Privacy Policy
Effective Date: December 2, 2025 • Last Updated: December 2, 2025
1. Introduction
HostHero.io ("HostHero," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (collectively, the "Service").
This policy applies to:
- Hosts: Property owners, managers, and their team members who use our platform
- Guests: Individuals who interact with HostHero through QR codes at properties
Please read this policy carefully. By using our Service, you consent to the practices described herein.
2. Information We Collect
2.1 Information You Provide
Host Account Information:
- Name and email address
- Organization name
- Password (stored securely using industry-standard hashing)
- Profile information (avatar, preferences)
- Payment information (processed by Stripe; we do not store full payment details)
Property Information:
- Property name, address, and timezone
- Knowledge base content (FAQs, house manuals, policies)
- QR code configurations
- Escalation settings and preferences
Guest Interaction Data:
- Chat messages and conversation history
- Language preference (auto-detected)
- Feedback and ratings provided
- Contact information (email or phone) when voluntarily provided for escalation purposes
2.2 Information Collected Automatically
Usage Data:
- IP address (hashed and anonymized)
- Device type and browser information
- Pages visited and features used
- Session duration and interaction patterns
- Referral source
Technical Data:
- Log files (error logs, access logs)
- Performance metrics (response times, system health)
- Cookies and similar technologies (see Section 7)
2.3 Information from Third Parties
Authentication Providers: If you sign in using Google OAuth, we receive your email address and profile information from Google in accordance with the permissions you grant.
Payment Processors: Stripe provides us with transaction status and limited billing information (last four digits of card, billing address country).
3. How We Use Your Information
3.1 To Provide the Service
- Create and manage your account
- Process subscriptions and payments
- Generate AI-powered responses from your knowledge base
- Deliver notifications and escalation alerts
- Provide customer support
3.2 To Improve the Service
- Analyze usage patterns to improve features
- Train and refine our AI models (using anonymized data only)
- Conduct research and development
- Fix bugs and optimize performance
3.3 To Communicate With You
- Send service-related notifications (billing, security, updates)
- Respond to your inquiries and support requests
- Send product updates and announcements (with your consent where required)
3.4 For Safety and Security
- Detect and prevent fraud, abuse, and security threats
- Enforce our Terms of Service
- Comply with legal obligations
3.5 For Analytics
- Generate aggregated, anonymized statistics
- Create reports for hosts about their property performance
- Monitor overall platform health and usage trends
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on:
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Performance of contract |
| Processing payments | Performance of contract |
| Sending service notifications | Legitimate interest |
| Improving the Service | Legitimate interest |
| Marketing communications | Consent |
| Complying with legal obligations | Legal obligation |
| Preventing fraud and abuse | Legitimate interest |
You may withdraw consent at any time where consent is the legal basis for processing.
6. Data Retention
We retain your information only as long as necessary for the purposes described in this policy:
| Data Type | Retention Period | Rationale |
|---|---|---|
| Account information | Duration of account + 30 days | Service provision |
| Chat transcripts | 90 days | Quality assurance, dispute resolution |
| System logs | 180 days | Security, debugging |
| Anonymized analytics | Indefinitely | Service improvement |
| Payment records | As required by law (typically 7 years) | Legal/tax compliance |
| IP addresses | Hashed; 180 days | Abuse prevention |
After the retention period, data is either deleted or anonymized.
8. Your Rights
8.1 All Users
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate data
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Portability: Receive your data in a structured, machine-readable format
- Withdraw Consent: Where processing is based on consent
8.2 EEA/UK/Swiss Residents (GDPR Rights)
In addition to the above, you have the right to:
- Object: Object to processing based on legitimate interest
- Restriction: Request restriction of processing in certain circumstances
- Complaint: Lodge a complaint with a supervisory authority
8.3 California Residents (CCPA Rights)
California residents have the right to:
- Know what personal information is collected and how it's used
- Request deletion of personal information
- Opt-out of the sale of personal information (note: we do not sell data)
- Non-discrimination for exercising privacy rights
8.4 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
- Email: privacy@hosthero.io
- Use the data request form in your account settings
We will respond to requests within 30 days (or as required by applicable law). We may request verification of your identity before processing requests.
9. Data Subject Access Requests (DSAR)
We support automated DSAR processing:
- Export: Request a full export of your data through account settings or by contacting us
- Deletion: Request deletion of your account and associated data
- Timeline: Requests are processed within 30 days
For guest data requests, please contact the property host who can facilitate the request, or contact us directly.
10. Data Security
We implement appropriate technical and organizational measures to protect your data:
10.1 Technical Measures
- Encryption in transit (TLS 1.2+)
- Encryption at rest for sensitive data
- Secure password hashing (bcrypt)
- Regular security assessments and penetration testing
- Automated vulnerability scanning
10.2 Organizational Measures
- Access controls and principle of least privilege
- Employee security training
- Incident response procedures
- Regular security audits
- Vendor security assessments
10.3 Row-Level Security
Our database implements row-level security (RLS) to ensure that hosts can only access data for their own properties and organizations.
10.4 Incident Response
In the event of a data breach that poses a risk to your rights, we will:
- Notify affected users within 72 hours
- Notify relevant supervisory authorities as required
- Take immediate steps to mitigate the breach
11. International Data Transfers
11.1 Where Data is Processed
Your data may be processed in:
- United States (primary infrastructure)
- European Union (backup and processing)
11.2 Transfer Safeguards
When transferring data outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where available
- Additional technical and organizational safeguards
12. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
13. Guest-Specific Privacy Information
13.1 What Guests Should Know
When you interact with HostHero at a property:
- Minimal Data Collection: We collect only the information necessary to assist you (chat messages, language preference)
- No Account Required: You can use the Service without creating an account
- Voluntary Contact Info: If you provide contact information for escalation, it is shared only with the property host
- Conversation History: Chat history is retained for 90 days for quality assurance
- AI-Powered Responses: Responses are generated by AI based on property-specific information
13.2 Guest Rights
As a guest, you can:
- Request deletion of your conversation history
- Opt out of providing contact information
- Contact us to exercise your privacy rights
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website
- Sending email notification to hosts
- Displaying a notice in the Service
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
HostHero.io Data Protection
Email: privacy@hosthero.io
Data Protection Officer (for EEA inquiries):
Email: dpo@hosthero.io
16. Supervisory Authority
If you are located in the EEA and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.