← Back to VirTrav

Privacy Policy

Last updated: 6 August 2026

This policy explains what personal data VirTrav collects, why we collect it, and the choices you have. It applies to the VirTrav website and platform.

1. Data we collect

  • Account data: your name, email address, password (stored only as a bcrypt hash), and account role.
  • Booking data: the properties you book, dates, guest counts, and any message you send to a host.
  • Payment data: the amount, currency, and status of transactions. Card details are handled by our payment provider and never reach our servers.
  • Wallet data: your VRT balance and transaction history. Custodial wallet keys are stored encrypted with AES-256-GCM.
  • Technical data: IP address, browser user agent, and session records, which we use for security, rate limiting, and audit logging.
  • Host data: listing details, images, and virtual tours you upload.

2. Why we use it

  • To operate your account and authenticate you.
  • To process bookings, payments, payouts, and refunds.
  • To detect and prevent fraud, abuse, and unauthorised access.
  • To meet legal, tax, and accounting obligations.
  • To support you when you contact us.

3. Legal bases

Where data protection law requires a legal basis, we rely on: performance of our contract with you (operating your account and bookings); our legitimate interests (securing the platform and preventing fraud); legal obligation (financial record keeping); and consent, where we ask for it.

4. Sharing

We do not sell your personal data. We share it only where necessary to run the platform.

  • With hosts, when you book: the information they need to receive you as a guest.
  • With our payment provider, to take payment and issue refunds.
  • With infrastructure providers that host our application and database.
  • With authorities, where we are legally required to disclose.

5. Retention

We keep account data for as long as your account is open. Booking and payment records are retained after closure where we need them for legal, tax, or dispute-resolution purposes. Audit and security logs are kept for a limited period and then deleted.

6. Security

  • Passwords are hashed with bcrypt and are never stored or transmitted in plain text.
  • Custodial wallet mnemonics are encrypted at rest with AES-256-GCM.
  • Sessions use httpOnly, SameSite cookies and can be revoked server-side.
  • Sensitive and administrative actions are recorded in an audit log.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact us through the contact page.

If you are unhappy with how we have handled your data, you may complain to your local data protection authority.

8. Cookies

We use a small number of strictly necessary cookies. The authentication cookie keeps you signed in and is required for the platform to function; it is httpOnly and cannot be read by scripts in your browser. We do not use advertising cookies.

9. International transfers

Our infrastructure providers may process data in countries other than your own. Where that happens, we rely on appropriate safeguards recognised under applicable data protection law.

10. Contact

For any privacy question or request, please reach us through the contact page.

Questions about this document? Reach us via the contact page.