The Quarters

Privacy Policy

Last updated: Jul 6, 2026

The Quarters is a property-management system for mid-term apartment rentals. Property operators (each an "organization" on the platform) use it to manage their properties, reservations, guest communication and contracts. This policy explains what personal data the platform processes, why, and how long it is kept. It covers both signed-in users (staff of an organization) and guests whose bookings an organization manages here.

What we process

Account data: your name, email address and password hash, plus session and sign-in records (including IP address) kept for security. Booking data, entered by staff or received from a connected website: guest names and contact details, stay dates, pricing, tenancy agreements and their signing status, and a log of the automated emails sent about a stay. Signing evidence: when a tenancy agreement is signed electronically we record the signature itself (the drawn image, or the typed legal name), the date and time, the signer's IP address and browser, and a checksum of the document. This is what makes the signature provable, and it is kept for as long as the agreement. Website inquiries: the contact details and message a prospective guest submits. Connected mailbox: where an organization connects its own shared guest mailbox (Outlook or Gmail), we keep an index of the correspondence in it (who wrote to whom, when, the subject line and a short preview) so that a guest's replies appear alongside their booking. We do not store the contents of those messages: the text of a message is fetched from your mail provider at the moment you open it and is not retained. Disconnecting the mailbox removes the index.

Why we process it

To run the bookings an organization manages: planning arrivals, departures and cleaning, sending contracts for signature, and emailing guests about their stay (performance of the rental agreement). Security records and the audit log serve our legitimate interest in keeping accounts and data safe. Financial booking records are kept to meet legal (tax) obligations.

Who receives data

Data is shared only with the service providers needed to run the platform: hosting and database infrastructure, an email delivery service (for guest and account emails), a contract-signing service (for tenancy agreements) and object storage (for property photos). Each acts as a processor on our instructions. Property and availability data an organization chooses to publish goes to its own public website. Where an organization connects its own mailbox, that mail is read from Microsoft or Google under a permission that organization grants and can withdraw at any time; those providers act for the organization rather than for us. We never sell personal data or use it for advertising.

How long we keep it

Reservation records, including the tenancy agreements, their signing evidence and the guest-email log that belong to them, are kept for seven years after the stay, matching the Dutch fiscal retention duty for business records. Website inquiries that do not become a reservation are removed at the latest twelve months after they were submitted. Account data is kept until the account is deleted; security and audit records for twelve months, except the audit trail of contract signings, which belongs to the agreement and follows the same seven-year term. Backups expire on a rolling schedule.

Your rights

Under the GDPR you can ask for access to, correction or deletion of your personal data, ask us to restrict or object to processing, and request a copy in a portable format. Guests can direct requests to the organization managing their booking (the data controller); account holders to their organization's administrator. Deletion cannot cut short the legal retention of financial booking records. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

How data is protected

Access is role-based and scoped per organization: staff see only their own organization's data. Connections are encrypted in transit. Sign-ins are rate-limited and recorded, and administrative actions are written to an audit log.

Contact

For questions about this policy or a privacy request, contact the organization that manages your booking. For stays booked through a connected website, its contact details are on that website. Account holders can reach their organization's administrator directly.

Changes

We update this policy when the platform's data processing changes, and adjust the date above. Material changes are announced to organization administrators.

© 2026 The Quarters

ennl