Settings
Configure your Rava Stays workspace
Language
Cleaning Team
Manage cleaner profiles and assignments from the Cleaning Team section.
Data privacy, isolation & compliance
Your business runs on secure, professionally-built infrastructure. Rava is engineered with privacy and security at its core — so you and your clients are protected by design.
Rava is built on GDPR-compliant, ISO 27001-certified infrastructure. These standards apply automatically to every business account on the platform — both existing and future.
Customer and guest information is available exclusively to the business that enters and manages it. Data is encrypted at rest and in transit.
Each business’s data remains separate and isolated through its unique business identifier (business ID). It is not shared, combined, or accessible by any other business using Rava — the tenant boundary is enforced on every request.
The platform owner cannot view your customer or guest information through the Rava administration interface. Any strictly necessary technical access for security, support, or compliance purposes is subject to strict controls and limitations.
When an account is closed, a GDPR-compliant deletion process anonymizes or permanently removes the business’s data. All payments are processed through Stripe (PCI Service Provider Level 1); card details are handled entirely by Stripe and are never stored by Rava.
These certifications are provided and independently audited by Rava’s infrastructure and hosting provider, Base44, and by our payment processor, Stripe. Rava operates on top of this certified infrastructure, so the GDPR and ISO 27001 guarantees apply automatically. The official certificates, audit reports and Data Processing Agreements can be requested from, and verified directly with, these providers using the official documents linked below.
Official documents & policies
