Last updated: December 22, 2025
This Privacy Policy describes how Shortstay collects, uses, stores, shares, protects, analyzes, and deletes personal data in the context of the use of its platform, application, website, customer service channels, reservations, contracts, payments, registration analysis, identity verification, check-in, check-out, and other services related to accommodation.
By using the platform, creating an account, submitting documents, requesting a reservation, signing a contract, making a payment, registering additional guests, accessing a property, or using any official Shortstay channel, the User declares that they are aware of this Privacy Policy.
This Policy should be read together with Shortstay's Terms and Conditions of Use.
Shortstay processes personal data only for purposes related to reservation, contract, payment, security, fraud prevention, identity validation, property access, support, maintenance, cleaning, inspection, legal compliance, and defense of rights.
Documents, selfies, financial data, conversations, contracts, receipts, reservation data, and detailed personal information are not shared with third parties without legal basis, identity validation, proven necessity, valid authorization, or order from a competent authority.
The presentation of a power of attorney, extrajudicial notification, OAB number, legal email, or claim of acting as a lawyer does not generate automatic access to personal data.
Shortstay provides services related to intermediation, organization, operational management, and support for flexible-term rentals, including, as applicable, registration analysis, reservation management, contracts, payments, support, maintenance, cleaning, inspections, communication with condominium associations, and other activities necessary for the execution of the accommodation.
For purposes of the General Law for the Protection of Personal Data — LGPD, Shortstay may act as a controller of personal data when it defines the purposes and means of processing related to its services.
This Policy applies to all interactions conducted with Shortstay, including:
Shortstay application;
official website and pages;
Help Center;
customer service channels;
emails;
WhatsApp or other official channels;
forms;
electronic contracts;
booking, check-in, stay, and check-out processes;
maintenance, cleaning, inspection, support, and billing requests;
registration of additional guests;
submission of documents and selfies;
requests related to privacy and data protection.
Shortstay collects only the necessary data to enable its services, protect platform security, comply with legal obligations, execute contracts, prevent fraud, and safeguard rights.
We may collect the following categories of data:
full name;
email;
telephone;
address;
nationality;
marital status, when necessary for contract;
profession;
company data, when the engagement involves a legal entity;
data of financial officers, representatives, or reservation managers, when applicable.
For registration analysis, identity validation, contract issuance, security, and fraud prevention, Shortstay may request and process:
CPF;
RG;
Driver's License;
Passport;
RNE/RNM or equivalent document;
Income statements;
Address verification documents;
Articles of association, CNPJ and corporate documents, where applicable;
Documents voluntarily submitted by the User for analysis of the reservation or stay;
Documents submitted by the reservation holder on behalf of additional guests, where applicable.
Shortstay may request a selfie, photo holding a document, facial images, document images and other visual verification elements for each reservation or whenever there is a need to confirm identity, prevent fraud, protect the holder, validate access to the property or protect the security of the platform.
The submission of selfies and documents may be a necessary condition for analysis, approval, maintenance, or renewal of the reservation. Unjustified refusal, failure to submit, or inability to validate identity may result in reservation refusal, preventive blocking, access suspension, cancellation of the contracting process, or inability to release check-in.
Depending on the technology used, this information may involve processing of biometric data or facial identification elements, especially when there is automated comparison, facial validation, proof of life, extraction of facial parameters, or electronic authentication.
The processing of this information shall be limited to the purposes of identification, authentication, fraud prevention, data subject security, platform security, compliance with legal obligations, contract execution, and regular exercise of rights.
Shortstay does not use selfies or facial data for advertising, profile sales, behavioral marketing, or any purpose incompatible with the reservation and platform security.
The reservation holder may register additional guests and, when requested by Shortstay, submit documents, registration data, selfies, identification information, or other data necessary for analysis, approval, security, release of access to the property, and compliance with the rules of the stay.
By submitting data or documents of additional guests, the reservation holder declares that they have authorization to provide them to Shortstay, that the information is true, complete and up-to-date, and that the respective additional guest is aware that their data may be processed in accordance with this Privacy Policy.
The submission of documents of an additional guest by the reservation holder does not transfer to the reservation holder the ownership of such data, nor does it generate an automatic right of access, copying, modification, deletion, or full receipt of documents, selfies, sensitive data, financial data, communications, or personal records of the additional guest.
Shortstay may inform the reservation holder only of operational data necessary for managing the stay, such as approval status, documentation pending, need for correction, authorization or refusal of additional guest, always observing the principles of necessity, security, purpose and data minimization.
The additional guest remains the holder of their own personal data and may exercise their rights directly with Shortstay through official privacy channels, subject to identity validation.
Shortstay may, at any time, request direct confirmation from the additional guest, new documents, selfie, identity validation or supplementary information, especially in case of inconsistency, suspected fraud, conflict between parties, use of third-party documents, security risk or legal compliance necessity.
Similarly, the additional guest shall not have automatic access to the personal data, documents, payments, contract, deposit, communications or financial information of the reservation holder, except where applicable legal basis exists, valid authorization is provided, proven operational necessity or order from competent authority.
We may process information related to:
payment method;
payment status;
billing history;
invoices;
receipts;
proof of payment;
payment dispute;
chargeback;
security deposit;
outstanding amounts;
fines, fees, consumption, maintenance, cleaning, or other charges related to the stay.
Complete credit card data may be processed directly by contracted payment providers, in accordance with applicable security rules.
When the User accesses the Shortstay website, application, or digital channels, we may collect:
IP address;
date and time of access;
device identifiers;
device model;
operating system;
browser;
login records;
usage logs;
approximate location or precise location, when authorized;
technical data necessary for account security;
error logs, failures, and security events;
anti-fraud data related to platform usage.
These data are used for platform operation, technical support, security, audit, fraud prevention, and service improvement.
Shortstay may store and process:
messages sent by the User;
support requests;
complaints;
files, photos, videos and audio files sent through official channels;
service history;
internal communication records related to the case;
interactions necessary for maintenance, cleaning, inspection, billing, renewal, check-in, check-out or termination of the stay.
These records may be used for service provision, quality control, security, audit, defense of rights and investigation of misuse of channels.
To enable access to the property and compliance with condominium rules, we may process:
reserved unit;
check-in and check-out period;
names of authorized guests;
minimum data required by condominium, gatehouse, management company or condominium administrator;
authorized vehicle license plates;
visitor data, when required by condominium rules;
records of incidents, notifications or condominium fines linked to the stay.
Shortstay does not intentionally request sensitive data such as religion, political opinion, union affiliation, health data or sexual life.
However, for purposes of identity verification, security, fraud prevention and account authentication, Shortstay may process selfies, facial images and, where applicable, biometric data or facial identification elements.
The processing of such data shall be carried out with restricted access, specific purpose, proven necessity, security measures and retention limited to what is necessary to fulfill the purposes described in this Policy.
If the User voluntarily sends unsolicited sensitive information, Shortstay may disregard, restrict, anonymize or delete such information, except when its retention is necessary to comply with legal obligations, defend rights or investigate relevant facts.
Shortstay may process personal data for the following purposes:
create and manage User accounts;
identify the User and authorized guests;
analyze reservation requests;
validate documents;
verify identity through selfie or other methods;
prevent fraud, use of third-party documents, fake accounts, improper multiple accounts, and abusive chargebacks;
execute contracts and preliminary procedures;
issue invoices, receipts, charges, and tax documents;
process payments and deposits;
authorize check-in and property access;
communicate minimal data to condominiums, security gates, property managers, or administrators;
provide support to the User;
organize maintenance, cleaning, inspections, and additional services;
comply with legal, regulatory, tax, accounting, and contractual obligations;
exercise rights in judicial, administrative, or arbitration proceedings;
investigate misuse of the platform or support channels;
protect the security of Shortstay, Users, property owners, properties, and third parties;
improve the platform, fix technical issues, and enhance User experience;
maintain audit, security, and compliance records;
analyze operational, registration, financial, contractual, and security risks.
Shortstay processes personal data based on the applicable legal bases of the LGPD, according to the nature of the data and the purpose of processing.
The main legal bases used are:
execution of contract and preliminary procedures related to reservation;
compliance with legal or regulatory obligation;
regular exercise of rights in judicial, administrative or arbitral proceedings;
legitimate interest of Shortstay, especially for security, fraud prevention, audit, service improvement and platform protection;
consent, when required or appropriate;
credit protection, when applicable;
assurance of fraud prevention and data subject security in identification and authentication processes in electronic systems, when there is processing of biometric data or sensitive data related to identity verification.
When processing depends on consent, the User may revoke it through official channels. Revocation does not affect processing carried out previously in a valid manner, nor does it prevent data retention when another applicable legal basis exists.
Shortstay may conduct manual, automated, or semi-automated verifications to protect the platform and prevent fraud.
These verifications may involve:
comparison between submitted documents and registration data;
analysis of selfie and document;
validation of consistency between name, CPF, email, phone, device, IP, payment method, and usage history;
verification of related accounts;
analysis of suspicious behavior;
detection of use of third-party documents;
prevention of reservations made by a person other than the account holder;
prevention of improper chargebacks;
review of unusual, abusive, or security-incompatible requests on the platform.
Shortstay may use its own tools or third-party tools for automated document reading, data extraction, OCR, authenticity analysis, information comparison, selfie verification, anti-fraud validation, risk analysis, and support for operational decision-making.
Decisions related to fraud, risk, blocking, booking refusal, or access limitation may involve automated processing or support from technological tools. The User may request review through official channels, in accordance with applicable legislation.
Shortstay may maintain internal records of risk analysis, security controls, justifications for personal data processing, access audits, and impact assessments, where applicable.
Shortstay does not sell personal data.
Shortstay also does not provide documents, contracts, receipts, conversations, invoices, registration data, financial data, selfies, or personal information of a User to third-party requesters based solely on informal messages, verbal claims, extrajudicial notifications, WhatsApp contacts, generic emails, claims of kinship, allegations of professional relationship, or declarations that the person is a lawyer, attorney, representative, or interested party.
Personal data may be shared only when there is a legitimate purpose, proven necessity, and applicable legal basis.
Sharing may occur in the following circumstances:
Shortstay may provide the data subject with information about their personal data, subject to identity verification and applicable legal limits.
Requests made by a representative, attorney-in-fact, or lawyer do not generate automatic access to personal data.
Shortstay may analyze requests made by a legally constituted representative only when there is:
complete identification of the account holder;
complete identification of the representative;
valid document of the account holder;
valid document of the representative;
specific, valid, and compatible instrument of representation with the request;
express powers to request, receive, or handle personal data of the account holder;
confirmation of the authenticity of the request;
validation through the official channel indicated by Shortstay;
internal technical and legal analysis.
Generic, incomplete, or unverifiable powers of attorney lacking specific powers, expired, incompatible with the request, or presented through insecure channels may be refused.
Even when a power of attorney is provided, Shortstay may limit, deny, or redirect service if there is a risk to privacy, security, confidentiality, third-party rights, trade secrets, fraud prevention, internal investigation, legal obligation, or regular exercise of rights.
To enable access to the property and comply with condominium security rules, Shortstay may share only the minimum necessary data, such as names of authorized guests, length of stay, unit, vehicle license plate and other information strictly required for access and security.
Shortstay will not share complete documents, financial data, payment data, conversations, selfies or information beyond what is necessary for access and security, except as required by law, court order from a competent authority or duly justified circumstances.
Shortstay may share data with service providers contracted to perform activities necessary for operations, such as:
payment providers;
cloud storage;
systems hosting;
technical support;
information security;
electronic signature;
document verification;
fraud analysis;
OCR and automated document reading;
accounting;
legal advisory;
customer service;
maintenance, cleaning and inspection, when necessary for service execution.
These third parties shall process the data in accordance with Shortstay's instructions, contracted purpose, confidentiality obligation, security measures and applicable legislation.
Shortstay may share personal data when there is a legal obligation, court order, valid request from a competent authority, applicable administrative determination, or necessity to exercise rights regularly.
When legally permitted, Shortstay may inform the User about legal requests involving their data. Shortstay may contest requests deemed abusive, generic, disproportionate, vague, lacking apparent jurisdiction, or incompatible with the LGPD.
Shortstay adopts a restrictive data protection policy.
As a rule, personal information, documents, proof of payment, contracts, financial data, payment data, reservation data, and service history are handled directly with the reservation holder or the data subject.
The presentation of a power of attorney, extrajudicial notice, professional identification card, OAB number, legal email, or claim of acting as an attorney does not obligate Shortstay to provide personal data immediately.
Any request made by a third party will be subject to internal review and may be refused when:
the request does not originate from the account holder;
the identity of the requester cannot be confirmed;
the power of attorney does not contain specific powers;
there is a risk of undue data exposure;
the request involves data of other account holders;
the channel used is not secure;
the request is excessive, generic, or disproportionate;
there is a risk of fraud, harassment, intimidation, conflict between guests, or misuse of information;
disclosure could violate the LGPD, contract, confidentiality, or third-party rights.
Court orders, orders from competent authorities, or legally binding requests will be handled in accordance with the law, following validation by the responsible team.
Shortstay does not share personal data of Users due to private disputes, family conflicts, relationship problems, conflicts between guests, commercial disagreements, personal pressure, threats, intimidation, public exposure, or attempts at coercion.
Each account holder is responsible for their own personal data.
The reservation holder does not have automatic access to the complete personal data of additional guests, and additional guests do not have automatic access to the personal, financial, contractual, or registration data of the reservation holder.
Shortstay may restrict, suspend, or refuse data requests when identifying risk of misuse, harassment, persecution, undue exposure, fraud, conflict between parties involved, or violation of third-party rights.
Requests related to personal data must be submitted exclusively through Shortstay's official privacy channel.
Shortstay may redirect requests made via WhatsApp, chat, telephone, social media, generic email, or channels not intended for privacy to the appropriate official channel.
To protect personal data, Shortstay may require:
identification of the requester;
validation of email or telephone;
identification document;
confirmation of account ownership;
clear description of the request;
documents proving representation, when applicable;
additional information necessary to prevent unauthorized access.
Incomplete, insecure, generic, abusive requests, those incompatible with the LGPD or involving third-party data may be refused, limited, or redirected.
Shortstay adopts technical and administrative measures to protect personal data against unauthorized access, loss, alteration, improper disclosure, misuse, destruction, or inadequate processing.
The measures may include:
Profile-based access control;
Authentication;
Encryption or encipherment where applicable;
Environment segregation;
Audit logs;
Security monitoring;
Internal access limitation;
Contractual confidentiality;
Backups;
Permission review;
Incident analysis;
Team training or guidance;
Anti-fraud controls;
Internal security and compliance records.
Despite the measures adopted, no system is completely immune to risks. Should a relevant security incident involving personal data occur, Shortstay will adopt the appropriate measures in accordance with applicable legislation.
In the event of suspected or confirmed security incident involving personal data, Shortstay may:
investigate the nature and extent of the incident;
identify the data and data subjects potentially affected;
adopt technical and operational containment measures;
block suspicious access;
review permissions and activity logs;
communicate with data subjects or competent authorities, when required by applicable legislation;
preserve records necessary for investigation, audit, and defense of rights.
The communication of incidents, when necessary, shall observe criteria of risk, severity, nature of data involved, potential impact to data subjects, and applicable legal requirements.
Shortstay retains personal data only for as long as necessary to fulfill the purposes described in this Policy, respecting legal, regulatory, contractual, and rights defense deadlines.
As a general rule, data may be retained for up to 5 years after the termination of the relationship with the User, or for a longer period when necessary to:
comply with legal, tax, accounting, or regulatory obligations;
fraud prevention;
chargeback analysis;
defense in judicial, administrative, or arbitration proceedings;
investigation of violations of the Terms of Use;
protection of Shortstay, Users, property owners, properties, or third parties;
compliance with orders from competent authorities.
Selfies, documents, and identity verification records may be retained for the period necessary to prove the regularity of the reservation, prevent fraud, audit the hiring, protect platform security, and exercise rights.
When retention is no longer necessary, data will be deleted, anonymized, or blocked according to technical and legal criteria.
The data subject may request, through Shortstay's official channels:
confirmation of the existence of processing;
access to data;
correction of incomplete, inaccurate, or outdated data;
anonymization, blocking, or deletion of unnecessary, excessive, or improperly processed data in violation of the LGPD;
data portability, where applicable;
information regarding data sharing;
information on the possibility of withholding consent and its consequences;
withdrawal of consent, when processing is based on consent;
review of decisions made solely on the basis of automated processing, where applicable.
Shortstay may request additional information to confirm the identity of the data subject and protect their data against unauthorized access.
Some requests may be refused, limited, or partially fulfilled when there is a legal obligation to retain data, a need for contract performance, fraud prevention, credit protection, regular exercise of rights, trade secrets, third-party rights, or another applicable legal basis.
The User may request the deletion of their account or certain personal data.
Deletion will not be immediate when data retention is necessary to comply with legal obligations, contract execution, collection, audit, fraud prevention, investigation of misuse, chargeback, security, or regular exercise of rights.
When possible, Shortstay may anonymize or block data instead of deleting it, especially when complete deletion could compromise mandatory records or the defense of rights.
Accounts terminated due to fraud, use of third-party documents, violation of Terms of Use, non-payment, abusive chargeback, unlawful conduct, or operational risk may have data retained for the period necessary to prevent new fraud and to exercise rights regularly.
Shortstay may enter into Personal Data Processing Agreements, Data Processing Agreements, contractual amendments, or equivalent instruments with suppliers, service providers, operational partners, technology providers, cloud services, payment platforms, electronic signature tools, OCR, document verification, fraud prevention, customer service, maintenance, cleaning, inspection, accounting, legal advice, and other third parties that process personal data in the context of Shortstay's services.
These instruments may establish rules regarding the purpose of processing, data categories, confidentiality, information security, access limitation, retention, deletion, subcontracting, security incidents, cooperation with data subjects and competent authorities, international data transfer, and other obligations applicable to personal data protection.
When a third party acts as a personal data processor on behalf of Shortstay, it must process the data only in accordance with Shortstay's instructions, the contracted purpose, applicable legislation, the duty of confidentiality, and security measures compatible with the processing risk.
The existence of contracts, DPAs, or equivalent instruments with third parties does not authorize unrestricted sharing of personal data. All sharing shall be limited to the necessary purpose, applicable legal basis, and LGPD principles, including necessity, purpose, security, transparency, and data minimization.
Shortstay may use technology, storage, security, electronic signature, customer service, document analysis, processing, OCR, fraud prevention, or infrastructure providers located in Brazil or abroad.
When there is international transfer of personal data, Shortstay shall adopt protection mechanisms compatible with LGPD, including standard contractual clauses, recognized equivalent clauses, appropriate contractual, technical and organizational measures, or other applicable legal mechanism.
The Shortstay platform is intended for persons over 18 years of age.
Shortstay does not permit minors to create an account or make reservations in their own name. If misuse by a minor is identified, the account may be terminated and data processed in accordance with applicable legislation.
Data of minors eventually provided in the context of a family stay or condominium authorization shall be processed only to the extent necessary for reservation execution, security, property access, or compliance with legal obligation.
Shortstay may send communications related to reservation, contract, payment, check-in, check-out, support, maintenance, cleaning, inspection, security, collection, renewal, policy updates, and platform operation.
Shortstay does not use personal data for sending spam.
Promotional communications, when applicable, shall comply with applicable rules and may allow unsubscription when required.
Shortstay may amend this Privacy Policy at any time to reflect legal, technical, operational, or commercial changes.
The updated version will be published on Shortstay's official channels, with indication of the update date.
Continued use of the platform following publication of the new version indicates awareness of the updated Policy, without prejudice to specific communications when required by law.
This Policy is governed by the laws of the Federative Republic of Brazil, particularly by the General Law for the Protection of Personal Data — LGPD.
The Court of the District of Curitiba, State of Paraná, is hereby elected, except where mandatory legal provisions provide otherwise.
Requests related to personal data must be submitted exclusively through Shortstay's official privacy channel:
Email: [email protected]
To protect data security, requests submitted through generic channels, third parties, lawyers, family members, additional guests, or unidentified individuals may be redirected to the official channel and subjected to identity verification.