Winter offer — choose annual and your year begins March 1.See plans

Security and data

Where your data is stored, how it is protected, and who else can see it.

Last reviewed 21 August 2026

Your bookings, your guests’ details, and your payments matter. Here’s exactly how Shushko handles them.

Where your data is stored

Your booking data, your guests’ details, and the content of your Host Site are stored in the European Union, on infrastructure operated by Amazon Web Services.

A small number of the providers we work with operate outside the EU — our payment processor among them. Where that happens, the transfer is covered by the safeguards set out in our Privacy Policy.

How your data is protected

Everything you send to and from Shushko travels over an encrypted HTTPS connection. Data is encrypted at rest in our database, and particularly sensitive fields — including guest identity document numbers, where the compliance features require them — carry an additional layer of field-level encryption.

Access to production systems is restricted to authorized personnel using individually assigned, permission-scoped credentials.

How you sign in

Shushko doesn’t use passwords. You sign in with a single-use code sent to your email address.

That means there’s no password for us to store, none for anyone to steal, and no risk carried over from a password you’ve reused somewhere else. Because your inbox is the key to your account, we’d recommend turning on two-factor authentication with your email provider.

Payments

Shushko never sees or stores your guests’ card details. All card processing is handled by Stripe, certified as a PCI Service Provider Level 1 — the highest level in the payment card industry.

When a guest books through your site, the money goes directly to you. You are the merchant of record for your own bookings. Shushko doesn’t sit between you and your revenue.

Your guests’ data belongs to you

For guest data flowing through Shushko, you are the data controller and Shushko is your data processor. In plain terms: it’s your data. We hold it on your behalf and act on your instructions.

Our Data processing agreement sets this out formally, including the security measures we commit to and how we handle the providers we work with.

Backups

Production data is backed up continuously, with point-in-time recovery covering the previous 35 days. Backups are stored within the EU.

Who else touches your data

Running Shushko means working with a small number of trusted providers — for hosting, payments, email delivery, analytics, and network security. Each is contractually bound to data protection obligations substantially similar to our own.

How long we keep your data

If you close your account we keep your reservation and payment records, so you can still meet your own tax and tourism-registration obligations — those laws usually require several years, and deleting everything the day you leave would put you at risk rather than protect you.

Guest identity document details are different. We delete those 12 months after the guest’s departure date, whether or not your account is still open, unless you have asked us to keep them longer and we have agreed.

Everything else is kept for at least 6 months after your subscription ends, and deleted within 12 months. You can ask for your data back at any point during that period, or ask us to delete it sooner.

Reporting a security issue

If you think you’ve found a vulnerability in Shushko, email [email protected] and we’ll respond promptly. We appreciate responsible disclosure.