Connectivity & Partners

Information for connectivity teams.

This page is written for partner and connectivity reviewers. It describes Stayara's product, architecture and security posture in precise terms, without marketing exaggeration.

What is Stayara?

Stayara is a multi-tenant operations platform (property management system) for professional vacation rental agencies. It consolidates booking operations, team and role management, Stripe payments, custom domains and a channel integration center into a single, secure workspace.

Which customer segment does Stayara serve?

Stayara serves professional vacation rental agencies and property managers in Europe — businesses that manage multiple properties and units, work in teams with distinct responsibilities, and require reliable, auditable operations rather than consumer-grade tooling.

Which connectivity capabilities are planned?

Stayara is building a tenant-isolated connectivity layer for availability, rates, reservations and content. The planned capabilities include:

  • Availability, rates and inventory synchronization (per connected channel)
  • Reservation delivery and status updates
  • Content and property data distribution
  • Webhook-based event processing, signed and idempotent

How are credentials protected?

Channel credentials are encrypted server-side before storage using AES-256-GCM with tenant- and provider-bound authenticated data. The encryption key resides exclusively in Google Secret Manager and is available only to the application runtime service account. API responses and audit events never contain plaintext credentials or ciphertext.

How is tenant isolation enforced?

Every business request is resolved and authorized server-side against the tenant context. Tenant, memberships, roles and settings are authoritative in PostgreSQL; Firebase custom claims are not used for authorization. Administrative safeguards include immediate access suspension and protection of the last active tenant administrator.

How are changes audited?

Administrative status changes — including role assignments, domain operations, payment status and integration status transitions — produce immutable, revision-grade audit entries. Integration activity is recorded as an append-only history per tenant and provider.

How are payments handled?

Each agency operates its own Stripe Connect account with Stripe-hosted onboarding. Stayara does not process or store card data and is not itself PCI-certified; card processing is handled entirely by Stripe. Payment status is synchronized server-side via signed, idempotent webhooks.

What is the current integration status?

The list distinguishes submitted requests, planned target channels and technical standards that are already available. A displayed brand does not imply an active partnership, certification or productive API connection.

ChannelStatusMeaning
Expedia GroupPlannedThe provider-neutral data model supports this target path; no active direct connection is claimed.
Booking.comPlannedThe provider-neutral data model supports this target path; no active direct connection is claimed.
AirbnbApplication submittedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
VrboAccess path under reviewThe provider-neutral data model supports this target path; no active direct connection is claimed.
HoliduTechnical reviewPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Google Vacation RentalsApplication submittedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
HomeToGoApplication submittedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
TravantoInterface requestedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
CHECK24 FerienwohnungenConnectivity requestedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Ferienwohnungen.deNetwork path plannedThe provider-neutral data model supports this target path; no active direct connection is claimed.
Traum-FerienwohnungenConnection requestedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Hundeurlaub.deCooperation requestedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Top-HundeurlaubCooperation requestedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Reinjas HundereisenCooperation requestedPartner access or a technical connection has been requested. Activation depends on review and approval by the provider.
iCal / ICSTechnically availableA limited technical standard is available and can be enabled per agency after configuration.

Who is the technical/business contact?

Connectivity teams can reach us directly at kontakt@stayara.de. We are prepared for sandbox access, webhook endpoints, API credentials handling and technical reviews, and we respond to partner requirements in a structured certification process.

Contact the connectivity team