Privacy Policy
Last updated: August 23, 2026
This Privacy Policy explains how Tahosa Systems LLC (“we”, “us”) collects, uses, and shares information in connection with StaySage. It covers both Hosts (property owners and managers with StaySage accounts) and Guests (people who use a StaySage guest page, chat, or SMS concierge during a stay). For Guest data supplied by a Host (such as your name, email, phone number, and stay dates), the Host determines why it is collected and we process it to provide the service.
1. Information we collect
- Host account data: name, email, sign-in identifiers (magic link or Google), and billing details when subscriptions launch.
- Property content: property details, house manuals, knowledge entries, contacts (names, emails, phone numbers of cleaners, maintenance, and similar), and calendar feed URLs. This can include sensitive operational details such as door codes; access to those is limited as the Host configures.
- Stay data: guest name, email, phone number, and stay dates, provided by the Host or imported from calendar feeds.
- Conversations: messages between guests (or hosts) and the AI concierge across web chat and SMS, plus AI outputs, classifications, escalations, and unanswered-question records.
- Technical data: logs, device and browser information, and cookies needed for sign-in sessions. We do not run third-party advertising trackers.
2. How we use information
- Provide the service: answer questions, render guides, manage stays and access links;
- Classify messages and notify Hosts or their designated contacts of escalations;
- Operate, secure, debug, and improve the service;
- Communicate with Hosts about their account and, when launched, process payments;
- Comply with law and enforce our terms.
We do not sell personal information, and we do not use your content to train our own or third-party foundation models.
3. AI processing
Conversations and property content are processed by third-party large language model providers (currently Anthropic) via API to generate answers, extract knowledge, and classify messages. Per Anthropic's commercial API terms, API inputs and outputs are not used to train their models. AI outputs may be inaccurate; see our Guest Terms.
4. Sharing
- With Hosts: guest conversations, escalations, and related records for the Host's properties are visible to the Host and their team.
- Service providers: hosting and infrastructure (Vercel), database and authentication (Supabase), AI (Anthropic), email delivery (Resend), SMS (Twilio), and, when launched, payments (Stripe) and voice (ElevenLabs). Each processes data only to provide its service to us.
- Legal: when required by law, to protect rights and safety, or in a merger, acquisition, or asset sale.
5. Retention
Host account and property data are kept while the account is active and for a reasonable period afterward. Conversation records are kept so Hosts can review them; Hosts can delete a property, which removes its knowledge, stays, conversations, and escalations. Guest access links expire automatically after checkout. Backups and logs age out on a rolling basis.
6. Your choices and rights
- Hosts can edit or delete knowledge entries, stays, and properties in the dashboard, and can request account deletion at support@staysage.app.
- Guests can decline to use the concierge; your stay does not depend on it. To access or delete your conversation data, contact your Host (the data controller for stay data) or us at support@staysage.app and we will assist.
- For SMS, reply STOP at any time to stop receiving messages.
- Depending on where you live (for example Colorado, California, or the EEA/UK), you may have rights to access, correct, delete, or port personal data, and to object to certain processing. Contact us to exercise them; we will not discriminate against you for doing so.
7. Security
We use industry-standard safeguards: encrypted transport, row-level access controls, scoped API keys, and time-limited guest links. Sensitive entries such as door codes can be limited to active stays. No system is perfectly secure; please use unique credentials and report concerns to support@staysage.app.
8. Children
The service is not directed to children under 13, and we do not knowingly collect their personal information. Contact us if you believe a child has provided personal information.
9. International transfers
We are U.S.-based and process data in the United States. If you use the service from elsewhere, you understand your information is transferred to and processed in the U.S.
10. Changes and contact
We will post updates here and note the effective date above; material changes will be highlighted through the service or by email to Hosts. Questions or requests: Tahosa Systems LLC · support@staysage.app.