Privacy Policy

Last updated: 4 September 2026

mik.rent is the guest booking site of MIKstay. It is operated by TheGarage SHPK, a company registered in Albania ("we", "us"). When you book a stay on mik.rent, you book it from the host who lists the place; we run the site the booking happens on and the tools the host uses to manage it.

That gives two roles. For the data mik.rent itself collects — the pages you visit, the cookies you accept, the account-free booking you make — we are the data controller. For the details of your stay once they reach your host (your name, contact details, dates, requests, documents), the host is the controller and we process them on the host's behalf. This policy explains both, and the rights you have under the EU General Data Protection Regulation and comparable laws.

1. What we collect when you book

Booking details: your name, email address, phone number, country of residence, the dates and the number of guests, an estimated arrival time and anything you write in "special requests".

Pre-arrival details, if your host asks for them: date of birth, nationality, and the type, number and issuing country of an identity document. Many countries require hosts to register every guest with the local authorities; these are the details that registration needs. Some hosts also ask you to upload a photo of the document.

Payment details: entered on the payment page of the host's payment provider (for example a card acquirer or a bank-transfer instruction). We receive confirmation that a payment happened and its amount. We never see or store full card numbers.

Messages: what you and your host write to each other through mik.rent, by email, SMS, WhatsApp or a booking site, so that the conversation stays in one place for both of you.

Reviews: the rating and text you leave after a stay, together with your first name and country.

Technical data: log events, request identifiers, device and browser information, and the cookies described in our Cookie Policy. We use a bot-protection check on the booking form.

2. Why we process it

  • To make and manage your booking, which is a contract between you and the host: confirmations, changes, cancellations, payments and check-in.
  • To let the host meet legal duties, such as guest registration with the authorities and tax records.
  • To keep the site secure and working, and to prevent fraud and abuse — our legitimate interest.
  • To send the emails a booking needs: confirmation, payment, pre-arrival details, and one request for a review after your stay. You can opt out of review requests from any such email.
  • With your consent, for non-essential cookies. You can withdraw it at any time.

3. Who sees your data

Your host, and the people your host has invited to work in their MIKstay account (for example a cleaner who sees arrival dates but not payment details).

The host's payment provider, to take your payment.

Booking sites, when your stay came from one of them: the site that holds your reservation keeps its own copy under its own policy.

Our service providers, each under a data-processing agreement: Neon (database hosting, EU region), Cloudflare (hosting, content delivery and file storage), Resend (email), Twilio (SMS and WhatsApp, where enabled), NextPax (connection to booking sites, where a host uses it), Anthropic (AI features such as message drafting and translation, on the host's request).

Local authorities, where the law requires the host to register guests. That transfer is made by the host, not by us.

We do not sell your data and we do not use it for advertising.

4. International transfers

We keep EU personal data in EU regions wherever we can. Where a provider transfers data outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses.

5. How long we keep it

Booking records are kept by your host for as long as accounting and tax law require; personal fields are anonymised when the host erases you as a guest.

Identity-document details and uploads are kept for the shortest period the host's legal duties allow and expire automatically.

Pre-arrival links expire two weeks after check-out. Review links can be used once.

Technical logs are kept for a limited period for security and troubleshooting.

6. Your rights

Subject to applicable law, you may ask for access to your data, a copy of it, correction, erasure, restriction of or objection to certain processing, and to withdraw consent where processing is based on it.

For the details of a stay, contact the host who manages your booking: they are the controller and can act directly. For anything about mik.rent itself, or if a host does not respond, write to privacy@mikstay.com and we will help. You also have the right to lodge a complaint with your local data-protection authority.

7. Security

Each host's data is isolated at the database level. Credentials are encrypted at rest, sensitive documents are served through short-lived signed links, and administrative actions are recorded in an append-only audit log.

8. Changes and contact

We may update this policy; the date at the top says when. Questions: privacy@mikstay.com.