The short version
- For a host's account, we are the data controller. For the guest information a host puts on their guest page, the host is the controller and we only process it on their instructions.
- Guests can read a guest page and ask the AI concierge without giving a name, an email, or creating an account.
- We never sell personal data, and we never share it for cross-context behavioural advertising.
- Nothing is loaded for analytics until a visitor accepts analytics cookies.
- Privacy requests go to privacy@hostbnb.example.com and we answer within one month.
This summary is a reading aid and is not part of the agreement. Where it differs from the text below, the text below is what applies.
Contents+
This policy explains what Hostbnb does with personal data. It covers the Hostbnb website, the host dashboard, and the public guest pages hosts publish at /stay/…. It applies alongside our Terms of Service and Cookie Policy.
Who we are
Hostbnb is operated by [Registered company name], [Entity type and country of incorporation], registered at [Street address], [City], [Prefecture / state], [Postal code], [Country]. Where this policy says we are a controller, [Registered company name] is that controller.
You can reach our privacy team at privacy@hostbnb.example.com or by post at the address above, marked for the attention of the privacy team.
Two different roles, and why it matters to you
Hostbnb sits between two groups of people, and we handle their data under different legal roles. Which role applies decides who you ask when you want your data.
| Data | Who decides what happens to it | Our role |
|---|---|---|
| A host's account: email, password, plan, billing | Hostbnb | Controller |
| A host's property content: guide text, photos, recommendations | The host | Processor, acting on the host's instructions |
| Guest tips, comments and concierge conversations on a guest page | The host who publishes that page | Processor, acting on the host's instructions |
| Website analytics on our own marketing pages | Hostbnb | Controller |
Guests: start with your host
If you stayed somewhere and want the tip you left, or a conversation you had with a concierge page, deleted — ask your host first. They control that page and can delete it themselves from their dashboard. If you can't reach them, write to us and we will pass the request on and help them action it.
What we collect from hosts
| What | Why | Legal basis (UK/EU) |
|---|---|---|
| Email address and password (stored only as a bcrypt hash — we never hold the password itself) | To create and secure the account | Performance of a contract |
| Name and preferred language, if given | To address you correctly and show the right language | Performance of a contract |
| Plan, subscription status, billing period, property count | To bill the right amount and enforce plan limits | Performance of a contract |
| Billing name, email and card details | To take payment. Card numbers go straight to Stripe and never reach our servers. | Performance of a contract |
| Referral code, and who referred the account | To credit referral rewards | Performance of a contract |
| Partner earnings, payout method and payout records | To pay a host their share of partner commissions | Performance of a contract; legal obligation for tax records |
| Server logs: IP address, user agent, timestamps, requested paths | To keep the service up, investigate faults, and stop abuse and rate-limit evasion | Legitimate interests — running a secure service |
| Product analytics events, if analytics cookies are accepted | To see which features get used and where people get stuck | Consent |
What we collect from guests
A guest page is designed to be useful without an account. A guest can open one, read it, and ask the concierge without telling us who they are.
| What | Why | How long |
|---|---|---|
| Questions asked to the AI concierge, and the answers given | To answer the question, and to show the host what guests are asking | Kept until the host deletes them or the property is deleted |
| A tip or comment left on a guest page, and the name attached if one is typed | So the host can review it and, if approved, show it to future guests | Kept until the host deletes it or the property is deleted |
| A page-view or unlock record for the property | So the host can see how much their page is being used | Kept while the property exists |
| A cookie proving the check-in code was entered correctly | So a guest does not have to re-enter the code on every visit | 30 days |
| A pseudonymous device identifier on partner links | So repeat taps by the same guest are counted once, and a commission is credited to the right host | Kept with the click record |
Please don't type sensitive details into a concierge chat
Concierge conversations are saved and are visible to the host of that property. Don't put payment card numbers, passport or ID numbers, health information, or anything else you would not want your host to read into the chat. If you need to send something sensitive, contact the host directly.
How the AI concierge uses what you type
When a guest asks a question, we search the host's own guide, recommendations, FAQs and approved guest tips for the passages most likely to answer it, and send those passages together with the question to our AI provider. The answer comes back grounded in the host's information.
- We do not send the AI provider a host's account details, billing data, or anything from another host's property.
- We ask our AI providers, by contract, not to train their models on what we send them.
- The conversation is stored so the host can read it in their dashboard, and so the concierge can follow a thread of questions.
- AI answers can be wrong. They are a convenience, not the last word — a host's own written guide and direct contact are what to rely on for anything that matters, such as safety or emergency information.
Cookies and tracking
We set a small number of cookies that the service cannot work without: a signed session cookie that keeps a host logged in, a cookie recording the language chosen, and a cookie proving a guest entered the correct check-in code. These are strictly necessary and are set without asking, because there is no service without them.
Analytics cookies are different. Nothing analytics-related loads until a visitor accepts it, the choice can be changed at any time, and declining costs nothing. The full list is in the Cookie Policy.
We do not use advertising cookies, and we do not run cross-site advertising trackers on any Hostbnb page or on any guest page a host publishes.
Who else processes your data
We use a small number of service providers to run Hostbnb. They act on our instructions, under contracts that hold them to confidentiality and security obligations at least as strict as ours. The current list:
| Provider | What it does | Where |
|---|---|---|
| Application hosting provider (Vercel Inc.) | Runs the Hostbnb web application and serves every page and API request. | United States, with a global edge network |
| Managed PostgreSQL database provider | Stores the production database: host accounts, property content, guest tips, chat transcripts. | Configured deployment region |
| Object storage provider (Amazon S3 or an S3-compatible service) | Stores images and files hosts upload for their guest pages. | Configured storage region |
| AI provider (OpenAI, L.L.C. or a configured OpenAI-compatible provider) (if configured) | Generates AI concierge answers, translations and writing suggestions, and computes the embeddings behind the search index. | United States, or the configured provider's region |
| Stripe, Inc. (if configured) | Takes subscription payments and stores the card details we deliberately never see. | United States and Ireland |
| Google LLC (Places and Maps APIs) (if configured) | Looks up places a host adds as a recommendation, and renders maps on guest pages. | United States and globally |
| PostHog, Inc. (if configured) | Product analytics: which features get used, where people get stuck. Runs only after a visitor accepts analytics cookies. | United States or European Union, depending on the configured region |
| Viator (Tripadvisor LLC) (if configured) | Supplies the tours and activities hosts can add to a guest page, and takes the booking when a guest books one. | United States |
| Transactional email provider (if configured) | Sends account email: sign-in, billing receipts, and service notices. | Configured provider's region |
The always-current list, with the data categories each one sees, is at Sub-processors. Hosts on a paid plan can subscribe there to be told before a new one is added.
Beyond these, we disclose personal data only: to a host, for their own property's data; where you ask us to; where the law requires it, such as a valid court order or a tax obligation; to our professional advisers under a duty of confidence; and to an acquirer if the business is sold, in which case we will tell you before your data moves and this policy continues to apply until you are given notice of a new one.
We do not sell your data
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act. We have not done so in the preceding twelve months, and that includes the personal data of anyone under 16.
International transfers
Hostbnb is used by hosts and guests around the world, so data may be processed in a country other than the one you are in — in practice most often the United States, and the region you or your provider configured.
When we move personal data out of the United Kingdom or the European Economic Area to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where the UK GDPR applies), together with the additional technical measures described under Security below. You can ask us for a copy of the clauses we rely on for a particular transfer.
How long we keep things
| Data | Retention |
|---|---|
| Host account | For as long as the account is open. Deleted within 30 days of a deletion request, apart from what we must keep (below). |
| Property content, guides, photos, recommendations | Deleted immediately when the host deletes the property, and with the account. |
| Guest tips and concierge conversations | Deleted when the host deletes them, the property, or the account. A host can delete any single tip or conversation at any time. |
| Analytics events on a property (page views, unlocks) | Deleted with the property. |
| Invoices, payment records and tax documents | Kept for as long as tax and accounting law requires, typically seven years, even after an account closes. |
| Partner commission and payout records | Kept for as long as tax and accounting law requires. |
| Server and security logs | Typically 30–90 days, longer only where a log is part of an open security investigation. |
| Product analytics | Retained per our analytics provider's configured retention, and deleted on request. |
Backups roll off on their own schedule. A record you delete leaves the live service immediately and is gone from backups within 35 days.
Your rights
Depending on where you live, you have some or all of the following rights. We honour all of them for everyone, wherever you are, rather than sorting people by passport.
- Access — ask what we hold about you, and get a copy.
- Portability — get the data you gave us in a machine-readable format, or have it sent to another provider where technically feasible.
- Correction — have inaccurate data fixed. Most of it you can edit yourself in the dashboard.
- Deletion — have your data erased, subject to what we must keep by law.
- Restriction and objection — ask us to pause a use, or object to processing we do on the basis of legitimate interests.
- Withdraw consent — for anything we do on the basis of consent, such as analytics cookies. Withdrawing does not affect what happened before.
- No discrimination — exercising any of these rights never gets you a worse price or a worse service.
- Automated decisions — we do not make decisions producing legal or similarly significant effects about you by automated means alone.
To exercise a right, write to privacy@hostbnb.example.com from the address on the account, or from the address you used on the guest page. We answer within one month. If a request is unusually complex we may take up to two months more, and we will tell you within the first month if that happens. An authorised agent may act for you if they can show us your written permission.
If you think we have got this wrong, please tell us first — we would rather fix it. You can also complain to your data protection authority. For us that is [Lead supervisory authority, e.g. Japan's Personal Information Protection Commission]; in the EU you may also complain to the authority where you live or work.
Security
- Traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting and storage providers.
- Passwords are stored only as bcrypt hashes. Nobody at Hostbnb can read a host's password.
- Session and guest-unlock cookies are signed,
HttpOnly, andSecurein production, so page scripts cannot read them. - Access to production data is limited to staff who need it for their job, and is logged.
- Sensitive fields on a guest page — check-in instructions, Wi-Fi, door codes — can be put behind a check-in code, so they are not readable by anyone who finds the link.
- Payment card details are handled entirely by Stripe, a PCI DSS Level 1 provider. They never reach our servers.
No service is perfectly secure. If we discover a breach that is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell affected people without undue delay. If you think you have found a vulnerability, please write to security@hostbnb.example.com — we will not pursue anyone who reports one in good faith and gives us reasonable time to fix it.
Children
Hostbnb is for adults running or staying in short-term rentals. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 (or the higher age of digital consent where you live). If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
When we change this policy we update the effective date at the top. For a change that materially affects your rights, we will tell hosts by email at least 30 days before it takes effect, so nobody finds out after the fact.
Questions about any of this: privacy@hostbnb.example.com.