Legal
Privacy policy
Two audiences read this page: the operator running a workspace, and the guest whose name, messages and identity document are inside one. The answers are different for each, so both are written out.
The short version
- We process your data to run the service for you, and for nothing else.
- We do not sell it, rent it, or use it to train machine-learning models.
- Your workspace is isolated from every other workspace in the database itself, not by a filter in the application.
- Card details never reach us; they go to the payment processor directly.
- Guest identity documents are handled more strictly than the rest of the record, with an audit row on every view.
Who is responsible for what
If you are an operator, you decide what guest data to collect and why. In data-protection terms you are the controller, and Stay N Host is a processor acting on your instructions. You are also responsible for telling your guests what you collect and why.
If you are a guest whose booking is in an operator's workspace, the business you booked with is the one that holds your data and answers your requests about it. Write to them first. If you cannot reach them, write to us with PRIVACY in the subject line at hello@staynhost.com and we will help you reach the right operator.
For the operator's own account data, the people who sign in, billing details and support correspondence, we are the controller.
What we process
- Account and workspace data. Names, email addresses, roles and property scope for the people you invite, plus sign-in and session records.
- Guest and booking data. Guest names and contact details, stay dates, prices, charges, payments and refunds, and the notes your team adds.
- Messages. Conversations on WhatsApp and in the guest app, along with the internal notes your team writes alongside them.
- Identity documents. Where a stay requires verification, the document a guest uploads and the decision a member of your team recorded about it.
- Payment evidence. Uploaded proof of a bank transfer or cash payment, and the verification decision. Card numbers are never among this; they go to the processor.
- Operational evidence. Turnover and inspection photographs, damage reports, and the timestamps attached to them.
- Technical records. Application and infrastructure logs used to keep the service running and to investigate problems, and an immutable audit row for every state change, recording who did what and when.
Why we process it
To provide the service under our agreement with the operator; to keep it secure and to investigate abuse; to bill for it; and to meet legal obligations. We do not process your data for advertising, we do not build profiles across operators, and we do not use it to train models.
Who processes data on our behalf
We use a small number of providers, each only for what its category says:
- Amazon Web Services (United States, us-east-1) for hosting, managed PostgreSQL and object storage. This is where your data lives.
- Meta Platforms, through the WhatsApp Business Platform, when you connect WhatsApp using your own account and credentials. Messages pass through Meta because that is what WhatsApp is.
- a card processor, if and when card payments ship and you enable them. Card details would go from the guest to that processor and never through us. No card rail exists in the product today, so no card data is processed at all.
- A channel manager, when you connect Airbnb, for the sync between the channel and your workspace.
- A transactional email provider, for sign-in emails, notifications and statements sent by email.
The current named list, including the email provider, is available on request at hello@staynhost.com. We will tell operators before adding a provider that processes personal data.
Where the data is
In the United States, in the AWS us-east-1 region, encrypted at rest with encrypted backups. In-region hosting for other geographies is a scaling item and is not available today, so if your regulator requires data residency in a particular country, ask before you subscribe.
How it is kept apart
Every table carries the workspace it belongs to, and isolation is enforced by the database with row-level security rather than by application code that could be bypassed. Seats can be scoped to specific properties by the same mechanism, and owner and investor portal access is scoped to that person's own position. Identity documents and payment evidence are handled at a stricter class, reachable only through short-lived signed links and only by seats holding the permission, with an audit row on every view. See the security page for more.
How long we keep it
For as long as the operator's workspace is active, because a rental business needs its own history: a booking from two years ago is evidence in a dispute today. Audit rows are append-only and are not edited or deleted by the product. When a workspace closes, its data is deleted after a wind-down window that leaves time to export, unless we are required to keep something longer for legal or tax reasons.
Operators can delete individual records within their own workspace where the product allows it, and should do so in line with their own retention policy.
Your rights
Depending on where you are, you may have rights to access, correct, export, delete or restrict the processing of your personal data, and to object to it. Operators can exercise these against us directly. Guests should exercise them against the operator they booked with, who holds the data; we will support that operator in answering.
Requests go to hello@staynhost.comwith PRIVACY in the subject line.
Cookies
This marketing site sets no tracking or advertising cookies and runs no third-party analytics. The application uses cookies that are necessary for it to work, principally to keep you signed in and to protect against request forgery. There is no consent banner here because there is nothing to consent to.
Children
The service is for businesses and is not directed at children. Where a guest record includes a minor travelling with an adult, the operator is responsible for collecting no more than the stay requires.
Changes
We may update this policy. Material changes are notified to operators before they take effect, and the date at the top always shows the current version.
Contact
hello@staynhost.com, subject line PRIVACY. See also the terms of service.