Skip to content

Security & data protection

EZ2Stay handles ID documents, selfies, and payment references for every guest who checks in without a front desk. Here's exactly what's encrypted, what's deleted, when, and who can see it.

Encryption

Secrets and PII are encrypted with AES-256-GCM. This covers stored credentials and personally identifiable guest data, both at rest and in transit over encrypted connections.

Biometric data (selfies)

A guest's selfie is collected only with explicit consent, asked at check-in before anything is stored. Refusing the selfie doesn't block check-in outright — it flags the booking for manual identity verification another way.

Selfies are deleted ≤30 days after checkout — this limit is not configurable by the hostel owner. Biometric data is stored separately from other guest records, with restricted access and its own audit trail, and it is never exportable through any API, including admin tools.

ID documents

Photographed ID documents (passport or EU ID card) are kept 90 days by default. The hostel owner can adjust this retention window in settings — biometric data cannot be adjusted the same way, since its 30-day limit is fixed by design.

Access & authentication

Access to guest data is role-based: staff accounts see only what their role requires, not the full guest record by default. Every access to sensitive data — ID documents and biometric records — is logged, so who viewed what, and when, is always traceable after the fact.

Payments

EZ2Stay never stores card data. Payments are processed by Stripe, and card details never pass through or sit on EZ2Stay's own systems.

Uptime

EZ2Stay works to a 99.9% uptime target. It's a target, not a contractual guarantee — there is no SLA credit scheme published today.

Certifications — the honest answer

EZ2Stay does not display SOC 2, ISO 27001, or any other compliance badge, because it hasn't earned one yet. Rather than imply a certification that doesn't exist, this page describes the actual controls in place: AES-256-GCM encryption, separated biometric storage with restricted access, role-based access control, and audit logging of sensitive-data access — the substance, without the badge.

Responsible disclosure

Found a security issue? Email contact@ez2stay.com with details. Reports are read directly by the founder, who also operates the production system at Popcorn Hostel — there is no security team queue to sit in.

Frequently asked questions about EZ2Stay for hostels

Where is guest data stored?

In the cloud infrastructure EZ2Stay runs on, encrypted at rest with AES-256-GCM. Biometric data (selfies) is kept in a separate store from ID documents and other guest records, with restricted access.

Who can see ID documents?

Only staff accounts with a role that requires it, and every view is logged with who accessed it and when. Biometric data has even narrower access than ID documents.

How do I request deletion of my data?

Contact the hostel you stayed with, or email contact@ez2stay.com. EZ2Stay honors GDPR deletion rights for personal data, with one exception: data that must be kept under legal retention rules — such as guest-registration records required by local law — is retained for the legally mandated period even after a deletion request, as explained on the relevant compliance page for that country.