Stay
Privacy Policy
How Stay handles your data at joinstay.co. Last updated September 2026.
What we collect
- Account — email and sign-in provider when you use Supabase Auth (Google, Apple, or magic link).
- Travel profile — handle, display name, home country, preferences you choose to save.
- Identity vault — guest contact and passport details you enter for faster checkout. Stored only when you save them on your profile.
- Bookings — stays you book through Stay, including guest details required by the supplier.
- Loyalty wallet — programmes and status you add manually. We do not store loyalty login passwords.
How we protect sensitive data
All traffic between your browser and Stay uses TLS. Passport, contact, guest, and OAuth token fields are sealed with AES-256-GCM before they are written to our database when STAY_DATA_ENCRYPTION_KEY is configured in production.
Database access is scoped with row-level security: your profile, bookings, price watches, and OAuth connections are readable only by your authenticated session. Server cron jobs use a separate service credential and never run in your browser.
Card numbers are not stored on Stay. Nuitée's secure payment SDK collects hotel-booking payments directly as merchant of record; Stay receives only booking and payment-status references needed to complete and service the reservation.
AI and your data
Stay uses your travel profile and loyalty wallet to rank properties and compress decisions. Passport numbers and payment details are never sent to language models. Your saved travel data is used only for checkout and trip management. It is not used to train underlying AI models or sold to advertisers.
Gmail and inbox access
Gmail travel ingestion is optional and not required to use Stay. When enabled, it requestsgmail.readonly, which technically permits viewing Gmail messages and settings. Stay limits access to travel-confirmation searches, processes message metadata and snippets transiently, and retains only derived travel preferences and a sync timestamp. Raw Gmail messages and snippets are not retained or sent to advertising, Customer.io, or language-model providers. See our Gmail safety page for details on revocation and deletion.
Stay's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is not used to train generalized AI models.
Service providers
We use trusted processors to run Stay. They process data only on our instructions:
- Supabase — authentication and encrypted database hosting.
- Vercel — application hosting and edge delivery.
- Nuitée / LiteAPI — hotel inventory, secure traveller payment as merchant of record, supplier booking, cancellations, and refunds.
- Resend — sign-in magic links only.
- Customer.io — lifecycle email for booking receipts, pre-arrival messages, and price alerts. Gmail content and Gmail-derived preferences are not sent to Customer.io.
- Stripe — a separate Stay subscription if offered; Stripe does not process the hotel-booking total.
- Sentry — error monitoring (no passport or card data).
- Google Analytics — consent-only page and traffic measurement. Advertising signals are disabled, and Stay does not send passport, payment, or Gmail data.
Retention and deletion
- Account deletion — from your profile page or
POST /api/account/delete. Immediately removes your vault, bookings, watches, and auth account, and suppresses your profile in Customer.io so lifecycle email cannot resume. - Data export —
GET /api/account/exportreturns a JSON copy of your profile and bookings while signed in. - Gmail disconnect — attempts to revoke access at Google, immediately deletes Stay's local OAuth tokens, and removes Gmail-derived travel preferences. Account deletion performs the same cleanup before deleting the remaining account data.
Contact
Privacy questions: privacy@joinstay.co. Partnerships: partnerships@joinstay.co.