Privacy Policy
Effective Date: February 6, 2026 | Last Updated: February 6, 2026
Hostary ("we," "us," or "our"), located in Clovis, California, operates the Hostary platform including our website at hostary.app, our web application at app.hostary.app, and the Hostary TV device software. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our Service.
In this policy, "Service" refers to the Hostary platform as a whole. "You" or "user" refers to hosts and property managers who use the Service. "Guest" refers to visitors staying at a vacation rental property managed through the Service.
1. Information We Collect
Information You Provide Directly
- Account information: name, email address, and password when you create an account.
- Property information: property names, addresses, descriptions, WiFi credentials, house rules, check-in/check-out instructions, and local recommendations.
- Guest information: guest names for personalized TV welcome screens and reservation dates.
- Payment information: billing details processed securely through Stripe. Hostary does not directly store your full credit card number.
- Communications: messages you send through our contact forms or support channels.
Information Collected Automatically
- Usage data: pages visited, features used, device pairing activity, and session duration.
- Device information: browser type, operating system, and IP address.
- Cookies: session cookies for authentication and preference management.
Information from Third Parties
- Firebase: authentication tokens and account verification data.
- Stripe: payment confirmation and subscription status.
2. How We Use Your Information
We use the information we collect to:
- Provide and operate the Service, including displaying personalized guest welcome screens and delivering property information to TV devices.
- Process payments and manage your subscription.
- Send service-related communications such as account confirmations, billing notices, and feature updates.
- Improve and develop the Service through usage analytics.
- Ensure security and prevent fraud.
- Comply with legal obligations.
We do not sell your personal information to third parties.
3. Legal Basis for Processing (GDPR)
For users in the European Union and United Kingdom, we process your personal data under the following legal bases:
- Contract performance: processing your account and property data is necessary to deliver the Service you signed up for.
- Legitimate interests: analytics to improve the Service and security monitoring to protect our platform and users.
- Consent: marketing communications, where applicable. You can withdraw consent at any time.
- Legal obligation: retaining tax and financial records as required by law.
4. How We Share Your Information
We share your information only in the following circumstances:
- Service providers: Firebase (authentication and database), Stripe (payment processing), and Vercel (website hosting) process data on our behalf to operate the Service.
- Guest-facing display: guest names and property information you enter are displayed on TV devices within the rental property. This is the core function of the Service.
- Legal requirements: when required by law, court order, or governmental authority.
- Business transfers: in connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity.
We do not sell your personal data.
5. Data Retention
- Account data: retained for the duration of your account plus 30 days after deletion.
- Billing records: retained as required by tax and financial regulations, typically up to 7 years.
- Guest data: guest names and reservation information are retained for the duration of the reservation plus 30 days.
- Usage analytics: aggregated and anonymized data may be retained indefinitely.
- Streaming app data on devices: automatically cleared at guest checkout.
6. Your Rights
All Users
Regardless of your location, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated data.
- Opt out of marketing communications.
Additional Rights for EU/UK Residents
Under the GDPR and UK GDPR, you also have the right to:
- Request portability of your data in a structured format.
- Restrict the processing of your data.
- Object to processing based on legitimate interests.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us at support@hostary.app.
7. International Data Transfers
Your data is processed and stored in the United States using Firebase (Google Cloud) infrastructure. For users in the EU and UK, data transfers are conducted under Standard Contractual Clauses or other lawful transfer mechanisms as required by applicable law. Google and Stripe maintain their own data protection certifications and compliance programs.
8. Cookies and Tracking Technologies
- Essential cookies: required for session authentication and security. These cannot be disabled.
- Analytics cookies: help us understand usage patterns and improve the Service. You can disable these in your browser settings.
We do not use advertising cookies or third-party tracking pixels. You can manage cookies through your browser settings.
9. Data Security
We take reasonable measures to protect your personal information, including:
- Encryption of data in transit using HTTPS/TLS.
- Firebase security rules to control database access.
- Secure password hashing.
- Regular security reviews.
No method of transmission or storage is 100% secure. We encourage you to use a strong, unique password for your Hostary account.
10. Children's Privacy
The Service is not directed to individuals under the age of 16 (or 13 in the United States under COPPA). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will promptly delete it.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website. The "Last Updated" date at the top of this page will reflect the most recent revision. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
- Email: support@hostary.app
- Address: Hostary, Clovis, CA
EU/UK users may also contact their local data protection supervisory authority.