Política de privacidad
Last update: 23/12/2025
1. Responsible for the Treatment
The person responsible for the processing of the personal data collected through this website, the mobile application “Jome Stays”/“GreetMe” and any other associated channel (hereinafter, together, the “Services”) is:
- Corporate name: New Places Management, S.L. (hereinafter,”NPM“,”Jome“,”we“or”The Company“).
- CIF: B70820014
- Registered office: Calle Maestro Gaztambíde 5, 03004 Alicante, Spain.
- Contact email: hello@jomestays.com
- Telephone: +34 667 233 244
- Data Protection Officer (DPO): NPM has not appointed a Data Protection Delegate because the assumptions provided for in Article 37 of the GDPR or in Article 34 of the LOPDGDD do not exist. Inquiries regarding privacy and the exercise of rights can be addressed to hello@jomestays.com.
2. Scope of application
This policy applies to the processing of personal data carried out by NPM in the following contexts:
- Navigation and use of the jomestays.com website.
- Registration and use of the mobile guest application.
- Reservations made directly with NPM or synchronized from third-party platforms (Airbnb, Booking.com, etc.).
- Online check-in process and mandatory documentary registration of travelers.
- Communications related to the stay (WhatsApp, email).
- Customer service and query management.
3. Personal data that we process
We process the following categories of personal data, depending on the context:
3.1. Registration and account details
- First and last name.
- Email address.
- Password (stored in encrypted form using hashing).
- Social login identifiers (Google, Facebook, Apple), when the user opts for these methods.
3.2. Reservation details
- Check-in and check-out dates.
- Number of guests and details of the holder of the reservation.
- Reserved property and, where appropriate, assigned room.
- Origin of the reservation (direct channel, Airbnb, Booking.com, etc.).
3.3. Data from the mandatory documentary registration of travelers (RD 933/2021)
In accordance with Royal Decree 933/2021 and public security regulations, we are legally obliged to collect and communicate to the Ministry of the Interior the following data from each guest over 14 years of age who spends the night in our accommodations:
- First name, first last name and, where appropriate, second last name.
- Sex.
- Date of birth.
- Nationality.
- Type and number of identity document (DNI, NIE, passport) and support number when applicable.
- Date of issue of the document.
- Full normal address (address, city, province, zip code, country).
- Landline and mobile phone.
- Email.
- Contract details: reference, dates, number of travelers, address of the establishment, total amount and method of payment.
- For children under 14 years of age: name, surname, gender, date of birth, nationality and kinship with the responsible adult.
3.4. Payment details
When a payment is made, the card details are not processed or stored by NPM. They are collected and processed directly by our payment service provider (Stripe), which complies with PCI-DSS standards. NPM only receives an identifier for the transaction and, where appropriate, the last four digits and the card’s expiration date for reconciliation purposes.
3.5. Communication data
- Content of the communications we have with the guest (email, WhatsApp, contact form).
- Telephone number used for WhatsApp communications.
3.6. Data for technical use
When you browse the website or use the application, we automatically collect:
- IP address.
- Type of device, operating system and browser.
- Pages visited, time spent and browsing patterns.
- Cookies and similar technologies (see our Cookie Policy).
3.7. Terms Acceptance Data
- Timestamp and proof of acceptance of the Terms and Conditions and of the reading of this Privacy Policy.
4. Purposes and legal bases of the treatment
We process your data for the following purposes, each with its corresponding legal basis in accordance with art. 6 RGPD:
PurposeLegal BaseData Processed to Create and manage your user accountExecution of a contract (art. 6.1.b GDPR) 3.1Manage your reservation and the provision of the hosting serviceExecution of a contract (art. 6.1.b GDPR) 3.1, 3.2, 3.4, 3.5Mandatory documentary registration of travelers and communication to the Ministry of the Interior Compliance with a legal obligation (art. 6.1.c RGPD), in accordance with RD 933/2021 and Organic Law 4/2015 on the Protection of Public Safety3.3 Comply with accounting, tax and commercial obligations Compliance with a legal obligation (art. 6.1.c GDPR), in accordance with tax regulations and the Commercial Code3.2, 3.4 Send you operational communications related to your reservation (confirmations, reminders, check-in instructions, access code, etc.) Execution of a contract (art. 6.1.b GDPR) 3.1, 3.2, 3.5 Respond to your queries through contact channelsExecution of a contract or pre-contractual measures (art. 6.1.b) or legitimate interest (art. 6.1.b), 3.5 Ensure the safety of the platform, prevent fraud and resolve technical incidentsLegitimate interest (art. 6.1.f GDPR) 3.1, 3.6Send commercial communications about new JME properties or servicesConsent of the interested party (art. 6.1.a GDPR), provided separately and revocable at any time3.1
Consequences of not providing data
The data of the mandatory documentary registration of travelers (section 3.3) They are from mandatory communication in accordance with RD 933/2021. The refusal to provide them legally prevents the formalization of the stay.
The data necessary for the creation of the account and the management of the reservation are essential for the provision of the service. The lack of optional data (for example, marketing) does not affect the provision of the contracted service.
5. Treatment of children’s data
The data of children under 14 years of age are only processed within the framework of the mandatory documentary registration of travelers (RD 933/2021), under the supervision and responsibility of the adult accompanying them, who must hold parental authority or guardianship.
Children under 14 cannot register their own account or make reservations. If a child under 14 years of age has provided data without the consent of their parents or guardians, they must inform us at hello@jomestays.com to proceed with its deletion.
6. Storage periods
We keep your data for the following periods:
- Data from the documentary record of travelers (section 3.3): 3 years from the end of the stay, in accordance with art. 7 of RD 933/2021. Once this period has elapsed, the data is automatically deleted or anonymized.
- Booking and billing information: during the term of the contractual relationship and thereafter during the applicable legal periods (in general, 6 years for commercial requirements of the Commercial Code and, for tax data, in accordance with tax regulations).
- User account details: as long as the account is active. In the event of prolonged inactivity or a request to cancel, the data is deleted or anonymized, without prejudice to the legal blocking applicable to those data that must be kept due to regulatory obligations.
- Operational Communications: for the time necessary to manage the consultation or stay and, thereafter, during the legal deadlines for formulating or defending against possible claims (in general, 5 years in accordance with the Civil Code).
- Data for sending commercial communications: until the interested party revokes their consent.
- Technical and security logs: 12 months
Once these periods have elapsed, the data will be irreversibly deleted or anonymized, unless its conservation is mandatory by legal imperative.
7. Recipients of the data
Your personal data may be communicated to the following recipients:
7.1. Transfers due to legal obligation
- Ministry of the Interior — SES.HOSPEDAJES System: mandatory communication of passenger registration data in accordance with RD 933/2021.
- Tax Administration, Social Security and other public bodies: when there is a legal obligation.
- State Security Forces and Bodies and Judicial Authorities: when they require it in the exercise of their powers.
7.2. Those responsible for the treatment
NPM uses service providers that process personal data in our name and on our behalf, subject to contracts for ordering treatment in accordance with art. 28 of the GDPR. The categories of managers are:
- Cloud infrastructure hosting services: Amazon Web Services
- Payment processor: Stripe Payments Europe Ltd. (Ireland).
- Transactional email sending services: Resend
- WhatsApp messaging services: Meta Platforms Ireland Ltd. and, where appropriate, associated technical providers.
- Hotel Management Systems (PMS) and Smart Locks: Amenitiz, Smart Orbita, Yacan or others, when applicable to the reserved property.
- Billing and accounting systems: Holded or others, when applicable.
- Social Authentication Services: Google, Apple, Facebook, when the user opts for those login methods.
7.3. We do not transfer data to third parties for commercial purposes
We do not sell, rent or transfer your personal data to third parties for commercial or advertising purposes.
8. International data transfers
Some of our suppliers may process data outside the European Economic Area (EEA), in particular in the United States. When this happens, we guarantee that the transfer is carried out with the appropriate safeguards provided for by the RGPD, mainly:
- Adaptation decisions of the European Commission, where they exist.
- Standard Contractual Clauses approved by the European Commission (SCC).
- Additional technical measures such as encryption in transit and at rest.
You can request a copy of the applied guarantees by writing to hello@jomestays.com.
9. Your rights
Under the GDPR and the LOPDGDD, you have the right to:
- Access: obtain confirmation of whether we are processing your data and, if necessary, access them.
- Rectification: correct inaccurate or incomplete data.
- Deletion (“right to be forgotten”): request the deletion of your data when they are no longer necessary or when you withdraw your consent, with the limitations derived from legal obligations (in particular, the 3 years of RD 933/2021).
- Limitation of treatment: request the limitation of treatment in certain cases.
- Opposition: object to processing based on legitimate interest or direct marketing.
- Portability: receive your data in a structured, commonly used and machine-readable format, and transmit them to another responsible party.
- Revoke consent: withdraw the consent given at any time, without affecting the lawfulness of the previous treatment.
- Not to be subject to automated decisions: that have legal or significant effects on you. NPM doesn’t make decisions like this.
How to exercise your rights
You can exercise any of these rights by sending a written request to:
- Email: hello@jomestays.com (with subject “Exercise of GDPR rights”)
- Postal mail: New Places Management, S.L. — Maestro Gaztambé Street 5, 03004 Alicante, Spain.
To verify your identity, we may request a copy of your identity document or additional information. We will respond to your request within the maximum period of One month upon receipt, extendable to an additional two months in cases of special complexity.
Complaint to the supervisory authority
If you consider that the processing of your data does not comply with the regulations, you have the right to file a complaint with the Spanish Data Protection Agency (AEPD):
- Jorge Juan Street, 6 — 28001 Madrid
- Electronic office: https://sedeagpd.gob.es
- Telephone: 901 100 099/91 266 35 17
We thank you that, before going to the AEPD, you try to resolve the issue with us by writing to us at hello@jomestays.com.
10. Data Security
NPM applies appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of communications using TLS.
- Encryption at rest of stored information.
- Role-based access control and audit logging.
- Pseudonymization when technically possible.
- Regular backups and recovery plans.
- Staff training in the field of data protection.
- Rigorous selection of suppliers and order contracts in accordance with art. 28 of the GDPR.
Despite the measures taken, no data transmission over the Internet can be 100% guaranteed. If you detect or suspect any security incident, please report it to us immediately at hello@jomestays.com.
11. Cookies
The website uses its own and third-party cookies for different purposes. For more information, see our Cookie Policy, where you can also manage your preferences.
12. Amendments to this policy
We may update this Privacy Policy to reflect legal, technical or business changes. Any substantial modification will be notified reasonably in advance through the website, the application or by email, as appropriate. The date of the last update appears at the beginning of this document.
13. Applicable Legislation
This policy is governed by applicable Spanish and European legislation, in particular:
- Regulation (EU) 2016/679 of the European Parliament and the Council, of April 27, 2016 (RGPD).
- Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
- Royal Decree 933/2021, of October 26, which establishes the documentary recording and information obligations of individuals or legal entities that carry out activities of lodging and renting motor vehicles.
- Organic Law 4/2015, of March 30, of the Protection of Public Safety.
New Places Management, S.L. — Last update: 23/12/2025