Privacy
Last updated: 11 September 2026
This page says what Bellbee stores about people, who else can see it, how long it is kept, and what you can ask us to do with it.
Who is responsible
Bellbee is a trade name of a sole trader registered in the Netherlands at Smakkelaarsveld 79, 3511 EB Utrecht. Chamber of Commerce 50812904, VAT NL001124200B52.
You can reach us through the contact form or at [email protected].
Two different roles
Bellbee handles personal data in two ways, and the difference decides who you ask about what.
For visitors to this site, people who write in, and the person who signs a property up, we decide what is collected and why. We are the controller, and this page is your notice.
For guests who send a request, and the team inside a customer's account, the property decides what is asked and recorded, and why. They are the controller and we only act on their instructions. If you stayed somewhere that uses Bellbee, or work for one, ask that property, not us. What we commit to as their processor is written into the terms.
No cookies, no third party
What we store in your browser, what we count, and who else is told.
Bellbee sets no cookies at all. There is no advertising, no tracking pixel, no social button and no third party script anywhere on this site, the guest pages or the console. The fonts are served by us. Nobody outside Bellbee is told that you were here, and there is no consent banner because there is nothing to consent to.
We do count page views on this site, ourselves. When you open one of these pages, your browser tells our own server which page it was, which site you followed a link from if you came from one, and which browser you are using. We look at it to see which pages people read and which ones are not worth keeping.
Nothing in that record names you. So that we can tell one person reading three pages from three people reading one, we turn your IP address, your browser and today's date into a single short code. The date is part of it, so the code is a different one tomorrow and today's reading cannot be joined to any other day's. We erase the IP address after thirty days.
This is the public side of the site, which includes the sign-in and sign-up pages. Guest pages, the request list and the console are not counted at all. None of these records holds your name, your email address, or anything else that points at your account.
Signing in stores two things in your own browser, in local storage rather than in a cookie: a session token, and the name and role we show in the corner of the screen. They are needed for you to stay signed in, they never leave your device except as the token on requests you make, and signing out removes them. The request list also remembers a few choices for that device, such as whether it plays a sound.
A guest's phone keeps a short code for each request it sent, for about 48 hours, so it can show whether the request is on its way. That code is the only way to look the request up, and nothing else can see which requests a phone sent.
What we hold
What we store depends on how you came to use Bellbee.
If you send a request as a guest
What you sent: the place the code belongs to, what you asked for, your answers, your note if you wrote one, and when you sent it. If the page asked for your room number or where you are staying, we keep your answer. There is no account, and we do not ask for your name, but anything you type in is kept as you typed it. The property sees all of it, along with who on their team picked it up and when it was done.
If you write in
The contact form takes your name, your email address, your property if you fill it in, and your message. We store it and email it to ourselves so we can answer. We also record the IP address the message came from, to stop the form being used to send junk.
If you open an account
Your name, email address, the name of your property and the country your business is registered in, which decides the VAT on your invoices. Your browser also tells us its timezone and we keep it, so "today" on the request list is today where your guests are. When you put a card on the account we hold the billing details you type, including your VAT number, and a reference from our payment provider. We never receive your card number.
If a property you work for invited you
Your name and email address, which they entered, and your role and groups. Then the work itself: which requests you picked up and finished, and when, and how you like your request list laid out. Every time you sign in we record the time and the browser your device reports.
Whenever anything is used
Our server keeps ordinary technical records of requests. We record IP addresses against a small number of events, such as a failed sign in, a signup, or a guest sending a request, so that somebody trying addresses one after another, or flooding a property with requests, can be slowed down.
Who else touches it
Three companies, each doing one job.
We do not sell personal data, we do not share it for advertising, and we do not use it to train anything. These are the only companies involved in running Bellbee:
- DigitalOcean hosts the site, the API and the database, in Amsterdam.
- Bird, formerly SparkPost, delivers the email we send: invitations, invoices and notices about an account.
- Mollie takes payment. Card details are typed on Mollie's own page and never reach us. Mollie decides for itself what it needs to hold to run a payment business, so for that part it is not acting on our instructions.
Everything is held inside the European Economic Area. If that ever has to change we will say so here and tell account owners first.
We will hand something over to an authority if the law obliges us to, and we will tell the account owner first unless we are forbidden to.
How long it is kept
And how it is protected while we have it.
Requests, guest pages and the team are kept while the account is open. When an account closes we keep it readable for ninety days in case the property comes back, then delete it, and an owner can ask us to delete it immediately instead.
A sign in lasts ninety days before it has to be done again, and an invitation link stops working after three days. IP addresses are erased after thirty days, both the ones recorded against security events and the ones behind the page views on this site. Invoices and the figures behind them are kept for seven years, because Dutch tax law requires it, and that obligation outlasts a request to delete an account.
Names, email addresses, what guests type into a request, and invoice details are encrypted before they are written to the database, so a copy of the database on its own does not name anybody. Everything travels over an encrypted connection. Passwords are stored in a form nobody can read back, including us.
What you can ask for
Your rights, and where to complain if we handle a request badly.
You can ask us for a copy of what we hold about you, to correct it, to delete it, to give it to you in a portable form, or to stop using it in a particular way. Get in touch and we will answer within a month, free of charge.
If you sent a request as a guest, or a property you work for gave you an account, the decisions about that data are theirs and not ours. Ask them first. If you ask us, we will pass it on and help them answer, but we are not allowed to delete their records for you.
If you think we have handled your data badly, tell us and we will try to put it right. You also have the right to complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens, and you can go to the one where you live instead.
When this page changes we move the date at the top, and we email account owners when the change matters.
