Privacy Policy
Last updated: 20 July 2026
This policy explains what personal data ErasmusPass collects when you apply for co-living in Bucharest, why we collect it, how long we keep it, and what rights you have over it.
What we collect
When you apply through erasmuspass.com, we collect: your name, email address, phone number, age, gender, nationality, home and host university, field of study, intended stay length and arrival date, lifestyle and interest information used for roommate matching (interests, music taste, personal style, smoking/cooking habits, sleep schedule, sociability), flatmate preferences, and any free-text notes you provide. If you start the application but don't finish it, we also retain what you'd entered up to that point (name, email, phone) as a partial record, so we can follow up if you'd like to complete it.
Why we collect it
To process your co-living application, match you with compatible flatmates, communicate with you about your stay, and — once you're part of the community — invite you to group trips and partner-property discounts.
Who has access
The ErasmusPass admin team, via a password-protected dashboard. We do not sell or share your data with advertisers or unrelated third parties.
Third parties
- Zoho Mail — sends the application-confirmation and admin-alert emails on our behalf (a data processor, not an independent controller of your data).
- Cloudflare — provides connection-level DDoS protection and content delivery in front of our domain; it sees standard connection metadata as part of that service.
How long we keep it
- Incomplete applications (started but never finished): deleted after 30 days.
- Declined applications: deleted after 365 days.
- Confirmed / completed stays: kept for the duration of your stay with ErasmusPass, and for up to 3 years afterward, to meet standard accounting, tax, and dispute-resolution obligations in Romania.
- Records of emails we've sent you are kept for up to 2 years for support/audit purposes, then automatically redacted.
Your rights
Under GDPR, you can ask us to access, correct, or delete your data at any time by emailing us at [email protected]. We can act on a deletion request directly from our admin dashboard, which permanently removes your application record.
Security measures
- Passwords are hashed, never stored in plaintext.
- The admin dashboard requires authentication and is rate-limited against brute-force login attempts.
- The public application form is rate-limited against automated abuse.
- Data is stored on a server we control directly, transmitted over HTTPS.
Contact
Questions about this policy or your data can be sent to [email protected].