Stayflow Privacy Policy
Last updated: 2026-08-30
Stayflow helps properties welcome their guests: check-in, messaging, requests, orders, and local recommendations, all in one place. To do that work, personal information passes through our hands. This page explains what we hold, why, for how long, and what you can do about it.
We wrote it to be read. If anything here is unclear, write to us — the address is at the end.
One note on words: throughout this policy, "property" means the accommodation you are staying at or working for — the business that invited you into Stayflow.
Who we are
Stayflow is operated by Stayflow Inc., 395 rue Mathieu-Da Costa, unité 363, Québec (Québec) G2K 0P6, Canada ("Stayflow", "we", "us"). We build the platform; we are not the property you are staying at.
Two roles, two responsibilities
Stayflow plays two distinct roles, and knowing which one applies to you tells you who is responsible for your data.
For guests, Stayflow is a processor. When you use a property's guest app, that property decides what information to ask you for and why. The property is the independent controller of your data; Stayflow processes it on the property's behalf, under its instructions. Your first point of contact for anything about your data is the property itself — though you can always write to us too, and we will help route your request.
For properties and their staff, Stayflow is a controller. We decide how account, sign-in, and billing data for our own customers is handled, and we answer for it directly.
For website visitors, Stayflow is likewise the controller of the little we collect (see below — it is genuinely little).
What we collect if you are a guest
Everything below comes either from you or from your property. We do not buy data about you, and we run no advertising or analytics trackers — none, anywhere.
Identity and contact details. Your name, email address, phone number, nationality, language, and any preferences you share. If your reservation was created in the property's booking system (such as Mews or Cloudbeds), these details may arrive from there. One thing we want to say plainly: Stayflow keeps a single guest record per email address across the whole platform. If you stay at two different properties that both use Stayflow, they share the same underlying identity record. This record is fully removed only once your last remaining stay anywhere on the platform is erased.
Pre-check-in answers. Arrival time, party size, and optional questions such as where you are travelling from, the reason for your visit, and your interests.
Travel companions. If you add the people travelling with you, their names and contact details are stored with your stay, included in any export of it, and removed when your stay is erased (unless they are also part of another stay).
Identity documents and signature (only where your property requires verified check-in). Photos of the front and back of your ID, a selfie, and your drawn signature. These live in private storage, never on a public link: hidden location data (EXIF, such as GPS coordinates) is stripped the moment a photo is uploaded, viewing links expire after 5 minutes, and every single time a staff member views your documents, that access is written to a permanent log before the documents are released — if the log entry cannot be written, the documents stay locked.
Messages. Your conversation with the property — in the app, and by SMS, WhatsApp, or email if you reply through those channels — along with photos and voice notes you send, and delivery/read receipts.
Orders and payments. What you ordered, any note you attach, and the payment outcome. Payment itself happens on Stripe's own secure pages: your card number never touches Stayflow's servers, and we store only transaction references and amounts.
Requests and feedback. Service requests you make (with an optional photo), your departure rating, and any comments.
Your device and notifications. A sign-in token for your device, its browser type, and — only if you opt in — a push notification subscription tied to your stay. Notifications for a stay stop when the stay ends, and you can switch them off at any time in the app.
Error reports. If the app hits a problem in your browser, an error event — with your IP address, browser details, and the page address scrubbed of anything sensitive — goes to our error-monitoring service so we can fix crashes.
Location: used, not collected. If you allow location for the map, we explain why before your phone asks you, your position is blurred to roughly 110 metres inside your own browser, it is never stored on our servers, and it is sent only to Google Maps as the centre of your search — with no name or identifier attached. Saying no works fine; the map simply centres on the property.
AI recommendations (only if your property switches them on). To suggest a day plan that fits you, we send your conversation with the property and your pre-check-in answers to Google's Gemini service — with your name and email address structurally removed first. The resulting travel profile is stored with your stay, included in any export of your data, and erased along with it.
What we collect if you work at a property
Your name, email, phone number, and role; your sign-in records through our authentication service; your messages in team chat; your push notification subscriptions (removed when you sign out everywhere); and, for the person who manages the subscription, billing contact details and payment references held with Stripe. Team chat is a staff space by policy — guest personal data does not belong there. And if a console hits a problem in your browser, an error event — with your IP address, browser details, and scrubbed page addresses — goes to our error-monitoring service so we can fix crashes.
What we collect if you just visit our website
Almost nothing. Our sites use no analytics, no advertising trackers, no third-party embeds. Exactly four first-party cookies exist across our sites: one remembers your language choice (for one year), and three exist purely to make sign-in work. The guest app sets no cookies at all — it keeps its settings in your device's own storage, where they stay.
Two third parties deserve a mention: when you pay, you are handed to Stripe's own website (any cookies there are Stripe's, on Stripe's domain, under Stripe's policy), and the map inside the guest app loads from Google, which — like any website you load content from — receives your IP address and browser details.
Why we use data, and on what legal grounds
Where the GDPR applies, every use of personal data needs a legal basis. For guest data, the property is the controller and determines the basis; the ones below reflect how the platform is built.
- Performing the contract of your stay — reservations, check-in, messaging, orders, requests, and your access to the guest app. This is the everyday work of the platform.
- Your consent — marketing messages (asked separately for each purpose — marketing by email and marketing by SMS are separate yes/no decisions, each recorded in a tamper-proof ledger, described below), location for the map, and push notifications. Each of these is genuinely optional, asked for in plain terms, and refusable without losing the service.
- Legal obligations and legitimate interests — keeping accurate billing and payment records, securing the platform, preventing payment fraud — including sharing fraud signals with our payment processor — and keeping the access log that protects your identity documents.
One honest detail: Stayflow records marketing consent, but does not currently send marketing messages. The ledger exists so that if a property ever runs a campaign, it can only reach guests who truly said yes.
For property accounts (where Stayflow is the controller), we process data to provide and bill the service (contract), to secure it (legitimate interest), and to meet tax and accounting obligations (legal obligation).
Québec's Law 25
Stayflow is built from Québec, and the Act respecting the protection of personal information in the private sector (as amended by Law 25) shapes how we work.
- The person in charge of the protection of personal information (personne responsable de la protection des renseignements personnels) is Marc-Antoine Claveau, CEO, reachable at [email protected].
- Confidentiality incidents. If an incident involving personal information presents a risk of serious injury, we commit to notifying the Commission d'accès à l'information, the affected persons, and — for guest data — the property concerned, and to keeping a register of incidents as the law requires.
- Privacy by default is not a slogan here: no trackers, opt-in notifications, location blurred on your own device, hidden photo metadata stripped at upload, and consent recorded in a ledger that even our own staff cannot rewrite.
Your rights, and the machinery behind them
You have the right to access your data, to receive a copy of it, to correct it, to have it erased, and to withdraw consent. Under the GDPR you may also object to certain processing and complain to your supervisory authority; in Québec, to the Commission d'accès à l'information.
These rights are not just words in a policy — they are built into the product:
- Access and portability. The property can produce a complete export of your stay: identity, pre-check-in answers, requests, orders and payment records, messages, devices, and the AI travel profile — exactly as stored. The export itself is recorded in the access log.
- Erasure. The property can trigger an irreversible purge of your stay. It deletes your ID photos, signature, chat and its media, request photos, travel profile, and devices in one operation, and anonymizes what must remain (see Retention); push subscriptions are removed when you unsubscribe or your browser drops them. The purge is logged by counts only — never by content — and erased data ages out of our backups within 14 days. One exception we will not hide: delivery ledgers for WhatsApp messages currently retain the destination number; we are closing this gap.
- The access log. An append-only trail — the database itself refuses edits and deletions — records exports, erasures, and every disclosure of identity documents. Properties can read it in their console.
- The consent ledger. Every marketing consent decision is an append-only event that records the exact wording you saw, in your language, with its version. Staff can record your withdrawal on your behalf, but the database physically refuses to let staff record a grant — only you can say yes.
How to exercise your rights, in practice: there is no self-serve button in the guest app today, so send your request to your property — they hold the controller role and the tools described above. If you cannot reach them, or your request concerns Stayflow itself, write to [email protected] and we will act or route it, and in any case respond within 30 days.
Property staff and account holders: write to us directly at the same address.
How long we keep things
Real numbers, because "as long as necessary" helps no one:
| What | How long |
|---|---|
| Stay data (identity, check-in, chat, photos, profile) | Automatically anonymized 24 months after check-out by default; a sweep runs continuously and its actions are audit-logged |
| Guest app access | Ends at check-out plus a grace period — 24 hours by default, property-adjustable between 0 and 168 hours |
| Sign-in magic links | Single-use, stored only as a hash, expire when your stay (plus grace) ends |
| One-time SMS/email codes | 10 minutes |
| Links to view photos and ID documents | 5 minutes |
| Shared day-plan links | Check-out plus 7 days, with all personal details stripped from the shared page |
| Backups | Nightly, kept 14 days off-site — so erased data is fully gone from backups within 14 days |
| Payment and settlement records | Retained as financial records (amounts, dates, references); message-delivery ledgers keep counts and amounts, with phone numbers scrubbed on erasure — except the WhatsApp delivery records noted under Erasure above, a gap we are closing; personal notes are scrubbed on erasure |
| The access log | Permanent by design — but names in it are resolved live, so an erased guest no longer appears in the trail |
| Team (staff) chat | Retained; guest personal data is kept out of it by policy |
When a stay is anonymized, the reservation survives only as a non-personal record (dates, room, status) so the property's history still adds up.
Where your data lives, and where it travels
Your data lives on Stayflow's own server, hosted by Hostinger in the United States, running our own database, file storage, and messaging systems — most of the platform is self-hosted rather than scattered across cloud services. Encrypted backups of that server go nightly to Google Cloud Storage and are kept for 14 days.
Some of the companies that help us run the service — for example Stripe (payments), Twilio (SMS and WhatsApp), and Google (maps, AI) — process data in the United States and elsewhere. Where personal data leaves the United States and Canada, we rely on Our own server is in the United States, and several of our providers process data there too. For every transfer outside Québec we rely on the provider's contractual data-protection commitments and assess, as Québec's Law 25 (s. 17) requires, that the information receives equivalent protection..
The companies that help us
We use a small number of service providers — for hosting, traffic protection, messaging, payments, maps, AI, backups, and error monitoring — and we name every one of them, with what data reaches each, on our Subprocessors page. Two are worth calling out here: AI recommendations run only for properties that switch them on, and a property's booking system (Mews, Cloudbeds) is connected only by that property's own choice.
Changes to this policy
When we change this policy in a way that matters, we will update the date at the top and tell properties through the console; properties are responsible for informing their guests of changes that affect them. We keep prior versions available on request.
Contact
Stayflow Inc. 395 rue Mathieu-Da Costa, unité 363, Québec (Québec) G2K 0P6, Canada Privacy: [email protected] — general questions: [email protected] Person in charge of the protection of personal information: Marc-Antoine Claveau, CEO — [email protected]
This policy is governed by the laws of Québec and the applicable laws of Canada.