Privacy Policy
Last updated: 8 September 2026
This Privacy Policy describes what personal data the operator of Nesta (not yet configured) collects through Nesta, why, and what control you have over it. It describes what the application actually does — not a generic template.
Data we collect
- Account data: name, email, phone number, password (stored as a one-way hash, never in plain text), and profile photo.
- Verification data: if you verify your identity or a property, the submitted document is stored in private object storage referenced by an internal key — it is never exposed through a public URL and is only accessible to the review process and to you.
- Listing data (hosts): property details, photos and videos you confirm you have the rights to, pricing, and — kept separate from the public listing — the exact address, coordinates, and access instructions of the property.
- Booking and payment data: booking dates, guest counts, and payment confirmation from our payment provider. Nesta does not store your card details itself.
- Communications: messages sent between guests and hosts through Nesta, and reviews you write.
- Usage data: basic technical data generated by using the service (e.g. session identifiers needed to keep you signed in). Nesta does not run third-party analytics or advertising trackers — see our Cookie Policy for the full, exact list of what is actually set.
How we use it
- To operate the booking flow: creating, confirming, and managing bookings and payouts.
- To enforce location privacy: an exact address is only ever shared with a guest whose booking for that property is paid and confirmed.
- To verify identity and listings where you request or a check requires it.
- To respond to support requests and to review content that has been reported.
- To maintain security: rate-limiting logins, detecting abuse, and keeping an audit trail of sensitive account actions.
Who we share it with
We share the minimum necessary data with the third-party services Nesta relies on to function — for example, a payment provider to process a booking payment, an email/SMS provider to deliver verification codes and notifications, and a mapping provider to resolve addresses to coordinates. Each of these is documented, with exactly what data reaches it, in our third-party services disclosure. We do not sell personal data.
A host never receives a guest's phone number, email address, government ID, or payout information through Nesta. A guest never receives a host's phone number, email address, or identity document. An exact address is shared with a guest only once the conditions above are met.
Your rights and controls
- Access/portability: download a copy of your data at any time from your profile settings.
- Correction: update your name, phone, and other profile fields directly in your profile settings.
- Deactivation: disable your account's ability to sign in at any time from your profile settings.
- Deletion: full erasure of your data is handled by our support team rather than as an automatic self-service action, since booking, payment, and payout records often need to be retained for the other party's records or for accounting reasons. Contact us via the Contact page to request it.
Data retention
We keep account, booking, payment, and audit-log data for as long as your account is active and, after deactivation, for as long as a legitimate reason exists to keep it (such as a pending dispute, an unresolved booking, or an accounting/record-keeping need for the other party to a booking). Nesta does not currently run an automated data-deletion schedule — retention decisions are made case by case rather than deleted automatically after a fixed period.
Security
Passwords are stored as salted hashes, never in plain text. Two-factor authentication is available for password-based accounts. Sensitive account actions are logged to an audit trail. Session cookies are marked HTTP-only and, in production, are only sent over HTTPS.
Pending professional legal review
International data transfers, the specific legal basis for processing under frameworks such as GDPR or POPIA, and the data protection officer / regulator contact details that may be required in your jurisdiction have not yet been drafted and need review by a qualified privacy lawyer before this policy can be considered complete for any specific country.
Children
Nesta is not directed at children and accounts require being of legal age to contract.
Contact
Questions about this policy can be sent to the address on our Contact page.