Privacy Policy

Veerelo · Legal

Privacy Policy

What we collect, why we collect it, and the rights you have over your data.

Last updated: 24 June 2026Version 1.0

1. Who we are

Veerelo ("we", "us", "our") operates the Veerelo platform, a marketplace that connects travelers and accommodation hosts. This Privacy Policy explains how we collect, use, share and protect personal data when you use our website, mobile apps and related services (the "Platform").

For the purposes of the EU/UK GDPR and the Israeli Protection of Privacy Law, 5741-1981, Veerelo is the data controller of personal data processed through the Platform. You can reach our privacy team at legal@veerelo.com.

2. Account information & login methods

Veerelo supports the following login methods, each of which causes different data to be collected:

  • Email & password: we store your email address and a salted hash of your password (we never see the plain-text password).
  • Google sign-in: Google shares your basic profile information (name, email, avatar URL, locale) with us under the scopes you approve.
  • Apple sign-in: Apple shares your name and email (or a private relay email if you choose) under the scopes you approve.

In all cases we also store your display name, handle, profile photo, language preference, accepted Terms version and the time you accepted our Terms.

3. Profile & content

We process content that you choose to add or upload, including biographical information, location, interests, photos, videos, stories, comments, reviews and messages.

User-generated content (photos, videos, reviews) is public by default on the Platform unless you mark it as followers-only. Do not upload personal data of others without their consent.

4. Booking & host information

When you make or receive a booking we process: travel dates, guest counts, message threads between Guest and Host, booking status, refunds and cancellations, and the listing involved.

Hosts additionally provide property details (address, photos, amenities, pricing, calendar). Exact addresses are revealed to Guests only after a booking is confirmed.

5. Payment information

Payments are processed by regulated third-party payment service providers. Veerelo does not store full card numbers on its own servers. We receive limited transaction data such as the last four digits of the card, brand, billing country, payment status and provider transaction IDs.

Our payment providers act as independent or joint data controllers for the payment data they process. Please consult their privacy notices for details.

6. Device & usage data

We automatically collect technical information when you use the Platform, including IP address, device type, operating system, browser, app version, locale, referring URLs, pages viewed, clicks, search queries and crash reports.

We use this data to operate, secure and improve the Platform, prevent fraud and abuse, and produce aggregated analytics.

7. Cookies & similar technologies

We use first-party cookies, local storage and similar technologies for essential functionality (authentication session, language preference, fraud prevention), analytics (understanding feature usage), and performance (caching).

Where required by law we will request your consent for non-essential cookies. You can manage cookies through your browser settings; disabling essential cookies may break parts of the Platform.

8. Analytics

We use privacy-conscious analytics tools to measure how the Platform is used in aggregate (sessions, popular listings, conversion funnels, search performance). We do not sell your personal data.

We may engage processors such as cloud hosting providers, error monitoring services, and product analytics tools, who process data on our behalf under contractual safeguards.

9. Communication preferences, marketing & push notifications

We use the contact details and devices linked to your account to send three categories of messages:

  • Transactional messages — booking confirmations, payment receipts, security alerts, host or guest replies and platform notices. These are required to operate your account and cannot be opted out of while the account is active.
  • Marketing communications — emails, in-app messages and other promotional content about new features, recommendations and offers. We send these only with your consent where required by law, and you can unsubscribe at any time via the link in the message or from Settings → Notifications.
  • Push notifications — when this feature becomes available, the Platform may send push notifications to your device (e.g. new messages, booking updates, host activity). Push notifications are sent only after you grant permission at the operating-system level, and you can disable them at any time from your device settings or from Settings → Notifications.

You can manage your communication preferences and notification channels at any time from Settings → Notifications.

10. How we share data

We share personal data only as needed:

  • Between Guest and Host: name, profile photo and message contents needed to operate the booking.
  • Service providers (hosting, payments, analytics, customer support, email/SMS delivery) acting as processors under written agreements.
  • Regulators, law enforcement or other parties when required by law, to enforce our Terms, or to protect rights, safety and security.
  • Successors in the event of a corporate transaction (merger, acquisition, restructuring), subject to confidentiality safeguards.

We do not sell your personal data and we do not share it for cross-context behavioural advertising.

11. International transfers

Personal data may be stored and processed in Israel, the European Economic Area, the United Kingdom and other jurisdictions where our service providers operate. Where transfers leave the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

12. Data retention

We retain personal data only for as long as needed for the purposes described in this Policy, to comply with our legal obligations, resolve disputes and enforce our agreements.

Account data is retained while your account is active and for a reasonable period afterwards. Transactional records (bookings, payments, tax invoices) are retained for the periods required by applicable tax and consumer-protection law (typically 7 years in Israel).

13. Your rights

Depending on your jurisdiction, you have rights to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to processing; data portability; and withdraw consent at any time. Users in Israel additionally have rights under sections 13–15 of the Protection of Privacy Law.

To exercise these rights, contact legal@veerelo.com from the email address linked to your account. We may need to verify your identity. You also have the right to lodge a complaint with your local data-protection authority.

14. Security

We implement administrative, technical and organisational measures to protect personal data — including encryption in transit (TLS), encryption of secrets at rest, role-based access controls, audit logging and routine vulnerability monitoring. No method of transmission or storage is 100% secure.

If we discover a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant authorities as required by law.

15. Children

The Platform is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal data, please contact us so we can delete it.

16. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app and may require renewed acceptance. The "Last updated" date above reflects the latest revision.

17. Contact us

For any privacy-related question, request, or complaint, contact us at legal@veerelo.com. We aim to respond within 30 days.

Privacy questions? Reach our team at legal@veerelo.com — we respond within 30 days.