Privacy Policy
At EASON STAYS LTD ("Eason Stays", "we", "us") we are committed to protecting and respecting your privacy. This policy, together with our Website Terms of Use (www.easonproperty.com), explains how we process personal data we collect from you or that you give us when you use our website, book with us, complete our online check-in, stay with us, or contact us by phone, email or online. It explains how we use that data, when we may share it, how long we keep it and how we keep it secure.
Who are we?
We are EASON STAYS LTD, a serviced apartment booking agent registered in England and Wales (company number 14585242). Our head office is 45 Highmeadow, Radcliffe, Manchester, England, M26 1YN.
We are the data controller for the personal data described in this policy, and we are registered with the Information Commissioner's Office (www.ico.org.uk) under registration number ZB500213.
Our Data Protection Officer is Jay Jackman. Email compliance@easonproperty.com, phone (+44) 0161 524 9717, or write to the address above.
How do we collect information from you?
We collect information when you:
- use our website or contact us by phone, email or online about our services;
- make a booking with us directly or through a booking platform such as Airbnb or Booking.com;
- complete our online check-in form before you arrive;
- stay with us, or buy extras such as early check-in or late checkout;
- sign up to our newsletter or email updates.
If your employer, an insurer or someone else books or pays for your stay, we may receive your details from them rather than from you.
What information do we collect?
We only ask for what we need to handle your enquiry, booking and stay.
- Contact and booking details: your name, email address, phone number, address, the property and dates booked, number of guests, arrival time, and any requests (for example a cot or high chair). We may also ask for the names of other adult guests.
- Check-in details: the answers you give on our online check-in form (your expected arrival time, the reason for your visit, whether you are likely to extend your stay and, where the property has parking, your vehicle registration for a parking permit), your agreement to the house rules, and a signature. If you complete the form on someone else's behalf, we also collect your name and email address as the booker.
- Identity documents: a photo of your passport, driving licence or national ID card, and (if you agree) a selfie. See "Identity checks" below.
- Guest record: the details the law requires hotels and similar accommodation to record. See "Our legal guest record" below.
- Payment details: when you pay a deposit, damage waiver, or for extras, your card is taken by our payment provider Stripe. We never see or store your full card number.
- Deposit and damage records: whether a deposit was held and returned, and, if there was damage, what was charged and photos of the damage to the property.
- Messages: what you send us and we send you through the booking platforms, email, phone or WhatsApp.
- Website and check-in usage: technical information such as your IP address, browser and pages visited. See "Cookies and analytics" below.
Identity checks
Because our properties are self check-in, we check that the person arriving is the person who booked. On the check-in form we ask the lead guest for:
- A photo of an identity document. Amazon Web Services (AWS) reads the name, date of birth, expiry date and, for passports and ID cards, the machine-readable strip. We use this to confirm the name matches the booking and the document is in date.
- A selfie, only if you agree. With your explicit consent, AWS compares your selfie with the photo on your document. Your face is turned into a set of measurements (biometric data) for that one comparison. AWS does this in London on our instructions and does not use your images to improve its own services. We store only the result, such as the match score.
- If you would rather not use facial recognition, choose "Verify manually instead" on the form. You upload your ID photo only, and a member of our team checks it by eye before your arrival.
No decision is made by the computer alone. If the check does not pass cleanly, a member of our team reviews it and contacts you if needed. Until your identity is confirmed we may hold back your arrival instructions.
Only our team can see your ID photo, selfie and signature. They are kept in private storage in London and deleted automatically 90 days after your stay ends.
Our legal guest record
The Immigration (Hotel Records) Order 1972 requires accommodation providers to keep a record of guests. For the lead guest we record:
- full name, nationality and date of arrival;
- if you are not a British or Irish citizen: your passport (or national ID card) number and where it was issued, and your next destination when you leave.
We read the document details from your ID photo where we can, so you do not have to type them. We keep this record for 12 months after your stay, then delete the nationality, document details and next destination. We never record passport numbers for British or Irish guests.
How is your information used?
We use your information to:
- take and manage your booking, and send your arrival details, door code and property guide;
- confirm your identity before arrival, to prevent fraud and protect our properties;
- keep the guest record the law requires;
- take payments, hold and return deposits, and deal with any damage;
- provide extras you ask for, such as early check-in or late checkout;
- answer your questions and keep in touch during your stay;
- keep our accounts and meet tax and legal duties;
- improve our website and check-in (using figures that do not identify you);
- send you marketing, only if you have agreed or are an existing customer who has not opted out.
Our lawful bases
The law requires a reason (a "lawful basis") for each use of your data. Ours are:
What we do | Lawful basis |
|---|---|
Take and manage your booking and stay, extras and payments | Contract: needed to provide what you booked |
Legal guest record (name, nationality, arrival date; document details and next destination for non-British and non-Irish guests) | Legal obligation: Immigration (Hotel Records) Order 1972 |
Check your ID photo and name against the booking | Legitimate interests: preventing fraud and protecting our properties, which are accessed without staff present |
Compare your selfie with your ID (facial recognition) | Your explicit consent. You can refuse and verify manually instead, and withdraw consent at any time |
Hold and settle deposits, charge for damage | Contract, and our legitimate interest in recovering the cost of damage |
Accounts and tax records | Legal obligation |
Website and check-in analytics | Legitimate interests: understanding where the check-in form goes wrong so we can fix it |
Marketing emails | Your consent, or for existing customers our legitimate interest (you can opt out at any time) |
Where we rely on legitimate interests we have weighed them against your rights and kept the data to what is needed. You can object at any time (see "Your rights").
How long do we keep your information?
We keep your information only as long as we need it, then delete it. Deletion of ID images and the guest record is automatic.
Information | How long we keep it |
|---|---|
ID photo, selfie and signature | 90 days after your stay ends, then deleted automatically |
Date of birth read from your ID | 90 days after your stay ends |
Legal guest record (nationality, document number and place of issue, next destination) | 12 months after your stay ends, then deleted. Your booking itself is kept (next row) |
Booking, payment, deposit and damage records | Up to 6 years after your last booking, for accounts and HMRC |
Unfinished check-in forms and their uploads | Deleted automatically 14 days after upload |
Marketing list | Until you unsubscribe |
If you ask us to delete your data, we will, except what we must keep by law or to establish, exercise or defend a legal claim. We will tell you if that applies. We review these periods regularly.
Who has access to your information?
We will not sell or rent your information, and we will not share it with others for their own marketing.
The property and its team. When you book, the people who clean and look after your property receive what they need to prepare for your stay, such as your name and dates.
Our service providers. We use the companies below to run our business. They act on our instructions, under contracts that require them to keep your data secure and not use it for their own purposes.
Provider | What they do for us | Where they process data |
|---|---|---|
Booking system and guest messaging | UK and Ireland (some support staff in the USA) | |
Vercel | Hosts our website, check-in form and private file storage | London (web servers since 29 September 2026; ID photos stored in London) |
Neon | Main database for bookings and check-ins | London (since 29 September 2026) |
Amazon Web Services | Reads ID documents and runs the facial-recognition check | London |
Stripe | Card payments, deposits and refunds | USA and Ireland |
Customer records and marketing emails (name, email, phone; never ID images) | USA | |
Email, spreadsheets used by our team, and website analytics | USA and elsewhere | |
Slack | Internal team alerts about bookings and check-ins | USA |
Asana | Internal team tasks for stays | USA |
PostHog | Check-in analytics that do not identify you | EU |
Upstash | Short-lived booking cache | London |
Airbnb, Booking.com and other booking channels are independent controllers of the data you give them on their platforms, not our processors.
Other disclosures. We may disclose your information if the law requires it (for example to the police or immigration authorities, or under a court order), to prevent fraud or crime, to establish or defend a legal claim, or if we sell or merge our business.
Transferring your information outside the UK
Your check-in data is stored in the UK: our main database, the servers that run our check-in form, your ID photos and selfies, and our booking cache are all in London. Some providers are themselves based outside the UK, mainly in the USA and the European Economic Area (EEA): Stripe, Slack, GoHighLevel, Google, Clerk (our staff login), Asana, and some of Uplisting's own sub-processors. Where they receive your data, it is protected by the UK-US data bridge or the UK International Data Transfer Agreement or Addendum.
We only transfer your data outside the UK with one of these protections in place:
- EEA countries are covered by UK adequacy regulations, so your data has equivalent protection there.
- US providers certified under the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge") are covered by UK adequacy regulations.
- Otherwise, we use the International Data Transfer Addendum or International Data Transfer Agreement approved by the Information Commissioner, built into our providers' contracts.
You can ask us for details of the protection that applies to a particular provider.
Children's personal data
You must be over 18 to book with EASON STAYS LTD. If children are travelling with you, we may ask their ages, but we do not need their personal details and you will never be asked for them. We may ask simple questions about your needs, for example whether you need a cot or high chair.
Social media
We are active on social media and use it to share news, stories and offers. If we run a competition or you contact us there, we use your details only as needed to reply or run the competition, based on our legitimate interests, and in line with this policy.
Your choices
We will not send you marketing by email, phone or text unless you have agreed, or you are an existing customer and have not opted out. Every marketing email has an unsubscribe link. You can change your preferences at any time by emailing compliance@easonproperty.com or calling (+44) 0161 524 9717.
Your rights
You have the right to:
- ask for a copy of the information we hold about you;
- ask us to correct information that is wrong or out of date;
- ask us to delete your information;
- ask us to restrict how we use it, or object to our use of it (including where we rely on legitimate interests);
- ask us to transfer information you gave us to another organisation, where we use it under a contract or your consent;
- withdraw your consent to facial recognition at any time. This does not affect checks already made. If you withdraw before your stay, we will check your ID by hand instead.
To use any of these rights, email compliance@easonproperty.com, call (+44) 0161 524 9717, or write to EASON STAYS LTD, 45 Highmeadow, Radcliffe, Manchester, England, M26 1YN. We reply within one month and do not charge. Some information we must keep by law (for example the guest record and accounts); we will tell you if that applies.
Security of your information
We protect your data with:
- Private storage. ID photos, selfies and signatures are stored in a private store in London. They cannot be opened from a web link; only signed-in members of our team can view them.
- Team-only access. Our admin system can only be used by verified members of our team; nobody else can create an account.
- Encryption in transit. Our website and check-in form use HTTPS, and card details go straight to Stripe.
- Automatic deletion on the timetable above.
No system is perfectly secure, but we take every reasonable step to protect your information. If a breach puts your rights at risk, we will tell you and the Information Commissioner as the law requires.
The Information Commissioner's Office
If you are unhappy with how we handle your data, please contact us first. You also have the right to complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/
Changes to this policy
We will post any changes on this page. Last updated: 30 September 2026.
Cookies and analytics
Cookies are small text files a website saves on your device.
Our website, www.easonproperty.com, uses cookies: some are needed for the site to work, and others come from Google (analytics and advertising), Meta (advertising) and our website chat provider. You can manage them through our cookie banner or your browser settings. Our Cookie Policy lists each cookie and what it does.
On our check-in form and guest portal we use PostHog, hosted in the EU, to see where guests get stuck so we can fix it. We do not record your screen, capture what you type, or link this data to your name, and booking links are removed before any data is sent. It sets no cookies and stores nothing on your device; visitors are counted with a daily-changing code that cannot identify you.
You can control cookies in your browser settings. To opt out of Google Analytics, visit https://tools.google.com/dlpage/gaoptout. For more on cookies, see www.allaboutcookies.org.