Privacy Policy
Version 3.0 · Effective: July 13, 2026
1. Data controller
Tim Draude SRL (Romania) is the data controller for personal data processed through Otiux, including otiux.com.
- Tax ID (CUI)
- 36387464
- Trade Register no.
- J03/1365/2016
- Registered
- 3 August 2016
- Registered office
- Strada Craiovei, parter, Complex Negoiu, Pitești, România
We are not required to appoint a Data Protection Officer under EU GDPR Article 37 for our current processing activities. Privacy requests are handled by our core team.
2. What we collect and why
2.1 Account data
| Data | Purpose | Retention |
|---|---|---|
| Email, name, password (hashed) | Account, authentication, support | While account active + 30 days after deletion |
| Phone (optional) | Profile / host contact if you add it | While account active |
| Profile photo | Public profile | Until you remove it |
| Language & country preference | Display currency, locale, emails | While account active |
2.2 Identity verification (optional)
| Data | Purpose | Retention |
|---|---|---|
| ID document images, selfie | Fraud prevention, trust badge | 90 days after review, then deleted |
| Verification status | Badge on profile / listings | While account active |
ID documents are stored encrypted (Cloudflare R2). Access is limited to authorised reviewers. They are not shared with other users or used for marketing.
2.3 Credits, unlocks, and payments
| Data | Purpose | Retention |
|---|---|---|
| Credit balance, transaction ledger | Service delivery, accounting | Up to 10 years (legal/accounting) |
| Unlock records (listing, dates) | Contact reveal, reviews eligibility | 3 years after stay period ends |
| Stripe payment references, amounts | Billing, refunds, tax | Up to 10 years |
| Card numbers | Processed by Stripe only — not stored by Otiux | — |
Otiux does not process or see lodging payments between host and guest — only credit pack purchases go through Stripe to us.
2.4 Communications and content
| Data | Purpose | Retention |
|---|---|---|
| In-platform messages | Host–guest communication | 3 years after last activity |
| Transactional emails | Account, unlocks, security | 2 years |
| Marketing emails | Newsletter (opt-in only) | Until unsubscribe |
| Listings, photos, reviews | Directory service | While published; reviews may be pseudonymised after account deletion |
| Check-in forms (guest → host) | Delivered to host; not used for Otiux marketing unless guest opts in | Per host retention practices |
2.5 Technical data
- IP address (anonymised or shortened after ~30 days where feasible)
- Browser, device, and operating system (user agent)
- Pages visited, referral source (aggregated analytics)
- Security and error logs
Used for security, abuse prevention, and improving the service.
3. Legal bases (EEA/UK users)
If you are in the EU, EEA, or UK, we rely on:
- Contract — to provide your account, credits, unlocks, and listings;
- Consent — optional ID verification, marketing emails, non-essential analytics cookies;
- Legal obligation — tax and accounting records;
- Legitimate interests — security, fraud prevention, aggregated analytics, and displaying reviews.
4. Who we share data with
4.1 Service providers (processors)
- Cloudflare Inc. — hosting (Pages, D1, R2, Workers). Primary storage in the EU. DPA: cloudflare.com/cloudflare-customer-dpa.
- Stripe Payments Europe Ltd. — credit purchases. Card data goes directly to Stripe. DPA: stripe.com/legal/dpa.
- Resend Inc. — transactional email (recipient address and message content). US-based with Standard Contractual Clauses / applicable transfer safeguards.
- Google Ireland Ltd. — Google Analytics 4 when you consent (EEA/UK) or
under our cookie policy elsewhere. Measurement ID:
G-KTVYZQYKRY.
4.2 Other Platform users
- Your public profile (name, photo, badges, average rating) is visible to others.
- After a credit unlock, the guest receives the host's phone, email, and WhatsApp (if provided). The host sees the guest's name and email.
- Reviews display your first name and profile photo next to your comment.
4.3 Authorities
We may disclose data when required by valid legal process (court order, law enforcement, tax authority) under applicable law.
We do not sell personal information. We do not share data for cross-context behavioural advertising.
5. International transfers
Most processing occurs in the EU. Some providers (email, analytics, CDN edge) may process data in the United States or other countries. Where required, we use Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, or equivalent safeguards.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or export your data, and to object to certain processing. Contact privacy@otiux.ro — we respond within 30 days (may extend by 60 days for complex requests with notice).
- Access & portability — receive a copy of your data in a structured format.
- Correction — fix inaccurate data (many fields editable in your profile).
- Deletion — delete your account; some billing records must be kept for legal retention and will be pseudonymised.
- Withdraw consent — for optional processing (ID verification, marketing, analytics cookies).
- Complaint — EEA/UK users may lodge a complaint with their local data protection authority.
We do not make solely automated decisions with legal or similarly significant effects about you.
7. Security
- HTTPS (TLS) on all connections.
- Passwords hashed with PBKDF2-SHA256 (unique salt per user).
- Session cookies: HttpOnly, Secure, SameSite=Lax, validated server-side.
- CSRF protection on forms; ID documents encrypted at rest.
If a personal data breach poses risk to your rights, we will notify you and relevant authorities as required by applicable law (e.g. within 72 hours under GDPR where applicable).
8. Children
Otiux is for adults 18+. We do not knowingly collect data from children. If you believe a minor has an account, contact privacy@otiux.ro and we will delete it.
9. Cookies and analytics
See our Cookie Policy for details. Essential cookies always run; analytics cookies require consent in the EEA/UK/CH via our banner.
10. Changes to this policy
We may update this policy. Material changes (new categories, new recipients, longer retention) will be notified by email or Platform notice where required. The version and date at the top always reflect the current text.
11. Contact
Privacy requests: privacy@otiux.ro · gdpr@otiux.ro (EEA requests).