bookhome.ge privacy policy
1. About this policy
This policy explains how bookhome.ge uses personal data: what we collect, why we collect it, who receives it, how long we keep it, and what your rights are.
bookhome.ge is a website where guests book short-term rental apartments in Georgia directly from their owners.
1.1 Who this policy is for
- Owners and managers list and manage apartments. They sign in with Google. An owner has full rights for an apartment. A manager helps with the calendar, prices, bookings, content and messages, but cannot see payouts or change members. This group includes people whom an owner invites.
- Guests book apartments. You can book without an account. You sign in with Google only if you want to message an owner before you book, or to see all your bookings in one place. This group includes guests whose bookings an owner records, for example a booking made by phone or on Airbnb or Booking.com.
- Affiliates recommend an apartment with a link or code from its owner, and earn a commission. Affiliates never sign in. The owner gives us their details.
- Visitors are everyone who opens bookhome.ge.
1.2 The main points
- We collect what we need to run bookings, payments and messages. We never ask guests for a passport or ID.
- Your stay is a contract between you and the owner. We give the owner the guest details that the stay needs. Phone numbers and other contact details are shared only after a booking is confirmed.
- Our platform admins can read conversations to prevent abuse, and can act as an owner to give support. We record every such access.
- Paysera handles card payments, and we never see your full card number. Crypto payments are recorded on public blockchains, which anyone can read and nobody can delete.
- We do not sell personal data. We do not show ads. We do not use analytics or advertising cookies.
- You can ask to see, correct or delete your data (section 12).
1.3 What this policy does not cover
- What owners do with guest data outside bookhome.ge, for example after they receive a guest's phone number. Each owner is responsible for that.
- Services of other companies that you use through bookhome.ge, such as Google sign-in, Paysera's payment page, Airbnb, Booking.com, WhatsApp, Telegram and Viber. Their own privacy policies apply.
1.4 Languages
We publish this policy in English, Georgian and Russian.
2. Who is responsible for your data
bookhome.ge is run by Geniuses Recruiting LLC, a company registered in Georgia. We decide why and how personal data is used on bookhome.ge, so we are responsible for it as its controller. In this policy, "we", "us" and "our" mean Geniuses Recruiting LLC.
- Company: Geniuses Recruiting LLC
- Identification code: 405728930
- Registered address: Paliashvili St., Tbilisi, Georgia
- Email for privacy requests: [privacy@bookhome.ge]
- Support: [support@bookhome.ge]
- Personal-data protection officer: [name and contact, if one is appointed]
- Representative in the EU: [name and contact, if one is required]
The footer of every public page of bookhome.ge also gives our company details.
We use personal data under.
3. What data we collect
3.1 Everyone who visits
- Connection data. Each time your browser asks for a page, Cloudflare (our network provider) and our server receive your IP address, your browser type, the page you asked for, the time, and the page that sent you to us. Some networks, for example in Russia, cannot reach Cloudflare. Visitors on them can reach guest pages and photos through a second server of ours (section 5.3), which receives the same data and passes the request on to Cloudflare and our server. We use this data to deliver pages, to keep the service secure and to stop abuse.
- Your country (IP country). Cloudflare tells us which country your IP address belongs to. If Cloudflare cannot tell, or if you use the Tor network, we get "unknown" or "Tor" instead. If you come through our second server, we look your IP address up in a country database that we keep on our own server (DB-IP Lite), so it is sent to no one for this; an address the database doesn't know counts as "unknown". If you use a VPN, we see the VPN's country.
- Language. Your browser's language setting, and the language you choose on the site. We keep your choice in a cookie and, if you are signed in, also with your account.
- Affiliate visits. If you arrive through an affiliate's link, we keep a random visitor ID in a cookie. We record which affiliate's link you used, for which apartment, and when.
- Security checks. To stop automated programs, some forms (checkout, starting a conversation, Find my booking and creating an apartment) carry a hidden field that people don't fill in, and we limit how often one IP address can send them. No script from another company checks your browser.
- Maps. When an apartment page shows its map, your browser loads the map images from OpenStreetMap's servers (section 5.3).
We do not use analytics tools, advertising trackers or social-media plugins.
3.2 Guests
When you book. Checkout asks for:
- your full name;
- your email address;
- your phone number, with country code;
- your country of residence;
- the number of adults and children (we do not ask for the children's names or ages);
- your approximate arrival time (optional);
- a message to the owner (optional);
- a promo code (optional).
We also record the booking: the apartment, the dates, the price breakdown, your choice to pay a prepayment or the full amount, the language you booked in, your acceptance of the house rules, the cancellation rule and our guest terms, your IP country, and the booking's status. If you are signed in, we fill in your name and email address from your Google account.
To stop abuse, we compare your email address, phone number, IP address and device with other open bookings and requests. For this check, we keep your IP address only in a one-way scrambled form (a hash), for 30 days. The hash is made with a secret key that we replace every 30 days, so it cannot be traced back to your IP address or linked to later hashes. We recognise your device by a random ID in a cookie, which lasts 30 days (section 8). Full IP addresses appear only in our server logs, including those of our second server, which we keep for 14 days.
Proving that a booking is yours.
- We email you a private link to your booking page. It works until 30 days after check-out, or until a newer link replaces it. A device that opened it stays signed in to the booking until 30 days after check-out, or until you use "Sign out other devices" on the booking page. That also stops every earlier link, and we email you a fresh one.
- For a booking request, we ask you to confirm your email address with a link. The owner sees the request only after you confirm it.
- We send a one-time code to your email when you cancel, when you give an address for a crypto refund, and when you link bookings to your account.
- If you cancel, you can tell us why.
- If you use Find my booking, we take the email address you enter. If bookings were made with it, including unpaid bookings and requests, we send new links for all of them to that address only. The old links stop working.
If you sign in with Google. Google sends us your Google account ID, your name, your email address, whether Google has verified that address and, for a work or school account, the account's domain. We never receive your Google password. We show you the bookings made with your email address. If your Google account uses an email address that Google does not manage (not Gmail or Google Workspace), we first email a code to that address to check that it is yours.
Messages. If you message an owner, we keep your messages, when they were sent, and who took part. Sections 6 and 7 explain who can read them and which details are hidden.
Card payments. You enter your card details on Paysera's payment page, not on bookhome.ge. We never see or keep your full card number or security code. Paysera tells us the order number, amount, currency, status and time of the payment. We keep Paysera's signed notifications as proof of payment.
Crypto payments. We record the network and coin, the amount, our receiving address, the transaction ID and the time. The blockchain also shows the address you paid from. If your payment window ends after you paid, you can tell us on the payment page that you already sent it, and we find your payment ourselves. We send crypto refunds in the coin and on the network you paid with, to an address that you give us and confirm with an email code. Crypto transactions are public (section 5.5).
Refunds and receipts. We record each refund (amount, method and status) and issue receipts for money paid through us.
Bookings an owner records for you.
- If you booked with the owner directly, for example by phone, the owner may enter your name, phone number, email address (optional), the price, the amount you paid, and notes. If the owner enters your email address, you get the booking emails and the welcome guide like any other guest. The owner can also send you a payment link. If the owner gave us no email address for you, the payment page asks for one, and we send your receipts and your booking link there.
- If you booked on Airbnb or Booking.com, we get only the dates of your stay, from those sites' calendar feeds. We never store the event descriptions. The owner may add your name, notes and the price.
- For any booking, the owner can add notes and record money you paid them directly (amount, date, method and a note). An owner can also block you from messaging them.
Affiliate credit. If you booked through an affiliate's link or code, we record which affiliate gets the credit.
3.3 Owners and managers
Your account.
- From Google: your Google account ID, your name, your email address, whether Google has verified it and, for a work or school account, its domain. We never receive your Google password.
- Your interface language, and which version of the owner terms you accepted and when.
- If you were invited: the email address we sent the invitation to, your role, and who invited you.
- If you connect Telegram: your Telegram chat ID. With each message or button press, Telegram also sends us your Telegram user ID and name. We keep each such update, as Telegram sends it, for 30 days. We email you when a Telegram chat is linked to your account.
Your apartments. Everything you enter: texts, facts, amenities, photos, prices, stay rules, discounts and promo codes, the exact address and map pin, check-in and check-out times, the welcome guide, the calendar links you paste from Airbnb and Booking.com, and how guests can pay you directly. For the apartment's contact person: a phone number, and which of WhatsApp, Telegram (with username) and Viber they use.
- When you upload a photo, we remove its hidden data, such as camera details and GPS location.
- The welcome guide keeps Wi-Fi details and door, lockbox and alarm codes in separate fields. We never translate, email or log them, or send them to any other company.
- Before an apartment is published for the first time, an admin reviews it and approves it, or refuses it with a reason. We keep the decision, who made it and the reason.
- Your published apartment page is public, and search engines can index it.
- We automatically check apartment texts for bank details, crypto addresses and web links, so that admins can review listings that may move payments off bookhome.ge.
Verification for online payments. To take card or crypto payments, you give us:
- a photo or scan of your passport or ID card, and your full name as it appears there;
- an IBAN in your own name, and the account holder's name;
- a link to the apartment's listing on Airbnb or Booking.com;
- a USDT wallet address and its network (optional, for crypto payments).
We record our decision, who made it, and our reason if we refuse. If you change your IBAN or wallet, we check it again before we pay out to it.
Money. Payments for your bookings; our fee and any fee rate agreed with you; payouts (amount, currency, date, destination and reference); refunds; amounts owed between us; and money you record as received directly from guests.
Your activity. The bookings you confirm, decline, cancel or create; your messages; the guests you block; the affiliates and promo codes you create; and changes to payout details, members and settings. Section 6.5 explains which actions go into our audit log.
Co-owners. Members of the same apartment can see each other's names and roles. We tell all owners of an apartment when a new owner joins, when an owner removes another owner or makes a manager an owner, when the payout recipient changes, and when payout details change.
3.4 Affiliates
Affiliates never sign in. The owner you work with gives us:
- your name;
- your email address (optional);
- your commission percentage and your code.
We record visits through your link (a random visitor ID, the apartment and the time), the bookings credited to you, your commission, and whether the owner has paid it. The owner pays you outside bookhome.ge. We do not contact affiliates.
3.5 People who contact us
If you email us, we receive your email address, your message and any attachments. Email to bookhome.ge addresses passes through Cloudflare's email routing to [our team mailbox provider].
3.6 What we do not collect
- Guests' passports or ID documents.
- Card numbers or card security codes.
- Your precise location. We use only your IP country.
- Sensitive data, such as data about health or religious beliefs. Please do not put it in messages.
We will never ask for your Google password, your card's security code, or your crypto wallet's recovery phrase or private key.
4. Why we use data, and our legal bases
We use personal data only for the purposes below. Each purpose has a legal basis:
- Contract: we need the data to provide the service you asked for under our owner terms or guest terms, or to take steps you ask for before that.
- Legal obligation: a law requires us to use the data.
- Legitimate interests: we, an owner or another person have a good reason to use the data, and your rights do not override it.
- Consent: you agreed. You can withdraw your consent at any time.
| # | Purpose | Whose data | Legal basis |
|---|---|---|---|
| 1 | Sign-in and accounts | Owners, managers, signed-in guests | Contract |
| 2 | Publishing apartment pages, and translating owners' texts automatically | Owners, managers | Contract |
| 3 | Taking bookings and requests; the private booking page and the welcome guide | Guests | Contract (guest terms) |
| 4 | Giving owners the guest details that the stay needs | Guests | Contract; legitimate interests of the owner |
| 5 | Card and crypto payments, refunds, receipts and payouts | Guests, owners | Contract |
| 6 | Accounting and tax records | Guests, owners, affiliates | Legal obligation |
| 7 | Verifying owners before they take online payments | Owners | Legitimate interests: preventing fraud and payouts to the wrong person |
| 8 | Messages, and hiding contact details until a booking is confirmed | Guests, owners, managers | Contract; legitimate interests: keeping payments on bookhome.ge and preventing fraud |
| 9 | Admins reading conversations and acting as owners | Guests, owners, managers | Legitimate interests: preventing abuse and fraud, and giving support |
| 10 | Country restrictions on bookings and messages | Visitors, guests | Legal obligation or legitimate interests |
| 11 | Stopping spam, fraud and abuse: hidden form fields, limits on repeated attempts, limits on open bookings, checks of listing texts | Everyone | Legitimate interests |
| 12 | Service emails about bookings, payments, messages and account security | Owners, managers, guests | Contract |
| 13 | Telegram notifications | Owners and managers who connect Telegram, and the guest details in the notices | Consent of the owner or manager; legitimate interests for the guest details |
| 14 | Calendar sync with Airbnb and Booking.com | Owners; dates of stays | Contract |
| 15 | Affiliate credit and commissions | Visitors, guests, affiliates, owners | Legitimate interests of owners and affiliates |
| 16 | Reports for owners | Owners, managers | Contract |
| 17 | Security: logs, error alerts, the audit log and backups | Everyone | Legitimate interests; legal obligation to protect personal data |
| 18 | Answering support and privacy requests | Anyone who contacts us | Legitimate interests; legal obligation for privacy requests |
| 19 | Legal claims, and requests from authorities | As needed | Legal obligation; legitimate interests |
Booking emails. We email guests about their booking: the request, the confirmation or decline, receipts, cancellations and refunds, and new messages. Two days before check-in we send a reminder with a link to the welcome guide, and with the address and check-in time. If a guest reached the payment page and the 30-minute hold ran out unpaid, we send one email to say so. Emails never contain Wi-Fi details or door, lockbox or alarm codes. Emails sent before a booking is confirmed contain no phone numbers.
Country restrictions. For legal, payment-provider and fraud reasons, we do not accept bookings or messages from some countries. If your IP country is one of them, the apartment's dates show as unavailable. At checkout, we also check your phone number's country code and your country of residence.
Automatic decisions. Country restrictions, the hidden-field check and the limits on open bookings can refuse a booking or a message automatically. We make no other decisions about you by automatic means alone that have a legal or similarly significant effect on you. If you think a check refused you by mistake, contact us, and a person will look at it.
What you must give us. To book, you must fill in the checkout fields that are not marked optional. Without them, we cannot take your booking. To take online payments, owners must pass verification.
No selling, no ads. We do not sell personal data, and we do not use it for advertising. We do not send marketing emails. If that changes, we will ask for your consent first.
5. Who receives your data
5.1 Owners and managers of the apartment
All owners and managers of an apartment can see its bookings and conversations. They see a booking request only after the guest has confirmed their email address.
- Before a booking is confirmed, they see the guest's first name, country, dates, number of guests, total price and message, with contact details hidden.
- After a booking is confirmed, they also see the guest's full name, email address and phone number.
Owners use guest data to provide the stay. They are responsible for how they use it outside bookhome.ge.
5.2 What guests see about owners
- On the apartment page: the host's first name, and a "Verified owner" badge once the owner has passed verification.
- At payment and on receipts: the owner's name, because we collect the payment on the owner's behalf.
- After a booking is confirmed: the contact person's phone number and messenger links, the exact address, and the welcome guide. The reminder email also gives the address. The guide's "getting in" section opens 24 hours before check-in.
5.3 Companies that help us run bookhome.ge
Cloudflare, Inc. Network, security and storage.
- All traffic to and from bookhome.ge passes through Cloudflare's network. Cloudflare decrypts it and encrypts it again on the way to our server. So Cloudflare processes everything sent to or from the site, including IP addresses.
- Cloudflare tells us each visitor's IP country.
- Cloudflare stores apartment photos, verification documents and our backups (Cloudflare R2). We encrypt the documents and the backups before upload, so Cloudflare cannot read them.
- Email sent to bookhome.ge addresses passes through Cloudflare's email routing.
Hetzner Online GmbH. Hosting.
- Our server, database and logs run at Hetzner, in [Germany or Finland].
[Second-server hosting provider] ([legal entity], [country]). A second route to guest pages.
- Some networks, for example in Russia, cannot reach Cloudflare. For visitors on them, a small server of ours at another hosting provider, outside Cloudflare and Hetzner, serves the apartment pages, checkout, the payment and booking pages, the welcome guide and the public photos. It passes each request on to Cloudflare and our server, and keeps no other data. Messages, sign-in and the dashboards never go through it.
- It receives the connection data of section 3.1 from the visitors who use it, and everything they send or receive on those pages, including booking details. It keeps its access logs, with full IP addresses, for 14 days.
Google. Sign-in and translation.
- Sign-in. Our pages load no Google scripts. The "Sign in with Google" button is our own link to Google, so Google learns nothing about your visit until you use it. When you sign in with Google, Google learns that you signed in to bookhome.ge. Google's own privacy policy applies to your Google account.
- Translation. When an owner saves a text, we send it to Google's Gemini service to translate it into the other two languages. This covers the apartment's summary, description and house rules, the welcome guide's text sections, and how guests can pay the owner directly. It never covers the guide's secret fields or guest messages. These texts can contain personal data, such as a phone number in the guide's emergency contacts.
- We use Gemini's paid tier. Under Google's terms for the paid tier, Google does not use these texts to improve its products, and people at Google do not review them for that purpose.
Paysera ([legal entity], [country]). Card payments.
- Paysera takes card payments and sends refunds. You give your card details to Paysera on its own payment page, under Paysera's privacy policy.
- We send Paysera the order number, amount and currency [and the guest's name and email address].
- [If we send payouts to owners' IBANs from our Paysera account, Paysera also receives the owner's name, IBAN and the amount.]
Telegram ([legal entity], [country]). Notifications.
- If an owner or manager connects Telegram, our bot sends them notices about new bookings and requests, payments, cancellations, messages and payouts. A notice can contain the guest's first name and country, the apartment, the dates, the number of guests, the total, and message text with contact details hidden.
- Our team also receives technical alerts and error alerts in a private Telegram chat. Error alerts leave out email addresses, phone numbers, bank and wallet details and message text, and the chat deletes them after a month.
- Telegram bot chats are not end-to-end encrypted.
Email. We send emails from our own mail server, at [provider, country]. If it fails, we may switch to a backup sending service: [provider, country]. Your own email provider receives the emails we send you.
Error alerts. When something fails on our server, it sends a short alert to our team's private Telegram chat (see Telegram above). The details stay in our server logs. We use no error-tracking service.
Blockchain data services: TronGrid, Tronscan, Toncenter, TonAPI, mempool.space and Blockstream. We read public blockchain data through these services to see crypto payments. We send them our own addresses and transaction IDs, never your name or email address.
OpenStreetMap ([OpenStreetMap Foundation, United Kingdom]). When an apartment page shows its map, your browser loads the map images directly from OpenStreetMap's servers. They see your IP address and that you are on bookhome.ge.
5.4 Airbnb and Booking.com
If an owner connects their Airbnb or Booking.com calendar:
- Airbnb and Booking.com read our calendar feed for that apartment. It contains only unavailable dates, marked "Not available", with no names or other personal data: confirmed bookings, dates the owner closed, and dates read from the other site. Requests and payment holds never appear in it.
- We read their calendar feeds and keep only the dates, an event ID and the event's type (reservation or block). We never store the event descriptions, which can contain guests' phone numbers.
Airbnb and Booking.com do not work for us. Their own privacy policies apply to bookings made on their sites.
5.5 Public blockchains
Crypto payments, refunds and payouts are recorded on public blockchains (TRON, TON and Bitcoin). Anyone can see the sending and receiving addresses, the amount and the time of each transaction. Nobody, including us, can change or delete these records. If someone links an address to you, they may see your other transactions from it. We do not publish which booking a transaction paid for. Owners: payouts to your USDT wallet are public in the same way.
5.6 Others
- Authorities and courts, when the law requires it, or when we must protect someone's rights or safety.
- Our professional advisers, such as lawyers, accountants and auditors, who must keep the data confidential.
- A buyer of our business, if bookhome.ge is sold or merged. The buyer must protect your data as this policy says.
We do not sell personal data.
6. Platform admin access
6.1 Who the admins are
Platform admins are a small number of our staff who run bookhome.ge. We protect admin access:
- admins work on a separate address, admin.bookhome.ge;
- admin.bookhome.ge sits behind Cloudflare Access, and admins must sign in with Google 2-Step Verification;
- an admin session ends after 8 hours at most;
- only an admin can make someone else an admin. We record each change and tell all admins.
6.2 Reading conversations
Admins can open and read any conversation between a guest and an owner. They do this only to prevent abuse, such as fraud, scams, harassment and attempts to take payments outside bookhome.ge.
- Admins see the original messages, including contact details that are hidden from the other side.
- In the admin conversation view, admins can read but cannot write.
- Each time an admin opens a conversation, we record who opened it and when.
- We do not tell guests or owners when an admin opens their conversation.
6.3 Acting as an owner
An admin can act as an owner only to give support, for example to help an owner who asks for it. When an admin does this:
- the admin must give a reason;
- it happens only on admin.bookhome.ge, inside the admin's protected session (section 6.1). The admin never signs in to bookhome.ge as the owner;
- the admin has the owner's rights, but cannot send messages in the owner's name, and cannot change payout details, the payout recipient or members;
- a banner shows the admin that they are acting as the owner;
- we record every page the admin opens and every change the admin makes, with both the admin's ID and the owner's;
- we do not email the owner when the session starts or ends. The audit log keeps the session and the admin's reason, and the owner can ask us for them (section 12);
- the session ends when the admin stops it or signs out, or when the admin's session reaches its 8-hour limit.
While acting as an owner, the admin can see what the owner sees, including guests' details and messages. We record each view of a guest's contact details. We do not tell guests.
6.4 Other admin access
Admins also see all bookings, payments, refunds and payouts. They approve or refuse apartments before their first publishing, review verification requests, suspend owners and apartments, and set country lists and fees. Only admins who check verifications can open verification documents. They see them only in a protected viewer on admin.bookhome.ge, which allows no download, and we record each view. If we suspend an owner's account, our support team runs its existing bookings and writes to their guests as bookhome.ge, never in the owner's name.
6.5 The audit log
Our audit log records:
- every time an admin, or an admin acting as an owner, opens a conversation, a verification document or a guest's contact details;
- every session in which an admin acts as an owner, with its reason;
- every approval or refusal of an apartment, with the reason;
- every money action, such as a refund or a payout;
- every change to an apartment's settings, including its payment settings and cancellation rule;
- every change to payout details, the payout recipient, members, fees, country lists, verification, suspensions and admin rights;
- every export of data.
Our application can add entries to the audit log, but cannot change or delete them. Each entry is linked to the one before it, so a change would show. Every day, a copy goes to separate storage, where entries can be added but not changed or deleted. We keep the audit log and its copy for 5 years. After that, we delete the oldest entries by period, never one by one. You can ask us which entries concern you (section 12).
7. Contact details in messages
To keep bookings and payments safe, we hide contact details until a booking is confirmed.
- Until a guest has a confirmed booking for the apartment, messages in both directions hide phone numbers, email addresses, messenger usernames (such as @name), and WhatsApp, Telegram and Viber links. The other side sees "[shown after booking]" instead.
- Message notifications by email and Telegram hide the same details.
- We store the original text, and hide the details only when we show it. Once the booking is confirmed, both sides see the hidden details, including in earlier messages.
- Platform admins always see the original text (section 6.2).
- Hiding is automatic. It can miss details written in an unusual way, and it does not hide everything: for example, it does not hide bank account numbers. Do not send payment details in messages. Pay through bookhome.ge, or as your booking page explains.
- Before you book, the owner sees only your first name in messages.
- The apartment's phone number, messenger links, exact address and welcome guide also appear only after a booking is confirmed.
8. Cookies
Cookies are small files that a website keeps in your browser. We set only the cookies below, and we send them only over secure connections.
| Cookie | What it does | How long it lasts | Needed for the site to work? |
|---|---|---|---|
| Sign-in | Keeps owners, managers and signed-in guests signed in | 30 days, renewed while you use the site | Yes |
| Sign-in check | Two short cookies, set while you sign in with Google, that check that Google's answer belongs to your sign-in | 15 minutes | Yes |
| Admin sign-in | Keeps admins signed in, on admin.bookhome.ge only. Cloudflare Access also sets its own sign-in cookie there | Up to 8 hours | Yes |
| Form security | Stops other websites from sending forms in your name | Until you close your browser | Yes |
| Booking access | Set when you complete checkout, or open your private booking link or a payment link. It lets this browser open that booking's page. The page address shows only the booking reference, which is not secret, so the address alone gives no access | Until 30 days after check-out, or until you use "Sign out other devices" on another device | Yes |
| Language | Remembers the language you chose on this device | 1 year | Yes |
| Device ID | Holds a random ID, so that we can limit the open bookings and requests made from one device (section 3.2). It holds nothing else | 30 days | Yes |
| Affiliate visitor ID | Holds a random ID, so that the affiliate whose link you used gets credit if you book. It holds nothing else | 30 days | No |
Cloudflare may also set its own security cookies on bookhome.ge, for example after a security check.
We do not use analytics, advertising or social-media cookies. Private booking pages load no scripts from other companies. No page loads scripts from Google.
Cookie banner. We do not show a cookie banner. We use only cookies that the site needs to work, plus the affiliate cookie, which holds only a random ID and is used only to credit affiliates.
Your choices. You can delete or block cookies in your browser settings. If you block the cookies that the site needs, you cannot sign in or open your booking page in that browser. If you delete the affiliate cookie, no affiliate gets credit for your booking.
9. How long we keep data
We keep personal data only as long as we need it for the purposes in section 4, or as long as the law requires. Then we delete it or anonymize it. To anonymize means to remove or replace everything that identifies you, so that what remains, such as dates and amounts, can no longer be linked to you.
| Data | How long we keep it |
|---|---|
| Server logs, including our second server's access logs: the only places where we keep full IP addresses | 14 days |
| Error alerts in our team's Telegram chat | 30 days |
| IP country, kept with a booking | 90 days |
| Hashed IP addresses, for the limits on open bookings and requests | 30 days |
| Device-ID cookie | 30 days |
| Guest details on a booking: name, email, phone, country of residence, arrival time, message to the owner, and the owner's notes and added names | Anonymized [N] months after check-out |
| Payments, refunds, payouts, fees and receipts | [N] years, as accounting and tax law requires |
| Paysera's payment notifications, and the blockchain data of each crypto transfer we receive | 5 years, or longer if accounting law requires it for the payment records |
| Messages | 2 years after the last message in the conversation |
| Verification documents (passport or ID card) | Deleted 30 days after our decision. We keep the decision, the reviewer and any reason for refusal for [period]. |
| IBANs and USDT wallets | While they are your payout destination. After a change, [period] with the payout records. |
| Owner and manager accounts | While the account is open; anonymized 90 days after it is closed, except records we must keep longer |
| Apartment content and photos | While the apartment is on bookhome.ge; [period] after the owner deletes it |
| Imported calendar dates | [period], for the calendar and owner reports. Event descriptions are never stored. |
| Affiliate details and commissions | While the owner keeps the affiliate; commission records for [N] years (accounting) |
| Affiliate visits (random visitor ID, apartment, time) | 90 days after the visit |
| Telegram link | Until you disconnect Telegram or close your account |
| Telegram updates: messages and button presses sent to our bot | 30 days |
| Invitations | Valid for 7 days; deleted 30 days after they expire |
| Emails and Telegram notices we send | The content for 90 days. After that we keep only which notice it was, the recipient, the time and whether it was delivered: as long as the booking it belongs to, or 1 year if it belongs to no booking |
| Audit log, and its copy on separate storage | 5 years, then deleted by period |
| Backups | Taken every 15 minutes, encrypted, and each kept for 12 weeks |
| Emails to our support and privacy addresses | [period] |
Backups. Data we delete or anonymize stays in backups until those backups expire, at most 12 weeks later. We use backups only to recover from failures and to practise recovery (section 10). If we restore a backup, we delete again any data that was deleted after that backup was taken.
Longer periods. If the law requires us to keep data longer, or we need it for a legal claim, we keep it until that need ends.
Other companies keep the data they receive under their own policies (section 5). Blockchain records are permanent.
10. How we protect data
- Encrypted connections. All connections use HTTPS with modern encryption (TLS 1.2 or newer), and browsers are told to use HTTPS only.
- Extra encryption for the most sensitive data. Our application encrypts IBANs and wallet addresses before it stores them. It also encrypts verification documents before it uploads them to private storage, so the storage provider cannot read them. Each of these records has its own key. Those keys are locked with a master key that is kept apart from the database and from our backups, so a copy of the database or of a backup alone cannot unlock them. We replace the master key every year, and after any security incident. Backups are encrypted.
- A locked server. Our server has no ports open to the internet. It can be reached only through an encrypted tunnel from Cloudflare. It refuses any request without a secret that only Cloudflare adds. Our second server (section 5.3) holds no data and reaches our server only through Cloudflare, like any visitor.
- Access control. Owners and managers see only their own apartments, and managers see no payout data. Guests see only their own bookings and conversations. We check every request against the user's rights. Admins need a second sign-in factor and have short sessions. We record admin access to conversations, verification documents and guest contact details, and every money action (section 6).
- Secret links. Booking, guide, payment and invitation links contain long random codes. We store only a hash (a one-way scrambled form) of each code. Private pages are not shown to search engines or kept in shared caches. Links expire:
- a booking link, 30 days after check-out or when a newer link replaces it (section 3.2);
- a payment link, at check-in, when the owner sends a newer one, or when the booking is cancelled;
- a guide link that an owner copies for an Airbnb, Booking.com or manual-booking guest, 30 days after that booking's check-out, or when the owner replaces it;
- an invitation link, after one use or 7 days;
- a link made with "Copy link" to move to another browser, after one use or 30 minutes.
- Less data. We do not collect guests' IDs or card numbers. We remove hidden data from photos. The public map shows only an approximate location, up to 300 metres from the apartment. Wi-Fi details and door, lockbox and alarm codes are never emailed, translated, logged or sent to any other company.
- Careful logging. Our logs hide email addresses, phone numbers, IBANs, wallet addresses and message text, and leave out secret codes. We remove personal data from error alerts as far as we can. We never log payment notifications, messages or welcome-guide text.
- Crypto. The private keys to our crypto wallets are never on a server.
- Testing. Our test systems use made-up data.
- Checks. We test the system's security before launch, and we practise restoring from backups. A practice restore uses a real backup, on a temporary, isolated Hetzner Cloud server that sends no emails or messages. We delete that server and its data the same day.
No system is completely secure. If a security breach puts your data at risk, we will tell you and the authorities as the law requires.
11. Transfers outside Georgia
We are based in Georgia. Some of the companies in section 5 process data in other countries:
| Company | Where the data goes |
|---|---|
| Hetzner | [Germany or Finland] |
| Second server for networks that cannot reach Cloudflare | [country] |
| Cloudflare | Its global network. Cloudflare, Inc. is a US company. Storage: [R2 location] |
| [USA and other countries] | |
| Paysera | [country] |
| Telegram | [country] |
| OpenStreetMap | [United Kingdom] |
| Backup email service, used only if our mail server fails | [country] |
| Blockchain data services and public blockchains | Worldwide |
12. Your rights
12.1 What you can ask for
You have the right to:
- know whether we use your data, and get a copy of it;
- have wrong or incomplete data corrected;
- have your data deleted;
- have the use of your data restricted (blocked);
- object to our use of your data based on legitimate interests;
- get the data you gave us in a common electronic format, or have it sent to another company;
- withdraw your consent at any time, where we rely on consent (for example for Telegram notifications). This does not affect what we did before;
- have a person review a decision that was made automatically (section 4);
- complain to, or go to court.
12.2 How to ask
- Email [privacy@bookhome.ge] from the email address on your booking or account, or write to the address in section 2.
- Tell us what you want and, if you know, which booking or account it concerns.
- We may ask you to confirm who you are, for example by signing in with Google or by entering a code that we email you. We will not ask for more than we need.
- We answer within [N] days. We do not charge for this.
You can also do some things yourself. Owners and managers can change their profile and apartment details in the dashboard, and can disconnect Telegram at any time. Guests can find their bookings with Find my booking, and can cancel a booking from their booking page.
12.3 Limits
- We may have to keep some data even if you ask us to delete it, for example payment records that accounting and tax law require, or data we need for a legal claim. If so, we tell you what we keep and why.
- We cannot change or delete blockchain records.
- Owners who received guest data keep their own copy. To have it deleted, ask the owner too.
- We can close an owner account only after its bookings, refunds and payouts are settled.
- Our application cannot delete single audit-log entries. We delete them only by age, after 5 years.
- If an owner gave us your details, for example as an affiliate or as the guest of a booking made by phone, you can contact us or the owner.
- For data that Airbnb or Booking.com hold, contact them.
13. Children
bookhome.ge is for adults. You must be at least [18] years old to create an account or make a booking. For children who stay, we ask only how many there are, not their names or ages. If we learn that a child has given us personal data, we delete it.
14. Changes to this policy
We may change this policy, for example when we add features or when the law changes. The date at the top shows the latest version. Before an important change takes effect, we tell owners, managers and signed-in guests by email [and show a notice on the site]. We keep earlier versions, and we send them on request.
15. Contact us
For any question about this policy or your data, contact:
- Geniuses Recruiting LLC, Paliashvili St., Tbilisi, Georgia
- Email: [privacy@bookhome.ge]
- Personal-data protection officer: [name and contact, if one is appointed]
- Supervisory authority: