Skip to content
EZ2Stay is in closed beta. We're onboarding hostels by invitation while we finish the platform for public launch — you can request access from the signup form.

Subprocessors

Who processes data, and on whose behalf

Some vendors below run on EZ2Stay's own account and serve every hostel on the platform ("platform-wide"). Others run on a vendor account that each hostel opens and pays for itself — EZ2Stay's software calls that account's API using the credentials the hostel entered, but the hostel is the one with the contract and the data-protection relationship with that vendor ("per-hostel"). The signed Data Processing Agreement for your account is the authoritative reference where this page and the DPA differ.

NamePurposeData categoriesRegionPlatform-wide or per-hostel
SupabaseDatabase, authentication, and file storageGuest and account data, credentials, encrypted secretsEU (Frankfurt)Platform-wide
VercelWeb hosting for the platform and marketing siteRequest/traffic data, server logsEU (Frankfurt, region fra1)Platform-wide
HetznerAPI hosting (from September 2026)Request/traffic data, server logsEU (Germany)Platform-wide
CloudflareEdge network / tunnel in front of the API today, and DNSRequest metadata (no guest content)Global network, EU-adjacentPlatform-wide
SendGridTransactional email to guests (check-in links, confirmations, guidebook)Guest email address, message contentUS/GlobalPlatform-wide
StripeCard payments and payment statusPayment status and metadata — EZ2Stay does not store full card numbers; card data is handled by StripeEU/USPer-hostel — each hostel connects its own Stripe account
DiditID document verification and selfie match, on Didit's own hosted pageID document images, biometric selfiesEUPer-hostel, and NOT an EZ2Stay subprocessor: each hostel holds its own Didit account and contract, so Didit processes on the hostel's own instructions, not EZ2Stay's
Beds24Channel manager and PMS sync — bookings and availability from Booking.com, Airbnb, Expedia and directBooking details, guest contact infoDepends on the hostel's own Beds24 accountPer-hostel — each hostel connects its own Beds24 account
SmartBillFiscal invoicing and e-Factura, in beta for RomaniaGuest/company billing detailsRomania (EU)Per-hostel — each hostel connects its own SmartBill account
sms-gate.appSMS relayed through the hostel's own Android phone and SIMGuest phone number, SMS contentPer-hostel phone, wherever it is locatedPer-hostel — nothing is shared with other properties on the platform
Meta Platforms (WhatsApp), via a linked deviceGuest messaging over the hostel's own WhatsApp Business number (linked-device relay)Guest phone number, message contentGlobalPer-hostel — the hostel's own WhatsApp number; EZ2Stay relays messages, it does not operate a shared WhatsApp account
TwilioSMS/WhatsApp messaging and phone verification (OTP) — optionalGuest phone number, message contentUS/GlobalPer-hostel, optional — only where a hostel configures it; not the default SMS or WhatsApp channel
AnthropicAI concierge — answering guest questions — optional, opt-in per hostelGuest messages/questions only; no ID documents or biometric images are ever sent (redacted before the request is built)US/GlobalPer-hostel, optional — only when a hostel enables the AI concierge

Keeping this list current

This list is updated before a new platform-wide subprocessor is added, not after. Customers are notified of subprocessor changes via this page; material changes are also reflected in the DPA's next review.

This is a general list, not a substitute for your contract

This page describes EZ2Stay's general subprocessor practices and is not legal advice. The signed Data Processing Agreement for your account is the governing reference for subprocessor terms.

Contact

Questions about a subprocessor, or to request notice of changes directly: contact@ez2stay.com.