Privacy Policy
Effective: 17 August 2026
This policy applies to the Huisly website and mobile applications. It explains our actual data practices; it does not describe advertising or profiling products that Huisly does not use.
Controller
Huisly, at Grote Berg 48B, 5611 KL Eindhoven, Netherlands, is the controller for Huisly account and product data. KVK: 96874619. VAT ID: NL005232149B61. Privacy requests can be sent to privacy@huisly.nl.
Data we process
- Account and authentication: the provider-neutral Huisly user ID, email, name and profile details supplied by you or your chosen identity provider, plus session and authentication tokens.
- Product data: language and theme preferences, alerts and their locations and filters, active-listing bookmarks, and subscription status.
- Search requests: the location, viewport and filters needed to return results. Searches are sent to Huisly but are not retained as a user search-history product. Of your housing-search criteria, only alert rules you deliberately save are retained for later use. Necessary account, bookmark, subscription and security records are described separately in this section.
- Optional precise location: when you choose Current location, your device provides coordinates after permission. They are used to position the map and request listings for its visible bounds. Huisly does not build a location-history profile from this feature.
- Notifications: mobile installation identifiers and notification preferences needed to deliver alerts.
- Purchases: RevenueCat/customer identifiers, product, store, entitlement, transaction state and dates. Huisly does not receive your complete card details.
- Operational and security data: IP address, user agent, app/browser version, request timestamps, security events and crash diagnostics needed to operate and protect the Service.
- Functional storage: browser or device storage for authentication sessions, language, theme, recent search/location state, and storage required by checkout. Huisly does not use advertising cookies or pixels.
- Listing-source data: publicly available listing and provider information needed to index, deduplicate, display, attribute and link to housing sources. Huisly names the source and sends the application, rental or purchase action back to the source from which the listing was obtained. Rights holders can send correction or removal requests to legal@huisly.nl.
Purposes and legal bases
- Contract: authentication, search, alerts, bookmarks, account sync, subscriptions, support and account deletion.
- Legitimate interests: security, abuse prevention, service reliability, debugging, limited aggregate operational measurement, and indexing, deduplicating, attributing, enriching and linking publicly advertised housing. We balance these interests against your rights.
- Consent: optional device location and push notifications, which can be withdrawn through device settings.
- Legal obligations: records required for tax, accounting, fraud prevention or lawful requests.
Where published listing or provider information identifies a person and was not collected directly from them, this policy provides the information required for that indirect collection. The categories are the public listing, provider, contact and provenance fields shown by the named housing source. Huisly uses them only to aggregate, attribute, enrich and link the housing offer, not to contact or profile that person. Correction, objection and removal requests can be sent to legal@huisly.nl.
For a listing-source correction or removal request, send the affected Huisly URL, the field or material concerned, and the reason for the request to legal@huisly.nl. We acknowledge the request within seven days and normally provide a decision within 30 days. We may temporarily suppress disputed material while checking the source and the requester's authority. These service targets do not limit any shorter statutory deadline or GDPR right.
No advertising tracking or data sales
Huisly does not sell or rent personal data, use advertising pixels, build advertising profiles, or use Google Analytics. RevenueCat page/UTM analytics are disabled. Infrastructure providers may still process limited request, security and transaction data to provide their services. We do not share search history or bookmarks with property providers. When you open a source link, that provider receives a normal browser request under its own privacy policy.
Service providers
- Our self-hosted Keycloak and any identity provider you select for authentication.
- Cloudflare for hosting, delivery, security and limited operational request data.
- RevenueCat and Paddle for web subscriptions and billing lifecycle management.
- Apple App Store and Google Play for mobile purchases.
- Apple Push Notification service, Firebase Cloud Messaging and Firebase Crashlytics for mobile notification delivery and crash diagnosis.
- Our self-hosted Unleash service for feature availability, maintenance and update controls.
- OpenFreeMap infrastructure for map tiles.
These providers process only the data needed for their role and may act as independent controllers for payments, app stores or external-source visits.
Deletion, storage periods, and security
Huisly has no search-history or location-history product. Ordinary unsaved searches and Current location coordinates are used to answer the request and are not added to your Huisly profile. Your browser may still keep visited URLs under its own history settings.
- Account details and preferences exist while your account is active. Alerts and bookmarks exist until you remove them or delete the account.
- Delete account in Profile calls the authenticated Huisly deletion endpoint, removes the Huisly account and application data, ends the local session, and clears local identity and plan caches. A later new account does not restore deleted data.
- Operational security, request, and crash records are not a user-history feature. They exist only while needed to investigate abuse, incidents, reliability, or legal claims, following the configured service schedule. Backups expire through their configured overwrite cycle.
- Tax, fraud, transaction, and subscription records exist only when and for as long as law or the independent store or payment provider requires. Deleting Huisly cannot delete records that an independent provider must keep under its own legal responsibility.
We use encrypted transport, access controls, least-privilege credentials and service monitoring. No online service can promise absolute security.
Your rights
Under the GDPR you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting prior lawful processing. Email privacy@huisly.nl; we may verify your identity and normally respond within one month. You can also delete your Huisly account in Profile. A store subscription must be cancelled separately through its store or customer portal.
You may complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or your local supervisory authority.
Huisly does not make decisions that produce legal or similarly significant effects about you solely through automated processing.
International transfers
Some providers may process data outside the European Economic Area. Where required, transfers use an adequacy decision, Standard Contractual Clauses and supplementary safeguards. Provider privacy notices explain their locations and transfer mechanisms.
Children
Huisly accounts are intended for people aged 18 or older. Contact us if you believe a child has created an account so we can investigate and remove it where appropriate.
Changes
We update the effective date when this policy changes and will give appropriate notice of a material change. Where consent is legally required, we will ask before applying the new use.
Contact
Privacy: privacy@huisly.nl
Legal and source-data requests: legal@huisly.nl