Skip to main content

Privacy Policy

Last updated: August 14, 2026 · Effective: August 14, 2026

1. Who We Are

KynStay is a product of Tilted Labs LLC, a California limited liability company. When we say "KynStay," "we," "our," or "us" in this policy, we mean Tilted Labs LLC operating as KynStay.

We are the data controller for the personal information we collect through the KynStay platform. This means we decide how and why your personal information is processed.

2. Information We Collect

2.1 Account information you provide

When you create an account, we collect:

  • Name and email address
  • Phone number (optional)
  • Password (stored only in hashed form—we cannot see your actual password)
  • Profile photo (optional)
  • Currency preference (USD, GBP, or EUR)

2.2 Property information

If you list a property, we collect:

  • Property address, description, photos, and pricing
  • Availability and booking calendar data
  • Property access information you choose to provide, such as WiFi credentials, lock codes, emergency contacts, and check-in instructions

2.3 Booking information

When bookings are made through the platform, we collect:

  • Check-in and check-out dates, guest count, and booking notes
  • Pricing details (base rate, cleaning fees, discounts)
  • Payment status and payment method — either a method you tell us you paid by (e.g., Venmo, Zelle, bank transfer) or, where the host accepts cards, a record of the card payment described in Section 2.6
  • A history of any modifications to bookings, including who made the change and what was changed

2.4 Information from third-party sign-in

If you sign in using Google or Apple, we receive your name, email address, and profile picture from that provider. We do not receive your password from these services.

2.5 Information collected automatically

  • IP address—used for security, rate limiting, and fraud prevention, and to estimate your country so we can suggest a currency. The IP addresses of your most recent and previous sign-in are stored on your account record and are visible to our administrators.
  • Device and browser information—included in standard web server logs
  • Session cookies—essential for keeping you logged in (see Section 4)

2.6 Information from Stripe

We use Stripe in two separate ways, and hold different information for each.

Your KynStay subscription.

When you subscribe to KynStay, your payment is processed by Stripe. We store your subscription plan, billing interval, subscription status, and a Stripe customer identifier to manage your account. We receive payment confirmations from Stripe, but we never receive or store your full credit card number. Card details are handled entirely by Stripe.

Card payments from guests to hosts.

Hosts may connect their own Stripe account so guests can pay them by card. Where a host has done that:

  • If you are the host, we store the identifier of your connected Stripe account, whether Stripe has enabled it to take payments, whether you have submitted your details, and the dates you completed setup and accepted Stripe's terms. If you later disconnect, we keep the identifier of the disconnected account so we can still match up past payments.
  • If you are the guest, we store Stripe's identifiers for the checkout session, the charge, the payment intent and any refund, together with the amount, the currency and the fee Stripe charged. As with subscriptions, we never receive or store your full card number.

Card payments are taken on the host's own Stripe account, not ours — KynStay never receives or holds the money. An important consequence for guests is described in Section 5.

3. How We Use Your Information

We process your information for the following purposes. Where required by UK and EU data protection law, we have identified the lawful basis for each.

How we use your information and the lawful basis for each purpose
Purpose Lawful basis
Provide and operate the KynStay platform (accounts, listings, bookings) Performance of contract
Process subscription payments via Stripe Performance of contract
Set up a host's connected Stripe account, and enable guests to pay that host by card Performance of contract
Record and reconcile card payments and refunds against the right booking Performance of contract
Send transactional emails (booking confirmations, payment reminders, subscription notices) Performance of contract
Authenticate your identity (password, magic link, or OAuth sign-in) Performance of contract
Geocode property addresses to display on maps Legitimate interest
Secure the platform, prevent fraud, and enforce rate limits Legitimate interest
Comply with tax, legal, and regulatory obligations Legal obligation

Where we rely on legitimate interest, we have assessed that our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interest (see Section 8).

4. Cookies and Similar Technologies

We use only essential cookies that are strictly necessary to operate the platform:

  • Session cookie—keeps you logged in while you use KynStay
  • CSRF token—protects against cross-site request forgery attacks
  • Remember-me cookie—keeps you signed in between visits (only if you choose this option)

We do not use analytics cookies, advertising cookies, or third-party tracking cookies. We do not use any tools that track your activity across other websites.

5. Who We Share Your Information With

We share your information only with the following parties, and only to the extent necessary:

Third parties we share your information with
Recipient Purpose Location
Stripe, Inc. Payment processing, subscription management, tax calculation USA
ActiveCampaign, LLC (Postmark) Transactional email delivery USA
Google LLC OAuth sign-in authentication USA
Apple Inc. OAuth sign-in authentication USA
Hetzner Online GmbH Server hosting and infrastructure Germany (EU)
OpenStreetMap / Nominatim Property address geocoding (address data only, no user identifiers) Various
Functional Collective, Inc. (Sentry) Error tracking and performance monitoring (no personally identifiable information is sent) USA

We also share information in these circumstances:

  • Other users: Property details (descriptions, photos, pricing, availability) are visible to guests you invite. Booking details are visible to both the host and guest involved.
  • Your host, if you pay by card: A card payment is taken on the host's own Stripe account, which makes that host the merchant of record for your payment — not KynStay. The host therefore sees the transaction in their own Stripe dashboard, including whatever Stripe shows them about it, and they — not we — decide how long they keep it and who else they let see it. Stripe's own privacy notice and your host's own practices govern that copy of the data. If you would rather not have a payment recorded on a host's Stripe account, use one of the host's manual payment methods instead.
  • Legal requirements: We may disclose information when required by law, regulation, court order, or governmental request.
  • Business transfers: If KynStay is acquired or merged with another company, your information may be transferred as part of that transaction. Where that happens, the acquiring company's privacy policy would apply to your information from the date we post that change here.

We do not sell your personal information. We have never sold personal information, and we have no plans to do so.

6. International Data Transfers

Your data is stored on servers located in Germany (EU), operated by Hetzner Online GmbH. Some of your data is also transferred to service providers in the United States (Stripe, Postmark, Google, and Apple) as described in Section 5.

Where data is transferred outside the European Economic Area (EEA) or the United Kingdom, we rely on the following safeguards:

  • EU-US Data Privacy Framework—where the recipient is certified under the framework
  • Standard Contractual Clauses (SCCs)—approved by the European Commission
  • UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs—for transfers from the UK

You can request further information about the safeguards we use by contacting us at privacy@kynstay.com.

7. How Long We Keep Your Information

How long we keep each type of data, and how that period is determined
Data type How long we keep it
Account data (name, email, phone, avatar) Deleted immediately when you delete your account. There is no grace period and no recovery window — deletion is permanent as soon as you confirm it.
Property listings and photos Deleted when you remove the property or delete your account
Booking and payment records Kept while your account is open, and deleted with it. We otherwise keep them for as long as needed to run the booking, resolve disputes about it, and meet our tax and accounting obligations — we do not currently enforce a fixed maximum period.
Server and security logs Kept for as long as needed to investigate security and abuse. We do not currently enforce a fixed maximum period.
Stripe webhook events 2 years, then automatically deleted
Invitation records Kept while the invitation is outstanding and afterwards as a record that it was sent; deleted with the account that sent it. We do not currently enforce a fixed maximum period.
In-app notifications 90 days after you read them, then automatically deleted (unread ones are kept until read or until your account is deleted)

Where a row above says we do not enforce a fixed maximum period, that is a statement of what our systems do today, not a claim that we keep the data forever by design. We are working to put automatic limits on each of these; until we do, we would rather tell you the criterion we actually apply than publish a period we do not keep to. You can ask us to delete your data at any time — see Section 8.

8. Your Privacy Rights

8.1 Rights for all users

Regardless of where you live, you can:

  • Access the personal information we hold about you
  • Correct inaccurate information in your account
  • Delete your account and associated data
  • Export your data in a portable format

8.2 Additional rights for UK and EU residents

Under the UK GDPR and EU GDPR, you also have the right to:

  • Restrict processing of your personal information in certain circumstances
  • Data portability—receive your data in a structured, commonly used, machine-readable format
  • Object to processing based on our legitimate interests
  • Withdraw consent at any time where consent is the basis for processing
  • Lodge a complaint with a supervisory authority—in the UK, this is the Information Commissioner's Office (ICO)

We will respond to rights requests within one month. If a request is complex, we may extend this by up to two further months, and we will let you know.

8.3 Additional rights for California residents

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the right to:

  • Know what personal information we collect, use, and disclose
  • Delete personal information we hold about you
  • Opt out of the sale or sharing of personal information—we do not sell or share your personal information as defined by the CCPA
  • Non-discrimination—we will not treat you differently for exercising your privacy rights

To exercise any of these rights, contact us at privacy@kynstay.com. We may need to verify your identity before processing your request.

9. Children's Privacy

KynStay is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we discover that we have collected information from a person under 18, we will delete their account and data promptly. If you believe a minor has provided us with personal information, please contact us at privacy@kynstay.com.

10. Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption of all data in transit using HTTPS/TLS
  • Password hashing using bcrypt (we never store plaintext passwords)
  • Rate limiting and automatic account lockout after repeated failed login attempts
  • No storage of credit card data—all card information is handled by Stripe using PCI-compliant tokenization
  • Filtering of sensitive parameters (passwords, tokens, email addresses) from server logs

While we work to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to following industry best practices and promptly addressing any security issues.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we post the updated policy on this page and change the "Last updated" date at the top.

Where a change materially affects your rights, we will say so on this page. Because we do not currently send you an individual notice of changes, please check this page from time to time. Your continued use of KynStay after a change means you accept the updated policy; if you do not agree with a change, you may stop using KynStay and close your account, as described in our Terms of Service.

12. Contact Us

If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us:

Email: privacy@kynstay.com

Entity: Tilted Labs LLC, California, USA

UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

Website: ico.org.uk

Phone: +44 0303 123 1113