Legal
Privacy policy
Effective from 25. 7. 2026. We process data under Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll.
Data controller
The BookNight portal, operated by OasisLabs s. r. o., with registered office at Palánok 1, 949 01 Nitra, company ID (IČO) 57762473.
Contact for data-protection matters: limba@oasislabs.sk.
1. What data we process
- Website visitors — anonymised visit statistics. We store a visitor only as a daily hash (SHA-256 of IP, browser and a salt) — we do not store the raw IP address.
- Guests (enquiry / booking) — name, phone, e-mail, stay dates, number of people, optionally a note and information about a pet. For a booking with a deposit, also the payment status and payment reference.
- Hosts — name/business name, contact details, property details, price list, optionally IBAN and account name to display the QR deposit payment.
2. Purposes and legal bases
- Facilitating contact between the guest and the host and handling the enquiry/booking — performance of a contract / steps prior to entering into a contract (Art. 6(1)(b)).
- Operation and security of the portal, protection against abuse and spam — legitimate interest (Art. 6(1)(f)).
- Fulfilling legal obligations (accounting for the host’s fee) — legal obligation (Art. 6(1)(c)).
3. Payments and deposits
BookNight does not process card payments and does not hold guests’ money. The guest sends the booking deposit directly to the host’s bank account (we display their IBAN in the QR payment). BookNight charges no commission on bookings.
4. Who we share data with (processors)
- Cloudflare — hosting and the portal database.
- Resend — sending e-mail notifications.
- SMS provider — sending SMS notifications to the host (if activated).
- Host — we pass the enquiry/booking data to the relevant host so they can contact you and confirm the stay.
Processors handle the data under contracts and appropriate safeguards. We do not sell the data or use it for advertising profiling.
5. Cookies and analytics
We use only essential technical cookies and minimalist first-party analytics with no third-party advertising trackers. We cannot re-identify a visitor — we store only a daily hash. You can restrict cookies in your browser at any time.
6. How long we keep data
- Enquiries and bookings — for the duration of handling and a reasonable period for any disputes.
- Hosts’ accounting documents — for the period required by the accounting act.
- Analytics — in anonymised form.
7. Record of incidents during a stay
The host with whom you stayed may report a specific incident from your stay (for example damage to property, an unpaid amount or repeated disturbance of night-time quiet). We keep a record of it covering: the name given in the booking, phone number, stay dates, incident category, a description and any photographs of the damaged item or the state of the property.
- Legal basis: legitimate interest under Art. 6(1)(f) GDPR — protecting hosts’ property and preventing repeated damage.
- Who has access to the record: only the host with whom you subsequently made a booking, and solely in connection with it. The record is not public, is not searchable, and hosts cannot browse the database.
- Only a guest with an actual booking with that host can be reported. There is at most one record per stay.
- Retention period: at most 3 years from the end of the stay, after which the record is automatically deleted.
- Your rights: you have the right to find out whether we keep a record about you, what it contains, to request its correction or erasure, and to object to the processing. Write to limba@oasislabs.sk. If we cannot rebut the objection with documented facts, we will remove the record.
- This is not a record of criminal offences or an assessment of a person — we record solely the factual course of a specific stay.
8. Your rights
You have the right to access your data, to have it corrected or erased, to restrict processing, to data portability, and the right to object. Send your request to limba@oasislabs.sk. If you believe we process data unlawfully, you can lodge a complaint with the Úrad na ochranu osobných údajov SR (Slovak Data Protection Authority), Hraničná 12, 820 07 Bratislava.
9. Changes
We may update this policy. The current version is always on this page with the effective date stated.