Guest assistant (when enabled)
When you use the optional assistant, Hostsy sends your question, the current guide text for that property and recent conversation context to OpenAI to generate an answer. Do not include personal or sensitive information in questions. The assistant can make mistakes; consult the cited guide information and contact the host when necessary.
Hostsy keeps usage metadata for 30 days, without question or answer text in that usage ledger. Recent conversation context is held in the session, reused for up to 20 minutes and cleared from active context when the guide changes. Session records and backups follow their own retention cycles. API requests disable response storage; this does not eliminate provider abuse-monitoring retention. OpenAI may retain such logs for up to 30 days under its applicable data controls.
Who is responsible
Hostsy is operated by Domain Controller - Serviços de Informática e Internet, Unipessoal Lda, identified below. We determine how account, service administration, security and support data are used. Accommodation operators determine the content they publish and the purposes for processing guest information they provide; when handling that information on their instructions, we act as a service provider processing data on their behalf.
Information we process
We process account and organisation names, email addresses, account roles, language preferences, authentication records and subscription information. We also store the accommodation details, contact information, images, documents and other content that account users upload or publish.
Support messages contain the information you choose to send. Operational logs may include IP addresses, browser information, timestamps and errors. Guide analytics record a visit identifier, date, guide, access channel, device category and page-view or interaction counts.
When payments are enabled, Stripe processes payment details. Hostsy uses Stripe customer and subscription identifiers, payment status and relevant billing details; full card numbers and card security codes are not stored in the Hostsy application database.
Purposes and legal bases
We use information to provide the service and support, manage accounts and subscriptions, and fulfil the contract or steps requested before a contract. Billing records may be retained to comply with legal obligations. Security, abuse prevention and service reliability rely on our legitimate interests, subject to your rights. Where consent is required for a particular use, that use must be based on consent, which can be withdrawn without affecting earlier lawful processing.
Cookies and guide analytics
Hostsy uses cookies for sessions, authentication, request protection and access to password-protected guides. The guide analytics implementation also uses a first-party visit identifier, eg_session, with a 30-day lifetime, to distinguish visits and produce usage statistics for the accommodation operator. A visit identifier is not a guarantee of anonymity.
Browser settings can delete or block cookies, although this may affect sign-in or guide access. Third-party maps, destinations and links can have their own privacy and cookie practices. This policy does not treat statistical cookies as automatically exempt from consent requirements.
Who receives information
Authorised members of your organisation can access information according to their roles. Content published in a guest guide is available to people who can access its link, subject to any access code configured by the operator; do not publish confidential information in a public guide.
We use infrastructure and storage providers, including DigitalOcean, transactional email delivery through Resend, and Stripe for payments when enabled. Google Maps or other external services may receive connection information when their features are loaded or followed. Providers process information under the terms applicable to their services. We may disclose information when required by law or to establish, exercise or defend legal claims.
International processing and retention
A provider may process data outside your country or the European Economic Area. Where international-transfer rules apply, the relevant processing must be covered by an applicable safeguard, such as an adequacy decision or standard contractual clauses. Contact us for information about the arrangements applicable to your data.
We retain account and service information for as long as needed to provide the service, resolve requests and comply with legal obligations. The period depends on the purpose, account activity and any outstanding billing or legal issue. Backups follow their retention cycle; closing an account does not immediately remove every backup copy. You can request information about retention and deletion using the contact below.
Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction, portability or object to processing. You may withdraw consent where processing depends on it and complain to a supervisory authority, including the Portuguese CNPD. We may need proportionate information to verify your identity.
Contact us using the address below. For information controlled by an accommodation operator, contact that operator; we can help direct your request. Providing account information is necessary to create and administer an account; without it, we cannot provide those functions.
Changes and contact
The version and date above identify this policy. We will make updated information available here and communicate material changes where appropriate. Contact us before sharing sensitive personal information or if you need details about processing on behalf of your organisation.