Privacy policy
Effective
BnB Console ("we", "us") provides software that helps short-term-rental hosts run their businesses. This policy explains what data we handle, why, and the choices you have. It covers both hosts (our customers) and the guests who interact with pages and emails that hosts operate through the platform.
Two roles: hosts and their guests
Hosts create accounts and use the console. For host account data, we decide how and why it is processed.
Guests book with a host, message a host, or pay a host. Guest data belongs to the host's business relationship with their guest: the host decides why it is collected, and we process it on the host's behalf to deliver the service — storing reservations, delivering emails, showing message threads and processing payments. Guests who want their data corrected or removed should contact their host first; we support hosts in honoring those requests.
What we collect
Host account data: name, email, password hash (or your Google/Facebook sign-in identity), business name, timezone and contact details.
Property and business content: listings, photos, pricing, rules, guides and templates the host writes.
Reservation and guest data: guest names, emails, phone numbers, party details, stay dates, prices and cancellation terms; messages between host and guest, including email replies and attachments; invoices and payment records.
Payment data: payments are processed by Stripe on the host's own Stripe account. Card numbers never touch our servers; we store only payment metadata (amounts, status, last four digits as reported by Stripe).
Technical data: session cookies for signed-in hosts, and rate-limiting and anti-abuse signals (such as IP-derived counters and captcha outcomes) on public booking forms.
What we do with it
We use data to operate the service: showing availability, sending booking emails, syncing calendars, processing payments, preventing abuse and providing support. We do not sell personal data, and we do not use guest data to advertise to guests.
Marketing emails to guests (price-drop and reminder nudges) are sent only to guests who explicitly opted in on a booking form, always with one-click unsubscribe, from a separate sending domain.
Service providers
We rely on a small set of processors to run the platform: Supabase (database, authentication and file storage), Vercel (hosting), Stripe (payments), Resend and SMTP providers (email delivery), and Cloudflare (spam protection on public forms). Where a host connects optional integrations — Google Business Profile, Facebook, Instagram or Google Maps — data flows to those providers only for the feature the host enabled, and connection credentials are stored encrypted.
Retention and security
Host content and reservation history are retained while the host account is active, because a booking record is a business record. Audit trails are kept for 90 days. Access to data is enforced row-by-row in the database, so one business can never read another's data; integration credentials are encrypted at rest; all traffic runs over HTTPS.
Your choices and rights
Hosts can update account and business data in the console, export their content, and request account deletion. Guests can unsubscribe from marketing at any click, and can ask their host — or us — for access, correction or deletion of their personal data. Depending on where you live (for example under GDPR or CCPA), these choices are also legal rights, and we honor them accordingly.
Data deletion
Hosts: to delete your account and your business's data, ask us via the contact page from the email on your account. We remove the account, its content and its sign-in identities, keeping only records we are legally required to retain (such as payment records held by Stripe).
Guests: booking records belong to your host's business — ask the host, or contact us and we will coordinate with them.
Signed in with Google or Facebook? Those sign-ins share only your name and email address with us. Deleting your account removes them; you can also disconnect a provider anytime from Settings → My account, or request deletion via the contact page without signing in.
Children
The service is for adults. We do not knowingly collect data from children; booking parties may include children, but the booking contact must be an adult.
Changes and contact
If this policy changes materially, we will post the new version here with a new effective date. Questions or requests: contact us.