This Privacy Policy explains how Supahost Inc., a Delaware corporation ("Supahost", "we", "us"), collects, uses, and shares personal data when you visit supahost.io, join the waitlist, or use the Supahost platform (together, the "Service"). It does not cover data that cannot identify a person, such as aggregated or anonymized statistics.
Each numbered section begins with a short "In plain words" note. Those notes are a courtesy summary only — the full text of each section is what applies.
What we collect
In plain words
Account details you give us, the workspace content you and your channels put in, and technical data about how the Service is used.
We collect the following categories of personal data:
- Account and waitlist data — name, email address, password credentials, company details, and preferences you provide when you join the waitlist or create an account.
- Workspace content — the property, listing, reservation, rate, task, and message data you and your connected booking channels submit to your workspace, which can include personal data about your guests and team members.
- Payment data — when paid plans launch, billing details are collected and processed by our payment processor; we receive transaction records but never store full card numbers.
- Usage and device data — log data, IP address, browser and device type, pages viewed, and actions taken, collected automatically to operate and secure the Service.
- Communications — messages you send us for support or feedback, and our records of them.
You can choose not to provide certain data, but some data is required to create an account and use the Service.
Guest data: our role as processor
In plain words
Your guests’ personal data belongs to your relationship with them. The host is the controller; we process it on the host’s instructions.
When a host manages reservations and guest messages through Supahost, the host is the data controller for their guests’ personal data and Supahost is the host’s processor. We process that data only to provide the Service on the host’s documented instructions, under this policy and any data processing addendum agreed with the host.
If you are a guest at a property managed through Supahost, please direct privacy questions and rights requests to the host you booked with; we will assist the host in honoring them. Where the law requires us to answer you directly, we will.
How we use data
In plain words
To run the Service, keep channels in sync, power the agent, keep things secure, support you, and — only if you opt in — send you product news.
We use personal data to:
- provide and operate the Service, including synchronizing rates, availability, reservations, and messages with the booking channels you connect;
- power product features you invoke, including the operations agent and other AI features described below;
- onboard you from the waitlist, provide support, and respond to your requests;
- secure the Service, prevent fraud and abuse, and debug and improve the product;
- send service communications about your account, and — with your consent or as otherwise permitted by law — product news you can opt out of at any time;
- comply with legal obligations and enforce our Terms of Service.
AI features
In plain words
The agent reads your workspace to propose changes you approve. Our AI providers may not train their models on your content.
The operations agent and other AI features process your workspace content to answer questions and propose changes; proposed changes are applied only after a user in your workspace approves them. We do not use AI features to make solely automated decisions that produce legal or similarly significant effects about you without human review.
Where AI features rely on third-party model providers, we send them only the data needed for the request, and our agreements with them prohibit using your content to train their models.
Data retention
In plain words
We keep data while your account is active. After you leave, you get 30 days to export, then we delete within 90 days.
We retain personal data for as long as your account is active and as needed for the purposes above. After your account is terminated, workspace content remains exportable for 30 days and is then deleted from our production systems, with backup copies purged within a further 90 days, except where the law requires longer retention (for example, financial records). We may retain aggregated, anonymized data that no longer identifies anyone.
Security
In plain words
Encryption, access controls, and workspace isolation — and honesty that no system is perfectly secure.
We protect personal data with technical and organizational measures, including encryption in transit and at rest, workspace-scoped access controls, least-privilege access for our staff, and logging and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Keep your credentials confidential and tell us immediately at support@supahost.io if you suspect unauthorized access; if a breach affects your data, we will notify you as required by law.
International transfers
In plain words
Data is processed in the United States. For transfers from Europe we use Standard Contractual Clauses.
We are based in the United States and process data there and in the countries where our subprocessors operate. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and equivalent UK and Swiss mechanisms.
Your rights (GDPR and similar laws)
In plain words
You can ask to see, fix, export, restrict, or delete your data — and complain to a regulator if we get it wrong.
Where the GDPR or a similar law applies, we process your personal data on these legal bases: performance of our contract with you, our legitimate interests in operating and securing the Service, your consent where we ask for it, and compliance with legal obligations.
You have the right to access, correct, delete, and receive a portable copy of your personal data; to restrict or object to certain processing; to withdraw consent at any time without affecting prior processing; and to lodge a complaint with your supervisory authority. To exercise a right, email support@supahost.io. We respond within the time the law requires and may need to verify your identity first.
California privacy rights
In plain words
California residents get the CCPA rights: know, delete, correct, and no discrimination. We do not sell or share your data.
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we collect and how we use it (described in the sections above), to access it, to correct it, to delete it subject to legal exceptions, and to not be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of.
To exercise these rights, email support@supahost.io. You may use an authorized agent; we will verify the request as the law allows.
Children
In plain words
The Service is for adults running rental businesses, not children.
The Service is intended for users 18 and older, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us at support@supahost.io and we will delete it.
Changes to this policy
In plain words
Material changes come with at least 30 days’ notice.
We may update this policy from time to time. For material changes we will give you at least 30 days’ notice by email or in the Service before they take effect; changes required by law may take effect sooner. The current version is always available at supahost.io/privacy, with its effective date at the top.
Contact us
In plain words
Privacy questions and requests go to one address.
Supahost Inc. · {{COMPANY_ADDRESS}} · support@supahost.io
If you are in the EEA or the UK and we are required to designate a local representative, their contact details will be listed here: {{EU_UK_REPRESENTATIVE}}.