Binding language version
This page is an English translation for reference and convenience only. If there is any difference between this text and the German StayBooking Privacy Policy (Datenschutzerklärung für StayBooking), the German version prevails. The English text has no independent legal standing.
Related documents
1. Scope and relationship to Wilken Privacy
This StayBooking Privacy Policy describes how Wilken UG (haftungsbeschränkt) (“Wilken”, “we”) processes personal data when you purchase or license StayBooking or use the related checkout, license server, customer area, or support features.
The general Wilken UG Privacy Policy also applies (including website visits, cookies, and contact forms). For StayBooking purchase and licensing, this StayBooking policy prevails in case of conflict; otherwise the Wilken Privacy Policy continues to apply.
Contractual terms for StayBooking are available in the supplementary StayBooking Terms.
2. Controller at Wilken
Controller for the processing described in this policy in connection with purchasing and licensing StayBooking: Wilken UG (haftungsbeschränkt), managing director Tim Wilken, Braugasse 14C, 50859 Cologne, Germany, email: info@wilken.solutions. Further details are in the legal notice on wilken.solutions.
3. Responsibility for guest and booking data on your website
StayBooking runs on your own WordPress installation. Personal data of your guests and other end users (e.g. name, contact details, booking details, payment references) collected via StayBooking on your website is generally processed by you alone as controller on your infrastructure. Wilken does not store such guest and booking data on its own servers for your business purposes.
You must inform your guests and website visitors about your processing, establish legal bases, and obtain consents where required. Wilken is not the controller of your hotel website’s content, tracking technologies, or privacy practices.
4. Data at purchase, account, and customer area
At checkout and for contract performance we process in particular: login email address, optional separate billing email, first and last name, company name (business customers), customer type (private/business), billing address (street, postal code, city, country), VAT/tax ID (business customers), domain labels (license identifiers/apex domain), selected plan (monthly/yearly), number of licenses, license keys, checkout batch ID, license/subscription status, and the timestamp and version of the accepted StayBooking Terms and StayBooking Privacy Policy.
In the customer area you may maintain profile and billing data; changes are stored in our systems and synced to Stripe where required. You may optionally set a customer-area password (stored as a hash, not in plain text).
Purposes: concluding and performing the contract, licensing, support, billing, abuse prevention, and evidence of acceptance. Legal bases: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (legitimate interest in secure operation and auditability).
5. Customer area access
We offer magic-link email login and optional password login for the customer area. Magic links are time-limited and used for authentication. After successful sign-in we set a strictly necessary session cookie to recognize you in the customer area; it does not contain plain-text passwords.
If the billing email differs from the login email, the billing email may receive limited dashboard access (invoices, payment methods, billing details) — magic link only, no password. The account owner (login email) manages licenses and technical settings.
To prevent abuse we temporarily store hashed identifiers (e.g. IP address, email) for rate limits on login requests.
Legal bases: Art. 6(1)(b) GDPR (contract/customer area use) and Art. 6(1)(f) GDPR (security).
6. Payments (Stripe)
Payments are processed via Stripe. Depending on configuration, Stripe processes payment data (e.g. card or payment-method details) as an independent controller and/or as a processor. Wilken does not store full card numbers on its own systems. We store Stripe customer and subscription IDs, invoice/receipt references, and payment status as needed for the contract and accounting.
Tax may be calculated automatically via Stripe Tax; Stripe then processes data required for tax calculation (e.g. country, VAT ID where applicable). In the customer area you can download invoices/receipts and manage payment methods via the Stripe customer portal.
See Stripe Privacy for more information. Legal bases: Art. 6(1)(b) GDPR; tax/retention duties may rely on Art. 6(1)(c) GDPR.
7. License server, plugin updates, and logs
To activate, periodically validate a license, and provide plugin updates, your WordPress installation may contact Wilken’s StayBooking license server. Processed data may include: license key, domain/hostname of the active installation, plugin version, timestamps, validation result, and technical connection data (e.g. IP address in server logs).
Guest or booking records from your WordPress database are not transmitted to Wilken. Wilken does not create backups of your operational booking data.
Purposes: contract performance, abuse prevention, update delivery, support. Legal bases: Art. 6(1)(b) and (f) GDPR. Logs are retained only as long as needed for security and traceability, then deleted or anonymized unless longer statutory periods apply.
8. Forms and support
StayBooking pages (checkout, cancellation, customer area) may use forms for cancellation requests (email, domain, optional reason) or support requests (subject, message, page URL).
Legal bases: Art. 6(1)(b) GDPR (contract/support) and Art. 6(1)(f) GDPR (security).
9. Emails
We send transactional emails (e.g. purchase confirmation, license information, magic links, invoice/receipt delivery, cancellation confirmation, support notifications) via Resend where configured, otherwise via WordPress/hosting mail.
Legal basis: Art. 6(1)(b) GDPR. Marketing emails only where consent or another lawful basis exists.
Emails to guests relating to bookings (e.g. booking confirmations) sent by StayBooking on your website are sent by you as controller via your own infrastructure or services you configure — not by Wilken, unless expressly described otherwise.
10. Recipients and processors
Recipients may include hosting provider (wilken.solutions), Stripe (payments), Resend (email), and Wilken staff who need access for support and operations. Where required, we conclude data processing agreements under Art. 28 GDPR.
See the current StayBooking Subprocessor List.
11. Retention
We store contract and billing data for the duration of the relationship and thereafter as required by statutory retention rules (e.g. commercial and tax law). License and validation data are kept while the license is active and thereafter as needed for evidence, defense of claims, or legal duties.
Session cookies and magic links expire automatically when their validity period ends. Password hashes remain stored until you change or remove the password or the account is no longer needed.
12. Your rights
You have rights under Art. 15–21 GDPR (access, rectification, erasure, restriction, portability, objection) and may withdraw consent with effect for the future where processing is based on consent. Contact info@wilken.solutions. You may lodge a complaint with a supervisory authority; for Cologne/NRW typically the LDI NRW.
Guest requests relating to booking data are directed to you as controller on your website; Wilken can handle such requests only to the extent they concern our own license and contract data.
13. Changes
We may update this StayBooking Privacy Policy when the product, technology, or legal requirements change. The current version is available at this URL; the last-updated date appears above.
Last updated: 2026-08-17