Skip to main content
← Legal & privacy

Staysi legal

Privacy Policy

How Staysi collects, uses, shares, and protects personal information.

Effective and version date: August 25, 2026 · Version 2026-08-25

Who we are and how this policy works

Staysi provides software that helps short-term-rental hosts share stay information, communicate with guests, respond to requests, and optionally provide limited smart-home controls.

This policy applies to Staysi websites, host applications, guest applications, support channels, and related services. It does not replace the privacy practices of a booking platform, property host, SmartThings, or another service you independently use.

For guest and reservation information supplied or controlled by a host, the host generally determines why that information is processed and Staysi generally acts as the host’s service provider or processor. For Staysi account administration, billing, security, fraud prevention, legal compliance, product operations, and direct support, Staysi may act as a business or controller. The exact legal role depends on the context and applicable law.

Information we collect

  • Host account information, such as name, email address, authentication identifiers, organization membership, account settings, and subscription status.
  • Stay and guest information supplied by a host, booking email, or authorized integration, such as guest name, email address, phone number, property, stay dates, reservation identifiers, and stay-access information.
  • Guest communications and service information, including questions, requests, troubleshooting responses, host replies, care cases, outcomes, and related timestamps.
  • Property information and content, including guide content, photos, location details, access instructions, Wi-Fi information, rules, amenities, and host-created knowledge.
  • Smart-home configuration information when a host connects SmartThings, including encrypted authorization tokens, eligible light metadata, selected devices, scenes, and command activity needed to provide guest controls.
  • Support information, including messages sent to Staysi and limited account context needed to diagnose or answer a request.
  • Technical and security information, such as device/session identifiers, authentication cookies, request metadata, audit events, errors, and information needed to protect the service.
  • Billing information. Card details are collected and processed by Stripe; Staysi receives billing status, customer/subscription identifiers, and transaction-related metadata rather than full card numbers.

How we use information

  • Provide, authenticate, personalize, and secure Staysi.
  • Create and manage properties and stays and deliver stay-specific information to authorized guests.
  • Answer routine guest questions, clarify requests, offer troubleshooting, route issues to hosts, and help hosts respond consistently.
  • Send transactional and service-related communications, including stay access, guest-care updates, and account notices.
  • Operate host-authorized SmartThings scenes and integrations.
  • Process subscriptions and maintain financial and business records.
  • Provide support, investigate failures, prevent abuse and fraud, monitor reliability, and enforce our terms.
  • Comply with legal obligations and establish, exercise, or defend legal claims.
  • Improve Staysi using de-identified, aggregated, or appropriately minimized operational information where permitted.

Artificial intelligence

Staysi uses AI-assisted features for tasks such as understanding guest questions, finding relevant host-provided knowledge, structuring requests, helping hosts draft or polish responses, extracting structured reservation information, assisting Staysi support, and enhancing property photos when requested. AI can make mistakes and is not an emergency service.

OpenAI business/API services are configured with store: false where supported. OpenAI states that business/API data is not used to train its models by default. Separate provider security or abuse-monitoring retention may still apply unless an applicable Zero Data Retention configuration is enabled. See the AI Processing Notice for more detail.

How we disclose information

We disclose information only as needed to provide the service, at a customer’s direction, for security or legal reasons, or in connection with a corporate transaction. Categories of recipients may include cloud hosting and database providers, authentication providers, AI providers, email/SMS delivery providers, payment processors, mapping providers, connected smart-home providers at the user’s direction, professional advisers, and authorities when legally required.

Our current service-provider list is maintained in the Subprocessor Register. Staysi does not sell personal information or share it for cross-context behavioral advertising.

Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide an active service, to preserve security and audit records, or to meet legal, accounting, tax, dispute, and contractual obligations. Different categories have different retention periods, and information that is no longer needed is deleted or de-identified according to the applicable retention process.

Canceling a paid subscription does not by itself delete all account data. Hosts may separately request deletion through the Privacy & data controls. Some records may be retained where required or permitted by law, including billing records, fraud/security records, and records necessary to establish or defend legal claims.

Your privacy choices and rights

Depending on where you live and our legal role, you may have rights to request access, correction, deletion, portability, restriction, objection, or information about processing. Hosts can submit and track requests from Host account → Privacy & data. We may need to verify identity and may route a guest request to the relevant host when that host is the controller of the requested data.

Guests may contact their host about stay or reservation information. The host can route a request to Staysi where Staysi is the relevant processor or service provider.

Staysi does not sell personal information or share it for cross-context behavioral advertising. Where a legally recognized browser-based opt-out preference applies to an activity we conduct, we will honor it.

Cookies, local storage, and device identifiers

Staysi uses cookies and browser/device storage needed for authentication, guest-session persistence, security, language/theme preferences, and application functionality. We do not currently use advertising cookies or behavioral-advertising trackers. See Cookies & Storage for the current inventory and purposes.

International processing

Staysi is operated from the United States and uses service providers that may process information in the United States and other countries. Where applicable law requires a transfer mechanism, Staysi will use an appropriate mechanism and associated safeguards.

Children

Staysi is not directed to children under 13 and is not designed for children to create host accounts. A travel party may include minors, but an adult host or booking party remains responsible for the stay relationship. Do not intentionally submit unnecessary information about children.

Security

Staysi uses administrative, technical, and organizational safeguards appropriate to the service, including access controls, encryption in transit, protected session credentials, encrypted SmartThings tokens, audit/security controls, and vendor-management practices. No system is completely secure.

Changes and contact

We may update this policy. Material changes will be communicated in a manner appropriate to the change. The effective version shown on this page controls from its effective date. Hosts can use Host account → Privacy & data for privacy requests and Staysi Host Support for support or legal questions. Guests can contact their host for stay-specific privacy questions; the host can escalate processor questions to Staysi.