Privacy Policy

Effective and last updated: July 31, 2026 | Version 2026-07-31

This Privacy Policy explains how HostMoat LLC, doing business as HostMoat ("HostMoat," "we," "us," or "our"), collects, uses, discloses, and retains personal information when you use our websites, applications, public pages, and related services (the "Service"). It should be read with our Terms of Service.

1. Information We Collect

Account and subscription information

We collect the email address used for passwordless authentication, profile information you provide, account roles, subscription and trial status, legal-document acceptance records, support communications, and related account settings. Stripe supplies billing identifiers, plan status, amounts, and payment status; HostMoat does not store full payment-card numbers.

Property, booking, guest, and operational information

We process information you enter, upload, import, or generate about properties, owners, guests, inquiries, bookings, calendars, rates, expenses, income, invoices, contracts, signatures, staff, maintenance, inventory, compliance, reviews, messages, photos, forms, guidebooks, and other rental operations.

Calendar, email, and integration data

When you connect iCal feeds, forward booking emails, or enable an integration, we receive the information those sources provide, which may include guest contact details, dates, pricing, confirmation identifiers, reservation links, message content, and integration status.

Bank and transaction data

If you connect a bank or credit-card account through Plaid, your financial institution credentials are entered into Plaid and are not provided to HostMoat. HostMoat receives and stores Plaid connection identifiers and tokens, selected account metadata, balances where enabled, transaction details, categories, synchronization cursors, and connection status so the Service can import and organize transactions. Connection credentials and tokens are kept in restricted server-side storage and are not displayed back to the browser.

Payment and contract data

Stripe processes subscription charges and payments made by guests. We receive transaction identifiers, amounts, status, limited payment-method descriptors, refunds, disputes, connected-account identifiers, and related records needed to operate payment workflows and financial reports. Signed contracts may include signer details, timestamps, IP addresses, acknowledgements, and stored signature artifacts.

AI Drafts and Public Chat

When Watchtower AI is used, we process the relevant message, conversation context, property facts, booking information, and configured knowledge needed to generate a draft or response. Depending on the configured provider, prompts may be processed by HostMoat's built-in provider, OpenAI, Anthropic, or an owner-configured Ollama endpoint.

Public chat may store visitor messages, AI responses, a session identifier, source page, limited browser information, and a name or email voluntarily provided by the visitor. Public-chat knowledge excludes designated guest-only access credentials, exact addresses, and private contacts. Standard infrastructure security logs may separately contain IP addresses.

Smart-device information

If you connect supported devices through Seam, we process device identifiers, capabilities, status, access-code schedules, alerts, noise or occupancy readings where enabled, and control results. We do not receive credentials that Seam or the device manufacturer keeps within its own authorization flow unless you explicitly provide an integration credential to HostMoat.

Usage, device, and security information

We collect IP addresses, browser and device details, pages and features used, timestamps, referral and campaign data, application events, security events, bot-detection signals, error logs, and diagnostic information. We use essential browser storage for authentication and account state and limited analytics to understand aggregate use.

2. How We Use Information

We use information to:

  • Authenticate accounts and provide, personalize, maintain, and support the Service
  • Sync calendars, import data, process direct-booking workflows, and operate integrations
  • Process subscriptions, guest payments, refunds, invoices, contracts, and related records
  • Send requested transactional, operational, account, security, and support communications
  • Generate reports, classifications, recommendations, AI drafts, and enabled public-chat responses
  • Operate smart-device workflows selected by the property owner
  • Monitor reliability, measure product use, prevent abuse and fraud, and protect users and the Service
  • Comply with law, enforce agreements, establish or defend legal claims, and complete corporate transactions

3. How We Disclose Information

We disclose information only as needed to operate the Service, at your direction, or for legitimate legal and business purposes. Recipients may include:

  • Supabase for database hosting, authentication, storage, and server functions
  • Cloudflare for website delivery, custom domains, security, bot detection, and edge services
  • Stripe for subscription billing, connected accounts, guest payments, and refunds
  • Plaid for bank linking and read-only financial transaction connectivity when enabled
  • Resend for email delivery and related delivery records
  • Seam for supported smart-device discovery and controls when enabled
  • OpenAI, Anthropic, or an owner-configured Ollama endpoint when selected for AI processing
  • Google Analytics for limited website and product measurement
  • Booking, calendar, market-data, and other integration providers when you connect or request those features
  • Your invited users and recipients, including owners, managers, staff, guests, vendors, and public-page visitors, according to the permissions and publishing settings you choose
  • Professional advisers, authorities, and transaction counterparties when reasonably necessary for legal compliance, security, claims, financing, reorganization, or a sale

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

4. Property Owners and Guest Data

For guest, owner, worker, and vendor information that a HostMoat customer controls, the customer determines why and how the information is used and HostMoat generally processes it as a service provider on the customer's behalf. Customers are responsible for required notices, permissions, requests, and lawful instructions. Individuals should first direct rental-specific requests to the relevant property owner; we will assist customers where required.

5. Public Pages and Your Publishing Choices

Information you publish through booking sites, directory listings, guidebooks, review pages, forms, widgets, and other public links can be viewed by visitors and may be indexed or copied outside HostMoat. Guest portals and staff links may be accessible to anyone who has the link. Review content and access settings before sharing a link, and rotate or disable it when appropriate.

6. Cookies and Similar Technologies

We use essential cookies and browser storage for authentication, security, preferences, account-scoped caches, and required Service functions. We use limited analytics technologies to measure aggregate site and product use. We do not use advertising cookies to build profiles for third-party targeted advertising.

7. Data Retention

We retain account and Service data while an account is active and as needed to provide the Service. Following account deletion, primary Service data is scheduled for deletion within 30 days, subject to backup expiry and narrow exceptions. The minimum legal-document acceptance record (account ID and email, document versions, server timestamp, and acceptance method) may be retained for up to seven years to establish, exercise, or defend legal claims. Signed-contract evidence, invoice and tax-relevant records, security or fraud records, payment records, and information subject to a legal hold may also be retained longer when reasonably necessary or required by law. Third-party providers retain information under their own policies.

Disconnecting an integration stops future access where supported and starts removal of HostMoat-held connection credentials and derived data according to the applicable workflow. Some imported records you independently saved or edited may remain until you delete them or your account.

8. Security

We use administrative, technical, and organizational safeguards designed to protect information, including encrypted connections, row-level database controls, server-side secret storage, scoped access, authentication, logging, and security monitoring. No system or transmission is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. You are responsible for protecting sign-in links, account access, public tokens, exported files, and credentials you control.

9. Your Choices and Rights

Depending on where you live and subject to legal exceptions, you may have rights to access, correct, delete, or obtain a copy of personal information; withdraw consent; restrict or object to certain processing; or appeal a denied request. Account holders can edit and export many records in the Service, disconnect integrations, change communication settings, and request account deletion.

To make a privacy request, contact [email protected]. We may need to verify your identity and authority. Authorized agents must provide proof of authorization. We will not discriminate against you for exercising a privacy right.

10. International Processing

HostMoat and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws. Where required, we use contractual or other recognized safeguards for cross-border transfers.

11. Children's Privacy

The Service is intended for business users age 18 or older and is not directed to children under 13. Do not use HostMoat to collect information from children unless it is lawful and genuinely necessary for the rental, and avoid collecting sensitive identifiers through general-purpose forms. If you believe a child provided information improperly, contact us.

12. Changes to This Policy

We may update this Privacy Policy as the Service or law changes. We will post the new version and provide additional notice for material changes when appropriate. We may ask account holders to acknowledge a materially revised version before continuing to use the Service.

13. Contact

Questions or privacy requests may be sent to [email protected]. Legal questions about the Service may be sent to [email protected].