This page is written for partner and connectivity reviewers. It describes Stayara's product, architecture and security posture in precise terms, without marketing exaggeration.
What is Stayara?
Stayara is a multi-tenant operations platform (property management system) for professional vacation rental agencies. It consolidates booking operations, team and role management, Stripe payments, custom domains and a channel integration center into a single, secure workspace.
Which customer segment does Stayara serve?
Stayara serves professional vacation rental agencies and property managers in Europe — businesses that manage multiple properties and units, work in teams with distinct responsibilities, and require reliable, auditable operations rather than consumer-grade tooling.
Which connectivity capabilities are planned?
Stayara is building a tenant-isolated connectivity layer for availability, rates, reservations and content. The planned capabilities include:
Availability, rates and inventory synchronization (per connected channel)
Reservation delivery and status updates
Content and property data distribution
Webhook-based event processing, signed and idempotent
How are credentials protected?
Channel credentials are encrypted server-side before storage using AES-256-GCM with tenant- and provider-bound authenticated data. The encryption key resides exclusively in Google Secret Manager and is available only to the application runtime service account. API responses and audit events never contain plaintext credentials or ciphertext.
How is tenant isolation enforced?
Every business request is resolved and authorized server-side against the tenant context. Tenant, memberships, roles and settings are authoritative in PostgreSQL; Firebase custom claims are not used for authorization. Administrative safeguards include immediate access suspension and protection of the last active tenant administrator.
How are changes audited?
Administrative status changes — including role assignments, domain operations, payment status and integration status transitions — produce immutable, revision-grade audit entries. Integration activity is recorded as an append-only history per tenant and provider.
How are payments handled?
Each agency operates its own Stripe Connect account with Stripe-hosted onboarding. Stayara does not process or store card data and is not itself PCI-certified; card processing is handled entirely by Stripe. Payment status is synchronized server-side via signed, idempotent webhooks.
What is the current integration status?
No channel integration is live at this time. Stayara does not currently synchronize availability, rates, reservations or content with any external channel.
Channel
Status
Meaning
Expedia Group
Application submitted
Connectivity application filed; review pending. No active connection.
Booking.com
Roadmap
Planned. No application filed and no active connection.
Airbnb
Application submitted
Connectivity application filed; review pending. No active connection.
Vrbo
Roadmap
Planned. No application filed and no active connection.
Holidu
Application submitted
Connectivity application filed; review pending. No active connection.
Who is the technical/business contact?
Connectivity teams can reach us directly at kontakt@stayara.de. We are prepared for sandbox access, webhook endpoints, API credentials handling and technical reviews, and we respond to partner requirements in a structured certification process.