Privacy notice
How the Guestcord pilot handles information about hosts and guests. Updated 23 September 2026.
Account registration
We store the contact name, business name, email, phone, registration and tax numbers, unit count, salted password hash, review status and sessions to provide account access, verification, onboarding and support. The operator’s registered identity and a data processing agreement must be confirmed before guest records are used commercially.
Who handles the data
Guestcord is a pilot developed for Manage Malta. For Manage Malta stays, Manage Malta determines the purpose of processing guest information. For future independent hosts' own records, the host will generally be the controller and the Guestcord operator a processor on documented instructions. Data received from a channel API may carry a separate controller role under that platform's terms, including Airbnb's API terms. The registered service provider, postal address and a signed data processing agreement must be provided before commercial onboarding. Privacy requests for this pilot: contact@managemalta.com.
Data and purpose
Property details, booking dates, guest name and contact details, stay notes, messages, access instructions, payments recorded by the host and draft invoices are used to manage stays and respond to guests. We do not collect payment card numbers in Guestcord. The public demo uses sample data saved locally in your browser. A guest portal link grants access to the corresponding stay, so recipients must keep it private.
Legal basis and sources
For Manage Malta stays, processing needed to arrange and perform a stay is based on the accommodation relationship; accounting records may be retained to meet legal duties. Guest details may come from the host, guest or an authorised channel or iCal feed. A future host is responsible for informing its guests about its own lawful basis. Marketing messages require a separate basis and are not enabled by this pilot.
Recipients and transfers
Hosting infrastructure and services used to operate the site may process data under contract. Authorised hosts and their staff can access their stays; guests see only their own portal link. Connected sales channels receive data only when a host explicitly authorises an integration. Before commercial launch the operator must publish its actual subprocessors, storage regions and any transfer safeguards. No direct Booking.com or Airbnb API integration is active today.
Retention and rights
Demo data remains in the browser until the user clears it. Pilot records in the server database remain until removed by the operator or host, subject to applicable legal retention obligations; an automated retention schedule is not yet in place. Ask contact@managemalta.com for access, correction, restriction, export or deletion, or to object where applicable. You can also complain to the Maltese Information and Data Protection Commissioner or your local authority.
Security and changes
Administrator access requires a private credential; host accounts use passwords and secure sessions. Guest portal links are secret and can expose stay instructions; do not forward them publicly. No system can guarantee absolute security. Material changes to this notice will be dated here. Commercial processing requires a signed processor agreement and a verified retention and incident-response procedure.
