Quick overview
✓
We collect only the necessary data
✓
Data is used to provide the service, security and legal compliance
✓
Data is deleted on request when there is no legal obligation to retain it
✓
Video content in the feed is deleted every 90 days
✓
Data processing is GDPR-compliant
For hosts – private data
First name, last name, email, phone number and address. This data is available only to you and the platform’s authorised systems.
For payouts (Stripe Connect) – banking data
IBAN is stored exclusively via Stripe Connect’s secure integration. Zvizz does not store IBAN on its own servers and does not have access to the full IBAN.
For hosts – public data (guests)
Property name, property phone number, property email address and location. Visible to registered users.
For guests
Name, email, phone number and stay dates. The Stripe payment token is private and available only through the Stripe system.
Video feed
Username or pseudonym, video content, description and comments (visible to registered users).
Automatically collected data
IP address, device type, access time and interactions (private, for security and abuse prevention).
Only for operating the platform
Managing reservations, payment processing, payouts, listing reviews and providing technical support.
Fee model
The platform uses a single commission-based fee model. Commission is charged to the host in line with the applicable price list.
Payments and payouts
Data is used to process payments via Stripe Connect and to pay out business users 7 days after the guest’s payment has been recorded.
Legal bases
Processing is based on a contract (bookings), legal obligations (tax/accounting requirements) or your consent (communication messages).
Communication
We send email notifications about bookings and important changes. You can unsubscribe from certain notifications at any time.
We do not sell data
Your data is not sold to advertisers or other third parties.
Video feed
Content you publish remains your property and is available only to registered users.
Active users
Data is kept while you are a registered user and for 30 days after account deletion, after which it is automatically deleted.
Bookings
In line with statutory retention periods (e.g., tax and accounting obligations) under applicable Croatian law.
Video feed content
90 days, after which it is automatically deleted (or earlier if you request it).
IBAN (Stripe Connect)
Not stored on our servers – kept exclusively on Stripe’s servers, in accordance with their privacy policy.
Encryption
SSL/TLS for all communications and AES-256 for the database.
Passwords
Passwords are hashed using bcrypt and are not visible to us in their original form.
Cards and IBAN
Stripe Connect processes all payments and IBAN data – we never see your full card number or IBAN. Stripe is PCI DSS certified and uses the highest security standards.
Bank details
IBAN is stored exclusively via Stripe Connect encryption – it is never available to our database or employees.
Technical system functions
Data is processed through protected server-side processes and controlled access, applying least-privilege principles and avoiding unnecessary exposure of data to the client application.
Data access
Only authorized staff can access data, and only when necessary for support or security.
Third parties and processors
Database
The database is hosted on EU servers with a signed Data Processing Agreement (DPA).
Payment processing and IBAN
Stripe Connect – we do not see card data or IBAN; Stripe is PCI DSS certified and IBAN is encrypted and stored on their servers.
Email notifications
We use a specialized email service provider with a DPA-compliant agreement to send emails.
Maps and location services
We use a maps/location service to display accommodation locations.
Media delivery
Images and video content are delivered via CDN services.
Security and DNS
We use DNS and CDN solutions to improve security and platform availability.
Hosting and deployment
The application is hosted and deployed on third-party infrastructure providers.
Transfers to third countries
In some cases, your data may be processed on servers outside the European Economic Area (e.g., by Stripe or a CDN). In such cases, we rely on appropriate safeguards such as EU Standard Contractual Clauses and technical encryption measures, and we transfer data only when necessary to provide the service.
Processor details
For detailed information about our processors and signed Data Processing Agreements, contact us at info@zvizz.com.
Legal bases for processing
Contract
Reservations, payment management and payouts – processing is necessary to perform the contract with you.
Legal obligation
Keeping booking-related data is required by tax/accounting regulations and other applicable Croatian laws.
Consent
Marketing communications and publishing video content in the video feed are carried out only with your explicit consent.
Legitimate interests
Platform security, fraud prevention and service improvement are our legitimate interests, while always considering your rights and freedoms.
Objection
If you object to certain processing, you can contact us at info@zvizz.com and submit an objection.
How bases apply by data category
Booking and account data is generally processed based on contract and legal obligation; technical and security logs (e.g., IP, device) based on legitimate interest; video feed content and marketing communications only based on your consent.
Essential cookies
Session token, CSRF protection and Stripe security cookies – necessary for platform operation and do not require your consent.
Technical cookies
Display preferences (e.g., dark mode, language) and account settings – retained up to 2 years.
IP address and device
Collected automatically for security and basic analytics, and kept for up to 3 months.
Automated decisions and AI
What automated decisions are
Systems that automatically process data to make certain decisions (e.g., approving or rejecting specific actions).
Use in the Zvizz app
Automated systems may be used to prevent fraud by analyzing behavioral patterns and activity on the platform.
Your rights
You have the right to know when a decision was made automatically and you can request a manual review.
Impact on the user
We do not make solely automated decisions, including profiling, that produce legal effects for you or similarly significantly affect you without the possibility of human intervention.
Disagreement
If you disagree with an automated decision, contact us at info@zvizz.com for clarification and review.
AI systems
We use AI for content recommendations and query processing, subject to system rules and oversight. AI does not have independent decision-making authority beyond the platform’s defined rules.
Your rights (GDPR – Articles 15–22)
Right of access
You can request confirmation of whether we process your personal data and obtain a copy by emailing info@zvizz.com.
Right to rectification
If your data is inaccurate or incomplete, you can request correction.
Right to erasure
You can request deletion of your data, except for data we must keep due to legal obligations (e.g., bookings for tax purposes).
Right to data portability
You can request your data in a structured, commonly used and machine-readable format (e.g., JSON or CSV).
Right to complain
If you believe your rights are violated, you have the right to file a complaint with the Croatian Data Protection Agency (AZOP).
How to exercise your rights
To exercise your rights, email info@zvizz.com with the subject 'GDPR request' and a clear description of what you request (e.g., access, correction, deletion, portability). We will respond without undue delay and no later than 30 days.
Video feed – special rules
Ownership
Content you publish remains your property.
Automatic deletion
Videos older than 90 days are automatically deleted.
Control
You can delete your video content at any time.
Visibility
Published video content is visible to registered users of the platform.
Pseudonyms
You may use a pseudonym when publishing video content.
People in videos
Showing people’s faces in videos (e.g., owner, guest, staff) is allowed provided you have obtained valid consent from all depicted persons.
Prohibited content
Pornographic content, violence, discriminatory content, content infringing copyrights or other laws is prohibited.
Legal responsibility
You are fully responsible for the content you publish and for having the rights to publish it.
Protection of minor users
Minimum age
Users under 16 may use the platform only with explicit parental or guardian consent.
Minors (16–18)
Minor users may use the platform with clear information about how their data is processed and protected.
Recommendation
We recommend users under 16 use the platform under parental/guardian supervision and support.
Parental responsibility
Parents/guardians are responsible for supervising how minors use the platform.
Changes to this Privacy Policy
Notices
We may notify you about changes via email or push notifications.
Minor changes
Minor changes are published directly on this Privacy Policy page.
Major changes
We will notify you of significant changes at least 30 days before they take effect.
No data selling
Selling your personal data to third parties is not allowed and is not practiced.
Data sharing
Sharing data with third parties without a valid legal basis or your consent is not permitted.
Data breach
If you suspect a data breach (e.g., unauthorized access), contact us at info@zvizz.com.
Contact
For any questions or requests related to processing personal data, contact us at info@zvizz.com.
Complaints
You can submit privacy-related complaints via info@zvizz.com.
Response time
We will respond without undue delay and no later than 30 days after receiving a valid request.
Identity verification
To protect your data, we may, where proportionate and necessary, request additional confirmation of identity.
Data Protection Agency
If you are not satisfied with our response, you may contact the Croatian Data Protection Agency (AZOP) at azop@azop.hr.
Legal obligation and applicable law
Applicable law
Processing of personal data is governed by Regulation (EU) 2016/679 (GDPR) and applicable Croatian law (including the Act on the Implementation of the GDPR).
Dispute resolution
We aim to resolve disputes concerning data processing directly, and where appropriate through ADR procedures (e.g., mediation). This does not affect consumers’ right to bring proceedings before a competent court.
Tax/accounting rules
Booking-related data is retained in line with statutory retention periods to the extent necessary to meet tax and accounting obligations.
Payments, payouts and Stripe Connect
How Stripe Connect works
IBAN is stored exclusively via Stripe Connect’s secure integration. Zvizz never sees, stores or has access to your full IBAN.
Platform commission
For each payment through the platform, commission is charged to the host in line with the applicable price list.
Stripe security
Stripe is a PCI DSS certified provider. All card and IBAN data is processed exclusively through Stripe, using the highest security standards.
Stripe relationship
For payment data (cards, IBAN), Stripe acts as a separate controller or processor depending on the specific service provided. We recommend reading Stripe’s Privacy Policy to understand how they process your data.
Payout of funds
Funds are paid out to the host’s registered Stripe Connect account 7 days after the guest’s payment has been recorded.
Single fee model
The subscription model is no longer active. Payments and payouts are carried out through Stripe Connect in line with the platform rules.
Cookies and technical tools
We use necessary security and functional cookies, Stripe security mechanisms, and limited basic analytics and technical tools for service stability and security.
Video feed
The video feed is visible to registered users and is fully optional – it is not required for standard platform use.
Important notices
We send only notices that are necessary to provide the service (e.g., booking confirmations and key changes).
Email address
An email address is required for communication, booking confirmations and important notices.
Phone number
A phone number is required for communication with guests and for additional account security.
Bank details
Bank details (IBAN) are required for payouts via Stripe Connect and are processed exclusively through Stripe infrastructure.
What Zvizz is
Zvizz is a digital platform for managing accommodation and boat rentals that enables hosts to manage reservations, availability calendars, payments and communication with guests.
Fee model
A single commission-based fee model through Stripe Connect is in place. The platform commission is paid by the host.
Contact email
For any information, contact us at info@zvizz.com.
Your rights under GDPR
•
Right of access – know what data we process
•
Right to rectification – correct inaccurate or incomplete data
•
Right to erasure – request deletion of personal data
•
Right to data portability – receive data in a machine-readable format
•
Right to complain – contact the Data Protection Agency (AZOP)