Retrieval of publicly available internet data | No personal data intentionally submitted | USA (SCCs in place) |
"SCCs" = EU Standard Contractual Clauses (Commission Decision 2021/914), which provide adequate safeguards for transfers to third countries under GDPR Art. 46(2)(c).
We do not share personal data with any other third parties except: (a) when required by law or valid legal process; (b) to protect the rights, property, or safety of Ownia, our users, or the public; or (c) in connection with a merger, acquisition, or sale of assets, subject to customary confidentiality obligations and advance notice to affected users.
8. International Data Transfers
Our primary infrastructure is hosted in the EU (Ireland) via Supabase/AWS eu-west-1. We therefore process most personal data within the EU/EEA.
Some personal data is transferred to sub-processors located in the United States (Stripe, Resend, Anthropic, ScraperAPI). These transfers are safeguarded by the EU Standard Contractual Clauses (SCCs) pursuant to GDPR Art. 46(2)(c). Where applicable, we also rely on supplementary technical and organisational measures to address risks identified in transfer impact assessments.
For UK users, transfers outside the UK are carried out using the UK's International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs as applicable.
9. Data Retention
9.1 General Principle
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law. When data is no longer needed, it is securely deleted or anonymised.
9.2 Retention Periods
| Data Category | Retention Period |
|---|---|
| Account data (name, email) | Duration of active subscription + 30 days following account deletion, unless extended retention is required by law. |
| Property and listing data | Duration of active subscription + 30 days following account deletion. |
| Guest data (name, email) | Duration of the Customer's active subscription + 30 days following account deletion or until the Customer deletes the record, whichever is sooner. |
| Technical logs (IP, access logs) | Up to 90 days for security and abuse-prevention purposes, then deleted or anonymised. |
| Support communications | 3 years from the date of the last communication, or such longer period as required to resolve a dispute. |
| Financial / billing records | 7 years, as required by applicable tax and accounting laws (EU and Irish law). |
9.3 Account Deletion
When you delete your account, we will initiate deletion of your personal data within 30 days, subject only to any mandatory retention obligations under applicable law (e.g., tax records). Anonymised, aggregated data that cannot be attributed to you may be retained for analytics purposes.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, without limitation:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256);
- Passwords stored exclusively as irreversible cryptographic hashes (bcrypt or equivalent);
- Role-based access controls limiting employee access to personal data on a need-to-know basis;
- Infrastructure hardened against common attack vectors (Row-Level Security policies on all database tables);
- Regular security reviews and penetration testing;
- Incident response procedures aligned with GDPR Art. 33–34 notification requirements.
Data breach notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware and, where the risk is high, will notify affected individuals without undue delay, in accordance with GDPR Art. 33–34.
No method of transmission or storage is 100% secure. You are responsible for maintaining the security of your account credentials.
11. Children's Privacy
The Services are not directed to children under the age of 16 (or a higher age where required by applicable national law). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@ownia.co and we will delete the relevant information promptly.
12. Your Rights — EU / UK (GDPR)
If you are located in the EU, EEA, or UK, you have the following rights under the GDPR and UK GDPR, subject to applicable exemptions:
- Right of access (Art. 15)You may request a copy of the personal data we hold about you and information about how it is processed.
- Right to rectification (Art. 16)You may request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17)You may request deletion of your personal data where there is no compelling reason for us to continue processing it (the “right to be forgotten”). This right may be limited where we must retain data for legal compliance.
- Right to restriction of processing (Art. 18)You may request that we restrict processing of your data in certain circumstances (e.g., while accuracy is contested).
- Right to data portability (Art. 20)You may request a machine-readable copy of personal data you have provided to us, to transfer to another service.
- Right to object (Art. 21)You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds that override your interests.
- Right not to be subject to automated decisions (Art. 22)We do not use your data for automated decision-making with legal or significant effects.
- Right to withdraw consentWhere processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@ownia.co. We will respond within 30 days (extendable by a further two months for complex or numerous requests, with notice). We may ask you to verify your identity before processing your request.
Supervisory authority complaints: If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with your national data protection authority. In Ireland, the supervisory authority is the Data Protection Commission (DPC): www.dataprotection.ie. UK residents may contact the ICO: www.ico.org.uk.
13. Your Rights — California (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights:
- Right to KnowYou may request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties with whom we share it.
- Right to DeleteYou may request deletion of personal information we have collected from you, subject to applicable exemptions.
- Right to CorrectYou may request correction of inaccurate personal information.
- Right to Opt-Out of Sale or SharingWe do not sell or share personal information for cross-context behavioural advertising. No opt-out is required, but you may contact us to confirm.
- Right to Limit Use of Sensitive Personal InformationWe do not process sensitive personal information (as defined by CPRA) beyond what is necessary to provide the Services.
- Right to Non-DiscriminationWe will not discriminate against you for exercising your CCPA/CPRA rights.
To submit a CCPA/CPRA request, email us at privacy@ownia.co with the subject line "California Privacy Rights Request." We will respond within 45 days, extendable by 45 additional days with notice. You may designate an authorised agent to submit a request on your behalf by providing written proof of authorisation.
In the preceding 12 months, Ownia has not sold, shared, or disclosed California residents' personal information to third parties for monetary or other valuable consideration.
14. Your Rights — Canada (PIPEDA / Law 25)
Canadian residents have rights under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Québec residents, Act respecting the protection of personal information in the private sector (Law 25):
- The right to access your personal information and be told how it is used;
- The right to challenge the accuracy and completeness of your personal information and have it amended;
- The right to withdraw consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions;
- The right to lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca;
- Québec residents additionally have the right to data portability, the right to be informed of and to contest automated decision-making, and enhanced breach notification rights under Law 25.
To exercise these rights, contact us at privacy@ownia.co.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services. If we make material changes, we will notify you by email or by posting a prominent notice in the platform at least 30 days before the changes take effect.
We encourage you to review this Policy periodically. The "Last updated" date at the top of this page indicates when the Policy was last revised.
16. Contact and Complaints
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:
You have the right to lodge a complaint at any time with your local data protection authority. We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, and ask that you contact us first.