← Back to HostMate.cc

Privacy Policy

Last updated: 6 March 2025

1. Who we are

HostMate.cc ("we", "us", "our") is a platform that helps retreat hosts manage their bookings, websites, and guest communications. We are operated by Stef Michalak. If you have any questions about this policy, contact us at hello@hostmate.cc.

2. Data we collect

Account data: When you create an account, we collect your name, email address, and any other information you provide during onboarding (business name, bio, slug).

Booking data: We process guest names, email addresses, booking details, and payment information (processed securely by Stripe — we never see full card numbers).

Usage data: We collect standard analytics data such as page views, browser type, and IP address to improve our service.

Cookies: We use essential cookies to maintain your login session and preferences. We do not use third-party advertising cookies.

3. How we use your data

We use your data to:

  • Provide and maintain the HostMate.cc platform
  • Process bookings and payments on your behalf
  • Send transactional emails (booking confirmations, password resets)
  • Improve our service and fix bugs
  • Communicate important product updates

We will never sell your data to third parties.

4. Data sharing

We share data only with trusted service providers necessary to run the platform:

  • Stripe — payment processing
  • Supabase — authentication and database hosting
  • Vercel — application hosting
  • Anthropic — AI features (bio improvement, no personal data stored)

5. Data retention

We retain your data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where we are legally required to retain it.

6. Your rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Withdraw consent for marketing communications

To exercise any of these rights, email hello@hostmate.cc.

7. Security

We take reasonable measures to protect your data, including encryption in transit (TLS), secure authentication via Supabase, and PCI-compliant payment processing via Stripe. However, no method of transmission over the internet is 100% secure.

8. Changes to this policy

We may update this policy from time to time. We will notify you of any material changes via email or an in-app notification. Continued use of the platform after changes constitutes acceptance of the updated policy.