st8ay ← Back to st8ay
Privacy

Privacy Policy

Last updated: July 31, 2026  ·  Effective: July 31, 2026

Who we are

st8ay is a product of QROMO OÜ, a company registered in Estonia (registry code: 17480292), with its registered address at Narva mnt 5, 10117 Tallinn, Estonia. QROMO OÜ is the data controller for the personal data described in this policy.

Questions about this policy or your data can be sent to team@qromo.xyz.

Who this policy applies to

This policy covers three groups of people, since st8ay connects them:

  • Guests — people who scan a QR code at a property and view or claim offers.
  • Hosts — property owners or managers who use st8ay to set up campaigns and local partnerships.
  • Local partners/merchants — businesses that redeem vouchers or offers guests bring them.

What we collect

From guests

  • Scan event data: which QR code was scanned, timestamp, and the property/campaign it belongs to.
  • Device and browser information (type, approximate location derived from IP, language) needed to show the offer page correctly.
  • If you choose to save rewards or use the mobile app: a phone number or email address, and your reward/redemption history.
  • If you use the embedded wallet feature: wallet address and transaction history connected to rewards you've claimed.

We do not require guests to create an account or provide personal information just to view or claim a first offer — that only happens if you choose to save rewards for later.

From hosts

  • Account information: name, business name, contact details, billing information for paid plans.
  • Property and campaign data you enter: property details, offers, local partner information you add.
  • Usage data: how you use the dashboard, campaign performance you view.

From local partners/merchants

  • Business name and contact details provided by the host or during onboarding.
  • Redemption logs: which vouchers were redeemed, when, at which location.

How we use it

  • Operate the core service — showing guests the right offers, letting hosts run campaigns, letting merchants confirm redemptions.
  • Distribute rewards and vouchers, and keep an accurate record of what's been claimed and redeemed (this also prevents duplicate or fraudulent redemptions).
  • Show hosts and merchants analytics about their own campaigns and redemptions — hosts and merchants only see data connected to their own properties or offers, not other hosts' guests.
  • Communicate with hosts and merchants about their accounts, and with guests who've opted in to save rewards.
  • Maintain security, detect abuse, and comply with legal obligations.

We do not sell personal data to third parties.

Legal basis for processing (GDPR)

Since QROMO OÜ is based in Estonia, the EU General Data Protection Regulation applies. We process data on these bases:

  • Contract necessity — processing needed to actually deliver the offer, reward, or dashboard functionality you're using.
  • Legitimate interest — fraud prevention, service security, and improving the product, balanced against your rights.
  • Consent — for anything not covered above, such as optional marketing communications, which you can withdraw at any time.

Who we share data with

  • Hosts see scan, claim, and redemption data connected to their own properties — this is the core function of the product (attribution). They do not see a guest's full identity unless the guest has chosen to share contact details with them directly.
  • Local partners/merchants see redemption confirmations for their own offers only.
  • Service providers who help us run the platform: hosting, cloud infrastructure, payment processing, and analytics providers. These providers are bound by contract to only use data to provide their service to us.
  • Legal and safety — if required by law, or to protect the rights, safety, or property of QROMO OÜ, our users, or the public.

A note on wallets and blockchain rewards

If you use the embedded wallet feature or receive a reward via a blockchain-based reward rail (for example, Solana, USDC, or EURC), be aware that transactions on public blockchains are, by their nature, recorded on a public, permanent ledger. This is different from a normal database entry — a wallet address and its transaction history can potentially be viewed by anyone, though it is not directly linked to your name unless you've connected that wallet elsewhere. We do not control the underlying blockchain and cannot delete or alter transactions once they're confirmed on-chain, even if you later request deletion of your account data with us.

This section needs specific legal review — the "right to erasure" under GDPR and the immutability of blockchain records is a genuinely unresolved tension that a lawyer should address directly, particularly before any real-money or mainnet transactions go live.

Cookies and similar technology

The browser-based scan experience uses cookies or similar local storage to keep track of your session (for example, so a claimed voucher shows correctly if you revisit the offer page).

[TBD] Insert specifics once the actual cookie/analytics stack is finalized — this section should list actual cookie names/purposes/durations once known, and if any non-essential analytics or advertising cookies are used, guests need a consent banner before those load, not just a policy mention.

International data transfers

[TBD] This needs a real answer: where is your hosting/cloud infrastructure located? If any data is processed or stored outside the EU/EEA, this section needs to name the safeguard in place — typically Standard Contractual Clauses — and should not be published as-is until it names the actual infrastructure provider(s) and has been checked.

Data retention

We keep personal data only as long as needed for the purposes described above — for example, redemption logs for as long as needed for fraud prevention and host reporting, and account data for as long as your account is active plus a reasonable period after closure for legal and accounting purposes.

[TBD] Insert specific retention periods once decided — GDPR expects concrete timeframes, not just "as long as necessary."

Your rights

If you're in the EU/EEA (and in many other jurisdictions with similar protections), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data (subject to the blockchain limitation noted above, and any legal retention requirements).
  • Object to or restrict certain processing.
  • Request a portable copy of your data.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local data protection authority — in Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — aki.ee.

To exercise any of these rights, contact us at team@qromo.xyz.

Children's privacy

st8ay is not directed at children, and we don't knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we'll remove it.

Security

We use reasonable technical and organizational measures to protect your data.

Do not list specific certifications, encryption standards, or security frameworks here unless they are actually true and verified — an inaccurate security claim here is a real liability, not just a marketing exaggeration.

Changes to this policy

We may update this policy as the product evolves. We'll update the "last updated" date above, and for material changes, we'll make a reasonable effort to notify hosts and registered guests directly.

Contact

QROMO OÜ
Narva mnt 5, 10117 Tallinn, Estonia
team@qromo.xyz

st8ay™ is a product of QROMO OÜ, Estonia. © 2026 QROMO OÜ.  ·  Back to st8ay