Legal
Privacy Policy
Effective August 17, 2026
HotelStride (“we,” “us”) provides a real-time operations platform for hotels. This policy explains what data we collect, why we collect it, and how we protect it. Contact us any time at hyunfree06@gmail.com.
1. What we collect
- Account data — when you sign in with Google or a magic link, we receive your email address, display name, and profile image URL from your identity provider.
- Operational data — property configuration you enter (floors, rooms, pantries, items, staff invitations), orders you create, routes computed, inventory adjustments, asset movements, and audit events.
- Session cookies — a Supabase authentication cookie required to keep you signed in. We do not use tracking or advertising cookies.
- Attachments — photos or files you upload against an order.
- Billing metadata — subscription state and identifiers returned by Lemon Squeezy webhooks. Payment card details are handled entirely by Lemon Squeezy and never touch our servers.
2. How we use it
Operational data is used solely to run the service on your behalf: to display orders, compute routes, track assets, keep your team in sync, and produce your reports. Email addresses are used to authenticate you and to send transactional notifications about your property.
We do not sell your data. We do not use your operational data to train models. We do not share your data with third parties for advertising.
3. Where it lives
- Application and database: Supabase (Postgres, Auth, Storage, Realtime).
- Application hosting: Vercel.
- Billing processing: Lemon Squeezy.
- Optional AI order-text parsing: OpenAI (only invoked when explicitly enabled and only for the operator-typed free-text you submit).
These providers act as data processors on our behalf and are contractually bound to confidentiality and appropriate security controls.
4. Access controls
Every property is isolated by row-level security. Members of one property cannot read or write another property’s data. Role-based permissions further scope what a given staff member can see or change (Owner, Front Manager, Runner, and so on).
5. Retention & deletion
Operational data is retained for as long as your property has an active subscription. When you delete your property or cancel your subscription, data is retained for a grace period (60 days) so you can reactivate, then permanently deleted from our active systems. Backups may retain data for up to a further 30 days before rotation.
6. Your rights
You have the right to access, correct, export, and delete your personal data. Owners can invite or remove staff at any time. To exercise a right or ask a question, email hyunfree06@gmail.com.
7. Security
All traffic is encrypted in transit (TLS). Secrets are stored in Vercel’s encrypted environment store; the service-role database key is never sent to the browser. Webhooks are cryptographically signed and verified before being applied.
8. Children
HotelStride is a business tool intended for hotel staff. It is not directed at children under 14 and we do not knowingly collect data from them.
9. International transfers
Our providers may store or process data in regions outside your country. By using the service you consent to such transfers, which are protected by standard contractual clauses or equivalent safeguards.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the product and, for account owners, by email at least 14 days before they take effect.
11. Contact
Questions or complaints: hyunfree06@gmail.com.