Privacy Policy
Last updated 2 August 2026
Isle Stay is a hosting platform for property owners, managers and agencies. This policy explains what we collect, why, and what we will never do with it. It covers islestay.appand every public page we serve on a host’s behalf — listings, welcome books, QR landing pages and flipbooks.
1. Who we are
Isle Stay is operated by Isle Network. For any privacy question, or to exercise any right described below, contact privacy@islestay.app.
When a guest sends an enquiry to a host through Isle Stay, that hostis the controller of the guest’s information and we process it on their instructions. For a host’s own account details, we are the controller.
2. What we collect
| What | Why |
|---|---|
| Account details — name, email, business name, phone, country, photo | To create and secure the account, and to contact the host about it |
| Property and content — listings, photos, descriptions, rates, welcome books | To provide the product and publish what a host chooses to publish |
| Guest enquiries — name, email, phone and message a guest submits | To deliver the enquiry to the host and let them reply |
| Connected accounts — tokens for services a host links, e.g. Google Calendar | To perform the sync the host asked for. Stored encrypted; never shown back |
| Usage — page views, QR and flipbook scan counts, device type, coarse referrer | To give hosts the analytics they came for, and to keep the service running |
Guest analytics are kept deliberately blunt: scans and views are counted against a one-way hash that changes daily, so we can tell repeat visits apart on a given day without building a profile of anyone.
3. Google Calendar
Connecting Google Calendar is optional and off by default. When a host connects it, we request one scope:
https://www.googleapis.com/auth/calendar.events— permission to create and manage calendar events.
We use it for exactly one thing:
- Writing viewings the host has received.When a guest books a viewing through a host’s listing or flipbook, we create a matching event on that host’s calendar. If the viewing is cancelled, we remove that event.
We do notread the host’s existing calendar entries, and we do not scan, index, analyse or store the contents of their calendar. The only calendar identifier we keep is the ID of an event we ourselves created, so that we can later update or delete it.
A host can disconnect at any time from Integrations in their hub, which deletes our stored Google tokens immediately; access can also be revoked from their Google Account permissions page. Events we already created remain on the calendar and are theirs to keep or delete.
Isle Stay’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide this feature, and we do not use it for advertising or to train AI or machine-learning models.
4. Calendar sync with booking platforms
Hosts may connect calendar feeds from Airbnb, Booking.com, Vrbo and similar platforms. We read those feeds to learn which dates are already booked, so we can warn about double bookings. We store the blocked date ranges and the name of the feed. We do not receive guest names, payment details or reservation contents from these feeds, and we do not send anything back to those platforms beyond the blocked dates a host chooses to publish.
5. Artificial intelligence
Some features — pricing suggestions, listing descriptions, welcome book sections and draft replies — use Anthropic’s Claude models. When a host uses one, the relevant content is sent to Anthropic to generate that suggestion.
- Nothing is sent to any AI provider unless a host presses a button that says so.
- Drafts are always shown to the host for review; nothing is published automatically.
- Data sent through the Anthropic API is not used to train their models. Anthropic processes it as our subprocessor.
6. Email
We send transactional email only — password resets, invitations, enquiry alerts and billing notices — through Resend. We do not send marketing email to guests, and we do not sell or share email addresses.
7. Who else touches the data
We use a small number of processors, each contractually bound to protect it:
- Vercel — application hosting
- Neon — database hosting
- Anthropic — AI features, when a host uses one
- Resend — transactional email
- Google — calendar sync, when a host connects it
We do not sell personal information. We disclose it otherwise only where the law requires it, and we will tell the affected host unless we are legally barred from doing so.
8. Where it lives and how long
Data is stored on servers in the United States and Europe. Because hosts here serve international travellers, information may be accessed from the Caribbean, the UK, the EU and North America.
We keep account and property data for as long as the account is open. When an account is closed we delete its data within 30 days, except where we must keep records longer for tax or legal reasons. Guest enquiries belong to the host and are deleted with the account.
9. Security
- All traffic is encrypted in transit (HTTPS).
- Passwords are hashed with bcrypt and are never recoverable, by us or anyone else.
- Tokens for connected services are stored encrypted and are never returned to the browser.
- Each host’s workspace is isolated at the query level, and staff access to a host’s account is recorded in an audit log.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, delete or restrict the use of your personal information, and to object to certain processing. Hosts can do most of this directly from their account settings; for anything else, write to privacy@islestay.app and we will respond within 30 days.
Guests who have sent an enquiry should contact the host they enquired with, since it is their record. If you cannot reach them, contact us and we will help.
11. Children
Isle Stay is a business tool and is not directed at children under 16. We do not knowingly collect their information; if we learn we have, we delete it.
12. Cookies
We use cookies only to keep hosts signed in and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies, and there is no third-party analytics tag on our public pages.
13. Changes
If we change this policy in a way that materially affects how we handle your information, we will email account holders before it takes effect.