guestavia

Privacy Policy

Last updated: 27 August 2026

On this page
  1. 1 · Two hats: when we decide and when you do
  2. 2 · What data we process
  3. 3 · Why we use it, and on what legal basis
  4. 4 · Artificial intelligence, explained straight
  5. 5 · Who we share data with (the complete list)
  6. 6 · How long we keep things
  7. 7 · Your rights and how to use them
  8. 8 · Cookies
  9. 9 · Security: what we do, and what we will not promise
  10. 10 · Addendum: data processing terms
  11. 11 · Minors
  12. 12 · Changes to this policy

Who operates this site

Legal nameVan Guardia Digital LLC
EntityLimited Liability Company, formed in the State of Wyoming, United States
EIN30-1494220
Registered address30 N Gould St, Ste N, Sheridan, WY 82801, United States
ProductGuestavia (guestavia.com)
Contact[email protected]

This policy explains, in plain language, what personal data we process when you use Guestavia, why we process it, who we share it with, and what you can require from us.

Guestavia is property management software for short-term rentals. That creates a distinction worth understanding up front, because it changes who answers for what.

1 · Two hats: when we decide and when you do

We handle two very different kinds of data, and our role differs in each:

Your account data
(you, the host)
Your guests' data
(entered by you or captured by your booking site)
Who decides how it is usedGuestaviaYou, the host
Legal roleControllerYou are the controller; we are the processor
What that means in practiceWe define what we keep about your account and whyWe only do what the software needs in order to work, and what you instruct. We never use your guests' data for our own purposes

Section 10 is the data processing addendum: the contractual terms you need if you have to demonstrate to anyone (or to the EU GDPR) that your software vendor is compliant. It forms part of this policy — there is nothing separate to sign.

2 · What data we process

2.1 · About you, our customer

2.2 · About your guests and team members

This is data you enter, or that arrives through channels you connect. Depending on the modules you use, it may include:

Sensitive data, stated plainly. Identity documents are special category data under several laws. They are stored only if you enable online check-in with those fields, and are visible only to your account. If your country requires you to report them to an authority (for example, the traveller registry in Spain), that obligation is yours as the host: the software helps you collect the data, it does not file on your behalf.

2.3 · About visitors to guestavia.com

3 · Why we use it, and on what legal basis

PurposeDataLegal basis
Providing the service you subscribed toaccount, usage, operational dataPerformance of a contract
Charging your subscription and issuing receiptsbilling dataContract · legal obligation
Answering your support requeststickets and emailsPerformance of a contract
Letting the AI Concierge reply to your guestsconversations and property contextPerformance of a contract (on your instruction)
Security, abuse prevention and rate limitstechnical logsLegitimate interest
Sending you the Host Kit and product emailsemail addressConsent (one-click unsubscribe in every email)
Improving the productaggregate statistics, no individuals identifiedLegitimate interest

What we do NOT do — a decision, not an oversight:

4 · Artificial intelligence, explained straight

The AI Concierge that answers your guests, and the assistant that helps you inside the dashboard, work by sending the conversation text — together with your property context — to the Anthropic API, which returns the reply.

AI can be wrong. Automated replies are help, not a guarantee: review the inbox and use the attention flag when something needs your judgement.

5 · Who we share data with (the complete list)

We share data only with the vendors the service genuinely requires. Each processes data on our behalf, under contract, and only for what this table says.

VendorPurposeWhat they receiveWhere
Anthropic PBCConcierge and assistant repliesconversation text and property contextUSA
Stripe, Inc.subscription billingname, email, card data (directly — never through us)USA / EU
Render Services, Inc.application and database hostingeverything stored in the softwareUSA
Cloudflare, Inc.DNS, content delivery and domain emailtechnical browsing dataglobal network
Meta Platforms, Inc.WhatsApp, Instagram and Messenger, if you connect themmessages and contact data on those channelsUSA / global
Mercado Pago (MercadoLibre S.R.L.)collecting from your guests, if you connect your accountproperty name, description, amount and booking code. Card details are entered by the guest on Mercado Pago and never pass through usLatin America
Brevo (Sendinblue SAS)product emails and Host Kit deliveryemail address and nameEuropean Union

We may also disclose data where a competent authority requires it through a valid legal process, or where necessary to defend our rights. If that happens and the law lets us tell you, we will.

International transfers. We are a US company and our servers are in the United States. If you are in the European Union or the United Kingdom, your data leaves your country. Those transfers rely on the Standard Contractual Clauses approved by the European Commission, which form part of our vendor agreements.

6 · How long we keep things

DataRetention
Account data and content you uploadWhile the account is active
After you cancel30 days so you can reactivate or export; then deleted
Billing records and receiptsAs required by applicable tax law (commonly up to 10 years)
Technical security logsUp to 12 months
Email left for the Host KitUntil you unsubscribe

You can ask us to delete data sooner by writing to [email protected], except where we are legally required to retain it.

7 · Your rights and how to use them

Whatever your nationality, with us you can:

Write to [email protected] from your account email. We answer within 30 calendar days. It is free; we may only ask you to prove your identity where there is reasonable doubt.

Frameworks we expressly recognise: Regulation (EU) 2016/679 (GDPR) and the Spanish LOPDGDD · Argentina's Law 25.326 · Brazil's Law 13.709 (LGPD) · Mexico's federal data protection law. If you believe we have treated you badly you may complain to your national supervisory authority — though we would rather you wrote to us first and gave us the chance to put it right.

8 · Cookies

We keep this lean. guestavia.com uses no advertising cookies and no third-party tracking cookies.

If we ever add analytics or advertising, we will ask for your consent first and this section will change before anything else does.

9 · Security: what we do, and what we will not promise

What is actually implemented:

And what we will not tell you, because it would not be true: no system is one hundred per cent invulnerable. We do not hold ISO 27001 or SOC 2 certification — we are a new, small company — and we would rather say so than imply otherwise. If we detect a breach affecting you, we will notify you without undue delay and, where applicable, the supervisory authority within 72 hours.

10 · Addendum: data processing terms

This section is contractual and applies to your guests' and team members' data, where you are the controller and Guestavia the processor. It serves as a Data Processing Agreement (DPA) for the purposes of Article 28 GDPR.

  1. Subject matter and duration: processing the data necessary to provide the service, for as long as your account is active and for 30 days after cancellation.
  2. Instructions: we process data only on your instructions — given through the product configuration — and as required by law. If an instruction appeared to us unlawful, we would tell you.
  3. Confidentiality: anyone with access is bound by confidentiality obligations.
  4. Security: we apply the measures in section 9.
  5. Sub-processors: those listed in section 5. We will give you reasonable prior notice before adding or replacing one, and you may object; on reasoned objection you may terminate without penalty.
  6. Assistance: we help you respond to your guests' rights requests and meet your security and notification obligations.
  7. Breaches: we notify you without undue delay after becoming aware, with the information we hold.
  8. Return and deletion: on termination you may export your data; we then delete it, unless legally required to retain it.
  9. Audit: we make available the information needed to demonstrate compliance with these terms.

If you need a signed DPA on your own letterhead, write to [email protected] and we will sort it out.

11 · Minors

Guestavia is a business tool: it is not directed at people under 18 and we do not knowingly create accounts for minors. Where a minor appears as a guest on a booking, that data is entered by the host, under the host's responsibility and limited to the minimum necessary. If we find we have collected a minor's data without a proper basis, we delete it.

12 · Changes to this policy

If we change it, we update the date above. Where a change is material — a new vendor, a new purpose — we tell you by email or in the dashboard before it takes effect. We do not make substantive changes quietly.

Questions, complaints or requests: [email protected].