Privacy Policy

Effective date: June 2026

Who we are

StayFlow is operated by Justin Whitaker, who acts as the data controller for the personal data we collect.

What we collect

  • Account data — name, email address, login credentials
  • Property data — addresses, photos, amenities, pricing, availability
  • Usage data — features you use, pages you visit, device identifiers, IP address
  • Support data — messages sent to our support team
  • Payment data — handled securely by our payment provider; we do not store card numbers

Why we collect it

  • Account data is used to create accounts, authenticate users, provide the service, and send essential notices. Legal basis: contract performance and legitimate interests.
  • Property and booking data is used to manage listings, reservations, guest communications, pricing, and cleaning workflows. Legal basis: contract performance.
  • Usage, device, and IP data is used for security, fraud prevention, troubleshooting, analytics, and product improvement. Legal basis: legitimate interests and, where required, consent.
  • Support messages are used to respond to requests and maintain service quality. Legal basis: contract performance and legitimate interests.
  • Marketing preferences are used only where permitted by law or with consent, and you can opt out at any time.

Who we share it with

We only share your data with trusted service providers who help us run StayFlow:

  • Paddle — our Merchant of Record for processing payments, managing subscriptions, handling tax compliance, and providing invoices
  • Cloud hosting providers — for secure data storage and processing
  • Analytics providers — to understand product usage (aggregated and anonymized where possible)
  • Professional advisers — legal and accounting professionals, when required
  • Authorities — regulators, courts, law enforcement, or other public bodies where required by law

We do not sell your personal data to third parties.

How long we keep it

We keep your data for as long as your account is active, and for a reasonable period afterward to fulfill legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete or anonymize it.

Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Restrict or object to certain processing
  • Receive your data in a portable format
  • Withdraw consent at any time

To exercise any of these rights, email us at privacy@stayflow.app. We will respond within 30 days or within the timeframe required by applicable law.

Security

We use industry-standard security measures including encryption in transit and at rest, access controls, and regular security reviews. No system is perfectly secure, but we take reasonable steps to protect your data.

Cookies

StayFlow uses essential cookies to keep you logged in and maintain your session. We also use analytics cookies to understand how the product is used. You can manage cookie preferences through your browser settings.

Contact us

If you have questions about this privacy notice, contact us at privacy@stayflow.app.