Last updated: 08/17/2026
This Privacy Policy explains how Kyhash Apartments collects, uses, stores and shares personal data when you visit www.kyhash.com, search for accommodation, make or manage a reservation, create a customer account, make a payment, request a cancellation or refund, or contact us.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable Polish and European data protection laws.
1. Data controller
The controller responsible for your personal data is:
Controller: YUGUO YANG
Trading name: Kyhash Apartments
Address: ul. Starowiślna 36/30, Kraków 31-032, Poland
Tax identification number (NIP): 6762493599
Email: [email protected]
Telephone: +48 660 476 206
Website: https://www.kyhash.com
We have not appointed a Data Protection Officer because we are not legally required to do so. Privacy-related questions and requests may be sent directly to the email address above.
2. Personal data we collect
The personal data we collect depends on how you use the website and our accommodation services.
2.1 Accommodation searches
When you search for accommodation, we may process:
- check-in and check-out dates;
- number of adult guests;
- number of children;
- selected accommodation;
- search and availability information;
- IP address and basic technical request data.
We normally collect only the number of children included in a search, not their names or other identifying information, unless such information is subsequently required for a specific and lawful purpose.
2.2 Reservations
When you make or manage a reservation, we may collect:
- first and last name;
- email address;
- telephone number;
- country of residence;
- billing or postal address, where required;
- selected apartment;
- check-in and check-out dates;
- number of guests;
- booking number;
- booking status;
- selected rate and services;
- price, taxes, fees and discounts;
- special requests and messages supplied by you;
- date and time of the reservation;
- acceptance of our Terms and Conditions.
Please do not include health information, identity-document details or other sensitive personal data in the special-request field unless it is necessary for your stay.
2.3 Payments, cancellations and refunds
Payments are processed through Stripe. In connection with a payment, cancellation, refund or payment dispute, we may receive and store:
- payment amount and currency;
- payment status;
- payment date and time;
- Stripe payment or transaction identifier;
- payment method type;
- card brand;
- the last four digits of the payment card;
- billing details;
- refund amount and status;
- cancellation date and reason, if provided;
- chargeback or payment-dispute information;
- fraud and security indicators supplied by the payment provider.
Kyhash Apartments does not receive or store your complete payment-card number or card security code. Payment credentials are entered into and processed through Stripe’s payment environment.
Stripe may separately process transaction, device, identity-verification and fraud-prevention data under its own privacy terms.
2.4 Customer accounts
If you create or use a customer account, we may process:
- name;
- email address;
- username or account identifier;
- encrypted password credential;
- contact and billing details saved in the account;
- current and previous reservations;
- account creation and last-login information;
- password-reset and security records.
We cannot see your password in plain text.
2.5 Communications and contact forms
When you contact us by email, telephone or a website form, we may process:
- name;
- email address;
- telephone number;
- message content;
- booking number;
- attachments or other information you voluntarily provide;
- dates and records of our correspondence.
2.6 Website and server information
When you visit the website, our web server and security systems may automatically record:
- IP address;
- date and time of access;
- requested page or file;
- browser and device type;
- operating system;
- referring page;
- HTTP response and error information;
- information associated with suspicious or malicious activity.
We use this information to operate, secure and troubleshoot the website.
2.7 Website Analytics – WP Statistics
We use WP Statistics to obtain limited statistical information about the use and performance of our website. This may include pages visited, referring websites, approximate geographic region, browser or device type, and the date and time of a visit.
WP Statistics is configured to operate without analytics cookies and is not used for advertising, cross-site tracking or the creation of individual marketing profiles. IP addresses are anonymised and hashed, full IP addresses are not stored, and website visits are not associated with logged-in customer accounts.
The statistical information is stored locally in the WordPress database on our own server and is not transmitted to WP-Statistics.com.
Detailed statistical records are retained for up to 180 days. After that period, the data is automatically aggregated: detailed information such as referrers, locations, IP-related identifiers, devices, browsers and individual sessions is deleted, while only anonymous totals for visitors and page views are retained for historical reporting.
The legal basis for this processing is our legitimate interest under Article 6(1)(f) GDPR in understanding website usage, maintaining website security, identifying technical problems and improving our services.
2.8 Data received from third parties
We may receive personal data from:
- Stripe and other payment providers;
- banks and payment-method providers;
- accommodation booking platforms through which you made a reservation;
- calendar or channel-synchronisation services;
- fraud-prevention and security providers;
- professional advisers or public authorities where legally permitted or required.
When you reserve through Airbnb, Booking.com or another third-party platform, that platform also processes your personal data under its own privacy policy.
3. Why we process your data and our legal bases
We process personal data only when we have a lawful basis under the GDPR.
| Purpose | Personal data involved | Legal basis |
|---|---|---|
| Searching availability and calculating prices | Dates, occupancy, selected accommodation and technical request data | Steps requested before entering into a contract; Article 6(1)(b) GDPR |
| Creating, confirming and managing reservations | Identity, contact, stay and booking information | Performance of a contract or pre-contractual steps; Article 6(1)(b) |
| Processing payments, deposits and refunds | Billing and transaction information | Performance of a contract; Article 6(1)(b) |
| Issuing invoices and maintaining accounting and tax records | Identity, billing, booking and payment information | Compliance with legal obligations; Article 6(1)(c) |
| Communicating about a reservation or stay | Contact details, booking information and correspondence | Performance of a contract; Article 6(1)(b) |
| Answering general enquiries | Contact details and message content | Legitimate interests in responding to enquiries and operating our business; Article 6(1)(f) |
| Managing cancellations, complaints and disputes | Booking, payment, refund and communication records | Performance of a contract and legitimate interests in establishing, exercising or defending legal claims; Articles 6(1)(b) and 6(1)(f) |
| Operating customer accounts | Account, identity, contact and booking information | Performance of a contract or services requested by the user; Article 6(1)(b) |
| Preventing fraud and protecting the website | Transaction, IP address, device, access and security data | Legitimate interests in protecting guests, payments, systems and our business; Article 6(1)(f) |
| Complying with lawful requests from authorities | Relevant booking, identity, payment or communication records | Compliance with a legal obligation; Article 6(1)(c) |
| Non-essential analytics or marketing, if introduced | Cookie identifiers, device and usage information | Consent; Article 6(1)(a) |
| Local website statistics through WP Statistics | Anonymised and hashed IP-related identifiers, visited pages, referrer, approximate region, device/browser type and visit time | Legitimate interests in understanding website usage, maintaining security and improving the website; Article 6(1)(f) GDPR |
Where processing is based on legitimate interests, we consider whether those interests are necessary and balanced against your rights and reasonable expectations.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn.
4. Is providing personal data required?
Providing data for a general enquiry is voluntary. However, we may be unable to answer if you do not provide sufficient contact information.
Certain information is necessary to search for accommodation, conclude and perform a booking contract, process payment or meet legal obligations. If you do not provide the required information, we may be unable to accept or fulfil the reservation.
Fields that are mandatory during checkout are marked or otherwise identified as required.
5. Payment processing through Stripe
We use Stripe to process online payments and refunds.
Depending on the payment method, personal data may be shared with:
- Stripe entities;
- your bank or card issuer;
- card networks such as Visa or Mastercard;
- payment-method providers;
- fraud-prevention and identity-verification providers;
- financial and regulatory institutions where required.
Stripe may collect transaction information, billing information, IP address, device information and payment credentials directly from you.
We generally receive only the information required to identify and administer the transaction, such as its status, amount, Stripe identifier, payment-method type, card brand and last four digits.
For more information, please review the Stripe Privacy Policy and Stripe Privacy Center.
6. Recipients and service providers
We disclose personal data only where necessary for the purposes described in this Policy.
Recipients may include:
- Stripe and other payment-service providers;
- banks, card networks and payment-method providers;
- our WordPress hosting, server and infrastructure providers;
- MotoPress Hotel Booking and related technical service providers;
- email hosting and email-delivery providers;
- website maintenance, cybersecurity and backup providers;
- accountants, tax advisers, legal advisers and insurers;
- booking platforms and calendar-synchronisation providers;
- public authorities, courts, law-enforcement bodies or regulators where disclosure is legally required;
- a purchaser or successor if the accommodation business is sold or reorganised, subject to appropriate confidentiality and legal safeguards.
Service providers acting on our instructions may process personal data only for agreed purposes and under appropriate contractual and security obligations.
We do not sell personal data.
7. International data transfers
We aim to process and store reservation data within the European Economic Area (“EEA”) where reasonably possible.
Some service providers, including Stripe and their subprocessors, may process personal data outside Poland or the EEA, including in the United States or other countries.
Where GDPR applies to an international transfer, the transfer will rely on an appropriate legal mechanism, such as:
- an adequacy decision adopted by the European Commission;
- the EU–US Data Privacy Framework where the recipient is validly certified;
- Standard Contractual Clauses approved by the European Commission;
- another transfer mechanism permitted by GDPR.
Additional technical, organisational or contractual measures may be applied where required.
Information about Stripe’s international transfer safeguards is available in the Stripe Privacy Center.
8. How long we retain personal data
We retain personal data only for as long as necessary for the relevant purpose and applicable legal obligations.
Our general retention periods are:
| Data category | General retention period |
|---|---|
| Availability searches not resulting in a booking | Normally retained only temporarily for the session, except for limited server and security logs |
| Incomplete or abandoned reservation information | Up to 12 months, unless a longer period is required for fraud prevention or a dispute |
| Confirmed booking records | For the duration of the booking and generally up to 5 years after the end of the relevant accounting or tax year, or longer where required by law |
| Invoices, payment and accounting records | For the period required by Polish accounting and tax law, generally 5 years calculated under the applicable statutory rules |
| Cancellation and refund records | Generally retained with the related booking and payment records |
| Chargeback, complaint or legal-dispute records | Until the matter is resolved and the applicable limitation periods have expired |
| General enquiries not resulting in a booking | Normally up to 12 months after the last correspondence |
| Reservation-related communications | Generally up to 3 years after completion or cancellation of the stay, unless required for accounting, complaints or legal claims |
| Customer accounts | Until the account is deleted or becomes inactive under our account-retention procedure; booking and accounting records may be retained separately where legally required |
| Server access and security logs | Normally up to 90 days, but longer where necessary to investigate a security incident or attempted abuse |
| Consent records | For as long as needed to demonstrate when and how consent was given or withdrawn |
| Backup copies | Until overwritten in accordance with our backup cycle, subject to restricted access |
When a retention period expires, data is deleted, anonymised or securely isolated unless continued storage is required by law or necessary for legal claims.
A request to erase an account does not necessarily require us to delete booking, payment, invoice or tax records that we are legally required to retain.
9. Cookies and similar technologies
The website may use cookies and similar technologies.
Essential cookies
Essential cookies are used for functions such as:
- maintaining booking and checkout sessions;
- remembering selected dates and accommodation;
- customer login and account security;
- payment and fraud-prevention functionality;
- load balancing and website security;
- remembering privacy or cookie preferences.
These cookies are necessary to provide the website or services requested by the user and do not require consent where the applicable legal exemption applies.
Non-essential cookies
Analytics, advertising or other non-essential cookies will be used only after obtaining consent where required by law.
If non-essential cookies are introduced, the cookie banner and Cookie Policy should identify:
- the cookie provider;
- purpose;
- duration;
- data processed;
- method for withdrawing consent.
You can change cookie preferences through the website’s cookie settings, if available, or through your browser. Blocking essential cookies may prevent the booking, payment or account functions from working correctly.
10. Security
We apply reasonable technical and organisational measures designed to protect personal data, including measures such as:
- encrypted HTTPS connections;
- access controls and restricted administrative access;
- secure payment processing through Stripe;
- software updates and security monitoring;
- firewalls and server protections;
- backups and recovery procedures;
- password hashing and account-security controls;
- limiting access to people who need the data for their work.
No internet service or storage system can be guaranteed to be completely secure. You are responsible for keeping account credentials and booking links confidential and for notifying us if you suspect unauthorised use.
11. Automated decision-making
Kyhash Apartments does not currently use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on guests.
Stripe and other payment providers may use automated systems to assess fraud, authenticate payments or decide whether a transaction can be processed. Further information is available in the relevant provider’s privacy documentation.
12. Marketing communications
We do not send electronic marketing communications unless we have an appropriate legal basis, including consent where required.
Operational messages concerning a reservation, payment, cancellation, refund, account or stay are not marketing communications and may be sent where necessary to provide the requested service.
If you consent to marketing, you may withdraw that consent at any time by using the unsubscribe mechanism in the message or contacting us.
13. Children’s data
Our accommodation may be booked for stays involving children, but reservations must be made by an adult.
We normally process only the number of children included in a reservation. We do not intentionally request children’s names, dates of birth or other personal details unless the information is necessary to provide the accommodation, meet a legal requirement or address a specific safety or accessibility request.
The adult making the reservation is responsible for supplying any child-related information lawfully and only where necessary.
14. Your GDPR rights
Subject to the conditions and limitations in the GDPR, you may have the right to:
- receive information about how your personal data is processed;
- access your personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain data in a structured, commonly used and machine-readable format;
- request transmission of eligible data to another controller where technically feasible;
- withdraw consent at any time where processing is based on consent;
- not be subject to certain solely automated decisions;
- lodge a complaint with a data protection authority.
These rights are not absolute. For example, we may need to retain booking, invoice or payment records to comply with tax and accounting laws or to establish, exercise or defend legal claims.
15. Exercising your rights
To exercise a data protection right, contact:
Email: [email protected]
Postal address: ul. Starowiślna 36/30, Kraków 31-032, Poland
Please describe your request and provide enough information for us to identify the relevant records.
We may request reasonable additional information to verify your identity, particularly where disclosure or deletion of booking and payment records is requested.
We will respond without undue delay and normally within one month. Where permitted by GDPR, this period may be extended by up to two additional months for complex or numerous requests. We will inform you if an extension is necessary.
We normally do not charge a fee. A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive, as permitted by GDPR.
16. Complaints
If you believe that your personal data has been processed unlawfully, please contact us first so that we have an opportunity to investigate and respond.
You also have the right to lodge a complaint with the Polish supervisory authority:
President of the Personal Data Protection Office
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stanisława Moniuszki 1A
00-014 Warszawa
Poland
Website: https://uodo.gov.pl
You may also be entitled to contact the supervisory authority in the EEA country where you normally live or work, or where the alleged infringement occurred.
17. External websites and third-party services
The website may contain links to Stripe, booking platforms, map services, social networks or other external websites.
Those organisations process personal data under their own privacy policies. We are not responsible for the privacy practices or content of websites and services that we do not control.
18. Changes to this Privacy Policy
We may update this Privacy Policy when our services, website, service providers or legal obligations change.
The current version will be published on this page with the “Last updated” date. If a change materially affects how existing personal data is processed, we will provide additional notice where required by law.
19. Contact us
For questions about this Privacy Policy or the processing of personal data, contact:
Kyhash Apartments
Controller: YUGUO YANG
Email: [email protected]
Telephone: +48 660 476 206
Address: ul. Starowiślna 36/30, Kraków 31-032, Poland
