Privacy Policy
Effective date: August 18th, 2025
If you have questions, contact chris@bnbdirect.to.
1) Introduction
This Privacy Policy explains how BnbDirect ("BnbDirect," "we," "our," or "us") collects, uses, and shares information when you use our software and services that help short‑term rental hosts generate and manage self‑hosted booking websites. BnbDirect is based in the United States.
This Policy applies to information we collect through our website, app, and related services (collectively, the "Service"). It does not cover the privacy practices of third parties you connect to, deploy on, or use with the Service.
2) Scope & Roles
- Controller: For account, billing, support, and product analytics data, BnbDirect acts as an independent data controller.
- Processor (limited): For content you provide (e.g., listing text, photos) to generate your site, we process that data on your behalf to deliver the Service.
3) Information We Collect
- Account & Contact Data: name, email, password (hashed), settings.
- Billing Data: subscription status, plan, and payment method details handled by our processor Stripe. We do not store full card numbers.
- Content You Provide: listing details, images, availability, pricing, and configuration needed to generate your self‑hosted site.
- Usage & Technical Data: IP address, device/browser type, pages viewed, referring URLs, timestamps, diagnostic logs, and event data.
- Cookies & Similar Tech: session cookies for authentication and security; optional analytics cookies (see Section 7).
4) How We Use Information
- Provide, operate, and secure the Service (including account authentication and fraud prevention).
- Generate and manage your self‑hosted booking site based on your configuration.
- Process subscription payments and manage billing (via Stripe).
- Respond to support requests and communicate service updates.
- Analyze product performance and improve features.
- Comply with legal obligations and enforce our Terms.
5) Legal Bases for Processing (EU/UK)
Where GDPR or similar laws apply, we process personal data under these legal bases: performance of a contract (providing the Service), legitimate interests (security, product improvement), consent (where required, e.g., certain cookies), and legal obligations.
8) Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. When no longer needed, we take steps to delete or de‑identify data.
9) Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information (e.g., HTTPS in transit, restricted access). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10) International Data Transfers
We are U.S.‑based and may process information in the United States and other countries. Where required, we implement appropriate safeguards for cross‑border transfers (e.g., standard contractual clauses).
11) Your Rights
- Access, Correction, Deletion: You can request access to, correction of, or deletion of your personal information by emailing chris@bnbdirect.to.
- Portability & Restriction: Where applicable, you may request a copy of your data or ask us to restrict processing.
- GDPR (EU/UK): You may have rights to object, withdraw consent (for consent‑based processing), and lodge a complaint with your local data protection authority.
- CCPA/CPRA (California): California residents may request access/portability and deletion of personal information. We do not sell or share personal information for cross‑context behavioral advertising. You will not be discriminated against for exercising your rights.
12) Emails & Communications
- Transactional: account, billing, and service‑related messages (cannot generally opt out).
- Product Updates/Marketing: you can opt out at any time using unsubscribe links or by contacting us.
13) Children’s Privacy
The Service is intended for adults involved in hosting activities and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child provided us information, contact us so we can delete it.
14) Guest Payments & Bookings
BnbDirect handles only subscription billing for access to the Service. We do not process or store payments between you and your rental guests, and guest booking transactions on your self‑hosted site are outside the scope of this Policy except to the extent you configure third‑party processors directly.
15) Third‑Party Links & Services
Your use of third‑party services (e.g., hosting providers, domain registrars, analytics, email services, or payment processors you connect) is governed by their own terms and privacy policies. For Stripe’s privacy practices, see stripe.com/privacy.
16) Changes to this Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice (for example, by email or in‑app notification). Your continued use of the Service after the effective date of an update constitutes acceptance.