Privacy Policy
This policy explains how Premsan Inc (“Premsan”, “we”, “us”) handles personal data in PMStay — this website, the web app, the API, and the PMStay apps for iPhone, iPad and Android. For your account, Premsan is the controller. For the personal data about guests kept in a property’s book, the property’s owner is the controller and Premsan processes it for them, as section 3 says.
1. What we collect
- Your account. Your name, your email address, and either a password — stored only as a hash — or, when you sign in with Apple or Google, your identifier there and the sign-in tokens the provider gives us. Each session records the IP address and the browser or device it was opened from, and when it expires. We also record the date on which you accepted the Terms, and which version.
- Each property’s book. The property’s name, address, phone number, email address, tax id, time zone and currency; each unit’s name, how it is booked, how many guests it holds, its prices, rates, discounts and tax, and the calendar links from booking sites added to it; the fees the property charges; each reservation’s number, unit, dates, number of guests, status, price, source, commission, expected arrival time and group, with the guest’s name, phone number, email address and notes as they are entered or approved from the assistant; the extras charged to it and the payments recorded against it, each an amount, a date, how it was paid and a note; the dates blocked; and the guest register: each guest’s name, nationality, identity document and its number, birth date and address. PMStay takes no payment from your guests, and a payment has no field for a card number.
- The people at a property. The owner and each person invited as staff: their account, their role and when they joined. An invite is kept only as a hash of its link, which works once and for 7 days. Each request to the assistant records who sent it. The owner sees the email address of everyone at the property, and everyone at a property sees the email address of whoever sent each message in its shared conversation.
- Each property’s conversation with the assistant. The messages each person at the property sends it, the photos attached — a booking screenshot, a guest’s chat, a guest’s passport or ID card, a list of rooms — made smaller to the size the model reads, the rows of the spreadsheets attached — a booking site’s export as a CSV or Excel file — and its replies and proposals, with whether each was approved or discarded.
- The plan. When your free use began, how many messages have been sent to the assistant since at the properties you own, whoever sent them, how many properties you own, and the state of your subscription. On the web, payment is taken by Stripe: it receives your email address and your account id, and your card details go to Stripe and never reach us. We keep the subscription’s id, your customer id at Stripe, when the current period ends and whether it renews. In the app, payment is taken by the App Store or Google Play; we receive the transaction’s id, confirm it with Apple or Google, and record it against your account.
- Help. When you write to us from Help, we keep your messages, the pictures you attach, and details that help us answer: whether you wrote from the web or the app, your browser or app version and operating system, your language, the screen you were on, the size of your window or screen, your time zone, and your most recent failed requests. They are kept with your account until you delete it. Our team reads them in our own support tool, where, if you have allowed the assistant, PMStay’s model may draft a reply that a team member reviews before sending.
- Usage. The number of requests you made to the assistant in the current hour, kept in your own account’s storage for the hourly limit. Server logs hold request metadata, including your IP address, error reports, and the size and cost of each of the assistant’s runs, for a short time, for security, debugging and our accounting.
- The bot check. Cloudflare Turnstile runs on our sign-in and sign-up pages, and in the app’s sign-in screen, to tell a person from a script.
- Nothing else. There is no advertising, no analytics, no tracking across sites or apps, no advertising identifier, and no data broker.
2. What we do with it
We use personal data to run PMStay: to keep each property’s book and show it to the people who work there, check each change against it, let the assistant read what they send it and propose changes, read the booking sites’ calendar links added to a unit and close the dates booked there, serve each unit’s own calendar link, sign you in, send you the emails the account needs — a verification link and a password reset — take payment and keep your subscription’s state, keep the service running and prevent abuse, answer you when you write to us, and meet legal obligations. PMStay sends your guests nothing. We do not use your data, your guests’ data or your conversations to train models, we do not sell personal data, and we do not share it for advertising.
3. Why we are allowed to
Where the GDPR or a law like it applies, we rely on these bases:
- Performing our contract with you — your account, your book, your conversations, and the subscription.
- Processing for you — the personal data about guests kept in the book of a property you own. We process it on your instructions, to keep the book and to let the assistant read it when the people at the property use the assistant; the staff you invite act for you, you decide what is collected from your guests and why, and you answer to them for it. A guest who asks us about their data is referred to you.
- Our legitimate interests — keeping PMStay running, finding failures, and stopping abuse and automated sign-ups. We limit this to the usage counts, the server logs and the bot check.
- A legal obligation — payment records and anything else the law requires us to keep.
4. Who else processes it
PMStay runs on Cloudflare: the servers, the storage that holds your account, your book, your conversation and your photos, the resizing of photos, the model that reads your messages and photos and proposes changes, the email we send, and the bot check are all Cloudflare services on our own account. Nothing the assistant reads goes to any other AI provider. The model runs on Cloudflare Workers AI, and the assistant sends it nothing until you allow that, on the web or in the app, when it asks before your first message or photo; you can turn it off in Settings (under Account in the phone app), and the assistant then asks again before your next message. At a property with staff, the assistant reads the property’s book only after its owner has allowed it, and each person allows it for their own messages. What it sends is the messages, the photos and spreadsheets attached, the list of the property’s units, and whatever it reads from the book to answer, which can include guests’ names, phone numbers, email addresses, notes, payments and the identity details in the guest register. Some email may be sent through Resend instead.
Stripe takes payment on the web and keeps the card; Apple and Google take payment in the app, and each tells us when a subscription you bought there renews, is cancelled or is refunded. When the app opens, it asks Expo’s update service whether a newer version of our code is available; that request carries the operating system, our project id and a random identifier the app created for itself — no account and no device identifier — and Expo sees the IP address it came from. These providers process data only on our instruction and are each bound to protect it at least as well as this policy does; we give notice here before a new one starts.
Signing in with Apple or Google sends us your identifier and email from that provider. Each acts on its own behalf there, not as our processor, and its handling of your account with it is governed by its own privacy policy; if you hide your email from us with Apple, mail reaches you through Apple’s relay. The App Store and Google Play are the sellers of what you buy inside the app, and their handling of your payment is governed by theirs.
When a calendar link from Airbnb, Booking.com, Vrbo or another site is added to a unit, our servers read that link every 32 minutes, identified as PMStay with our contact address; the site sees that request from our servers, and we send it nothing else. Each unit also has its own calendar link to give to those sites: anyone who holds it can read the unit’s booked and blocked dates, each shown only as “Not available” under the property’s and the unit’s names, with no guest’s details. A new link can replace it at any time, and the old one then stops working. Each site acts on its own behalf, and its handling of the link is governed by its own privacy policy.
5. Where it is
Your data is processed on Cloudflare’s network, which spans the world, and stored on it under Cloudflare’s own commitments for international transfers. Premsan is in Japan, a country the European Commission recognises as protecting personal data adequately.
6. On the phone
The app keeps on your device a sign-in token, the language and appearance you chose, and the random identifier its update check uses. It asks for the camera only when you choose to photograph a booking, a guest’s message or a guest’s passport or ID card, or to scan a reservation’s QR code; you can turn it off in the operating system’s settings. It reads a photo only when you pick one, to send the assistant or to attach to a Help message, through the system’s photo picker, which needs no permission, and it makes a photo smaller before sending it. It reads a spreadsheet only when you pick one to send the assistant, through the system’s file picker, which needs no permission either. It asks for no other permission, carries no advertising or analytics library, and purchases go through the store’s own sheet.
7. Cookies
On the web we set the cookies the product cannot work without: the one that keeps you signed in, and the ones Cloudflare Turnstile sets to tell a person from a bot on the sign-in and sign-up pages. This website and the web app keep your theme and language in your browser’s own storage. That is the whole list: no advertising cookies, no cross-site trackers, and no analytics that follows you between sites. Clearing them signs you out.
8. How long we keep it, and deleting it
We keep your account and the book of each property you own for as long as the account exists. Deleting a reservation, a unit or any other record removes it from the book, and clearing a property’s conversation with the assistant deletes its messages, its proposals and the photos and spreadsheets attached to them. Deleting a property deletes its book, its conversation and its files for everyone who works there. A person removed from a property, or who leaves it, can no longer open it.
You can delete your account at any time: on the web under Account in Settings, or in the app under Account. We then erase everything we hold for you — the properties you own, each with its book, every guest in it, its conversation and its photos, for everyone who works there; Help messages, usage counts and the subscription’s state — remove you from the properties where you are staff, and then delete the account itself, and a subscription bought on the web ends. The messages you sent at a property where you were staff stay in its conversation, which is its owner’s. This cannot be undone.
These records remain after the account is deleted:
- A purchase made in the app. We keep the store’s transaction id, the date and the id of the account it was bought for, so that a store sending the same receipt again cannot credit it to another account, and because the law requires payment records to be kept. The account it names no longer exists.
- Payment providers’ records. Stripe, Apple and Google keep their own records of a payment under their own legal obligations.
- Backups. Cloudflare keeps restorable copies of our databases for up to 30 days so that they can be restored after a failure; they then expire.
- Server logs. They are deleted automatically after a short time.
9. Your rights
You can read, change and delete everything in a property’s book, download its records as CSV files, clear your conversation and delete your account in the web app or the phone app, without asking us. Depending on where you live, you may also have the right to a copy of the rest of what we hold about you, to restrict how we process it, to object to processing we base on legitimate interests, and to move your data elsewhere. Write to support@pmstay.com and we will answer within one month. If you stayed at a property that uses PMStay, the property decides what it keeps about you, so ask it; if you write to us, we pass your request on to it.
If you live in California or another U.S. state with a similar law, you have the right to know what personal data we hold about you, to delete it, and to correct it; the controls above do that. We do not sell or share personal data as those laws define the words, so there is no opt-out to offer, and exercising a right gets you the same service on the same terms.
If you think we have handled your personal data wrongly, you can complain to a data protection authority — in the EEA or the United Kingdom, the one where you live or work or where the problem happened; in Japan, the Personal Information Protection Commission. You may contact us first, but you do not have to.
10. Security
Every connection is encrypted in transit. Passwords are stored as hashes. Each property’s book and conversation, and each account, are kept in their own isolated storage and are deleted with the property or the account, apart from the records listed in section 8. The app keeps its sign-in token in the operating system’s secure store. Credentials never enter our server logs. If you find a security weakness, write to security@pmstay.com and allow us time to fix it before you disclose it to anyone else.
11. Children
PMStay is not for anyone under 16, and we do not knowingly hold a child’s account. If you think a child has an account, tell us and we will delete it.
12. Changes
We may update this policy. When a change matters we will say so in the web app or the phone app, or by email. The date at the top is the version that stands.
13. Contact
Premsan Inc — 530-0001, 12-12, Osaka Ekimae Dai-2 Bldg., 1-2-2 Umeda, Kita-ku, Osaka-shi, Osaka, Japan. support@pmstay.com.