Legal · Effective August 18, 2026

Privacy Policy

See also: Terms of Service

This Privacy Policy explains how Supahost Inc., a Delaware corporation ("Supahost", "we", "us"), collects, uses, and shares personal data when you visit supahost.io, join the waitlist, or use the Supahost platform (together, the "Service"). It does not cover data that cannot identify a person, such as aggregated or anonymized statistics.

Each numbered section begins with a short "In plain words" note. Those notes are a courtesy summary only — the full text of each section is what applies.

What we collect

In plain words

Account details you give us, the workspace content you and your channels put in, and technical data about how the Service is used.

We collect the following categories of personal data:

  • Account and waitlist data — name, email address, password credentials, company details, and preferences you provide when you join the waitlist or create an account.
  • Workspace content — the property, listing, reservation, rate, task, and message data you and your connected booking channels submit to your workspace, which can include personal data about your guests and team members.
  • Payment data — when paid plans launch, billing details are collected and processed by our payment processor; we receive transaction records but never store full card numbers.
  • Usage and device data — log data, IP address, browser and device type, pages viewed, and actions taken, collected automatically to operate and secure the Service.
  • Communications — messages you send us for support or feedback, and our records of them.

You can choose not to provide certain data, but some data is required to create an account and use the Service.

Guest data: our role as processor

In plain words

Your guests’ personal data belongs to your relationship with them. The host is the controller; we process it on the host’s instructions.

When a host manages reservations and guest messages through Supahost, the host is the data controller for their guests’ personal data and Supahost is the host’s processor. We process that data only to provide the Service on the host’s documented instructions, under this policy and any data processing addendum agreed with the host.

If you are a guest at a property managed through Supahost, please direct privacy questions and rights requests to the host you booked with; we will assist the host in honoring them. Where the law requires us to answer you directly, we will.

How we use data

In plain words

To run the Service, keep channels in sync, power the agent, keep things secure, support you, and — only if you opt in — send you product news.

We use personal data to:

  • provide and operate the Service, including synchronizing rates, availability, reservations, and messages with the booking channels you connect;
  • power product features you invoke, including the operations agent and other AI features described below;
  • onboard you from the waitlist, provide support, and respond to your requests;
  • secure the Service, prevent fraud and abuse, and debug and improve the product;
  • send service communications about your account, and — with your consent or as otherwise permitted by law — product news you can opt out of at any time;
  • comply with legal obligations and enforce our Terms of Service.

AI features

In plain words

The agent reads your workspace to propose changes you approve. Our AI providers may not train their models on your content.

The operations agent and other AI features process your workspace content to answer questions and propose changes; proposed changes are applied only after a user in your workspace approves them. We do not use AI features to make solely automated decisions that produce legal or similarly significant effects about you without human review.

Where AI features rely on third-party model providers, we send them only the data needed for the request, and our agreements with them prohibit using your content to train their models.

How we share data

In plain words

We never sell your data. It goes to the vendors that run the Service, to the channels you connect, and where the law requires.

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share personal data only with:

  • Subprocessors — vendors that help us run the Service, limited to these categories: cloud hosting and databases, payment processing, transactional email delivery, product analytics, error monitoring, background-job infrastructure, channel-connectivity infrastructure, AI model providers, and customer-support tooling. Each is bound by contract to protect your data. The current named list is available at {{SUBPROCESSOR_LIST_URL}}.
  • Third-Party Services you connect — when you link a booking channel or other integration, we exchange your data with it at your direction, under that service’s own terms.
  • Legal and safety — where required by law, legal process, or to protect the rights, safety, or property of Supahost, our customers, or the public.
  • Corporate transactions — in a merger, acquisition, financing, or sale of assets, with notice to you as required by law.

Cookies

In plain words

Essential cookies to sign you in, a privacy-respecting measure of what gets used, and no third-party advertising cookies.

We use essential cookies to authenticate you and keep the Service secure, preference cookies to remember settings such as your theme, and first-party analytics to understand which parts of the Service are used. We do not use third-party advertising cookies or tracking pixels on the Service.

You can control cookies through your browser settings. Blocking essential cookies will prevent sign-in from working.

Data retention

In plain words

We keep data while your account is active. After you leave, you get 30 days to export, then we delete within 90 days.

We retain personal data for as long as your account is active and as needed for the purposes above. After your account is terminated, workspace content remains exportable for 30 days and is then deleted from our production systems, with backup copies purged within a further 90 days, except where the law requires longer retention (for example, financial records). We may retain aggregated, anonymized data that no longer identifies anyone.

Security

In plain words

Encryption, access controls, and workspace isolation — and honesty that no system is perfectly secure.

We protect personal data with technical and organizational measures, including encryption in transit and at rest, workspace-scoped access controls, least-privilege access for our staff, and logging and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Keep your credentials confidential and tell us immediately at support@supahost.io if you suspect unauthorized access; if a breach affects your data, we will notify you as required by law.

International transfers

In plain words

Data is processed in the United States. For transfers from Europe we use Standard Contractual Clauses.

We are based in the United States and process data there and in the countries where our subprocessors operate. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and equivalent UK and Swiss mechanisms.

Your rights (GDPR and similar laws)

In plain words

You can ask to see, fix, export, restrict, or delete your data — and complain to a regulator if we get it wrong.

Where the GDPR or a similar law applies, we process your personal data on these legal bases: performance of our contract with you, our legitimate interests in operating and securing the Service, your consent where we ask for it, and compliance with legal obligations.

You have the right to access, correct, delete, and receive a portable copy of your personal data; to restrict or object to certain processing; to withdraw consent at any time without affecting prior processing; and to lodge a complaint with your supervisory authority. To exercise a right, email support@supahost.io. We respond within the time the law requires and may need to verify your identity first.

California privacy rights

In plain words

California residents get the CCPA rights: know, delete, correct, and no discrimination. We do not sell or share your data.

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we collect and how we use it (described in the sections above), to access it, to correct it, to delete it subject to legal exceptions, and to not be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of.

To exercise these rights, email support@supahost.io. You may use an authorized agent; we will verify the request as the law allows.

Children

In plain words

The Service is for adults running rental businesses, not children.

The Service is intended for users 18 and older, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us at support@supahost.io and we will delete it.

Changes to this policy

In plain words

Material changes come with at least 30 days’ notice.

We may update this policy from time to time. For material changes we will give you at least 30 days’ notice by email or in the Service before they take effect; changes required by law may take effect sooner. The current version is always available at supahost.io/privacy, with its effective date at the top.

Contact us

In plain words

Privacy questions and requests go to one address.

Supahost Inc. · {{COMPANY_ADDRESS}} · support@supahost.io

If you are in the EEA or the UK and we are required to designate a local representative, their contact details will be listed here: {{EU_UK_REPRESENTATIVE}}.