Hostly is a front-desk app for small guest houses, inns and B&Bs. This policy explains what the app collects, why, where it is kept, and the choices you have. If anything here is unclear, please write to us — we're happy to explain.

Hostly is used by the people who run a guest house — an account holder and the staff they invite. Much of what you enter is information about your guests (their names, contact details and stays). For that guest information, you are responsible for how it is collected and used; Hostly stores and processes it on your behalf, under your instructions. See section 4.

Hostly requires an account, because it is a shared tool. Accounts are created on our website, not inside the app. To sign in we store your email address or username, your display name and role (admin, staff, reporting or view-only), and the name of the organization you belong to.

Your password is handled by our authentication provider and stored only as a secure one-way hash. Nobody at Hostly — and no other user — can see it.

Everything below is data you and your team enter to run the house. It is kept in your organization's account and shared only among the users you have invited to it.

When you record a guest, you are entering another person's details into Hostly. You decide what to collect and are responsible for having a proper basis to do so under the laws that apply to you — for example, telling guests you keep a record and only asking for an ID number where you need it. The ID field is optional for exactly this reason.

Hostly acts as your processor for this data: we store it, sync it to your team's devices and keep it secure, and we use it only to provide the app to you — never for our own purposes.

Your organization's data is stored in a hosted database and file storage operated by our infrastructure provider, Supabase, on secure cloud servers. Data is encrypted in transit (HTTPS) and at rest. Access is restricted by database rules so that each account can reach only its own organization's records, and each user sees only what their role allows.

If you attach a receipt or a work photo, Hostly asks for access to your camera or photo library at that moment. The image is downscaled on your device and uploaded to your organization's file storage, where it is shown to your team alongside the entry it belongs to. Hostly does not read your photo library otherwise, and does not use your camera in the background.

Hostly can deliver small improvements between store releases. To do that, the app checks for updates with Expo's update service, which involves your device contacting Expo's servers. That check carries only technical details needed to serve the right update (such as the app version and platform) — no personal data and none of your organization's records.

Your data is shared only with the users you invite into your organization, and with the service providers who make the app work — principally Supabase (hosting and storage) and Apple / Google for app distribution. These providers process data on our behalf and are not permitted to use it for their own purposes. We may also disclose data if the law requires it. We do not sell your data.

We keep your organization's data for as long as your account is active, so your history and reports stay available to you. You are in control day to day:

Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold, or to object to certain processing. You can do most of this directly in the app; for anything else, contact us and we will help. If your guests ask you to exercise these rights over their information, we will support you as your processor.

Hostly is a tool for running a business and is not directed at children. We do not knowingly create accounts for anyone under 13 (or the age set by your local law).

If we change how Hostly handles data, we will update this page and change the date at the top. Material changes will also be called out in the app's release notes.