Cookies & Browser Storage at Stayflow
Last updated: 2026-08-30 Who we are: Stayflow is operated by Stayflow Inc., 395 rue Mathieu-Da Costa, unité 363, Québec (Québec) G2K 0P6, Canada. Questions about this notice go to [email protected] — for readers in Québec, that is also how to reach Marc-Antoine Claveau, CEO, our personne responsable de la protection des renseignements personnels (Loi 25).
The short version
Stayflow uses no advertising cookies, no analytics cookies, and no trackers. None. No Google Analytics, no advertising pixels, no fingerprinting, no third-party fonts, no hidden embeds — not on our marketing site, and not in any of our apps. We checked, and we keep checking.
Everything we do store on your device falls into two plain categories:
- Strictly necessary — it keeps you signed in or makes the app work (including offline). Without it, the product breaks.
- Preference — it remembers a choice you made, like your language or a toggle you switched.
That's the whole list. Nothing on your device is used to profile you, follow you across the web, or measure you for marketing.
Why there is no cookie banner
Consent banners exist because most websites set cookies that watch you. We don't set any of those. The law (including Québec's Loi 25 and similar rules elsewhere) does not require consent for storage that is strictly necessary to provide the service you asked for, and our preference storage is only ever written when you make the choice yourself — picking a language is the consent to remember the language. So a banner here would be theater, and we'd rather be honest than theatrical.
Two features in the guest app do ask before they act, in their own words, at the moment it matters: sharing your location on the map, and receiving push notifications. Saying no to either is fully supported, and the app remembers your "no" so it doesn't nag.
Who is responsible for what
Stayflow is a platform used by independent properties.
- When you are a guest, the property you're staying with decides what guest information is used and why; Stayflow processes that data on the property's behalf (the property is the controller, Stayflow the processor). Questions about your stay data go first to your property.
- When you are a property operator, Stayflow is responsible for your account, sign-in, and billing data as the controller.
This notice covers only what is stored in your browser. What happens to data on our servers is covered by our Privacy Policy.
Cookies — the complete list
Four cookies exist across all of Stayflow. The guest app sets zero cookies.
On the marketing site (www.stayflow.com)
| Name | Purpose | Class | Lifetime |
|---|---|---|---|
sf_lang |
Remembers the language you picked (English, French, Spanish) | Preference | 1 year |
That is the only cookie on the marketing site. Nothing else.
In the operator consoles (sign-in on *.stayflow.com)
| Name | Purpose | Class | Lifetime |
|---|---|---|---|
sf_authed |
A yes/no hint that you have an active sign-in session, so our apps can sign you in silently instead of bouncing you to the login page | Strictly necessary | ~30 days |
sf_logout |
Notes when you signed out, so signing out of one Stayflow app signs you out of the others | Strictly necessary | ~30 days |
| Sign-in session cookie | Set by our own sign-in service at auth.stayflow.com; keeps your login session alive | Strictly necessary | 30 days |
sf_lang |
Your language choice, shared across Stayflow subdomains | Preference | 1 year |
The guest app: no cookies, only on-device storage
The guest app (the one you open during a stay) sets no cookies at all. It keeps a small amount of data in your browser's local storage — data that stays on your device and is not sent anywhere for tracking. The main items:
| Name(s) | Purpose | Class | Lifetime |
|---|---|---|---|
sf_device_token |
Your sign-in key for this stay — this is how the app knows it's you | Strictly necessary | Until sign-out (it stops working when your access ends) |
sf_session_cache:* |
A copy of your stay details so the app opens instantly and works offline | Strictly necessary | Until sign-out |
sf_sr_outbox, sf_chat_outbox |
Messages and requests you sent while offline, held until they can be delivered | Strictly necessary | Until delivered |
sf_paid_return_at, sf_folio_paid_at |
Markers used while returning from a payment page | Strictly necessary | Until the tab closes |
sf_branding, sf_map_chunk_retry |
The property's colors/logo, and a one-time guard after app updates | Strictly necessary | Until the tab closes |
sf_lang, sf_temp_unit, sf_map_traffic |
Language, °C/°F, map traffic toggle | Preference | Until you clear it |
sf_explore_recents |
Your recent map searches (clearable inside the app) | Preference | Until you clear it |
sf_geo_ok |
Remembers that you agreed to share your location on the map | Preference | Until you clear it |
sf_push_optout |
Remembers that you said no to push notifications | Preference | Until you clear it |
sf_install_dismissed and similar |
Remembers prompts you dismissed, so we don't show them again | Preference | Until you clear it |
sf_chat_draft:*, sf_hotel_tz:*, offline snapshots (sf_guide_snapshot:*,
sf_plan_snapshot:*, sf_sky_last, …)
|
Unsent chat drafts, your property's timezone, and offline copies of your guide, plan, and local weather | Strictly necessary (offline use) | Until sign-out or refreshed |
The guest app also uses a service worker — a standard browser feature — to cache the app's own files and up to 200 map place photos (kept at most 7 days) so the app loads fast and works with a weak connection. This is functional caching, not tracking.
The operator consoles store a similar, smaller set: your sign-in token, sign-in flow state, your active organization/property context, and remembered preferences (list vs. board views, calendar density, notification sounds, unsent drafts, a short-lived dashboard cache). Same two classes, same honesty: necessary or preference, nothing else.
Third-party services, explained plainly
Stripe (payments). We never load Stripe's code into our pages and we never see your card number. When you pay, we hand you over to a checkout page hosted by Stripe on Stripe's own website; Stripe sets its own cookies on its own domain during that visit, under Stripe's privacy notice. When payment finishes, you come back to us. No Stripe cookies are set on Stayflow pages.
Google Maps (guest app only). The map inside the guest app is Google Maps, loaded from Google's servers. When the map is on screen, your browser talks directly to Google: Google receives your IP address and your map activity (pans, zooms, searches), and if you're signed in to Google in that browser, those requests may carry your existing Google cookies. Google Maps does not set cookies on the Stayflow domain. If you use "share my location," your position is coarsened on your device (to roughly a city-block scale) before it is used, is never saved by us, and is sent to Google only as a map search center with no name attached.
Error reporting (Sentry). If one of our apps hits a problem, your browser sends an error report to our error-monitoring service, Sentry, in the United States: technical details of the error, your IP address and browser information, and the page's web address — scrubbed of its sensitive parts inside your browser before it is sent. This exists so we can fix crashes; it sets no cookies and is never used for tracking.
Your browser's push service. If you opt in to notifications, they are delivered through your browser's own built-in push service (run by Apple, Google, or Mozilla, depending on your device), which sees only a device endpoint, an encrypted payload, and its timing — never the readable content.
Beyond these, no other third party receives anything from your browser through Stayflow pages.
What blocking each class breaks
- Blocking strictly necessary storage: you cannot stay signed in. The operator consoles will loop back to the login page; the guest app cannot open your stay at all, since your sign-in key lives in that storage. Offline use and unsent-message recovery also stop working.
- Blocking preference storage: everything still works, but the product forgets you — language resets to your browser default on every visit, toggles and dismissed prompts come back, and drafts are not kept.
- Blocking Google's domains: the map in the guest app will not load; the rest of the app works normally.
- Blocking Stripe's domains: you will not be able to complete a payment, since checkout happens on Stripe's site.
How to clear or control this
All of this lives in your browser, under your control. Your browser's settings let you view, block, or delete cookies and site data for stayflow.com (or your property's custom guest-app domain) at any time — usually under "Privacy" → "Cookies and site data." Signing out of the guest app also clears its Stayflow keys from your device.
Changes to this notice
If we ever add a category of storage — and especially if we ever add anything that would require your consent — we will update this notice and, where the law requires it, ask you first. This notice is governed by the laws of Québec and the applicable laws of Canada.