Privacy Policy
We keep the amount of personal data we hold about you deliberately small. This policy explains, in plain language, what Hostsyro collects, why, on what legal basis, and how you can see, export or delete it. It is written to meet the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act.
Last updated: 31 July 2026
1. Who is responsible for your data
The data controller is Hostsyro, a business established in Denmark (EU). You can reach us for any privacy matter at admin@hostsyro.com. We are not required to appoint a Data Protection Officer; privacy requests are handled directly by the operator.
2. What we collect
If you only browse: we do not require an account and we do not ask for your name or email. Our server processes technical request data (IP address, user agent, requested URL, timestamp) in short-lived logs needed to serve pages and defend against abuse.
If you create an account:
- your email address and an encrypted password hash (or, if you use Google sign-in, your Google account identifier, email and — if you allow it — your name and profile picture);
- your display name, and optionally a short bio and a profile picture you upload;
- reviews you write (rating, title, text, recommendation, and the moderation status), and which hosts you have saved;
- authentication metadata such as sign-in timestamps, and whether two-factor authentication is enabled;
- any emails you send us and our replies.
Cookies and similar technologies: essential cookies and local storage for sign-in, security, your theme choice and your cookie decision; and — only with your consent — analytics and advertising identifiers. See the cookie policy.
We do not knowingly collect special categories of data (health, political opinions, biometrics), and we ask you not to put such information in reviews or your bio. Payment card data is never collected — we do not sell anything.
3. Why we use it, and our legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your member account | Email, password hash, display name, avatar, bio | Contract — Art. 6(1)(b) |
| Publish your reviews and saved hosts | Review content, ratings, moderation status | Contract — Art. 6(1)(b) |
| Moderate content, prevent fake reviews, fraud and abuse | Account and review metadata, technical logs | Legitimate interests — Art. 6(1)(f) |
| Keep the site secure and available | Technical request logs, auth events | Legitimate interests — Art. 6(1)(f) |
| Service emails (confirmation, password reset, moderation outcome) | Email address | Contract — Art. 6(1)(b) |
| Analytics about how the site and guides are used | Analytics identifiers, page views | Consent — Art. 6(1)(a) |
| Showing and measuring advertising | Advertising cookies/identifiers set by our ad partners | Consent — Art. 6(1)(a) |
| Answering your emails and legal requests | Correspondence | Legitimate interests / legal obligation — Art. 6(1)(f)/(c) |
We do not use your data for automated decision-making that has legal effects on you, and we do not profile you to build advertising audiences ourselves.
4. What is publicly visible
When a review of yours is approved, your display name, profile picture, bio, rating and review text become publicly visible on the host's page and may appear in search engine results and link previews. Your email address is never shown publicly. You can change your display name at any time, or delete a review to remove it from public view.
5. Who we share data with (processors)
We do not sell your personal data and we do not share it with hosting companies. We use a small number of service providers who process data on our instructions under Art. 28 data processing agreements:
- Supabase — application hosting, database, authentication and file storage for your profile picture.
- Cloudflare — content delivery, DNS and protection against attacks.
- Google — Google Sign-In (only if you choose it) and, subject to your consent, Google Analytics.
- aads.com — the advertising network whose ad code we embed, which only loads after you consent to advertising cookies.
- Public registry lookups (RDAP/WHOIS) when you use the domain availability tool: the domain you type is sent to the responsible registry. Do not enter personal information there.
We may also disclose data where we are legally required to (for example a valid order from a Danish authority or court).
6. International transfers
Our infrastructure is chosen to keep data within the EU/EEA where possible. Some processors (notably Google and Cloudflare) are US-based or operate global networks, so data may be transferred outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with technical measures such as encryption in transit. You can request more detail about a specific transfer at admin@hostsyro.com.
7. How long we keep it
- Account data (email, profile, saved hosts): for as long as your account exists. Deleting your account removes it immediately.
- Reviews: until you delete them or delete your account. Rejected reviews are removed within 90 days of the decision.
- Profile pictures: deleted together with your account.
- Technical and security logs: typically up to 30 days, longer only where needed to investigate a specific abuse or security incident.
- Email correspondence: up to 24 months.
- Your cookie decision: 12 months, then we ask again.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15) — use Download my data in your account settings for an instant machine-readable export.
- Rectification of inaccurate data (Art. 16) — edit your profile and reviews directly.
- Erasure (Art. 17) — use Delete my account in your account settings, which removes your profile, reviews, saved hosts and picture.
- Data portability (Art. 20) — the JSON export is provided for exactly this purpose.
- Restriction and objection (Art. 18 and 21), including objecting to processing based on our legitimate interests.
- Withdraw consent at any time (Art. 7(3)) for analytics and advertising cookies, without affecting anything done before withdrawal.
Email admin@hostsyro.com to exercise any right we cannot serve self-service. We answer within one month, as required by Art. 12(3). Using these rights is free, and we will never restrict your access to the site for using them.
9. Complaints
If you think we have handled your data incorrectly, please tell us first so we can fix it. You also have the right to complain to the Danish Data Protection Agency, Datatilsynet (Carl Jacobsens Vej 35, 2500 Valby, Denmark), or to the supervisory authority in your own EU/EEA country of residence.
10. Security
Data is transmitted over HTTPS, passwords are stored only as salted hashes, database access is restricted by row-level security policies so members can only read their own data, and optional two-factor authentication (TOTP) is available to every member and required for staff accounts. If a personal data breach ever poses a risk to you, we will notify Datatilsynet within 72 hours and inform you where the law requires it.
11. Children
The site is not directed at children. You must be at least 16 to create an account. If you believe a child has created an account, contact admin@hostsyro.com and we will remove it.
12. Changes to this policy
We update this policy when our processing changes. The date at the top always reflects the current version, and material changes affecting account holders are announced by email or in-app notice before they take effect.
Questions about this page? Email admin@hostsyro.com. These pages describe how Hostsyro actually operates; they are not legal advice.