HostDesk Privacy Policy
Effective Date: July 2, 2026 Last Updated: July 6, 2026
This Privacy Policy explains how 26Triumphus LLC ("HostDesk," "we," "us") collects, uses, and shares information through the HostDesk website, dashboard, and guest-facing pages (the "Service").
This policy covers two different groups of people, and we handle their data differently — read Section 2 first, it matters.
1. Information We Collect
From Hosts (people with a HostDesk account)
- Account information: name, email address, phone number (optional), password/authentication credentials (via our authentication provider, Supabase).
- Property information: property name, address, listing details, photos, guestbook content you write.
- Payment information: if you subscribe to a paid plan or use Stripe Connect for Upsells, Stripe collects and stores your payment details directly — we don't store full card numbers on our servers. We do store your Stripe customer/account identifiers and subscription status.
- Usage data: how you use the dashboard (pages visited, features used, e.g., whether you've opened the Revenue report), collected via our analytics provider, PostHog.
About Guests (people who stay at a Host's property)
Guests don't create HostDesk accounts. The Host provides us with:
- Booking information: Guest name, email address, phone number (optional), check-in and check-out dates.
- Guest chat activity: questions Guests ask the AI concierge, so the Host can see common questions and so unanswered ones can be flagged. Chat conversation history is temporarily cached (see Section 7, Data Retention).
- Access logs: when a Guest verifies access via their booking link or email, we log that verification for security purposes (e.g., detecting abuse of the access system).
- Usage data: how Guests use their guestbook page (pages/sections viewed, general device/browser information), collected via our analytics provider, PostHog, on the same basis as Host usage data above.
We do not run advertising trackers on Guest-facing pages, and we do not use this usage data for advertising or marketing purposes.
Automatically, from anyone visiting our marketing site
Standard technical data (IP address, browser type, pages visited) via PostHog, for understanding how our marketing site performs. You can decline non-essential cookies where required by law.
2. Two Roles: When We're the "Business" vs. the "Service Provider"
Under US privacy frameworks like the CCPA, the entity that decides why and how personal data is used is the "business" (or "controller"); an entity that processes data on behalf of and under the instructions of another business is a "service provider" (or "processor"). This distinction matters here:
- For Host account data (your name, email, billing info, usage of our dashboard), HostDesk is the business/controller. This policy describes our own data practices directly to you.
- For Guest personal information you enter into HostDesk (your Guests' names, emails, phone numbers, stay dates), you (the Host) are the business/controller, and HostDesk acts as your service provider/processor. We process that data only to provide the Service to you — granting Guest access, sending messages you configure, and powering the AI concierge — not for our own independent purposes. If a Guest wants to know how their data is used, the first point of contact should be the Host whose property they stayed at; we'll assist Hosts in responding to Guest requests.
3. How We Use Information
We use the information above to: operate and maintain the Service; authenticate accounts and grant/revoke Guest access to guestbooks; process subscription and Upsell payments; send transactional emails and SMS you've configured (booking confirmations, guestbook links, order notifications); power the AI concierge; detect and prevent fraud, abuse, and security incidents; understand how Hosts use the dashboard so we can improve it; and comply with legal obligations.
We do not sell personal information, and we do not use Guest personal information for advertising or marketing purposes.
4. Cookies and Similar Technologies
- Authentication cookies: used to keep you signed in (Hosts) or to verify a Guest's booking-linked access (httpOnly, can't be read by JavaScript, scoped to prevent misuse).
- Analytics cookies (PostHog): set on both host-facing pages (marketing site, login/signup, dashboard) and Guest-facing guestbook pages, to understand product usage. Advertising/marketing cookies are never set on Guest-facing pages, and Guest usage data is never used for advertising or marketing purposes.
5. AI Processing Disclosure
The AI concierge feature sends Guest questions and relevant guestbook content to our AI provider, currently Anthropic (Claude API), to generate a response. This is necessary to make the feature work.
As of this writing, our understanding of Anthropic's commercial API terms is that data submitted through the API is not used to train Anthropic's underlying models by default. Confirm this against Anthropic's current terms before publishing this policy, and update this section if their policy changes. We retain AI chat questions (see Section 7) so Hosts can review what their Guests are asking, improve their guestbooks, and see which questions the AI couldn't confidently answer.
We do not currently use Guest or Host data to train our own AI models.
6. Who We Share Information With
We share information with the following categories of service providers, each of which processes data only as needed to provide their specific function to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication, database, file storage | Host account data, property/booking data |
| Stripe | Subscription billing, Upsell marketplace payments | Host billing info, Guest name (for orders), payment amounts |
| Anthropic | AI concierge responses | Guest questions, relevant guestbook content |
| Resend | Transactional email delivery | Host and Guest email addresses, email content |
| Twilio | SMS delivery | Guest phone numbers, message content |
| Upstash | Caching, rate limiting, chat history | AI chat messages (temporary), rate-limit counters |
| Mapbox | Local-area maps, address geocoding | Property address/coordinates |
| PostHog | Product analytics (Host and Guest pages) | Host usage events, Guest usage events, device/browser data |
| Vercel | Application hosting | All data in transit to/from our servers |
We may also disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of HostDesk, our users, or the public. If HostDesk is involved in a merger, acquisition, or asset sale, personal information may be transferred as part of that transaction, subject to this policy or a materially similar one.
7. Data Retention
- AI chat conversation history: cached for 48 hours to maintain conversation context, then automatically expires.
- Logged AI questions (used for the Host's "AI Insights" dashboard): retained for as long as the associated property/account is active, so Hosts can track recurring guest questions over time. Deleted when the Host deletes the property or closes their account.
- Booking and Guest contact data: retained for as long as the Host's account is active, or until the Host deletes the booking/property. Guest magic-link access automatically expires shortly after the stay window ends, independent of data retention.
- Host account data: retained while your account is active. If you close your account, we delete or anonymize your data within 30 days, except where we're required to keep it longer (e.g., financial records for tax/legal compliance, generally 7 years for payment-related records).
- Order/payment records: retained as required for tax, accounting, and fraud-prevention purposes, consistent with standard financial recordkeeping requirements.
8. Your Rights
Depending on where you live, you may have rights under laws like the California Consumer Privacy Act (CCPA/CPRA) or other US state privacy laws, including the right to:
- Know what personal information we (or, for Guest data, the Host) hold about you
- Request deletion of your personal information
- Correct inaccurate information
- Opt out of the "sale" or "sharing" of personal information — we don't sell personal information, so there's nothing to opt out of, but you can still contact us with questions
- Not be discriminated against for exercising these rights
Hosts can exercise these rights directly from account settings or by contacting us at hostdesk7@gmail.com.
Guests whose data was entered by a Host should generally start with that Host, since the Host controls what data is collected and why. If you're a Guest and can't reach your Host, contact us at hostdesk7@gmail.com and we'll do our best to help, including relaying your request to the relevant Host.
We'll respond to verified requests within the time required by applicable law (generally 45 days under CCPA, extendable once by 45 more days if needed).
9. Data Security
We use industry-standard measures to protect data, including encryption in transit (HTTPS/TLS), httpOnly cookies for authentication (not readable by client-side scripts), tokenized/time-limited Guest access links rather than permanent public URLs, rate limiting on sensitive endpoints, and access controls limiting who can view Host and Guest data. No system is perfectly secure, and we can't guarantee absolute security — if we become aware of a data breach affecting your personal information, we'll notify you as required by applicable law.
10. Children's Privacy
The Service is not directed at children, and we don't knowingly collect personal information from anyone under 13 (or 16, where applicable state law requires it). If you believe a child has provided us personal information, contact us and we'll delete it.
11. International Users
The Service is hosted and operated in the United States. If you access it from outside the US, your information will be transferred to and processed in the US, which may have different data protection laws than your home country.
12. Changes to This Policy
We may update this policy from time to time. If changes are material, we'll notify Hosts (e.g., by email or in-app notice) before they take effect. The "Last Updated" date at the top reflects the most recent revision.
13. Contact Us
Questions about this policy or your data? Contact us at hostdesk7@gmail.com.