Privacy Policy
Last updated: August 2026
Home In Leonidio ("Home In Leonidio", "we", "us") operates homeinleonidio.com, an advertising and software-tooling platform for short-term rental listings in Leonidio, Greece. This policy explains what personal data we process, why, and the rights you have over it, under the EU General Data Protection Regulation (GDPR) and applicable Greek law. For any privacy question or request, contact us at the email address at the bottom of this page.
We collect and process the following categories of personal data:
- Host account information: name, email address, and phone number provided when you create an account or contact us; subscription and billing details, processed by our payment provider, Stripe.
- Listing information: property descriptions, photos, pricing, amenities, and the property's AMA registration number, entered by the host.
- Minimal calendar/booking data: for each reservation synced from a connected channel (e.g. Airbnb, Booking.com), we store only the stay dates, booking status, the connecting channel, and, where available, guest count. We do not store the guest's name, contact details, or pricing information.
- Full reservation details, on demand, not stored: when a host chooses to view a booking's full details (guest name, contact information, pricing) in their dashboard, this is fetched live from the connected channel manager (Channex) and displayed directly - it is never written to our database.
- Guest messages, not stored: messages exchanged between a host and guest through our messaging tool are relayed live through Channex and are not stored by us.
- Guest reviews: synced from connected channels as already-public content the guest chose to publish.
- Staff access information: email addresses a host enters to grant a staff member view-only access to their calendar.
- Cookies and similar technologies: see our separate Cookie Policy for details.
We rely on the following purposes and legal bases for processing:
- To provide the platform's core functionality - listings, calendar sync, and host management tools (necessary to perform our contract with hosts).
- To process subscription payments (contract necessity, via Stripe).
- To communicate with hosts about their account or property.
- To maintain the security and integrity of the platform (legitimate interest).
- To comply with legal obligations we're subject to.
Guests are not Home In Leonidio account holders. Guest reservation and message data reaches us only via our connected channel manager, Channex, as part of showing a host their own booking - we do not independently collect, market to, or contact guests. Any data protection request from a guest relating to their reservation should generally be directed to the platform they booked through (e.g. Airbnb, Booking.com) or to Channex directly, though we will assist where we can.
Minimal calendar/booking data (see "Information We Collect" above) is retained indefinitely to support the calendar and channel-sync tools; no automatic deletion period currently applies.
Full guest reservation details and messages are never stored - retention doesn't apply to them.
Host account data is retained for as long as the account is active, plus any period required by law (e.g. billing records).
We work with the following third parties to run the platform:
- Channex.io - our channel manager, connecting listings to Airbnb, Booking.com, and similar platforms.
- Firebase / Google Cloud Platform - hosting, database (Firestore, stored in the EU), authentication, and push notifications.
- Stripe - subscription billing.
We don't sell personal data, and don't share it with anyone else outside what's needed to run these services.
Our database is hosted in the EU (Google Cloud's eur3 region), and our backend functions run in the EU (europe-west1). Some sub-processors (e.g. Stripe, Google) may process data outside the EU under their own standard contractual safeguards.
We use reasonable technical and organizational measures - access controls, encrypted transport, and scoped database permissions - to protect the data we hold.
Under GDPR, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise any of these, contact us using the email address below. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your own country's supervisory authority.
Our platform is not directed at children, and we don't knowingly collect data from anyone under 16.
We may update this policy from time to time; the "Last updated" date at the top reflects the most recent revision.
For any privacy question or request, including exercising your rights under GDPR, contact us at:

