Privacy Policy
Last updated: 4 September 2026 · Controller: Paris Al Shiblawi trading as live-1.life, Cardiff, United Kingdom · info (at) live-1.life · Sole trader
Paris Al Shiblawi, trading as live-1.life, is currently the Data Controller for the personal data processed through the live-1.life marketplace, under the UK GDPR and the Data Protection Act 2018. live-1.life is currently operated as a sole-trader business by Paris Al Shiblawi. The business may be incorporated as a limited company in the future. If the legal entity responsible for operating live-1.life changes, this Privacy Policy will be updated to identify the new data controller and explain any relevant changes.
ICO registration: we are reviewing our obligations to the Information Commissioner's Office (ICO), including whether a data protection fee is payable. Where registration or payment of the ICO data protection fee is required, we will complete it and publish the relevant registration details when available. You can verify registered controllers through the ICO's public register at ico.org.uk.
Data protection contact: live-1.life does not currently have a statutory Data Protection Officer. Privacy questions, data protection concerns and data-subject rights requests can be sent to Paris Al Shiblawi at info (at) live-1.life with the subject line “Data Request”.
Data we collect
- Guest and host accounts: name, email address, an encrypted password (or a Google/Apple sign-in identifier if you use one) and, where you give it, a phone number.
- Host business details: the information you add to your host profile, and the ownership or permission documents you upload when you apply to list.
- Listings: photographs, descriptions, location and map coordinates, pricing, availability and facilities.
- Bookings and messages: dates, guest numbers, the message you send with a booking request, booking status and the emails we send about a booking.
- Payments: card details never reach our servers — Stripe processes them. We store the payment status, amounts, and Stripe's own reference for the payment.
- Technical and usage: IP address, browser type, pages visited and, if you accept analytics cookies, aggregated usage statistics.
How we use it, and our lawful bases
- Creating and running your account, listings, booking requests and messages — contract.
- Taking deposits and handling refunds through Stripe — contract.
- Sending service emails about accounts and bookings — contract.
- Reviewing host applications and listings, preventing fraud and keeping the site secure — legitimate interests.
- Understanding how the site is used through Google Analytics — consent, given through the cookie banner.
- Marketing emails, only where you opt in — consent.
- Keeping accounting, tax and dispute records — legal obligation.
Who we share data with
We do not sell your data. Hosts do not see a guest's email address or phone number until the booking is confirmed — that is, once a deposit has been paid or the host has accepted the request. Until then the host sees only the dates, party size, first-line details and the message. After confirmation the host receives the contact details needed to perform the booking. Guests see the host details needed to arrive and stay.
The providers we actually use are listed below. Where a provider's exact legal role under UK data protection law has not yet been confirmed against their current documentation or contract terms, we say so rather than state it as a fact.
- Lovable Cloud — website hosting, database, sign-in, file storage, and the managed delivery of our service emails. Acts on our instructions; the exact contractual terms are to be confirmed.
- Neo — the email provider behind our info address mailbox and our domain email records. Acts on our instructions; the exact contractual terms are to be confirmed.
- Stripe — Stripe is our payment services provider. Deposits are charged to our Stripe account, and hosts are paid through Stripe Connect: a host creates a Stripe connected account and provides their identity and bank details directly to Stripe, which holds and verifies them. Stripe's legal role for each activity, its data-processing locations and any international transfer mechanisms are to be confirmed against Stripe's current documentation and terms.
- Google — Google Maps for the maps on listing pages, and Google Analytics where you have accepted analytics cookies. Google's legal role for each of these services is to be confirmed against Google's current terms.
We may also disclose data where the law requires it, including to Action Fraud or the police. We do not share personal data with any provider we do not use.
International transfers
Some of the service providers we use may process personal data outside the United Kingdom. We have not yet confirmed the specific countries involved, or the specific transfer safeguards each provider relies on, so we do not state them here. Where a transfer outside the UK takes place, we will identify and document appropriate safeguards as required under the UK GDPR, and we will update this policy with those details once they are confirmed.
How long we keep it
- Account data: while your account is open, and for up to 12 months after you close it so that we can deal with any late query, then deleted.
- Listings and host documents: while the listing is live, and for 12 months after it is removed, so we can show what we checked and when if a complaint is made.
- Bookings, payments and refunds: 6 years from the end of the relevant financial year, because these records may be needed for legal, accounting, tax, dispute and record-keeping purposes. The exact period is to be reviewed by a UK solicitor.
- Emails about bookings: 24 months, so that we can evidence what was sent if a booking is disputed.
- Technical logs: 12 months, for security and fault investigation.
Your rights
Under the UK GDPR you have the rights below. Each of them is subject to the conditions and exemptions set out in the UK GDPR and the Data Protection Act 2018, so whether a right applies depends on the circumstances and on the lawful basis we rely on. We will normally respond within one calendar month of receiving your request, and will tell you if we need longer because the request is complex.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion of your data. This generally applies where we no longer need it, or where we rely on consent and you withdraw it, and not to records we are required to keep.
- Restriction — pausing our use of your data, for example while we check an accuracy dispute.
- Objection — you can object to processing based on our legitimate interests, and we will stop unless we can show compelling grounds. You can object to direct marketing at any time and we will stop.
- Portability — a machine-readable copy of data you gave us, generally where we process it by consent or under a contract, by automated means.
- Withdraw consent — for analytics cookies or marketing, at any time, without affecting anything done before you withdrew it.
- Automated decisions — we do not make decisions about you by automated means alone that have a legal or similarly significant effect.
Email us with the subject line “Data Request” at info (at) live-1.life or use the contact form.
Cookies
Essential cookies, including the ones that keep you signed in, are always on. Analytics cookies are only set after you accept them in the cookie banner — until then the analytics tag is not loaded at all. You can change your choice at any time by clearing this site's data in your browser, and the banner will appear again. See our Cookie Policy.
Complaints
Please contact us first. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
This wording is written in plain UK English. It should be reviewed by a UK solicitor, along with our Terms & Conditions, Host Terms and Trust & Safety wording, before launch and before the first real booking is accepted. Publishing these documents does not by itself mean live-1.life is legally compliant.