Beta notice. HostBridge is currently in closed beta. Data may be reset during this period with at least 48 hours notice to affected accounts. Production-grade SLAs begin at general availability.

Privacy Policy

Last updated: February 9, 2026

Policy version: 2026-02-09

1. Introduction

HostBridge ("we," "our," or "us") operates a digital guest experience platform for vacation rental hosts. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

By using HostBridge, you consent to the data practices described in this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our services.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password when you create an account.
  • Property Information: Property details, addresses, WiFi credentials, house rules, and other content you add to your guest guide.
  • Payment Information: Payment card details processed securely through Stripe. We do not store your full card number.
  • Guest Information: Names, email addresses, phone numbers, and stay details that hosts enter for their guests.
  • Communications: Messages sent through our platform between hosts and guests.

2.2 Information Collected Automatically

  • Usage Data: Pages viewed, features used, time spent on pages, and interactions with the platform.
  • Device Information: Browser type, operating system, device type, and unique device identifiers.
  • Log Data: IP address, access times, and referring website addresses.
  • Cookies: We use cookies and similar technologies to maintain sessions and improve your experience.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send push notifications (with your consent)
  • Respond to your comments, questions, and support requests
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues and security threats
  • Send you marketing communications (you can opt-out anytime)
  • Personalize your experience on our platform

4. Data Sharing and Disclosure

We may share your information in the following circumstances:

4.1 With Service Providers

We share data with third-party vendors who perform services on our behalf, including:

  • Supabase: Database and authentication services
  • Stripe: Payment processing
  • Vercel: Hosting and content delivery
  • Resend: Transactional email delivery
  • Google: Maps and places data

4.2 With Hosts and Guests

Hosts can see information about guests who access their property guide, including in-app activity for their stay: which sections and places a guest opens, places they save, and questions they ask the concierge. This helps hosts spot and fix problems during a stay (for example, out-of-date Wi-Fi details). Hosts cannot see a guest's device location, photos, or messages exchanged with anyone other than the host and the property's concierge. Guests can see property information and host contact details shared by their host.

4.3 Legal Requirements

We may disclose information if required by law, subpoena, or other legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:

  • Guest session data (name, email, phone, stay details): Automatically deleted 12 months after departure date.
  • Conversation messages: Guest-sent messages are deleted at 12 months. Host-sent messages are anonymized (guest identity removed) and retained for host business records.
  • Activity/analytics data: Deleted with the guest session at 12 months post-departure.
  • Push notification subscriptions: Deleted with the guest session at 12 months post-departure.
  • WhatsApp session data: Deleted with the guest session at 12 months post-departure.
  • Consent records: Retained as an immutable audit log for legal compliance, even after guest data is deleted.
  • Host account data: Retained for as long as the host account is active. Deleted upon account closure and completion of any outstanding payment obligations.

Data retention is enforced automatically via a daily cleanup process. You can request early deletion of your data at any time through the app or by contacting us.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Row-level security policies in our database
  • Regular security audits and vulnerability assessments
  • Secure authentication with password hashing
  • Rate limiting and brute force protection

However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to certain processing of your data
  • Withdraw Consent: Withdraw consent for optional data processing

Self-service options: As a guest, you can exercise your data access, portability, and deletion rights directly through the app. Open your Account menu and use "Download My Data" (access/portability) or "Delete My Data" (deletion). You can also manage cookie and analytics preferences through the cookie settings banner.

For any other requests or if you need assistance, please contact us at privacy@hostbridge.io. We will respond within 30 days.

8. Cookies and Tracking

We use cookies and similar technologies on our platform. We categorize them as follows:

8.1 Essential Cookies (Always Active)

These cookies are strictly necessary for the platform to function and cannot be disabled:

  • Session cookie (guest_session_id): Maintains your authenticated session. httpOnly, secure, expires after 7 days.
  • CSRF token (csrf_token): Protects against cross-site request forgery. httpOnly, secure.

8.2 Analytics (Opt-in)

With your consent, we collect usage data to understand how guests interact with the platform and improve our services. This includes page views, feature interactions, and session duration. This data is stored in our own database and is not shared with third-party analytics providers.

You can manage your analytics preferences at any time through the cookie consent banner that appears on your first visit, or by visiting your Account settings and selecting "Cookie preferences."

8.3 No Third-Party Tracking

We do not use third-party tracking cookies, advertising pixels, or social media trackers. We do not serve ads. Your browsing data is never sold to or shared with advertisers.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. Our infrastructure is hosted in the United States via Supabase and Vercel. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdiction with data transfer restrictions, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) with our service providers
  • Data processing agreements with all sub-processors
  • Encryption of data in transit and at rest

10. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulation (GDPR) provides you with specific rights regarding your personal data. This section supplements the rest of our Privacy Policy.

10.1 Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract performance (Article 6(1)(b)): Processing necessary to provide our services to you as a guest, including your name, contact details, and stay information.
  • Legitimate interests (Article 6(1)(f)): Security monitoring, fraud prevention, and service improvement. We balance these interests against your rights and freedoms.
  • Consent (Article 6(1)(a)): Analytics/usage tracking, WhatsApp messaging, push notifications, and marketing communications. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

10.2 Your GDPR Rights

In addition to the rights listed in Section 7, you have the right to:

  • Lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.
  • Restrict processing in certain circumstances (e.g., while we verify accuracy of data you dispute).
  • Object to automated decision-making, including profiling. We do not make any purely automated decisions that produce legal or similarly significant effects.

10.3 How to Exercise Your Rights

You can exercise your rights directly through the app using the "Download My Data" and "Delete My Data" features in your Account menu. Alternatively, contact our data protection team at privacy@hostbridge.io. We will respond to all GDPR requests within 30 days.

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights regarding your personal information.

11.1 Categories of Personal Information

We collect the following categories of personal information:

  • Identifiers: Name, email address, phone number, IP address
  • Internet/electronic activity: Pages viewed, interactions with the platform, device and browser information
  • Geolocation data: Approximate location based on IP address (not precise GPS)
  • Commercial information: Concierge service bookings, payment records (processed by Stripe)

11.2 We Do Not Sell Personal Information

We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.

11.3 Your CCPA Rights

  • Right to Know: You have the right to know what personal information we collect, use, and disclose about you.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You have the right to request correction of inaccurate personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

11.4 How to Submit a Request

Use the self-service "Download My Data" and "Delete My Data" features in your Account menu, or contact us at privacy@hostbridge.io. We will verify your identity and respond within 45 days.

12. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will delete that information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

HostBridge

Email: privacy@hostbridge.io