Skip to content
Legal

Privacy Policy

Last updated: 4 September 2026

This Privacy Policy explains what data Hostberg collects, how it's stored, and what rights you have over it — both as an operator using Hostberg, and as a guest whose stay is recorded in it.

1. What we collect

Operator account data. When you sign up, we collect your name, email address, and organization name, to create and secure your account.

Property, booking, guest, and payment data.Everything you or your staff enter into Hostberg to run your properties — property and room details, reservations, guest names and contact details, payment records, tasks, and messages — we only pull in what's needed to operate the booking calendar and front desk.

Guests do not create Hostberg accounts.A guest's data reaches us because their host (the operator) enters it in, not because the guest signs up directly. The one guest-facing surface in the product is a read-only, tokenized stay-summary link an operator can share with a guest — it shows the guest their own name, property, room, and dates, and nothing financial.

2. How it's stored

Hostberg is built on Supabase, which provides our database, authentication, and file storage, hosted on infrastructure Supabase operates. Access to your organization's data is enforced at the database level (row-level security) — each organization's data is isolated from every other organization's, not just hidden in the interface. We don't maintain a separate copy of your data outside Supabase.

3. No AI or third-party processing of your data

We do not currently send your booking, guest, or payment data to any AI model, machine-learning service, or third-party API for processing. Automatic calendar sync (for Airbnb, Vrbo, and Booking.com, via their public iCal feed links) only reads a unit's blocked date ranges to prevent double-bookings — it does not receive guest names, contact details, or payment information, since a standard iCal feed doesn't include them. Only direct bookings (a guest who books straight with you) are entered manually, since there is no calendar to sync for those. We do not run analytics or tracking scripts on this site or in the product today. If this changes in the future — for example, if we introduce an AI-assisted feature — we will update this policy first and make it an explicit, described part of the product rather than a silent addition.

4. Who can see your data

Only your organization's own users — accounts you or another owner in your organization have invited — can see your properties, bookings, guests, and payments, governed by the role and permissions you assign them. We (Hostberg, as the service operator) can access data as needed to provide support you request, investigate a reported issue, or maintain the Service — we do not access it to look at your business for any other reason.

5. Your rights

You, or a guest whose data appears in your account, can request:

  • Access — a copy of the personal data we hold.
  • Correction — a fix to inaccurate data. For guest data this is usually best done directly in the product by the operator, since the operator is the data controller for their own guests.
  • Deletion — removal of your account and login. Your organization's bookings, guests and payment records stay intact (they belong to the business, not to any one person's login) — only your personal account and its attribution on those records is removed. An organization's sole owner can't self-delete without first adding another owner, so the account always has someone able to manage it.

You can delete your own account directly from Settings inside the product — no request needed. For anything else (a correction, a full organization shutdown, a guest's data request), send it to fcbjahan@gmail.com. A guest asking us directly about their own data will typically be redirected to the property operator they stayed with, since the operator — not Hostberg — controls the underlying guest relationship and the data attached to it.

6. Changes to this policy

We'll update this page and its "Last updated" date as the product changes — most importantly if we introduce payment processing, analytics, or AI-assisted features that touch operator or guest data.

7. Contact

Questions about this policy can be sent to fcbjahan@gmail.com.