LEGAL

Privacy Policy

Last updated: June 29, 2026

This Privacy Policy explains how Hosttello (“Hosttello”, “we”, “our”, or “us”) collects, uses, shares and protects personal information when you use our hostel- and camp-management platform, our websites, and the booking tools we host on your behalf. It applies to customers and visitors worldwide.

Who we are. Hosttello is operated by [Hosttello — legal entity & registered address to be inserted]. For questions about this policy or to exercise your rights, contact privacy@hosttello.com.

1. Our two roles: controller and processor

Privacy law distinguishes the party that decides why and how data is processed (the “controller”) from the party that processes it on their behalf (the “processor”). Hosttello acts in both roles:

2. Information we collect

Account information: name, email, a securely hashed password, business name, location, phone number and timezone.

Guest data (processed on your behalf): guest names, phone numbers, emails, check-in/out dates, booking and stay notes, and messages exchanged through connected channels.

Payment information: subscription billing is handled by a third-party, PCI-DSS-compliant payment processor. We never receive or store your full card number.

Messaging data: if you connect a messaging channel, we store the messages sent and received through the platform so the shared inbox and automations work.

Usage data: basic, largely aggregated metrics (pages visited, features used, errors) used to operate and improve the product.

3. How we use information, and our lawful bases

Where the GDPR or UK GDPR applies, we rely on these lawful bases:

We never sell your data or your guests' data, and we do not use guest data for our own marketing.

4. Data storage, security and international transfers

We host data with reputable infrastructure providers using data centres in the European Union, and we protect it with industry-standard safeguards including encryption in transit and at rest, strong password hashing, access controls, and regular automated backups (retained for a limited period and then deleted).

If personal data is transferred to, or accessed from, a country outside the EU/EEA or UK that is not covered by an “adequacy” decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant). You can request more detail about the safeguards we use by emailing privacy@hosttello.com.

5. Service providers (sub-processors)

We use a small number of vetted service providers to deliver the platform, each bound by a data-processing agreement and permitted to use data only to provide their service to us. We engage them by category:

We will give reasonable notice of new sub-processors and provide the current named list on request to privacy@hosttello.com.

6. Data retention

We keep account data for as long as your account is active. If you cancel, your data stays available in read-only mode for 30 days so you can export it, after which it is permanently deleted from production systems (and shortly afterwards from backups). We may retain limited records longer where required for legal, tax or fraud-prevention purposes.

7. Your rights (EU / EEA & UK)

If you are in the EU/EEA or the UK, you have the rights to: access your data; correct inaccurate data; erase your data; restrict or object to processing; data portability; and to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority. You can act on most of these from your dashboard Settings, or by emailing privacy@hosttello.com. Where Hosttello is a processor (your guests' data), please direct your guests' requests to you as the controller — we will assist you in responding.

8. California privacy rights (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to or deletion of that information, to correct inaccurate information, and to be free from discrimination for exercising these rights. We do not sell or “share” personal information as those terms are defined under the CCPA/CPRA. To make a request, email privacy@hosttello.com.

9. Other regions (including Morocco) and international users

We aim to honour the core data-protection rights described above for all users, wherever you are. Customers in Morocco are additionally protected under Law No. 09-08 on the protection of individuals with regard to the processing of personal data, and customers in other jurisdictions retain any rights granted by their local law. If your local law grants you stronger rights than those set out here, those rights apply.

10. Cookies

Our application uses only the essential cookies needed for sign-in and security. Our marketing site uses optional analytics/advertising cookies that load only with your consent. See our Cookie Policy for details.

11. Children

Hosttello is a business tool not intended for anyone under 18, and we do not knowingly collect data from children. As our customer, you are responsible for any guest data you choose to store and for complying with the rules that apply to minors' data in your jurisdiction.

12. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email or in-app and update the “Last updated” date above.

13. Governing law & contact

This policy is governed by the laws of [registered jurisdiction to be inserted], without prejudice to any mandatory data-protection or consumer-protection rights you have under your local law. Questions, requests, or complaints: email privacy@hosttello.com or visit our contact page.