This page is written for partner and connectivity reviewers. It describes Stayara's product, architecture and security posture in precise terms, without marketing exaggeration.
What is Stayara?
Stayara is a multi-tenant operations platform (property management system) for professional vacation rental agencies. It consolidates booking operations, team and role management, Stripe payments, custom domains and a channel integration center into a single, secure workspace.
Which customer segment does Stayara serve?
Stayara serves professional vacation rental agencies and property managers in Europe — businesses that manage multiple properties and units, work in teams with distinct responsibilities, and require reliable, auditable operations rather than consumer-grade tooling.
Which connectivity capabilities are planned?
Stayara is building a tenant-isolated connectivity layer for availability, rates, reservations and content. The planned capabilities include:
Availability, rates and inventory synchronization (per connected channel)
Reservation delivery and status updates
Content and property data distribution
Webhook-based event processing, signed and idempotent
How are credentials protected?
Channel credentials are encrypted server-side before storage using AES-256-GCM with tenant- and provider-bound authenticated data. The encryption key resides exclusively in Google Secret Manager and is available only to the application runtime service account. API responses and audit events never contain plaintext credentials or ciphertext.
How is tenant isolation enforced?
Every business request is resolved and authorized server-side against the tenant context. Tenant, memberships, roles and settings are authoritative in PostgreSQL; Firebase custom claims are not used for authorization. Administrative safeguards include immediate access suspension and protection of the last active tenant administrator.
How are changes audited?
Administrative status changes — including role assignments, domain operations, payment status and integration status transitions — produce immutable, revision-grade audit entries. Integration activity is recorded as an append-only history per tenant and provider.
How are payments handled?
Each agency operates its own Stripe Connect account with Stripe-hosted onboarding. Stayara does not process or store card data and is not itself PCI-certified; card processing is handled entirely by Stripe. Payment status is synchronized server-side via signed, idempotent webhooks.
What is the current integration status?
The list distinguishes submitted requests, planned target channels and technical standards that are already available. A displayed brand does not imply an active partnership, certification or productive API connection.
Channel
Status
Meaning
Expedia Group
Planned
The provider-neutral data model supports this target path; no active direct connection is claimed.
Booking.com
Planned
The provider-neutral data model supports this target path; no active direct connection is claimed.
Airbnb
Application submitted
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Vrbo
Access path under review
The provider-neutral data model supports this target path; no active direct connection is claimed.
Holidu
Technical review
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Google Vacation Rentals
Application submitted
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
HomeToGo
Application submitted
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Travanto
Interface requested
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
CHECK24 Ferienwohnungen
Connectivity requested
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Ferienwohnungen.de
Network path planned
The provider-neutral data model supports this target path; no active direct connection is claimed.
Traum-Ferienwohnungen
Connection requested
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Hundeurlaub.de
Cooperation requested
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Top-Hundeurlaub
Cooperation requested
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
Reinjas Hundereisen
Cooperation requested
Partner access or a technical connection has been requested. Activation depends on review and approval by the provider.
iCal / ICS
Technically available
A limited technical standard is available and can be enabled per agency after configuration.
Who is the technical/business contact?
Connectivity teams can reach us directly at kontakt@stayara.de. We are prepared for sandbox access, webhook endpoints, API credentials handling and technical reviews, and we respond to partner requirements in a structured certification process.