Every reservation that runs through Best Guest carries sensitive personal data — passport numbers, home addresses, signatures. Guests hand this over because the law requires it, not because they enjoy it, which is exactly why we treat their trust as something to protect, not just collect.

Here’s a short summary of how that plays out in the platform.

Encryption, by default

Guest data is encrypted both at rest and in transit. Database storage is kept isolated from application services, and the encryption keys that protect it are managed separately from the data itself — so access to one doesn’t mean access to the other.

Access on a need-to-know basis

A guest can only see the information they personally submitted. Guests traveling on the same reservation don’t automatically see each other’s records — sharing only happens through an explicit invitation. On the host side, role-based permissions (owner, manager, member, cleaner) mean staff only see what their role actually requires.

Built for GDPR from the start

Best Guest was designed around European data protection expectations: data minimization, purpose limitation, and storage within the EU. We collect what’s needed for check-in and legal reporting — nothing more — and we support hosts in meeting their own reporting obligations, like foreigner registration (UbyPort) and accommodation tax.

Read the full breakdown

This post is a summary. For the complete picture of what we process, how it’s protected, and the principles behind it, see our Security & Trust Center.

Questions about security or compliance? Reach out at privacy@bestguest.cz.