MINTApartments

Privacy Policy

Last updated: July 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

MINT Apts. – Timo Schalow

Blumenthalstr. 4

10783 Berlin

E-Mail: [E-Mail geschützt]

2. Collection and Storage of Personal Data

a) When visiting the website

When you access our website, information is automatically sent to our website server by the browser used on your device. This information is temporarily stored in a so-called log file. The following information is recorded without your intervention and stored until automatic deletion: IP address of the requesting computer, date and time of access, name and URL of the retrieved file, website from which access is made (referrer URL), browser used and, if applicable, the operating system of your computer and the name of your access provider.

The aforementioned data is processed by us for the following purposes: ensuring a smooth connection to the website, ensuring comfortable use of our website, and evaluating system security and stability. The legal basis for data processing is Art. 6 (1) sentence 1 lit. f GDPR.

b) When making a booking

For booking an apartment, we collect the following data: first and last name, email address, phone number (optional), travel period and number of guests. This data is required for the fulfillment of the accommodation contract. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment).

c) When contacting us

When you contact us by email or via a contact form, the data you provide (e.g. name, email address, message content) is stored by us to answer your inquiry. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR or Art. 6 (1) sentence 1 lit. f GDPR.

d) When booking a parking space

If you additionally book a parking space, we collect your vehicle license plate number. The purpose is the management and allocation of the parking space. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment).

3. Payment Processing via Stripe

We use the Stripe service (Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA) for payment processing. Stripe processes your payment data (e.g. credit card number, expiry date, CVC) on their own servers and is subject to PCI DSS Level 1 standards. We do not receive or store complete credit card data. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment). For more information, see Stripe's privacy policy at:

https://stripe.com/de/privacy

3a. Digital Check-in and Registration Form

As part of our digital check-in process, we collect the following data: first and last name, nationality, email address, phone number and estimated arrival time. This data is required for the fulfillment of the accommodation contract (Art. 6 (1) sentence 1 lit. b GDPR).

For foreign guests, we additionally collect the following in accordance with § 29/30 of the German Federal Registration Act (BMG): home address (street, house number, postal code, city, country), date of birth and names of accompanying persons. This data is recorded on the electronic registration form. The legal basis is Art. 6 (1) sentence 1 lit. c GDPR (legal obligation).

Security Deposit via Stripe

To protect against possible damage, you store a payment method for a security deposit during the digital check-in. Processing is handled by our payment service provider Stripe. The deposit is reserved on your card as a pre-authorization at check-in and is not charged; for longer stays the reservation may be renewed. It is released after the stay, provided there is no damage. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment).

ID Verification via Stripe Identity

As part of the digital check-in, we conduct – depending on the booking channel – digital ID verification through the Stripe Identity service (Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA). The following data is processed: photo of the ID document and data extracted from it (name, date of birth, document number, nationality). Verification is carried out solely by means of the ID document; no selfie comparison takes place. This data is processed and stored directly by Stripe. We only receive the verification result (verified/not verified) and the extracted basic data.

The legal basis for ID verification is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment) in conjunction with Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest in fraud prevention and identity verification). Insofar as Stripe processes special categories of personal data within the meaning of Art. 9 GDPR as part of the document check, this is based on your explicit consent pursuant to Art. 9 (2) lit. a GDPR, which you give in the Stripe Identity dialog. For more information about data processing by Stripe Identity, see:

https://stripe.com/de/privacy

4. Booking Management via Smoobu

We use the Smoobu service (Smoobu GmbH, Berlin) for managing our bookings and checking availability. As part of a booking, your contact data (name, email, phone number) and booking data (period, apartment, number of guests) are transmitted to Smoobu. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment). Smoobu processes your data according to their own privacy policy.

5. AI-Assisted Guest Communication (Chatbot and Voicebot)

Messages that you send us as a guest via booking platforms (e.g. Airbnb, Booking.com) or our communication channels are processed in part automatically using AI services in order to answer your inquiries efficiently and promptly. This involves processing the content of your messages as well as associated booking context data (e.g. booking period, apartment, name).

For this purpose we use the following services:

  • ElevenLabs (ElevenLabs Inc., USA) – voice dialogue/voicebot for voice-based guest support.
  • Google Gemini (Google LLC, USA) – text-based chatbot “Minty” for the automated answering of text messages.
  • Anthropic/Claude (Anthropic PBC, USA) – classification of messages to decide whether handling by a staff member (human escalation) is required.

The purpose of the processing is automated guest support and communication. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (fulfillment of the accommodation contract) and Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest in efficient and prompt guest support).

ElevenLabs, Google and Anthropic process the data (also) in the USA. For the safeguards for this transfer to a third country, see Section 14 “Transfer to the USA”.

No automated decision in an individual case producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR takes place; the AI serves to prepare and answer your inquiries, with a staff member taking over where necessary.

6. Keyless Access via Nuki

For keyless access to your accommodation we use the Nuki access system (Nuki Home Solutions GmbH, Graz, Austria). For this purpose we generate guest-specific, time-limited access codes and process door logs, i.e. the times of entries (locking and unlocking events). The purpose is to enable access to the accommodation and the security of the property. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment) and Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest in property security).

7. Invoicing and Accounting via Lexoffice

For creating invoices and for our accounting we use the Lexoffice service (Haufe-Lexware GmbH & Co. KG, Freiburg, Germany). For this purpose we transmit your name, address, email address and booking/service data to Lexoffice. The purpose is proper invoicing and compliance with commercial and tax retention obligations. The legal basis is Art. 6 (1) sentence 1 lit. c GDPR (legal obligation) and Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment).

8. Translations via DeepL

To translate content and messages – in particular in multilingual guest communication – we use the DeepL service (DeepL SE, Cologne, Germany). Insofar as the content to be translated contains personal data (e.g. the content of guest messages), it is transmitted to DeepL. The purpose is cross-language communication with you. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment) or Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest in comprehensible communication). DeepL processes the data on servers within the European Union.

9. File and Photo Storage (Supabase)

Files and photos uploaded within the scope of our services – including photos that guests upload in connection with reviews – are stored with the Supabase service (Supabase, Inc.). The purpose is the technical provision and storage of this content. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR (contract fulfillment) or Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest in providing the feature). Insofar as storage takes place outside the EU/EEA, the safeguards under Section 14 apply.

10. Reviews and Tips

On our team/review page you have the option to leave a review and optionally give a tip. This involves processing your review (review content/text) and any uploaded photos (see Section 9). Only your first name becomes publicly visible. The payment of a tip is processed via our payment service provider Stripe (see Section 3). The legal basis is Art. 6 (1) sentence 1 lit. a GDPR (consent) or – for the payment processing – Art. 6 (1) sentence 1 lit. b GDPR.

11. Hosting

This website is hosted by an external hosting provider. Personal data collected on this website is stored on the host's servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact data, names, website accesses and other data generated via a website. The legal basis is Art. 6 (1) sentence 1 lit. f GDPR.

12. Cookies and Web Analytics

a) Technically necessary cookies

Our website uses technically necessary cookies that are required for the operation of the website (e.g. language settings, cookie consent status). Consent is not required for technically necessary cookies (Art. 6 (1) sentence 1 lit. f GDPR).

b) Google Analytics 4

We use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to analyze website usage. Google Analytics uses cookies that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transferred to a Google server and stored there.

Google Analytics is only activated when you expressly consent via our cookie banner. The legal basis is Art. 6 (1) sentence 1 lit. a GDPR (consent). You can revoke your consent at any time by deleting your cookie settings in your browser. For more information, see Google's privacy policy at:

https://policies.google.com/privacy

c) Vercel Analytics and Speed Insights

We use Vercel Analytics and Vercel Speed Insights (Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA) to analyze website usage and measure website performance (Web Vitals such as loading time, interactivity and visual stability). Vercel Analytics collects anonymized page view data without the use of cookies and without collecting personal data. No individual visitors are tracked. The legal basis is Art. 6 (1) sentence 1 lit. f GDPR (legitimate interest in optimizing our website). For more information, see Vercel's privacy policy at:

https://vercel.com/legal/privacy-policy

13. Recipients and Processors (Overview)

The following overview lists the service providers to whom we transmit personal data for the purposes described above, or who process such data on our behalf:

RecipientPurposeLocation / Processing
Stripe / Stripe IdentityPayment processing, deposit, ID verificationUSA
Smoobu (Smoobu GmbH)Booking managementEU (Germany)
VercelHosting, website analyticsUSA
Google (Analytics 4, Gemini)Web analytics, AI chatbotUSA
ElevenLabsAI voicebotUSA
AnthropicAI classification / escalationUSA
Nuki (Nuki Home Solutions GmbH)Keyless accessEU (Austria)
Lexoffice (Haufe-Lexware)Invoicing, accountingEU (Germany)
DeepL (DeepL SE)TranslationsEU (Germany)
Supabase (Supabase, Inc.)File and photo storageEU/USA

14. Transfer to the USA (Art. 44 et seq. GDPR)

Some of the services we use process personal data (also) in the USA, a third country within the meaning of the GDPR. This concerns in particular: Stripe and Stripe Identity (payments, ID verification), Vercel (hosting/analytics), Google (Google Analytics 4, Google Gemini), ElevenLabs (voicebot) and Anthropic (message classification), as well as possibly Supabase (file/photo storage, depending on the storage region).

For these transfers to the USA we rely on the Standard Contractual Clauses adopted by the European Commission (Art. 46 (2) lit. c GDPR) and – where the respective provider is certified – on the EU-U.S. Data Privacy Framework (adequacy decision of the EU Commission, Art. 45 GDPR).

We point out that a level of data protection equivalent to European law cannot be guaranteed in the USA. In particular, there is a residual risk that US authorities may access your data without you having effective legal remedies against this. The transfer takes place on the basis of the aforementioned safeguards or – where applicable – your explicit consent pursuant to Art. 49 (1) lit. a GDPR.

15. Your Rights

You have the following rights with respect to the personal data concerning you:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)

To exercise your rights, please contact us using the contact details provided above.

16. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR. The supervisory authority responsible for us is:

Berlin Commissioner for Data Protection and Freedom of Information

Friedrichstr. 219

10969 Berlin

17. Storage Period

Personal data is deleted as soon as the purpose of storage no longer applies. For booking and invoicing data, there is a retention obligation of 10 years in accordance with commercial and tax law requirements (§ 257 HGB, § 147 AO). Contact inquiries are deleted after final processing and at the latest after 6 months, provided there are no legal retention obligations.

Registration form data is retained for one year in accordance with the statutory periods of the German Federal Registration Act and subsequently deleted on time. From the ID verification we only receive and store the verification result and the extracted basic data for the duration of the contractual relationship. The ID images and the associated personal verification data stored with Stripe are irrevocably deleted there (redaction) as soon as the security deposit is released after check-out, and at the latest a few days after departure; if the deposit is withheld due to a damage claim, deletion takes place once the claim has been settled. The text data legally required for the registration form (name, date of birth, document number) remains stored in accordance with the German Federal Registration Act. Access codes and door logs are deleted promptly after the stay, unless they are required to clarify a specific incident.

18. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy. The new privacy policy will then apply to your next visit.