borrou

Privacy policy

Last updated: 15 September 2026

This is a courtesy translation. The binding version of this policy is the Spanish one, available at borrou.es/privacidad. In the event of any discrepancy, the Spanish text prevails.

1. Data controller

The controller of the personal data collected through borrou.es is Alejandro Carvajal Martínez, resident in Santa Cruz de Tenerife (Spain). Contact address for data protection matters: info@borrou.es, through which the controller’s remaining identifying details may be requested.

This policy has been drawn up in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

2. Data we process and where it comes from

We process only the data that the user provides themselves and the data generated by use of the service:

Identifying dataName, email address, phone number where provided, and profile photo where uploaded.
Verification dataThe result (verified or not verified) of the identity check process. The documentation and the facial image are supplied directly to the verification provider; the Platform neither accesses nor keeps them.
Transaction dataBookings, dates, amounts, fees, incidents and reviews. Full card details are supplied directly to the payment institution; the Platform keeps only a payment identifier and the last four digits where the institution provides them.
Published contentListings, item photographs, photographs of the condition at handover, messages exchanged in the chat, and reviews.
Usage and security dataTechnical error logs, and an identifier derived from the IP address by means of a keyed hash function, used exclusively to limit abusive requests. The IP address is not stored in the clear.
Location dataThe town or approximate area associated with a listing. Precise device geolocation is not collected.

3. Purposes and legal bases

Providing the serviceManaging registration, publishing listings, handling bookings, processing payments and transfers, and enabling communication between users. Basis: performance of the contract (art. 6.1.b GDPR).
Verifying identityChecking that whoever books is who they say they are, as an anti-fraud and safety measure for the other party. Basis: performance of the contract and legitimate interest in preventing fraud (arts. 6.1.b and 6.1.f).
Resolving incidentsReviewing damage, delays and claims, using the handover photographs and the messages attached to the booking. Basis: performance of the contract and legitimate interest in resolving disputes.
Complying with legal obligationsAccounting and tax obligations and retention of payment records. Basis: legal obligation (art. 6.1.c).
Service communicationsNotices about bookings, payment, returns and incidents. Basis: performance of the contract. No marketing communications are sent without prior consent.
Platform securityError detection, abuse prevention and rate limiting. Basis: legitimate interest in ensuring the security of the service.

4. Retention periods

Data is kept for as long as is strictly necessary for each purpose and, thereafter, blocked and available to the competent authorities for the applicable limitation periods:

Account dataFor as long as the account remains active. Once deletion is requested, it is erased or irreversibly dissociated, except for data subject to the periods below.
Bookings and payment recordsSix (6) years from the transaction, under article 30 of the Spanish Commercial Code, and four (4) years for tax limitation purposes (Law 58/2003).
Messages, handover photos and incidentsUp to five (5) years from the end of the rental, the limitation period for personal actions under article 1964 of the Spanish Civil Code, given their evidential value in the event of a claim.
Published reviewsFor as long as the listing or the reviewed account remains active. When the author closes their account, the review is kept dissociated from their identity.
Error logsNinety (90) days, after which they are deleted automatically.
Rate-limiting identifiersThirty (30) days, after which they are deleted automatically.

5. Recipients and processors

Personal data is neither sold nor transferred to third parties for advertising purposes. It is disclosed only to the providers needed to deliver the service, which act as processors and are bound by contract under article 28 GDPR:

Supabase Inc.Database, authentication and file storage. Data is hosted in European Union data centres (eu-west region).
Vercel Inc.Application hosting and aggregated web analytics. Server functions run in European Union data centres.
Stripe Payments Europe, Ltd.Payment processing, transfers to owners and identity verification. Stripe acts as an independent controller in respect of payment data, under its own policy.
Resend, Inc.Sending the service’s emails.
Functional Software, Inc. (Sentry)Logging and diagnosis of application errors.
OpenStreetMap FoundationConverting coordinates into town names when a listing is published.

In addition, certain data is shown publicly by the very nature of the service: the name, profile photo, length of time on the Platform, the verified-identity badge and the reviews received are visible on the public profile. No other data is accessible to other users.

6. International data transfers

Some of the providers listed are based in the United States. In such cases transfers are covered by the Standard Contractual Clauses approved by the European Commission and, where applicable, by the adequacy Decision on the EU-US Data Privacy Framework, together with any supplementary measures required. Further information about those safeguards may be requested by writing to info@borrou.es.

7. Automated decisions

The identity verification process is carried out automatically by the relevant provider and its result determines whether a booking can be completed. A user whose verification is refused may request human intervention, express their point of view and contest the decision by writing to info@borrou.es. No other automated decisions with legal effects are made, and no profiling is carried out.

8. Rights of data subjects

You may exercise at any time the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent given, by writing to info@borrou.es stating the right you wish to exercise. The request will be dealt with within a maximum of one month, extendable under article 12.3 GDPR.

Many of these rights can be exercised directly from the application: profile data can be changed at any time and the account can be deleted from the profile editing section.

If you consider that the processing does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid - www.aepd.es).

9. Cookies and similar technologies

The Platform uses only technical cookies necessary to keep the session open and to ensure safe browsing, which are exempt from the consent requirement under article 22.2 of Law 34/2002.

The usage analytics used are aggregated and use neither cookies nor persistent identifiers, so they do not allow individual users to be recognised. No advertising or third-party profiling cookies are used. Should any be added in future, prior consent would be requested through the appropriate mechanism.

10. Security measures

Technical and organisational measures appropriate to the risk are applied, in accordance with article 32 GDPR, including:

  • Encryption of communications in transit and of stored data.
  • Row-level access control in the database, so that each user can access only the information that belongs to them.
  • Minimisation: the Platform stores neither full card numbers nor identity documents, which are handled directly by the specialised providers.
  • Restricted access to handover and incident photographs, which are served through temporary links and are not publicly accessible.
  • Pseudonymisation of the IP addresses used for rate limiting.
  • Logging and review of errors and anomalous access.

In the event of a personal data breach entailing a risk to the rights and freedoms of data subjects, the Spanish Data Protection Agency will be notified within 72 hours and, where appropriate, so will the people affected, in accordance with articles 33 and 34 GDPR.

11. Minors

The service is not aimed at minors and its use is reserved to those aged 18 and over. If an account belonging to a minor is detected, it will be deleted immediately.

12. Changes to this policy

This policy may be updated to adapt it to regulatory changes or to how the service evolves. Any change will be published on this page with an indication of its update date and, where it substantially affects the processing, users will be informed beforehand.

13. Contact

For any question about this policy or about the processing of personal data: info@borrou.es. The conditions of use of the service are in the terms and conditions.