TellMyStay
Host login
TellMyStay
Host login
Terms of ServicePrivacy policy

Privacy Policy

Effective 15 August 2026

This Privacy Policy explains how TellMyStay (“we”, “us”) collects, uses, and shares information when you use our website, host dashboard, WhatsApp guest concierge, and property welcome pages (the “Service”). It should be read with the Terms of Service.

1. Who is responsible

TellMyStay is operated from Israel. Privacy requests: tellmystay@gmail.com.

Hosts create accounts and enter property and guest details. For host account data, TellMyStay is the controller (or equivalent under applicable law).

For guest information a host enters, and for concierge messages sent for a stay, the host decides what is collected and why. TellMyStay processes that information on the host’s instructions to run the concierge and welcome page. Guests who want a correction or deletion should usually start with the host. You can also email us; we will act or refer the request to the host.

2. Host-provided guest information

When a host enters a guest’s WhatsApp number, email, name, or stay dates, the host is responsible for having a lawful basis and any required permission to give us that information and to have the concierge contact the guest on WhatsApp.

Hosts must not enter special-category data (such as health, religion, or biometrics) about a guest, and must not enter details for anyone who asked not to be contacted or for a child. TellMyStay does not verify consent. A welcome-page link may be opened by anyone who has the URL; hosts should not put information there that they are not willing to expose if the link is forwarded.

3. Information we collect

Depending on how you use the Service, we collect:

  • Account data: email and authentication identifiers when hosts register or sign in (including Google sign-in).
  • Property data: what the host enters, name, address, Wi-Fi, access codes, arrival instructions, house information, photos, voice notes, and imported documents.
  • Stay records: dates, a stay code, and guest contact details the host enters (WhatsApp number, and optionally email and name).
  • Feedback: messages hosts send from the dashboard, and the property they relate to.
  • Usage counters: per-property totals for AI messages and tokens. These are numbers; they are not message transcripts.
  • Technical data: session and locale cookies; IP addresses used in memory for rate limiting and bot protection; and operational logs from our hosting provider (which may include IP address and request metadata).
  • Analytics: Vercel Analytics may record page views and coarse device or browser information. We do not use it to show ads.

4. Guest messages are not stored in our database

Conversations between a guest and the concierge are held only in server memory for a short time, a small number of recent turns, discarded within 24 hours or when the server instance recycles, whichever comes first. TellMyStay does not write guest message content to its database. Hosts have no chat inbox or transcript in the dashboard.

Messages still pass through our providers to deliver the concierge (see section 5). When a stay ends or access is revoked, we may keep the guest’s phone number on a suppression list so the concierge stops replying.

5. Who we share information with

We do not sell personal information. We do not share it for cross-context behavioral advertising. We share it only with providers who process it to run the Service, and if the law requires disclosure:

  • OpenAI: generates concierge replies, transcribes voice notes, and analyses uploaded guide photos. Guest messages and relevant property information are sent for that purpose. We use OpenAI’s API under its business terms and do not opt in to use this data to train their models.
  • Meta Platforms (WhatsApp Business Platform): delivers messages between the guest and the concierge, under Meta’s terms and privacy policy.
  • Supabase: database, authentication, and file storage, hosted in the EU (eu-central-1).
  • Vercel: application hosting, routing, bot protection, operational logs, and Analytics.
  • Google: sign-in, and Calendar access if a host connects a calendar. We store an encrypted authorization token and read events; we do not write to the host’s calendar.
  • Authorities: if we are legally required to disclose information, or to protect the Service, users, or others from harm.

6. Cookies

We use cookies that are needed to run the Service: authentication and session cookies, and a locale cookie that remembers your language. Vercel Analytics may set its own cookies or similar storage. You can block cookies in your browser; some features (including staying signed in) will not work without essential cookies.

7. AI processing

Replies are generated by OpenAI from the host’s property information and the guest’s message. We do not train our own models on guest messages or property data. We do not control how providers handle data under their own policies.

The concierge produces automated text. It does not make legal or similarly significant decisions about a guest (for example credit, employment, or immigration).

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

If a host connects Google Calendar, we read events only to create guest stays (dates and an optional access code). We do not use Google user data (raw, aggregated, or derived) to create, train, or improve foundational or generalized machine learning or artificial intelligence models.

8. How long we keep information

We keep information only as long as needed to run the Service:

  • Account and property data: while the account exists. Deleting a property or the account removes the related data from the live system.
  • Stay records and guest contact details: while the stay record exists. Hosts can delete a stay at any time. Stays are not currently auto-deleted after checkout.
  • Guest conversation content: not retained in our database, see section 4.
  • Guest access sessions: expired sessions are pruned about 60 days after expiry. Access is also rotated periodically, which invalidates old links.
  • Suppression list: a phone number from an ended chat may be kept so messaging does not resume.
  • Operational logs: according to our hosting provider’s schedule.
  • Backups: deleted records may remain in encrypted backups for a limited time until those backups expire.

9. Legal bases (EEA/UK)

Where GDPR or UK GDPR applies, we rely on: performance of a contract with the host; legitimate interests (security, abuse prevention, reliability, and support); consent where required; and legal obligation. Where a host provides guest information, the host is responsible for the legal basis for collecting it and instructing us to process it.

10. Israeli privacy law

Where the Privacy Protection Law, 5741-1981 and its regulations apply (including Amendment 13) we handle personal information in accordance with them, and we apply the Protection of Privacy (Data Security) Regulations, 5777-2017 to the databases we operate.

People in Israel may inspect information held about them and request correction or deletion. Email the address below. Complaints may be sent to the Israeli Privacy Protection Authority.

11. California and similar US state laws

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under those laws, other than to provide the Service. To exercise access, deletion, or other rights, email tellmystay@gmail.com. We will not discriminate against you for exercising a privacy right.

12. Your rights

Depending on where you are, you may have rights to access, correct, delete, restrict, or port your information, and to object to certain processing. Hosts can view, edit, and delete property and stay data in the dashboard, and can delete the account in Settings.

Email tellmystay@gmail.com to exercise a right. If the request is about information a host entered about you as a guest, we may need to contact that host. You may also complain to your local supervisory authority.

13. Security

Traffic is encrypted in transit. Sensitive credentials (Wi-Fi passwords, door and access codes, and calendar tokens) are encrypted at rest (AES-256-GCM). Database access is limited to server-side credentials. Sensitive endpoints are rate-limited.

No transmission or storage is completely secure. We cannot guarantee absolute security, and we are not liable for unauthorized access that we could not reasonably prevent.

14. Children

The Service is not directed to children under 16. Host accounts are for people 18 or older. Hosts must not enter a child’s contact details as a guest contact. If you believe a child’s data was provided, contact us.

15. International transfers

Our database is hosted in the European Union. Other providers (including AI, messaging, analytics, and hosting) may process data in the United States and elsewhere. Where required, transfers rely on safeguards such as the European Commission’s Standard Contractual Clauses.

16. Changes

We may update this Policy. The new version is posted here with a new effective date. Material changes may also be notified in the Service or by email. Continued use after the effective date is acceptance of the updated Policy.

17. Contact

Privacy questions and requests: tellmystay@gmail.com

PricingPrivacyTerms

© 2026 TellMyStay