Privacy Policy
Last updated: 1 August 2026
This Privacy Policy describes how SMN Properties OÜ ("we", "us") processes personal data when you use Simple Guests (a brand of SMN Properties OÜ). We provide guest registration and police-compliance software to accommodation providers in the European Union.
1. Roles
Staff users (your team) — we are the controller for account, billing, and support data.
Guest data (ID scans, registration forms, signatures) — your organization is the controller; we process on your instructions to run check-in and compliance submission.
2. Data we collect
- Account data: name, work email, role, organization name, billing selections, Stripe customer references.
- Guest check-in data: identity fields from MRZ/OCR or manual entry, document images, signature, booking metadata, timestamps — as required by your jurisdiction pack.
- Technical data: logs (request IDs, errors), IP-derived region for security, email delivery events.
3. How we use data
To provide the service, calculate usage billing, send transactional email (verification, login links, payment confirmations), submit data to authorities you configure, and improve reliability. We do not sell personal data.
4. Storage, encryption, and location
- Infrastructure is hosted in EU AWS regions (currently eu-west-1). Customer data is not intentionally transferred outside the EU except where you configure third-party integrations (e.g. Stripe, Postmark, PMS/messaging providers) under their own terms.
- Document images are stored in private object storage with access controlled by your tenant context; uploads use short-lived presigned URLs.
- Authority credentials, where an authority requires them (e.g. SES/Mossos passwords — some authorities, like France's fiche individuelle de police, require none), are protected with AES-256-GCM envelope encryption before being written to the database; plaintext secrets are not stored in application logs.
- Data in transit uses TLS. Database and disk encryption are provided by our cloud providers.
5. Retention
We retain guest and compliance records according to your jurisdiction requirements and configured retention jobs. Account data is kept while your subscription is active and for a limited period afterward for legal and billing obligations. You may request deletion subject to statutory retention minimums.
6. Sub-processors
We use vetted providers including AWS (hosting), Neon or equivalent (database), Stripe (payments), Postmark (email), and optional integration partners you enable (PMS, WhatsApp, SMS). A data processing agreement is available on request for business customers.
7. Your rights
Under GDPR, individuals may request access, rectification, erasure, restriction, portability, or objection. Staff users can contact us directly; guest requests should normally be directed to the accommodation provider (controller). Contact: hello@simpleguests.com. You may lodge a complaint with your local supervisory authority.
8. Security
We apply tenant isolation, least-privilege access, encrypted credentials, and audit logging for sensitive operations. No system is perfectly secure; report suspected incidents promptly.
See also our Terms of Service.