- 1 · Two hats: when we decide and when you do
- 2 · What data we process
- 3 · Why we use it, and on what legal basis
- 4 · Artificial intelligence, explained straight
- 5 · Who we share data with (the complete list)
- 6 · How long we keep things
- 7 · Your rights and how to use them
- 8 · Cookies
- 9 · Security: what we do, and what we will not promise
- 10 · Addendum: data processing terms
- 11 · Minors
- 12 · Changes to this policy
Who operates this site
| Legal name | Van Guardia Digital LLC |
|---|---|
| Entity | Limited Liability Company, formed in the State of Wyoming, United States |
| EIN | 30-1494220 |
| Registered address | 30 N Gould St, Ste N, Sheridan, WY 82801, United States |
| Product | Guestavia (guestavia.com) |
| Contact | [email protected] |
This policy explains, in plain language, what personal data we process when you use Guestavia, why we process it, who we share it with, and what you can require from us.
Guestavia is property management software for short-term rentals. That creates a distinction worth understanding up front, because it changes who answers for what.
1 · Two hats: when we decide and when you do
We handle two very different kinds of data, and our role differs in each:
| Your account data (you, the host) | Your guests' data (entered by you or captured by your booking site) | |
|---|---|---|
| Who decides how it is used | Guestavia | You, the host |
| Legal role | Controller | You are the controller; we are the processor |
| What that means in practice | We define what we keep about your account and why | We only do what the software needs in order to work, and what you instruct. We never use your guests' data for our own purposes |
Section 10 is the data processing addendum: the contractual terms you need if you have to demonstrate to anyone (or to the EU GDPR) that your software vendor is compliant. It forms part of this policy — there is nothing separate to sign.
2 · What data we process
2.1 · About you, our customer
- Sign-up and account: name, email address, password (stored hashed — nobody at Guestavia can read it, including us), country and language.
- Billing: plan, currency, number of properties, invoice history. We do not store card numbers. Payments are processed by Stripe and card details go straight to them without passing through our servers.
- Service usage: technical logs (access date and time, IP address, browser type) used for security, anti-abuse limits and troubleshooting.
- Support: whatever you write in tickets, enquiries or emails.
2.2 · About your guests and team members
This is data you enter, or that arrives through channels you connect. Depending on the modules you use, it may include:
- Guest name, email, phone number and language.
- Booking dates, amounts, payment status and source channel.
- Conversations: messages from your web chat, your booking site and — if you connect those channels — WhatsApp, Instagram Direct and Facebook Messenger.
- Online check-in fields you configure, which may include identity document and address where your local law requires it.
- Photos uploaded by your cleaner in the property checklist.
- Name, email or phone of team members you invite to your account.
Sensitive data, stated plainly. Identity documents are special category data under several laws. They are stored only if you enable online check-in with those fields, and are visible only to your account. If your country requires you to report them to an authority (for example, the traveller registry in Spain), that obligation is yours as the host: the software helps you collect the data, it does not file on your behalf.
2.3 · About visitors to guestavia.com
- If you leave your email to download the Host Kit: that address and the date.
- If you write to us through the site chat: the content of that conversation.
- Basic technical browsing data (see section 8, cookies).
3 · Why we use it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service you subscribed to | account, usage, operational data | Performance of a contract |
| Charging your subscription and issuing receipts | billing data | Contract · legal obligation |
| Answering your support requests | tickets and emails | Performance of a contract |
| Letting the AI Concierge reply to your guests | conversations and property context | Performance of a contract (on your instruction) |
| Security, abuse prevention and rate limits | technical logs | Legitimate interest |
| Sending you the Host Kit and product emails | email address | Consent (one-click unsubscribe in every email) |
| Improving the product | aggregate statistics, no individuals identified | Legitimate interest |
What we do NOT do — a decision, not an oversight:
- We never sell or rent personal data to anyone.
- We do not use your guests' data for our own marketing.
- We do not use your data or your guests' data to train AI models, and we do not allow our vendors to do so either.
- We do not show third-party advertising inside the product.
4 · Artificial intelligence, explained straight
The AI Concierge that answers your guests, and the assistant that helps you inside the dashboard, work by sending the conversation text — together with your property context — to the Anthropic API, which returns the reply.
- Anthropic acts as our sub-processor, under contract.
- Under their commercial API terms, that content is not used to train their models.
- We send only what is needed to answer: the message, recent history of that conversation, and the property data you entered. Your billing data is never sent.
- If you would rather the AI stayed out of it, you can switch it off and run the software manually: messages simply wait in the inbox for you.
AI can be wrong. Automated replies are help, not a guarantee: review the inbox and use the attention flag when something needs your judgement.
5 · Who we share data with (the complete list)
We share data only with the vendors the service genuinely requires. Each processes data on our behalf, under contract, and only for what this table says.
| Vendor | Purpose | What they receive | Where |
|---|---|---|---|
| Anthropic PBC | Concierge and assistant replies | conversation text and property context | USA |
| Stripe, Inc. | subscription billing | name, email, card data (directly — never through us) | USA / EU |
| Render Services, Inc. | application and database hosting | everything stored in the software | USA |
| Cloudflare, Inc. | DNS, content delivery and domain email | technical browsing data | global network |
| Meta Platforms, Inc. | WhatsApp, Instagram and Messenger, if you connect them | messages and contact data on those channels | USA / global |
| Mercado Pago (MercadoLibre S.R.L.) | collecting from your guests, if you connect your account | property name, description, amount and booking code. Card details are entered by the guest on Mercado Pago and never pass through us | Latin America |
| Brevo (Sendinblue SAS) | product emails and Host Kit delivery | email address and name | European Union |
We may also disclose data where a competent authority requires it through a valid legal process, or where necessary to defend our rights. If that happens and the law lets us tell you, we will.
International transfers. We are a US company and our servers are in the United States. If you are in the European Union or the United Kingdom, your data leaves your country. Those transfers rely on the Standard Contractual Clauses approved by the European Commission, which form part of our vendor agreements.
6 · How long we keep things
| Data | Retention |
|---|---|
| Account data and content you upload | While the account is active |
| After you cancel | 30 days so you can reactivate or export; then deleted |
| Billing records and receipts | As required by applicable tax law (commonly up to 10 years) |
| Technical security logs | Up to 12 months |
| Email left for the Host Kit | Until you unsubscribe |
You can ask us to delete data sooner by writing to [email protected], except where we are legally required to retain it.
7 · Your rights and how to use them
Whatever your nationality, with us you can:
- Access the data we hold about you.
- Correct anything wrong or incomplete.
- Delete your data ("right to be forgotten").
- Object to processing or ask us to restrict it.
- Take your data with you in a machine-readable format (portability).
- Withdraw consent where consent is the basis, without affecting past processing.
- Not be subject to solely automated decisions with legal effect. Guestavia makes no such decisions about people.
Write to [email protected] from your account email. We answer within 30 calendar days. It is free; we may only ask you to prove your identity where there is reasonable doubt.
Frameworks we expressly recognise: Regulation (EU) 2016/679 (GDPR) and the Spanish LOPDGDD · Argentina's Law 25.326 · Brazil's Law 13.709 (LGPD) · Mexico's federal data protection law. If you believe we have treated you badly you may complain to your national supervisory authority — though we would rather you wrote to us first and gave us the chance to put it right.
8 · Cookies
We keep this lean. guestavia.com uses no advertising cookies and no third-party tracking cookies.
- Strictly necessary: the session that keeps you signed in to the dashboard, and your language preference. The product cannot work without them, so no consent is required.
- Stripe: at checkout, Stripe sets its own cookies for fraud prevention, governed by Stripe's privacy policy.
- Cloudflare: may set a technical cookie to distinguish legitimate traffic from attacks.
If we ever add analytics or advertising, we will ask for your consent first and this section will change before anything else does.
9 · Security: what we do, and what we will not promise
What is actually implemented:
- All traffic is encrypted with HTTPS/TLS.
- Passwords are stored using hashing functions: they exist nowhere in readable form.
- Account isolation verified by automated tests: no customer can see another customer's data. It is one of the things we test hardest.
- Team member permissions enforced on the server, not merely by hiding buttons on screen.
- Sensitive access data (door code, WiFi password) is not sent to the guest's browser until the conditions you defined are met.
- Rate limits to stop automated abuse.
And what we will not tell you, because it would not be true: no system is one hundred per cent invulnerable. We do not hold ISO 27001 or SOC 2 certification — we are a new, small company — and we would rather say so than imply otherwise. If we detect a breach affecting you, we will notify you without undue delay and, where applicable, the supervisory authority within 72 hours.
10 · Addendum: data processing terms
This section is contractual and applies to your guests' and team members' data, where you are the controller and Guestavia the processor. It serves as a Data Processing Agreement (DPA) for the purposes of Article 28 GDPR.
- Subject matter and duration: processing the data necessary to provide the service, for as long as your account is active and for 30 days after cancellation.
- Instructions: we process data only on your instructions — given through the product configuration — and as required by law. If an instruction appeared to us unlawful, we would tell you.
- Confidentiality: anyone with access is bound by confidentiality obligations.
- Security: we apply the measures in section 9.
- Sub-processors: those listed in section 5. We will give you reasonable prior notice before adding or replacing one, and you may object; on reasoned objection you may terminate without penalty.
- Assistance: we help you respond to your guests' rights requests and meet your security and notification obligations.
- Breaches: we notify you without undue delay after becoming aware, with the information we hold.
- Return and deletion: on termination you may export your data; we then delete it, unless legally required to retain it.
- Audit: we make available the information needed to demonstrate compliance with these terms.
If you need a signed DPA on your own letterhead, write to [email protected] and we will sort it out.
11 · Minors
Guestavia is a business tool: it is not directed at people under 18 and we do not knowingly create accounts for minors. Where a minor appears as a guest on a booking, that data is entered by the host, under the host's responsibility and limited to the minimum necessary. If we find we have collected a minor's data without a proper basis, we delete it.
12 · Changes to this policy
If we change it, we update the date above. Where a change is material — a new vendor, a new purpose — we tell you by email or in the dashboard before it takes effect. We do not make substantive changes quietly.
Questions, complaints or requests: [email protected].