Privacy policy
Effective
BnB Console ("we", "us") provides software that helps short-term-rental hosts run their businesses. This policy explains what data we handle, why, and the choices you have. It covers both hosts (our customers) and the guests who interact with pages and emails that hosts operate through the platform.
Two roles: hosts and their guests
Hosts create accounts and use the console. For host account data, we decide how and why it is processed.
Guests book with a host, message a host, or pay a host. Guest data belongs to the host's business relationship with their guest: the host decides why it is collected, and we process it on the host's behalf to deliver the service — storing reservations, delivering emails, showing message threads and processing payments. Guests who want their data corrected or removed should contact their host first; we support hosts in honoring those requests.
What we collect
Host account data: name, email, password hash (or your Google/Facebook sign-in identity), business name, timezone and contact details.
Property and business content: listings, photos, pricing, rules, guides and templates the host writes.
Reservation and guest data: guest names, emails, phone numbers, party details, stay dates, prices and cancellation terms; messages between host and guest, including email replies and attachments; invoices and payment records.
Payment data: payments are processed by Stripe on the host's own Stripe account. Card numbers never touch our servers; we store only payment metadata (amounts, status, last four digits as reported by Stripe).
Technical data: session cookies for signed-in hosts, rate-limiting and anti-abuse signals (such as IP-derived counters and captcha outcomes) on public booking forms, and the analytics described under Analytics and advertising.
What we do with it
We use data to operate the service: showing availability, sending booking emails, syncing calendars, processing payments, preventing abuse and providing support. We do not sell personal data, and we do not use guest data to advertise to guests.
Marketing emails to guests (price-drop and reminder nudges) are sent only to guests who explicitly opted in on a booking form, always with one-click unsubscribe, from a separate sending domain.
We email hosts tips and product news: a few emails in a new account's first weeks that explain how to set up, and occasional newsletters about what's new. Every one has a one-click unsubscribe, and the switch on My account turns them off or back on. Emails about your account and your bookings are separate and always sent. We don't track whether these emails are opened or which links are clicked.
To open the live demo you give us your email address. We sign you in to the demo, keep the address with the wording you saw and when you agreed, which page and campaign brought you, your country (from your connection), and how often you come back, and set one cookie holding a random id so that signing up with another address still stops our emails. We send you a link back to the demo and a few emails about setting up your own over the following ten days, then newsletters for up to six months after your last visit, all stopping as soon as you sign up or unsubscribe. Opening the demo from one of these emails counts as a visit; we don't otherwise track whether they are opened or which links are clicked. If you never sign up, we erase your address a year after your last visit.
Analytics and advertising
Across the site, Vercel Web Analytics counts page views and a few button presses (Start free, trying the demo, signing up). It sets no cookies and stores nothing on your device.
On our marketing pages, sign-up and sign-in, we also use Google Analytics to learn which searches, pages, campaigns and ads bring hosts to sign up. It sets first-party cookies (_ga and _ga_…, kept for up to two years) and, since we advertise with Google Ads, Google Ads cookies (_gcl_…) so a sign-up can be counted for the ad that led to it. Google receives the pages you visit, those button presses, your approximate location and device, and, if you sign up, that you did and whether by email or another sign-in, never your email, name or account. Google keeps it for 14 months.
Where Google Analytics never runs: for visitors in the European Economic Area, the United Kingdom, Switzerland or Quebec; for anyone signed in to BnB Console; inside the console; and on hosts' booking pages, portfolio pages and booking widgets.
No ad personalisation. We don't use Google signals, remarketing lists or personalised advertising, so your visit is never used to target ads at you. We measure our ads; we don't follow you with them.
Opting out. Google's Analytics opt-out browser add-on stops Google Analytics on every site, and blocking or clearing cookies for bnbconsole.com stops it here.
Service providers
We rely on a small set of processors to run the platform: Supabase (database, authentication and file storage), Vercel (hosting), Stripe (payments), Resend and SMTP providers (email delivery), Cloudflare (spam protection on public forms), and Google (Analytics and Ads measurement on our marketing site). Where a host connects optional integrations — Google Business Profile, Facebook, Instagram, WhatsApp or Google Maps — data flows to those providers only for the feature the host enabled, and connection credentials are stored encrypted.
Retention and security
Host content and reservation history are retained while the host account is active, because a booking record is a business record. Audit trails are kept for 90 days. Access to data is enforced row-by-row in the database, so one business can never read another's data; integration credentials are encrypted at rest; all traffic runs over HTTPS.
Your choices and rights
Hosts can update account and business data in the console, export their content, and request account deletion. Guests can unsubscribe from marketing at any click, and can ask their host — or us — for access, correction or deletion of their personal data. Depending on where you live (for example under GDPR or CCPA), these choices are also legal rights, and we honor them accordingly.
Text message (SMS) alerts
Hosts can choose to receive text alerts about their own reservations — a message when a guest asks to book one of their properties, and a message when a guest writes to them. This is an account setting, off by default, and it applies only to the host's own account.
How consent is given. A signed-in host enters their own mobile number under Settings → My account → Text alerts, and we text a six-digit code to that number. Nothing else is sent until the host enters that code back into the console. We never add a number any other way: numbers are not imported, purchased, or entered by anyone but the person who owns them.
What is sent, and how often. A one-time verification code when the number is added, and thereafter one alert per booking request or guest message, capped so that a burst of guest activity cannot produce a burst of texts. Frequency varies with the host's own reservations. We never send marketing or promotional messages by text.
Stopping them. Reply STOP to any message to end them for good, or HELP for assistance. Alerts can also be switched off, and the number removed entirely, in the same account screen. Message and data rates may apply.
Mobile numbers and SMS consent are never shared with third parties, and are never sold or used for marketing. The number is used only to deliver the alerts described above, and is passed only to the messaging carrier that delivers them.
Click-to-chat. A host can publish a WhatsApp number. Guests then see a link that opens WhatsApp on their own device with a message already typed. Nothing passes through us, and we store nothing about the conversation.
A host's own WhatsApp connection. A host can connect their business's own WhatsApp messaging through Meta's signup window. We then hold the identifiers Meta gives the host's WhatsApp Business Account, phone number and business portfolio; the number as displayed, its display name and Meta's review status for that name; its quality rating; and whether a payment method is set up. We also hold an access token and the number's two-step verification PIN, both encrypted at rest. We use them only to run the messaging the host turned on. The account and the number stay the host's, and Meta bills the host directly.
Guests. A guest can choose to get updates about their booking on WhatsApp: by ticking a box when booking or accepting a quote, or with a switch in their stay guide. The box is never ticked for them, and a host cannot turn updates on for a guest. We keep a record of that choice (the number given, the words shown, where and when it was given, and the browser's address and type) so the host can show the guest agreed.
While updates are on, four messages about that booking may also come on WhatsApp, from the host's own connected number: the booking confirmation, a pre-arrival message with the stay guide link, a reminder when a payment is due, and a review request, which is never sent to guests whose booking came from another booking site. The guest's number and these messages pass to Meta, which delivers them under WhatsApp's own terms and privacy policy and tells us whether each one was delivered and read. Guest phone numbers are never sold and never used for marketing on WhatsApp.
Stopping WhatsApp updates. A guest can turn them off at any time in their stay guide, or by replying STOP to any of these messages, and the host can turn them off for a guest who asks. Emails about the booking continue either way. Other replies on WhatsApp are not read yet, so guests reach their host through the stay guide or by email.
Disconnecting and deletion. When a host disconnects, we discard the access token at once and stop all messaging; the number and the WhatsApp Business Account are left untouched. We keep the PIN so the same number can be connected again, and only the business's hosts can see it. Removing BnB Console in Meta's business settings disconnects it the same way. Deleting the business deletes the connection, the token and the PIN.
Guest reviews
After a stay booked direct or entered by the host, a guest is asked to rate it on a review page reached by their own private link. Every rating counts towards the host's guest rating: an average shown on the host's booking pages, with how many reviews it counts, and never with a name. A guest's words appear on those pages only if they tick the box to agree, under their first name and the initial of their last name (or “A guest” when the booking carries no usable name) with the month of their stay. Their full name, email address and booking are never shown. The host may take a review's words off their pages, though its rating still counts. A guest can withdraw their agreement at any time by opening their review link again and unticking the box, or by asking the host.
Data deletion
Hosts: sign in and open Settings → My account, where you can download everything as one file and permanently delete your account. A business you are the last member of goes with it; one you share keeps working without you. If you cannot sign in, ask us via the contact page from the email on your account. We keep only records we are legally required to retain (such as payment records held by Stripe). Full detail is on the data deletion page.
Guests: booking records belong to your host's business — ask the host, or contact us and we will coordinate with them.
Signed in with Google or Facebook? Those sign-ins share only your name and email address with us. Deleting your account removes them; you can also disconnect a provider anytime from Settings → My account, or remove the app from your Facebook settings — we are notified and delete the stored credentials.
Children
The service is for adults. We do not knowingly collect data from children; booking parties may include children, but the booking contact must be an adult.
Changes and contact
If this policy changes materially, we will post the new version here with a new effective date. Questions or requests: contact us.