Sosta Glass · Transparency pillar

Full transparency. No black-box broker.

Here, in plain language, is what Sosta does with data — and what it deliberately does NOT: no brokering, no tracking, your data is yours. For talents, establishments and customers, each to the point.

Servers in the EUGDPR Art. 9No brokering18+/AVS2FA + passkeys available for admin accountsSubprocessors transparentCookieless

What Sosta does NOT do

Sosta is a management and overview tool — not a broker. These red lines are architectural, not just a promise: they protect talents, establishments and customers alike.

No brokering

Sosta does not match customers with talents. Bookings happen directly between the parties — we only host the contact form.

No per-booking commission

Sosta earns from flat subscriptions — never from the individual deal, never per booking (§181a line). And: the trust level cannot be bought — it grows only from authenticity signals, never from a subscription.

No chat between customer and talent

There is no chat between customer and talent, and we don't mediate contact between them. Contact runs directly through the channels the talent releases herself — or through the house.

No matching, no ranking

We recommend no one, sort by no "suitability", push no profile. You see what you search for — neutrally.

No public reviews

No rating battles, no public shaming. Ratings, if any, stay k-anonymous and house-internal.

We bind ourselves to each region's law

Sosta is software for room rental and self-presentation — not a broker. What we enable depends on what is legally permitted locally.

Features follow the law

Where local law does not support an establishment organising a worker or profiting from her, we simply do not offer those features there. We adapt the product to the law — not the other way around.

The worker owns her data

Regardless of region, every worker controls her own presentation herself. A house presents itself and its rooms — never the person against her will.

Neutral directory vs. full platform

Some establishments we carry only as a neutral directory entry with public business data — no profiles, no brokering. Full management exists only where it is legally supported.

Concretely, for you

Every role has different worries. Pick your view — and see what Sosta does for you.

Your data, your rules.

Download protection, your choice

You decide per photo whether the protection applies — no easy grabbing, no hotlinking. On top, every protected photo carries a subtle watermark that keeps screenshot copies traceable. It's all on by default for every photo.

Your photos reach the linked house (your contract partner, like a CV) — but photo protection applies there too. Publicly, only what you approve appears (reviewed + with your consent).

No house needed — independently visible

You don't need a house: as an independent advertiser you present yourself in your region — your own profile, your own released contact channels, your own reach. You decide everything yourself.

Disappear at the push of a button

Hard-delete truly removes everything: profile, images in storage, audit log anonymised, backups rotate in under 30 days. Right to be forgotten — reliably.

You control every visibility

Per house, per surface (house site, showcase, directory) — revocable anytime, hidden instantly. Hidden when you're not working.

A house cannot show you without asking — visibility stays with you.

Age & identity private

Your date of birth is never public — you choose the displayed age yourself. Pseudonym instead of real name.

No forced direct contact

Depending on the profile, inquiries run directly via the released channels or via the house. In free text we strip phone/email/social automatically — Sosta won't become a stalking channel.

A customer only gets the channels you release yourself — nothing else. In free text we strip contact details automatically, and you can use a privacy number.

Nothing sensitive without your yes

Special-category data (gender, origin, preferences, limits) is stored only with your explicit consent — revocable anytime. You maintain your own profile.

The house sees your limits and preferences house-internally — precisely so they're respected. It cannot change them.

Understand the data flow

Data flows from you to the next role — at every boundary a protection applies.

Talent
Contract-partner view · photo protection applies here too · the talent controls the link · the house cannot change the main profile
House
Only released + approved · suggestive public, explicit only behind 18+/AVS · only the protected public copy, never the original
Directory
Anonymous · no tracking · no mediation · contact directly or via the house, depending on profile
Customer

Talents decide for themselves whether to release their own direct channels or have inquiries run via the respective house. Sosta only hosts — no matching, no brokering, no booking.

Who may do what

Five roles — here you see the permissions each has. This matrix is the single source of truth: it determines what is actually allowed in the backend.

Tenant Owner

Establishment owner: full management of their own house — roster, website, billing, settings. No access to other houses.

Manager

Office team: day-to-day (maintain profiles, publish) — but no hard-delete, no billing, no house settings.

Worker

Talent: full control over their own profile, images, visibility and consents. Sees only their own data.

Public Visitor (Phase 2)

Customer: sees only the curated public directory behind age verification. No personal worker data, no direct contact.

Sosta Superadmin

Sosta platform: operations + compliance oversight, admin access with 2FA/passkey option (recommended), every action in the audit log. No selling of data, disclosure only with a court order.

Where your data lives

Database, storage and backups are in the EU. Images are never stored in the database but separately in object storage. Backups are encrypted and rotate in under 30 days — so a hard-delete truly takes effect.

Security & subprocessors

2FA + passkeys available and recommended for administrator accounts, complete audit log of every sensitive action.

We answer law-enforcement requests only with a written legal basis — we disclose nothing without a court order.

Your login — comfortable, your choice

Two-factor protection at Sosta is optional, never required. You stay signed in for a long time — no code on every visit — and you can sign out everywhere at any time.

If you want extra protection, you have the choice:

  • Passkey — Face ID, fingerprint or device PIN (recommended on mobile)
  • Authenticator code — the 6-digit code from a separate device (ideal on desktop)

Subprocessors

We work with as few providers as possible. Core infrastructure — hosting, storage, backups — is in the EU. Two services (email, maps) are US providers; any data transfer there is based solely on EU standard contractual clauses (SCC). All disclosed here:

  • Hostinger (Anwendungs-VPS)Application hosting
    EU
  • MinIO (self-hosted)Image and file storage (separate from the database)
    EU
  • Contabo Object StorageEncrypted backups
    EU
  • ResendTransactional emails (login codes, notifications)
    USA (SCC)
  • Mapbox (statische Karten)Maps in the directory
    USA (DPF/SCC)
  • CARTO (interaktive Karten-Kacheln)Maps in the directory
    USA (SCC)
  • Umami (self-hosted)Cookieless, anonymous reach measurement
    EU
  • seven.io (seven communications GmbH)SMS delivery for phone verification (worker code)
    EU
  • GlitchTip (self-hosted)Technical error monitoring (no personal data)
    EU

What exactly can Sosta do — and on what legal basis?

The features catalogue answers the most common questions from houses, talents and visitors — briefly and in depth, with the legal norms behind them.

To the features catalogue

Logged in, you see even more

In the logged-in area you see the full permission matrix for your role, your own audit log and your consent history.

To sign in
Transparency — Sosta