This Privacy Policy explains how TellMyStay (“we”, “us”) collects, uses, and shares information when you use our website, host dashboard, WhatsApp guest concierge, and property welcome pages (the “Service”). It should be read with the Terms of Service.
1. Who is responsible
TellMyStay is operated by Mickael Benlolo, a small business (osek za'ir) registered in Israel. Privacy requests: contact@tellmystay.com.
Hosts create accounts and enter property and guest details. For host account data, TellMyStay is the controller (or equivalent under applicable law).
For guest information a host enters, and for concierge messages sent for a stay, the host decides what is collected and why. TellMyStay processes that information on the host’s instructions to run the concierge and welcome page. Guests who want a correction or deletion should usually start with the host. You can also email us; we will act or refer the request to the host.
2. Host-provided guest information
When a host enters a guest’s WhatsApp number, email, name, or stay dates, the host is responsible for having a lawful basis and any required permission to give us that information and to have the concierge contact the guest on WhatsApp.
Hosts must not enter special-category data (such as health, religion, or biometrics) about a guest, and must not enter details for anyone who asked not to be contacted or for a child. TellMyStay does not verify consent. A welcome-page link may be opened by anyone who has the URL; hosts should not put information there that they are not willing to expose if the link is forwarded.
Guests first hear from us in the WhatsApp message or email sent before check-in, which says the concierge is an AI. The welcome page links to this policy. If a guest writes before receiving that message, the concierge’s first reply says it is an AI, and it confirms this whenever asked.
3. Information we collect
Depending on how you use the Service, we collect:
- Account data: email and authentication identifiers when hosts register or sign in (including Google sign-in).
- Property data: what the host enters: name, address, Wi-Fi, access codes, check-in and check-out times, arrival instructions, house information, photos, voice notes, and imported documents.
- Stay records: dates, a stay code, and guest contact details the host enters (WhatsApp number, and optionally email and name).
- Feedback: messages hosts send from the dashboard, and the property they relate to.
- Custom-price requests: how many properties you have, email, and optional phone and note.
- Usage counters: per-property totals for AI messages and tokens. These are numbers; they are not message transcripts.
- Technical data: IP address and your browser’s language setting, used to pick the site language and, from the IP, your country (Hebrew is offered only in Israel); IP addresses used in memory for rate limiting and bot protection; and operational logs from our hosting provider (which may include IP address and request metadata).
- Analytics: Vercel Analytics counts page views with coarse device, browser, and country information. It does not use cookies and does not follow you across other sites. We do not use it for ads.
4. Guest messages and what we keep
Conversations between a guest and the concierge are held only in server memory for a short time, a small number of recent turns, discarded within 24 hours or when the server instance recycles, whichever comes first. Hosts have no chat inbox or transcript in the dashboard.
One exception: when the concierge cannot answer a question, we store the text of that question, not the rest of the conversation and not the guest’s name or phone number, so the host can be told in a missed-questions email and add the answer. It is linked to the stay, sent only to that host, and deleted 14 days after the question was last asked. If the host turns the missed-questions email off, these questions are not stored at all.
Messages still pass through our providers to deliver the concierge (see section 5). When a stay ends or access is revoked, we may keep the guest’s phone number on a suppression list so the concierge stops replying.
5. Who we share information with
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not send marketing emails or messages without your prior consent. We share it only with providers who process it to run the Service, if the law requires disclosure, or to protect the Service, users, or others from harm:
- OpenAI: generates concierge replies, transcribes voice notes, and analyzes uploaded guide photos. Guest messages and relevant property information are sent for that purpose. We use OpenAI’s API under its business terms and do not opt in to use this data to train their models. OpenAI may keep API inputs and outputs for up to 30 days to detect abuse, then deletes them, unless the law requires it to keep them longer.
- Meta Platforms (WhatsApp Business Platform): delivers messages between the guest and the concierge, under Meta’s terms and privacy policy.
- Supabase: database, authentication, and file storage, hosted in the EU (eu-central-1).
- Vercel: application hosting, routing, bot protection, operational logs, and Analytics.
- Google: sign-in.
- Paddle: processes payments as our Merchant of Record. Paddle’s script (Paddle.js, including Paddle Retain, formerly ProfitWell) loads only on the pricing page and in the host dashboard, to show prices, run checkout, and manage subscriptions.
- Resend: sends email from the Service, including follow-up on custom-price requests.
- Authorities: if we are legally required to disclose information, or to protect the Service, users, or others from harm.
6. Cookies
We only use cookies and browser storage the Service needs. We do not use advertising cookies.
You can block or clear cookies in your browser. Some features, including staying signed in, will not work without essential cookies.
- tms-auth: keeps hosts signed in. Essential.
- tellmystay_locale: remembers a language you picked. Kept for 1 year.
- tms_host_price: briefly remembers the Host price in your currency. Up to 12 hours.
- Browser storage on your device: theme (light or dark), text size, and the last property you opened in the dashboard.
- Paddle: on the pricing page and in the host dashboard only, Paddle.js and Paddle Retain may set their own cookies or storage to run checkout, prevent fraud, and manage subscriptions.
7. AI processing
Replies are generated by OpenAI from the host’s property information and the guest’s message. We do not train our own models on guest messages or property data. We do not control how providers handle data under their own policies.
The concierge produces automated text. It does not make legal or similarly significant decisions about a guest (for example credit, employment, or immigration).
We do not make decisions with legal or similarly significant effects about anyone solely by automated means.
8. How long we keep information
We keep information only as long as needed to run the Service:
- Account and property data: while the account exists. Deleting a property or the account removes the related data from the live system.
- Guest contact details (name, WhatsApp number, email): deleted automatically 24 hours after check-out, or within 24 hours after a host deletes or cancels a stay. Stay dates and the stay code are kept, without contact details, for the host’s records while the property exists.
- Guest conversation content: not retained in our database, except unanswered questions as described in section 4.
- Questions the concierge could not answer (used for the host’s missed-questions email): deleted automatically 14 days after the question was last asked, and not stored at all if the host has turned that email off.
- Welcome page sessions: expired sessions are pruned about 60 days after expiry.
- Suppression list: a phone number from an ended chat is kept for 30 days so the concierge does not start replying again, then deleted automatically.
- Operational logs: according to our hosting provider’s schedule.
- Backups: deleted records may remain in encrypted backups until those backups expire, at most 30 days.
9. Legal bases (EEA/UK)
Where GDPR or UK GDPR applies, we rely on: performance of a contract with the host; legitimate interests (security, abuse prevention, reliability, and support); consent where required; and legal obligation. Where a host provides guest information, the host is responsible for the legal basis for collecting it and instructing us to process it.
10. Israeli privacy law
Where the Privacy Protection Law, 5741-1981 and its regulations apply (including Amendment 13) we handle personal information in accordance with them, and we apply the Protection of Privacy (Data Security) Regulations, 5777-2017 to the databases we operate.
People in Israel may inspect information held about them and request correction or deletion. Email the address below. Complaints may be sent to the Israeli Privacy Protection Authority.
11. California and similar US state laws
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under those laws, other than to provide the Service. To exercise access, deletion, or other rights, email contact@tellmystay.com. We will not discriminate against you for exercising a privacy right.
12. Your rights
Depending on where you are, you may have rights to access, correct, delete, restrict, or port your information, and to object to certain processing. Hosts can view, edit, and delete property and stay data in the dashboard, and can delete the account in Settings.
Email contact@tellmystay.com to exercise a right. If the request is about information a host entered about you as a guest, we may need to contact that host. You may also complain to your local supervisory authority.
We reply within one month (30 days where Israeli law applies), and may extend this where the law allows. Where we rely on consent, you can withdraw it at any time, without affecting earlier processing.
You are not legally required to give us personal information. Hosts need an email address to open an account, and without it we cannot provide the Service. Other fields are optional.
13. Security
Traffic is encrypted in transit. Sensitive credentials (Wi-Fi passwords, door and access codes) are encrypted at rest (AES-256-GCM). Database access is limited to server-side credentials. Sensitive endpoints are rate-limited.
No transmission or storage is completely secure. We cannot guarantee absolute security, and we are not liable for unauthorized access that we could not reasonably prevent.
If a security incident puts personal information at real risk, we will act to contain it, report it to the Israeli Privacy Protection Authority where the law requires, and notify affected hosts without undue delay so they can inform their guests if needed.
14. Children
The Service is not directed to children under 16. Host accounts are for people 18 or older. Hosts must not enter a child’s contact details as a guest contact. If you believe a child’s data was provided, contact us.
15. International transfers
Our database is hosted in the European Union. Other providers (including AI, messaging, analytics, and hosting) may process data in the United States and elsewhere. Where required, transfers rely on safeguards such as the European Commission’s Standard Contractual Clauses.
16. Changes
We may update this Policy. The new version is posted here with a new effective date. We will tell you about material changes in the Service or by email. Continued use after the effective date is acceptance of the updated Policy.
17. Contact
Privacy questions and requests: contact@tellmystay.com