Hostcraft
Privacy Policy
Last updated: 10 September 2026
1. Controller
- Name
- Foxwebcraft, obrt za računalne djelatnosti, vl. Stefan Flaschko
- Address
- Balančane 2, 21220 Trogir, Croatia / Hrvatska
- OIB
- 27108726414
- [email protected]
- Phone
- +49 1577 3125228
The controller for Hostcraft is Foxwebcraft.
2. Scope
This privacy policy explains how we process personal data when you visit the Hostcraft website, send a contact message, create a host account, pay for the service, or when we host a guest website for a host. Hostcraft can be used by private persons and by businesses.
On a live guest website the host is the controller for guest enquiries and bookings. We process that data as a processor for the host, as described in section 10 and in the Hostcraft terms.
3. Legal bases
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka, NN 42/2018). Depending on the case, processing is based on:
- Art. 6(1)(b) GDPR – performance of a contract or steps prior to entering into a contract
- Art. 6(1)(c) GDPR – compliance with a legal obligation
- Art. 6(1)(f) GDPR – legitimate interests, in particular operating, securing and improving Hostcraft and handling enquiries
We have not appointed a data protection officer.
4. Website and server logs
To deliver this website, the web server processes technical access data, which may include IP address, date and time of the request, requested URL, referrer, browser and operating system, and the amount of data transferred. This is necessary to provide the site, ensure stability and protect against misuse. Legal basis: Art. 6(1)(f) GDPR. Log data that is no longer required is deleted or anonymised, as a rule within 30 days, unless a longer retention is needed to investigate a security incident.
5. Cookies
We use strictly necessary cookies to keep you signed in to the host dashboard and the operator admin, and a functional cookie (`hc-theme`) to remember a design preference on demo pages. These cookies are not used for advertising. Legal basis: Art. 6(1)(f) GDPR and, for the login cookies, Art. 6(1)(b) GDPR. No consent banner is required for these cookies. You can delete cookies in your browser at any time.
6. Analytics (Umami)
On the Hostcraft marketing site and the host dashboard we use Umami, a privacy-focused analytics tool, self-hosted at umami.foxweb.dev. Umami is configured without tracking cookies and without identifying individual visitors. Typical data include pages visited, referrer, device type, browser and an approximate region. Full IP addresses are not stored for identification. Legal basis: Art. 6(1)(f) GDPR (understanding how the service is used and keeping it reliable). Guest websites of hosts do not load this script. We do not use Google Analytics, advertising pixels or similar marketing trackers.
7. Contact form
If you send the contact form or email us, we process the data you provide (typically name, email, phone and the content of the message) in order to handle your enquiry. Legal basis: Art. 6(1)(b) GDPR where the enquiry relates to a contract or pre-contractual steps, otherwise Art. 6(1)(f) GDPR. We delete enquiry data when it is no longer needed, unless statutory retention periods apply.
8. Host accounts
When you create a Hostcraft account we process your name, email, phone, password (stored as a hash), billing details you give us for invoices (address and, where relevant, OIB or VAT ID), legal name, property and accommodation content, bank details you enter so guests can pay you by transfer, and technical logs of your use of the dashboard. Purposes are providing the service, communicating with you, invoicing, and securing the account. Legal basis: Art. 6(1)(b) and (c) GDPR.
If you close your account we delete or anonymise account data that we no longer need, except records we must keep for accounting and tax law.
9. Billing (Stripe)
Subscriptions and setup fees are paid through Stripe. Stripe processes identification, payment and billing data as an independent controller or as our processor, depending on the processing. Stripe Payments Europe, Limited is established in the EU; Stripe, Inc. in the United States may receive data under the EU-US Data Privacy Framework or other safeguards under Articles 44 to 49 GDPR. Legal bases: Art. 6(1)(b) and (c) GDPR. We do not store full card numbers.
10. Guest bookings and enquiries (processor)
On a host’s published website, guests may send an enquiry or complete a booking request (name, email, phone, accommodation, dates, number of guests, message). We store this on behalf of the host, show it in the host dashboard, and may send transactional email to the guest and the host. We do not take payment from guests: they pay the host by bank transfer. The host is the controller; we are the processor (Art. 28 GDPR). The data-processing terms are part of the Hostcraft terms of service.
The demonstration website is operated by us. Sample booking pages do not create a real stay. Data entered there is used only to show how the product works and is not treated as a live booking.
11. Email
We send transactional email (enquiries, booking status, payment instructions, password reset links, account messages) through our email provider. Legal basis: Art. 6(1)(b) GDPR, or Art. 6(1)(f) GDPR for service messages needed to operate the platform. We do not send a marketing newsletter.
12. Recipients and third countries
We do not sell personal data. Data are disclosed only where necessary for the purposes above, where we use processors bound by Art. 28 GDPR (for example hosting, email, Stripe), or where we are legally obliged to do so. Recipients may also include tax advisors, banks and public authorities. We aim to use providers in the EU / EEA. Transfers to third countries take place only if an adequacy decision exists or appropriate safeguards under Articles 44 to 49 GDPR are in place.
13. Retention
Accounting and tax records are generally kept for eleven years under the Croatian Accounting Act (Zakon o računovodstvu). Other business correspondence and account data are retained only as long as needed for the purpose or for the assertion, exercise or defence of legal claims. Guest booking data is retained for the host for the duration of the hosting contract and as instructed by the host.
14. Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection, as provided by Articles 15 to 21 GDPR, and the right to lodge a complaint with a supervisory authority. We do not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR. To exercise your rights, email us at the address above. Guests who want to exercise rights about a booking should contact the host first; we will assist the host as processor.
15. Changes
We may update this privacy policy when our processing or the legal situation changes. The current version is always available on this page.