Fair processing for guests and hosts
Identity data moves on an encrypted stay link with a clear purpose: operate the stay and support local formalities you configure. Not a broadcast to a personal chat thread.
Europe · Origin
NextStay was created by European developers and frequent travellers who saw the same problem across many destinations: accommodation providers must collect and manage guest information, while arrival workflows still depend on personal messages and manual key handovers. Requirements vary across European countries and cities.
The story
NextStay started with people based in the European Union who build software for a living — and travel enough to see how accommodation really works between booking and sleep. On one trip you are the guest: tired after a flight, asked to photograph your passport into a stranger’s chat, or waiting on a pavement because the owner is stuck in traffic. On the next trip you talk to hosts: they want lawful check-in and calm arrivals, but the tools in front of them are still personal phones and improvised PDFs.
That gap — between what lodging rules expect in a given destination and what daily practice looks like — is why we built NextStay. Requirements vary across European countries and cities. We did not build a generic global PMS clone: NextStay is a Europe-first stay platform where verification can happen before the key turns, on a proper stay link, with GDPR-minded handling for everyone in the journey.
What we kept seeing
01
Hosts and cleaners asked for passport or national ID photos on WhatsApp, Telegram, or a private camera roll — convenient for the desk, risky for the guest, and hard to defend under GDPR minimisation and security expectations.
02
Requirements vary across European countries and cities — many destinations expect registration or identity confirmation before or at arrival. In practice, many short-lets still unlock first and sort formalities later — or skip the audit trail entirely.
03
Travellers landing late, hosts stuck in traffic, keys left under a mat, and hours wasted coordinating a physical handoff when the stay itself was already paid.
04
Codes sent too early, or held back so aggressively that guests wait outside — with no structured path to verify identity, house rules, and local formalities in one place.
The decision
We set out to replace the informal stack: WhatsApp ID photos, scattered house manuals, and meet-ups that punish both travellers and hosts. NextStay gives guests one encrypted stay dashboard for check-in, instructions, and services — and gives hosts a workspace that can hold verification before self check-in unlocks.
Local rules still differ by city and property type. Hosts remain responsible for what applies to their accommodation. Our job is to make the lawful, fair path the easy path — and to stay honest about what software can and cannot guarantee.
Related: EU security & compliance · Destination guides · Online check-in
Alignment
Europe is pushing for trustworthy digital services, stronger personal-data protection, and clearer short-term rental accountability. These are the threads we design against.
Identity data moves on an encrypted stay link with a clear purpose: operate the stay and support local formalities you configure. Not a broadcast to a personal chat thread.
Where hosts choose self check-in, NextStay is designed so formalities can complete before door instructions release — aligning operational practice with the lodging-accountability logic long present in Schengen materials.
As Member States implement short-term rental registration and platform data sharing under Regulation 2024/1028, operators need clean property identity and guest-journey records — not screenshots scattered across phones.
Europe’s tourism transition asks for digital tools that raise trust without erasing hospitality. We build for that middle path: calmer arrivals, clearer duties, no theatre of false legal guarantees.
References
Purpose limitation, data minimisation, integrity and confidentiality for personal data — including identity documents collected for lodging.
Lodging providers across Schengen states are expected to be able to account for who stayed where — the public-security logic behind many national guest-registration duties.
Harmonises how Member States collect and share short-term rental activity data via platforms where registration systems exist (applicable from 20 May 2026). It does not set EU-wide night caps; it does raise the bar for clean property identity and reporting readiness.
Sets duties for online intermediaries around transparency and a safer digital space. NextStay is built so accommodation operators can run guest journeys with clearer accountability than informal messaging channels.
Guidance amplifying lawful processing, fairness, and security expectations that inform how we design stay links, retention, and access to identity data.
Commission work on a greener, more digital, and more resilient European tourism ecosystem — where compliant digital check-in and trustworthy guest data practices belong.
This page explains product intent and European context. It is not legal advice. Hosts and operators should confirm local obligations with competent authorities and counsel. Official texts prevail over our summaries — follow the EUR-Lex and Commission links above for the binding wording.
Fair for every party
We will keep following EU data-protection principles and evolving lodging frameworks — so the stay link stays fair as the rules mature.