Privacy Policy
Last updated September 24, 2026
Stayverly (“we”, “us”) gives vacation-rental hosts and experience hosts their own booking websites, and gives travelers a way to book directly with those hosts. This policy explains what we collect, why, who we share it with, and the choices you have. If anything here is unclear, email privacy@stayverly.com.
Who this covers
- Hosts who create an account and build a site, including hosts who connect other services (Stripe, Hospitable and similar tools, Google Search Console, and social accounts for Studio auto-posting).
- Guests and visitors who browse, inquire about or book a stay or experience on a site built with Stayverly. For guest bookings, the host is responsible for the stay and we process guest information on the host's behalf.
What we collect
From hosts
- Account details: name, email address and a hashed password.
- Site content you import or write: listing text, photos, amenities, prices, house rules, reviews you choose to show, and your area guide.
- Connections you set up: access tokens for services you connect (stored encrypted), and basic account details those services return, such as an account name or ID.
- Payouts are handled by Stripe. We never see or store your bank or card numbers.
From guests and visitors
- Booking and inquiry details: name, email, phone number, dates, party size, messages to the host, and anything the host asks for at checkout (for example an ID check or a signed rental agreement).
- Payments are processed by Stripe. We receive the payment status and the last four digits of a card, never the full card number.
- Reviews, guestbook entries and sign-ups you choose to submit.
- Basic usage data: pages viewed, the site that referred you, and campaign tags in links (for example utm_source), kept in first-party cookies so a host can see which channel led to a booking. We don't sell this data or use it for advertising profiles.
Social accounts connected for Studio auto-posting
Hosts can connect Instagram, Facebook Pages, Threads, Pinterest and TikTok so the Studio can publish posts they make or approve. When you connect one of these accounts, we receive and store:
- The account's ID, username or Page name, and profile picture, so you can see which account you're posting to.
- An access token (and a refresh token where the network issues one), stored encrypted, used only to publish posts you created or approved and to keep the connection working.
- For Pinterest, your board names so you can choose where a pin goes. For TikTok, the posting settings TikTok provides (such as which audiences you can post to), which we show before every post.
- For posts you schedule: the image or video file, caption, schedule, and the resulting post's ID and link.
We only use these permissions to publish your posts and show their status. We do not read your messages, followers, comments or other content, and we never post anything you haven't made or approved. Rendered media files are deleted from our servers about 30 days after they're posted or canceled.
Disconnecting. Remove an account any time from Studio → Auto-post, which deletes its tokens and its post history from Stayverly (posts already published stay on the network unless you delete them there). You can also remove Stayverly from the network's own settings: Facebook and Instagram (Settings → Apps and Websites), Threads, Pinterest (Settings → Apps) and TikTok (Settings → Security → Manage app permissions). When Meta tells us you removed Stayverly or asked for your data to be deleted, we stop posting and delete the stored account data.
Use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
How we use information
- To run the service: build and host sites, take bookings and payments, send confirmations and messages you ask us to send, and publish posts you schedule.
- To keep it safe: prevent fraud and abuse, secure accounts, and debug problems.
- To improve it: understand, in aggregate, which features get used.
- To meet legal obligations, such as tax records for bookings.
We don't sell personal information, and we don't share it for cross-context behavioral advertising.
Who we share it with
- The host of the stay or experience you book or contact.
- Service providers that run parts of Stayverly for us, under contract: hosting (DigitalOcean), payments (Stripe), email delivery (Resend), and AI features that write copy or describe listing photos (Anthropic). They may only use the data to provide their service to us.
- Services a host connects, only as needed for that connection (for example sending a booking to the host's property manager, or publishing a post to their Instagram).
- Authorities, when the law requires it, or to protect people's safety or our rights.
How long we keep it
We keep host account data while the account is open and for a short time after it's closed. Booking records are kept as long as tax and accounting rules require. Connected social account tokens are deleted as soon as the account is disconnected. You can ask us to delete your data sooner, subject to those legal requirements.
Your choices and rights
You can access, correct, export or delete your information by emailing privacy@stayverly.com. Guests can also contact the host directly. Depending on where you live (for example California, the EU or the UK), you may have additional rights, including to object to or restrict certain processing and to complain to a data protection authority. We won't treat you differently for using these rights.
Security
Passwords are hashed, access tokens for connected services are encrypted at rest, and all traffic uses HTTPS. No system is perfectly secure, so please use a strong, unique password.
Children
Stayverly isn't meant for children under 16, and we don't knowingly collect their information.
Changes
If we make a material change, we'll update this page and the date above, and tell hosts by email.
Contact
Questions or requests: privacy@stayverly.com.