Security & privacy
Security software cannot ignore
The strongest controls are the ones software cannot ignore. Stayflow's property isolation, access log, and consent ledger are enforced beneath the application, not just promised by it — built for GDPR and Québec's Law 25.
One property cannot see another
Isolation is a rule of the foundation, not a habit of the code.
Property boundaries are enforced beneath the application, not just promised by it — a layer of enforcement the code above cannot talk its way past. It holds for every screen, every export, every request.
Reservation-scoped guests
A guest session is tied to one stay, not one email address. Other stays and other properties are simply out of reach — the boundary holds whether or not anyone remembers to check.
Scoped staff access
Staff permissions come from role templates you control — front desk sees front-desk things, housekeeping sees housekeeping things — and property boundaries are enforced again beneath all of it.
Identity documents get the strictest path
Where a property turns on verified check-in, guests upload ID photos and a signature. That path has four locks.
Private storage
ID photos and signatures never sit on a public link. They live in private storage from the moment they arrive.
Hidden metadata removed
A photo carries more than pixels. Hidden metadata — including GPS coordinates — is stripped the moment a photo is uploaded.
Links that expire in minutes
Every viewing link is temporary. Minutes after it is issued, it is dead — a link that leaks is a link that no longer works.
No record, no access
Every staff view lands in a permanent access log before the documents open. No record, no access.
Records that cannot be rewritten
An editable audit trail is not a trail.
The access log and the consent ledger cannot be edited — not by staff, not by us. What was written stays written.
The access log
Exports, erasures, and every disclosure of an identity document land in a permanent trail. Properties can read it in their console. Nobody can rewrite it.
The consent ledger
Marketing consent is asked per purpose — email and SMS are separate decisions — and each answer is stored with the exact wording and version the guest saw. Staff can record a withdrawal, but never a grant. Only the guest can say yes.
No trackers, anywhere
The easiest data to protect is the data we never collect.
- No advertising or analytics trackers — not on our websites, not in the console, not in the guest app. Open your browser's inspector and count — we'll wait.
- Exactly four first-party cookies across all our sites. The guest app sets zero cookies.
- Guest location is used, not collected — blurred on the device, never stored on our servers, and shared with Google Maps carrying no identifier at all.
- AI suggestions can be switched off per property, and the guest's name and email are structurally removed before anything reaches Stayflow AI.
- Even our error reports are scrubbed — the query and fragment of every page address, where sign-in credentials live, are stripped before an error leaves the browser.
Secrets, payments, and sessions
Encrypted provider secrets
API keys managed in the console are sealed with AES-256 before they are stored. They are never kept in plain text.
Payments stay on Stripe
Guests pay on Stripe's own pages. Card numbers never touch Stayflow's servers — we store only transaction references and amounts.
Short-lived guest sign-in
Guest sign-in links work exactly once — the first device to open one burns it — and they die with the stay. One-time codes expire ten minutes after they are issued, on their own — a stale code is a dead code.
Sign-out that means it
When a staff member signs out, the session ends on our server too — the token is refused the next time it is used, not just cleared in the tab you clicked, and one sign-out covers every Stayflow app on that device. Sign out everywhere, in the profile, ends every session the account holds on every device: the control for a phone left in a taxi.
Law 25 and GDPR, built into the product
Stayflow is built from Québec. For guest data, the property is the controller and Stayflow is the processor — and the rights machinery is real, not just written down.
The person in charge of the protection of personal information is Marc-Antoine Claveau, CEO, reachable at [email protected]. We keep an incident register and will notify the Commission d'accès à l'information whenever the law requires it.
- Detailed security documentation is available on request.
Export
A property can produce a complete export of a stay — identity, pre-check-in answers, orders, messages, devices, and the Stayflow AI travel profile — exactly as stored. The export itself lands in the access log.
Erasure
A property can trigger an irreversible purge of a stay in one step, logged by counts only — never by content. Erased data leaves our encrypted backups quickly and permanently; the exact schedule is in our privacy policy.
Retention by default
Stay data does not linger. It is anonymized automatically after check-out — on a schedule published in our privacy policy — and every anonymization is logged.
Named third parties
Every provider that touches guest data is listed on our subprocessors page, with what each one receives and a 30-day notice commitment before anything changes. Most of the platform runs on infrastructure we operate ourselves and involves no third party at all.
Questions, answered.
Is Stayflow SOC 2 or ISO 27001 certified?
Stayflow holds no security certifications, and we won't imply otherwise. What this page describes are the actual controls — enforced beneath the application, not just promised by it — and our legal pages document them in detail. If your review needs more, ask for the detailed security documentation as a written pack or a walkthrough call — either is fine.
Where is guest data hosted?
Guest data is hosted in the United States on infrastructure we operate ourselves — fewer third parties, fewer places for data to travel. The full list is on our subprocessors page.
Does Stayflow store card numbers?
No. Guests pay on Stripe's own pages, and card numbers never touch Stayflow's servers. We store only transaction references and amounts.
Can a guest's data be exported or erased?
Yes — both are built in. Export produces the complete stay exactly as stored, and the export itself lands in the access log. Erasure is an irreversible purge, done in one step and logged by counts only — never by content — and erased data leaves backups quickly and permanently. Stay data also anonymizes automatically after check-out; the exact schedules are in our privacy policy.
Live the same day.
Create your property, connect your PMS, print the QR codes. Your first guest can check in tonight.
Cards never touch Stayflow Guest data exportable and erasable