Safeguest Protect is live — $29 per stay. Up to $20,000 in eligible Protect benefits.Learn more

Privacy Notice

What we do with your data, in plain words.

Short version: we verify an ID, then delete it. Everything else is below, and this page keeps a permanent address so it can be linked to from anywhere.

Our data-protection standard

Wherever you are in the world, SafeGuest applies UK GDPR and EU GDPR-equivalent data-protection standards to Host and Guest personal data — not just the minimum required by local law. Our data-processing terms were developed with UK-qualified data-protection counsel following an EU-compliant legal review.

In practice that means strict purpose limitation, prompt breach notification, defined data-subject rights, and minimal retention: identity documents and biometric images are deleted immediately after the verification event completes. There is no such thing as GDPR certification, so we don’t claim it — we align with the standard and say exactly what we do.

About SafeGuest

SafeGuest FCZO (“SafeGuest”) is a company incorporated in the United Arab Emirates, with an address of IFZA Business Park, DDP, Premises Number - 46261 001, Dubai Silicon Oasis, Dubai, United Arab Emirates.

SafeGuest is a guest verification and risk management platform. By using biometric liveness screening and ID verification, Safeguest can provide hosts and property managers of short-term rental bookings with data points to enable them to assess the risk of a stay.

SafeGuest acts primarily as a processor when providing guest verification and risk scoring services on behalf of Property Managers, who remain the Data Controllers at all times.

SafeGuest acts as the Data Controller of any personal information we collect to manage our internal business operations, website, and marketing activities.

SafeGuest commits to processing your personal information in accordance with all applicable laws, including the UK and EU General Data Protection Regulations (GDPR) and the Data Protection Act 2018 (DPA 2018).

What is personal data?

The term “personal data” means any information relating to you as an individual, that identifies you, or through which you can be identified, either directly or indirectly. In particular, by reference to an identifier such as a name, an identification number, location data, or an online identifier or to one or more factors specific to your physical, physiological, genetic, mental, economic, cultural, or social identity.

The purpose of this Privacy Notice

The purpose of this Privacy Notice is to let you know how we process your personal data. This Privacy Notice explains what personal data we collect from you and how we collect, use, store and disclose it. It also contains information about your rights under applicable data protection legislation.

We are committed to compliance with data protection laws. We believe that ensuring data protection compliance is the foundation of trustworthy business relationships.

It is important that you read this Privacy Notice together with any other Privacy Notice we provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Privacy Notice supplements the other notices and is not intended to override them.

How do we use your personal data?

We process your personal data for the purpose of providing SafeGuest services. The data we process will include personal identifiers such as your name, contact details, and, where necessary, may include some sensitive personal data. Sensitive personal data, also referred to as Special Category personal data, is defined as data that needs more protection due to its inherently sensitive nature. Additional obligations are placed on the Data Controller and/or Processor under Article 9 of the UK GDPR for them to process Special Category personal data lawfully.

When we are acting as a processor, we will only process your personal data on the strict instruction of the Data Controller. Where we are acting as a Data Controller, we will only use your personal data for the purpose we collected it. In all cases, we will only use your personal data in accordance with the law. We will not use your personal data for any other purpose without your prior consent. The only exception to this is if it is required or permitted by law.

How do we process your personal data?

Reservation details: SafeGuest is provided with guest personal data from booking forms and reservation details, which includes data such as the date and duration of guest stays, party size, and amount paid. This is accomplished through direct API integration with the property manager’s Property Management System (PMS). We process this data to verify guest identity, administer Damage Deposits and the No Deposit Option on behalf of property managers. We also process data from booking forms to provide risk scoring of guests to property managers. SafeGuest processes guest data (name, email, telephone, and patterns in guest behaviour) solely on the instruction of the property manager.

Guest Verification: To verify guest identity and mitigate fraud, SafeGuest engages a secure third-party specialist identity verification provider. This involves: (1) Document verification — guests provide an image of Government-issued ID; the name and address are checked against booking details. If an address is not available, the provider may use the guest’s network IP address to obtain a broad location to compare with ID. (2) Biometric matching — guests provide a live selfie, mathematically compared to the photograph on the ID. (3) Mobile number verification — via SMS or WhatsApp.

For all areas of guest verification, the Data Controller (property manager) determines the lawful basis. Your ID and selfie are securely transmitted, used only for ID verification, and securely deleted once verification is complete. SafeGuest does not retain any verification data beyond fulfilment of the verification.

Guest Risk Assessment Profiling: SafeGuest provides property managers with a guest risk assessment service, processing Reservation Details and Guest Verification data to supply actionable risk scores. SafeGuest may, on instruction from property managers, utilise a proprietary AI agent to perform sentiment assessments of previous reviews on guest Airbnb profiles. Sentiment data will not be retained by SafeGuest following provision of the service. Safeguest functions as a temporary pass-through and dashboard platform — sensitive identity data does not persist, and isn’t stored or extracted by our systems once the verification event is complete. We do not use automated decision-making tools; decisions regarding stays and risk thresholds are defined solely by the Property Manager.

Cookies: The SafeGuest website uses cookies. ‘Cookies’ are small files that websites store on your device to remember information about you. SafeGuest uses cookies to operate and administer the website and to target marketing. See the SafeGuest Cookie Policy for details and consent options.

Business Agreements, Sales, and Partnerships: We process personal data from individuals within our associates, clients, vendors, suppliers, and partners primarily to establish, manage, and fulfil our contractual obligations. The categories of data collected include professional contact details, financial details (for invoicing, where necessary), and technical access data.

Employment Opportunities: If we advertise a job posting or you are interested in working as a contractor for us, we may process your name, contact information, CV, cover letter, publicly available profiles, and references. If you let us know about a disability or health condition (or provide us with any other special category data), we will process this data under our legal obligations in relation to employment and equality laws.

Our legal bases for processing your data

When we process your data to verify identity and assess stay-related risks, we are doing so as a Data Processor on the instruction of the Data Controller (Property Manager), who defines the legal basis.

Where we are collecting data directly from you (B2B relationships, employment, website visits), we may be acting as a Data Controller. Our legal bases are: (a) your consent; (b) contractual obligation; (c) legal obligation; (d) vital interest; (e) public task; (f) legitimate interest.

For special category data, we additionally rely on a condition under Article 9 UK GDPR: explicit consent; employment, social security and social protection; vital interests; not-for-profit bodies; data made public by the data subject; legal claims or judicial acts; substantial public interest; health or social care; public health; or archiving, research and statistics.

Do we share your data?

SafeGuest may share your data with other organisations as an essential part of business operations, under appropriate data protection contractual agreements.

Where instructed by the Data Controller, your selfies and government-issued ID may be shared with our verified third-party provider, for the purposes of biometric identity checks and ID verification.

Once verification is completed, SafeGuest will return the verified contact information to the Property Manager, either directly or through integrations with their chosen PMS.

In some jurisdictions, there is a statutory requirement to share guest identity with centralised lists, such as the Alloggiati Web platform maintained by the Italian State Police. Under instruction from the Property Manager, SafeGuest may automatically extract guest credentials from booking data to complete these administrative requirements on their behalf.

Do we transfer your data internationally?

SafeGuest is incorporated in the United Arab Emirates. Personal data may be transferred and processed in the UAE. We may also use third-party service providers located outside the UK or EEA.

For service provision, SafeGuest utilises data centres based in France. The UK recognises France as providing an adequate level of data protection.

If we transfer your personal data out of the UK or EEA, we ensure appropriate technical and organisational measures: only allow personal data to be processed in countries which the European Commission have confirmed have adequate protection; and/or enter into appropriate contracts which the European Commission have confirmed provide adequate protection.

How long do we keep your personal data (Data Retention)?

We only retain your personal data for as long as is necessary to fulfil the purpose of processing, including for the purposes of satisfying any legal, accounting, or reporting requirements.

Guest Verification data processed on behalf of property managers is returned to the Data Controller on completion of the verification, unless we are legally required to retain it by law enforcement, a court, or regulatory authorities.

Where we have legal obligations (e.g. financial reporting) to keep your data beyond its immediate use, this will never be longer than the industry standard period.

Business or contractual personal data used in our internal business operations will generally be retained for no more than six years after the end of the contract.

Marketing

We may send you marketing communications about our products and services. Where we rely on Legitimate Interest, we may send B2B marketing emails to corporate contacts where we believe our products are relevant to your professional role. We may also contact you by telephone, provided your number is not on the UK CTPS list.

You have the absolute right to object to processing of your personal information for marketing purposes at any time. Email support@SafeGuest.ai to change your marketing preferences.

Security of your personal data

We implement appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk involved in gathering guest data, verification, and risk assessment. These may include: encryption in transit and at rest; role-based access controls and authentication; secure, industry-standard cloud storage; and ongoing monitoring and testing of our security measures.

Your Rights

Your rights vary depending on whether we are acting as a Processor on behalf of Property Managers, or as Controller. Because we do not retain data related to guest verification or risk assessment, requests to access, delete, or correct this information must be directed to the Data Controller (Property Manager).

Subject Access Request — you have a right to receive a copy of personal data we hold about you. Email support@SafeGuest.ai.

Rectification — if data is incomplete or inaccurate, you have a right to have it corrected.

Erasure (right to be forgotten) — you can ask us to delete your personal data where there is no good reason for us to continue processing it.

Objection — you can object where we rely on legitimate interests; you have an absolute right to object to direct marketing.

Restriction — you can ask us to restrict processing in certain circumstances.

Portability — you can ask us to transfer personal data you have provided to another party in a structured, commonly used, machine-readable format.

Right to withdraw consent — where processing is based on consent, you can withdraw it at any time.

We do not use automated decision-making tools. To exercise any of your rights, contact support@SafeGuest.ai. If you are not satisfied with our response, you can complain to the ICO at https://ico.org.uk/make-a-complaint/.

Questions? Email support@safeguest.ai.