Privacy policy
1. Introduction
This Privacy Policy explains how Shushko Ltd (“Shushko,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data when you use our website at shushko.com (the “Website”), our platform at app.shushko.com (the “Platform”), and any related services (together, the “Service”). It also explains our role in processing data through the booking websites Hosts build using Shushko (each, a “Host Site”).
This Policy applies whether you are:
- a visitor browsing the Website,
- a prospective customer submitting your details through a form or waitlist,
- a registered user of the Platform (“Host” or “Customer”), or
- a guest whose details are processed through a Host Site or otherwise through the Service (“Guest”) — see Section 9 below, as a different legal relationship applies to this data.
We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and other applicable data protection laws.
2. Who we are (data controller)
For the purposes described in Sections 4–8 of this Policy, the data controller is:
Shushko Ltd., 13 Todor Kableshkov Str., fl. 4, apt. 11, Sofia 1618, Bulgaria, Company registration number (UIC/EIK): 207234239 Contact email: [email protected]
For questions about this Policy or to exercise your rights, contact us at the email address above.
3. What personal data we collect
3.1. Website visitors
When you browse the Website, we may automatically collect technical and usage information, such as your IP address, device and browser information, and how you interact with our pages, via cookies and similar technologies (see Section 6). If you contact us or request information, we collect the details you choose to provide.
3.2. Registered platform users (Hosts)
When you create an account and use the Platform, we collect the information needed to provide the Service. This may include account and contact details, business and property information, content you upload, billing and subscription information, payment and payout details you provide so that Guests can pay you, usage and activity data, and information you share with us through support or other communications. Where full payment card details are involved, these are collected and processed directly by our payment processor, Stripe, and are not stored on our own systems (see Section 7).
Some of the information you provide is published on your Host Site or shared with Guests so they can book and pay you — for example, your business contact details and any payment details you choose to make available. You control what you publish.
3.3. Guest data (processed on behalf of Hosts)
When a Guest makes a booking through a Host Site, or where a Host uses the Service to collect guest registration details without a Host Site, we process the relevant booking, payment, and — where enabled by the Host — identity or registration information on behalf of the Host, who is the data controller for that information. This may include information Hosts are legally required to collect and report under local tourism, hospitality, or public-security laws, such as identity or travel document details (see Section 9).
3.4. Whether you are required to provide your data
Providing the information necessary to create an account and use the Service is required in order for us to enter into and perform our contract with you. Providing other information, such as through optional forms or marketing sign-ups, is voluntary.
4. How we use your data and our legal basis
We only process personal data where we have a valid legal basis under Article 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Operating, securing, and providing the Website, Platform, and Service | Performance of a contract (Art. 6(1)(b)) and/or legitimate interest (Art. 6(1)(f)) |
| Responding to inquiries and communicating with prospective and existing customers | Legitimate interest (Art. 6(1)(f)) and/or steps prior to entering a contract (Art. 6(1)(b)) |
| Processing payments and complying with billing, tax, and accounting obligations | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Analytics, cookies, and similar tracking technologies (see Section 6) | Consent (Art. 6(1)(a)) |
| Marketing communications | Consent (Art. 6(1)(a)), with opt-out available at any time |
| Preventing fraud, ensuring security, and complying with legal obligations | Legitimate interest (Art. 6(1)(f)) and/or legal obligation (Art. 6(1)(c)) |
5. How we share your data
We do not sell your personal data. We share personal data only with:
- Stripe, Inc. — our payment processor, for subscription billing and Guest payment processing (see Section 7)
- Service providers who help us host, operate, secure, and improve the Service, including infrastructure, analytics, communications, and related technology providers
- Legal and regulatory authorities, where required by law, court order, or to protect our legal rights
- A successor entity, in the event of a merger, acquisition, or sale of business assets, subject to the same protections described in this Policy
Each third-party processor is contractually bound to process personal data only per our instructions and to apply appropriate security measures.
6. Cookies and tracking technologies
The Website and Platform may use cookies and similar technologies, including:
- Strictly necessary technologies — required for core functionality (e.g. login sessions). No consent is required to store or read these, as they are strictly necessary to provide the service you have asked for.
- Analytics and performance technologies — help us understand how the Website and Platform are used. Used only with your consent.
- Advertising and marketing technologies — used to measure ad performance and build audiences for our own marketing. Used only with your consent.
You can manage or withdraw consent at any time via the cookie banner/settings on the Website, or through your browser settings. For more detail on the specific cookies we use, see our Cookie policy page.
7. Payment processing
All subscription payments are processed by Stripe. When you subscribe to Shushko, your payment card details are entered directly into Stripe’s secure systems and are not received or stored by Shushko. Stripe’s use of your data is governed by Stripe’s own Privacy policy. We receive limited transaction confirmation data from Stripe (e.g., payment status, last 4 digits of card, billing name) necessary to manage your subscription.
8. International data transfers
Some of our service providers (such as Stripe and certain hosting or analytics providers) may process data outside the European Economic Area (EEA), including in the United States. Where this occurs, we rely primarily on the European Commission’s Standard Contractual Clauses (SCCs) as the safeguard for such transfers. Where a service provider is also self-certified under the EU-US Data Privacy Framework (DPF), that may provide an additional basis for the transfer; however, we do not rely on DPF certification alone, given ongoing legal challenges to the framework before EU courts. You may request more detail on the specific safeguards used for a given transfer by contacting us (see Section 2).
9. Guest data and our role as a processor
Where a Guest books through a Host Site, or where a Host uses the Service to collect guest registration details without a Host Site, the Host is the data controller for that Guest’s personal data, and Shushko acts as a data processor, processing the data solely on the Host’s instructions to provide the booking, payment, and — where the Host enables it — guest registration functionality. This applies whether the form or page the Guest uses is served from the Host’s own domain or from a Shushko domain. This may include processing identity or travel document information that Hosts are legally required to collect and report under local tourism, hospitality, or public-security laws. Where the relevant authority provides a technical interface for this, where we have built support for it, and where the Host has enabled that functionality, we may transmit the required information to the relevant government or regulatory system on the Host’s instructions. Where no such functionality is available or enabled, we make the information available to the Host and the Host makes the submission themselves. In either case the Host remains responsible for the accuracy, completeness, and timeliness of what is reported, and for confirming that any submission has been made and accepted. Our processing obligations, security commitments, and sub-processor arrangements in this role are set out in our Data processing agreement (DPA), which is incorporated by reference into our Terms of Service for Hosts.
If you are a Guest and have questions about how your data is used, please contact the Host whose property you booked directly, as they determine the purposes of that processing.
10. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable law. In particular, accounting and tax-related records relating to your subscription are retained for the period required under Bulgarian accounting law (currently 10 years). Where we no longer have an ongoing need to process personal data, we will delete it or render it anonymous.
Guest data. Where we process Guest data on behalf of a Host (see Section 9), we apply the retention periods set out in our Data Processing Agreement. Guest identity and travel document details are deleted 12 months after the departure date of the booking they relate to. Reservation and payment records are retained as described in that Agreement. Hosts are responsible for satisfying themselves that these periods meet their own record-keeping obligations, and may ask us to delete data sooner.
11. Your rights under GDPR
Subject to applicable legal conditions, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”), subject to legal retention obligations
- Restrict processing in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Object to processing based on legitimate interest, including direct marketing
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal
To exercise these rights, contact us at [email protected]. We will respond within the timeframes required by GDPR (generally one month).
You also have the right to lodge a complaint with the data protection supervisory authority responsible for our processing:
Commission for Personal Data Protection (CPDP) Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria Website: cpdp.bg
You may also complain to the supervisory authority in your own EU member state of residence.
12. Data security
We apply appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or disclosure, including encryption in transit, encryption at rest, additional field-level encryption for identity and travel document details, access controls, and use of reputable, security-vetted sub-processors (such as Stripe for payments). No system is completely secure, and we cannot guarantee absolute security of data transmitted to us. In the event of a personal data breach affecting your data, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with our obligations under Articles 33 and 34 GDPR.
13. Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on you.
14. Children’s privacy
The Service is intended for business use by adults operating short-term rental properties. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal data, please contact us so we can delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. Changes take effect when posted, and the “Last updated” date at the top reflects the most recent revision. We encourage you to review this Policy periodically.
This Policy is published in English. Where we provide a translated version, it is for convenience only, and the English version shall prevail in the event of any inconsistency or conflict.
16. Contact us
For any questions about this Privacy Policy or our data practices, email us at [email protected]. Our full company details are listed in Section 2 above.