HostDesk Privacy Policy

Effective Date: July 2, 2026 Last Updated: July 6, 2026

This Privacy Policy explains how 26Triumphus LLC ("HostDesk," "we," "us") collects, uses, and shares information through the HostDesk website, dashboard, and guest-facing pages (the "Service").

This policy covers two different groups of people, and we handle their data differently — read Section 2 first, it matters.


1. Information We Collect

From Hosts (people with a HostDesk account)

About Guests (people who stay at a Host's property)

Guests don't create HostDesk accounts. The Host provides us with:

We do not run advertising trackers on Guest-facing pages, and we do not use this usage data for advertising or marketing purposes.

Automatically, from anyone visiting our marketing site

Standard technical data (IP address, browser type, pages visited) via PostHog, for understanding how our marketing site performs. You can decline non-essential cookies where required by law.

2. Two Roles: When We're the "Business" vs. the "Service Provider"

Under US privacy frameworks like the CCPA, the entity that decides why and how personal data is used is the "business" (or "controller"); an entity that processes data on behalf of and under the instructions of another business is a "service provider" (or "processor"). This distinction matters here:

3. How We Use Information

We use the information above to: operate and maintain the Service; authenticate accounts and grant/revoke Guest access to guestbooks; process subscription and Upsell payments; send transactional emails and SMS you've configured (booking confirmations, guestbook links, order notifications); power the AI concierge; detect and prevent fraud, abuse, and security incidents; understand how Hosts use the dashboard so we can improve it; and comply with legal obligations.

We do not sell personal information, and we do not use Guest personal information for advertising or marketing purposes.

4. Cookies and Similar Technologies

5. AI Processing Disclosure

The AI concierge feature sends Guest questions and relevant guestbook content to our AI provider, currently Anthropic (Claude API), to generate a response. This is necessary to make the feature work.

As of this writing, our understanding of Anthropic's commercial API terms is that data submitted through the API is not used to train Anthropic's underlying models by default. Confirm this against Anthropic's current terms before publishing this policy, and update this section if their policy changes. We retain AI chat questions (see Section 7) so Hosts can review what their Guests are asking, improve their guestbooks, and see which questions the AI couldn't confidently answer.

We do not currently use Guest or Host data to train our own AI models.

6. Who We Share Information With

We share information with the following categories of service providers, each of which processes data only as needed to provide their specific function to us:

ProviderPurposeData involved
SupabaseAuthentication, database, file storageHost account data, property/booking data
StripeSubscription billing, Upsell marketplace paymentsHost billing info, Guest name (for orders), payment amounts
AnthropicAI concierge responsesGuest questions, relevant guestbook content
ResendTransactional email deliveryHost and Guest email addresses, email content
TwilioSMS deliveryGuest phone numbers, message content
UpstashCaching, rate limiting, chat historyAI chat messages (temporary), rate-limit counters
MapboxLocal-area maps, address geocodingProperty address/coordinates
PostHogProduct analytics (Host and Guest pages)Host usage events, Guest usage events, device/browser data
VercelApplication hostingAll data in transit to/from our servers

We may also disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of HostDesk, our users, or the public. If HostDesk is involved in a merger, acquisition, or asset sale, personal information may be transferred as part of that transaction, subject to this policy or a materially similar one.

7. Data Retention

8. Your Rights

Depending on where you live, you may have rights under laws like the California Consumer Privacy Act (CCPA/CPRA) or other US state privacy laws, including the right to:

Hosts can exercise these rights directly from account settings or by contacting us at hostdesk7@gmail.com.

Guests whose data was entered by a Host should generally start with that Host, since the Host controls what data is collected and why. If you're a Guest and can't reach your Host, contact us at hostdesk7@gmail.com and we'll do our best to help, including relaying your request to the relevant Host.

We'll respond to verified requests within the time required by applicable law (generally 45 days under CCPA, extendable once by 45 more days if needed).

9. Data Security

We use industry-standard measures to protect data, including encryption in transit (HTTPS/TLS), httpOnly cookies for authentication (not readable by client-side scripts), tokenized/time-limited Guest access links rather than permanent public URLs, rate limiting on sensitive endpoints, and access controls limiting who can view Host and Guest data. No system is perfectly secure, and we can't guarantee absolute security — if we become aware of a data breach affecting your personal information, we'll notify you as required by applicable law.

10. Children's Privacy

The Service is not directed at children, and we don't knowingly collect personal information from anyone under 13 (or 16, where applicable state law requires it). If you believe a child has provided us personal information, contact us and we'll delete it.

11. International Users

The Service is hosted and operated in the United States. If you access it from outside the US, your information will be transferred to and processed in the US, which may have different data protection laws than your home country.

12. Changes to This Policy

We may update this policy from time to time. If changes are material, we'll notify Hosts (e.g., by email or in-app notice) before they take effect. The "Last Updated" date at the top reflects the most recent revision.

13. Contact Us

Questions about this policy or your data? Contact us at hostdesk7@gmail.com.