Subprocessors
Last updated: 2026-08-30
A subprocessor is another company we rely on to help run Stayflow — for example, the company that hosts our servers, or the one that carries a text message to your phone. When one of these companies handles personal data on our behalf, we list it here and we stay responsible for what it does with that data. Each provider processes personal data under the data-protection commitments in its service agreement — the major providers incorporate a data-protection agreement into their standard terms — and we review that coverage for every provider on this list. We keep this page current: before a new subprocessor begins handling guest data, we update this list and give our property customers advance notice (30 days) so they can raise questions or objections.
Who is responsible for what
Stayflow is a platform used by independent accommodation providers — we call them properties. Each property decides why and how its guests' data is used; in privacy-law terms, the property is the controller of its guests' data, and Stayflow (Stayflow Inc.) is its processor, acting on the property's instructions. The companies below are our subprocessors for that work.
For the data of our own customers — the accounts, contact details and billing records of the people who run properties on Stayflow — Stayflow is the controller, and some of the same companies (for example, our payment and email providers) act as our processors.
Our subprocessors
| Service | What it does for Stayflow | Personal data involved | Location / region |
|---|---|---|---|
| Hostinger | Hosts the servers everything on Stayflow runs on | All Stayflow data at rest and in processing: guest profiles, ID photos, chat messages, consent records, staff and customer accounts | United States |
| Cloudflare | Protects and speeds up traffic to stayflow.com and its subdomains | All traffic in transit between your browser and Stayflow: sign-in, ID photo uploads and downloads, chat, app requests | Global network |
| Twilio | Sends and receives SMS and WhatsApp messages between guests and properties, and delivers one-time sign-in codes | Guest and staff phone numbers, message content, one-time codes, delivery status | United States |
| Meta (WhatsApp) | Carries the WhatsApp messages we send and receive through Twilio | Guest phone numbers and message content † | United States (global infrastructure) |
| SendGrid | Delivers Stayflow's email (sign-in links, chat replies, notifications), receives guest email replies, verifies properties' email sending domains †, and reports whether emails were delivered and opened | Guest and staff email addresses and full message content, both outbound and inbound; domain names; email delivery and open events | United States |
| Stripe | Processes payments and helps us prevent payment fraud. Guests and property customers enter card details on Stripe's own pages — Stayflow never sees or stores card numbers | Name, email and card details (entered directly with Stripe); order amounts and item names; billing records for property customers; where a payment turns out to be fraudulent, the card and email involved are shared with Stripe as fraud signals, so future payments from them are declined | United States (Stripe, Inc.) |
| Google Maps Platform | Powers the map, place search and directions in the guest app | From our servers: the searches and map areas a guest chooses, with no guest identifiers attached. From the guest's browser: their IP address and map interactions go directly to Google | United States (global infrastructure) |
| Google Gemini | Generates the optional AI suggestions and day plans in the guest app † | Guest–property chat content, pre-check-in answers (reason for visit, interests, where the guest is from), stay details, party size, language, and the guest's free-text wishes | United States |
| Google Cloud Storage | Stores our nightly offsite backups, which are kept for 14 days | A full copy of the database (guest records, contact details, consent records, staff accounts) and of stored files (ID photos, chat media, avatars, request photos) | Google Cloud Storage, {{OWNER: bucket region}} |
| Sentry | Collects error reports so we can fix problems quickly | Technical error details, including IP address and browser information; web addresses are scrubbed of sensitive parts before sending | United States (sentry.io) |
| Seam | Connects a property's smart locks to Stayflow † | Currently only device details and the property's lock-account connection — no guest personal data | United States |
| Mews | Syncs reservations from a property's property-management system † | Reservation details and guest profiles pulled in from the PMS; only check-in and check-out status is sent back | European Union |
| Cloudbeds | Syncs reservations from a property's property-management system † | Same as Mews: guest and reservation data pulled in; only check-in and check-out status sent back | United States |
| Apple, Google & Mozilla push services | Deliver app notifications to guest and staff devices | Notification content is encrypted end-to-end to the device; the push service sees only a device endpoint, an encrypted payload and its timing | Determined by the recipient's browser and device |
| Let's Encrypt | Issues the security certificates for properties' custom guest-app domains † | Domain names and our administrative email address only | United States (non-profit certificate authority) |
† See "Services a property configures itself" below.
One thing that is not on this list: the eSIM offer shown in the guest app is a plain link to a partner's website. Tapping it takes the guest there directly — Stayflow sends the partner nothing about the guest.
What we run ourselves
Quite a lot of Stayflow is deliberately not outsourced. Our database (PostgreSQL), cache (Redis), file storage for ID photos, chat media, avatars and request photos (MinIO), sign-in service (Casdoor), real-time messaging (Centrifugo), outbound mail relay (Postfix) and web server (Caddy) all run as our own software on our own server. These are not subprocessors — no separate company operates them or can look inside them. Your ID photo, for instance, sits in storage we run ourselves, in a private bucket, reachable only through short-lived, permission-checked links.
Services a property configures itself
Some connections marked † above exist only when a property switches them on, and each property connects its own account: its own Mews or Cloudbeds PMS, its own Seam smart-lock accounts, its own WhatsApp sender number, its own email sending domain, its own custom guest-app domain, and the per-property toggle for AI suggestions (Gemini). When a property connects its own account with one of these companies, data also flows under that property's direct agreement with the provider. Guests can ask their property which of these it uses.
Changes to this list
When we plan to add or replace a subprocessor that handles guest data, we will update this page and notify property customers in advance (by email to account owners, 30 days before the change takes effect). Removing one, or adding one that handles no personal data, may simply be reflected here.
Questions
Privacy questions — including requests to see or delete guest data, which properties handle through Stayflow's built-in export and erasure tools — can be sent to:
Marc-Antoine Claveau, CEO — person in charge of the protection of personal information (Loi 25 "personne responsable de la protection des renseignements personnels") Stayflow Inc. 395 rue Mathieu-Da Costa, unité 363, Québec (Québec) G2K 0P6, Canada [email protected]
This page is governed by the laws of Québec and the applicable laws of Canada.