Ασφάλεια και δεδομένα
Where your data is stored, how it is protected, and who else can see it.
Your bookings, your guests’ details, and your payments matter. Here is exactly how Shushko handles them.
Where your data is stored
Your booking data, your guests’ details, and the content of your website are stored in the European Union, on infrastructure operated by Amazon Web Services.
Some of the providers we work with operate outside the EU — our payment processor, our live chat provider, our analytics and advertising providers, our maps and sign-in provider, and our network security provider among them. Where that happens, the transfer is covered by the safeguards set out in our Privacy Policy.
How your data is protected
Everything you send to and from Shushko travels over an encrypted HTTPS connection. Data is encrypted at rest in our database, and particularly sensitive fields — including guest identity document numbers, where the compliance features require them — carry an additional layer of field-level encryption.
Access to production systems is restricted to authorized personnel using individually assigned, permission-scoped credentials.
How you sign in
Shushko does not use passwords. You sign in with a single-use code sent to your email address, or with your Google account.
That means there is no password for us to store, none for anyone to steal, and no risk carried over from a password you have reused somewhere else. If you sign in with Google, we never see your Google password. Google only confirms who you are.
Your email account or your Google account is the key to Shushko. We recommend turning on two-factor authentication there.
Payments
Shushko never sees or stores your guests’ card details. All card processing is handled by Stripe, certified as a PCI Service Provider Level 1 — the highest level in the payment card industry.
When a guest books through your site, the money goes directly to you. You are the merchant of record for your own bookings. Shushko does not sit between you and your revenue.
Your guests’ data belongs to you
For guest data flowing through Shushko, you are the data controller and Shushko is your data processor. In plain terms: it is your data. We hold it on your behalf and act on your instructions.
Our Data processing agreement sets this out formally, including the security measures we commit to and how we handle the providers we work with.
Backups
Production data is backed up continuously, with point-in-time recovery covering the previous 35 days. Backups are stored within the EU.
Who else touches your data
Running Shushko means working with a small number of trusted providers — for hosting, payments, email delivery, live chat, analytics, maps, sign-in, and network security. Each is contractually bound to data protection obligations substantially similar to our own. The full list of providers who handle guest data is published in Annex III of our Data processing agreement.
How long we keep your data
If you close your account we keep your reservation and payment records, so you can still meet your own tax and tourism-registration obligations — those laws usually require several years, and deleting everything the day you leave would put you at risk rather than protect you.
Guest identity document details are different. We delete those 12 months after the guest’s departure date, whether or not your account is still open, unless you have asked us to keep them longer and we have agreed.
Everything else is kept for at least 6 months after your subscription ends, and deleted within 12 months. You can ask for your data back at any point during that period, or ask us to delete it sooner.
Reporting a security issue
If you think you have found a vulnerability in Shushko, email [email protected] and we will respond promptly. We appreciate responsible disclosure.
Ready to take bookings on your own website?
Build free. Pay when you go live.