Privacy Policy
Last updated: February 25, 2026
1. Who We Are
KynStay is a product of Tilted Labs LLC, a California limited liability company. When we say "KynStay," "we," "our," or "us" in this policy, we mean Tilted Labs LLC operating as KynStay.
We are the data controller for the personal information we collect through the KynStay platform. This means we decide how and why your personal information is processed.
2. Information We Collect
2.1 Account information you provide
When you create an account, we collect:
- Name and email address
- Phone number (optional)
- Password (stored only in hashed form—we cannot see your actual password)
- Profile photo (optional)
- Currency preference (USD, GBP, or EUR)
2.2 Property information
If you list a property, we collect:
- Property address, description, photos, and pricing
- Availability and booking calendar data
- Property access information you choose to provide, such as WiFi credentials, lock codes, emergency contacts, and check-in instructions
2.3 Booking information
When bookings are made through the platform, we collect:
- Check-in and check-out dates, guest count, and booking notes
- Pricing details (base rate, cleaning fees, discounts)
- Payment status and claimed payment method (e.g., Venmo, Zelle, bank transfer)
- A history of any modifications to bookings, including who made the change and what was changed
2.4 Information from third-party sign-in
If you sign in using Google or Apple, we receive your name, email address, and profile picture from that provider. We do not receive your password from these services.
2.5 Information collected automatically
- IP address—used for security, rate limiting, and fraud prevention
- Device and browser information—included in standard web server logs
- Session cookies—essential for keeping you logged in (see Section 4)
2.6 Information from Stripe
When you subscribe to KynStay, your payment is processed by Stripe. We store your subscription plan, billing interval, trial period dates, subscription status, and a Stripe customer identifier to manage your account. We receive payment confirmations from Stripe, but we never receive or store your full credit card number. Card details are handled entirely by Stripe.
3. How We Use Your Information
We process your information for the following purposes. Where required by UK and EU data protection law, we have identified the lawful basis for each.
| Purpose | Lawful basis |
|---|---|
| Provide and operate the KynStay platform (accounts, listings, bookings) | Performance of contract |
| Process subscription payments via Stripe | Performance of contract |
| Send transactional emails (booking confirmations, payment reminders, subscription notices) | Performance of contract |
| Authenticate your identity (password, magic link, or OAuth sign-in) | Performance of contract |
| Geocode property addresses to display on maps | Legitimate interest |
| Secure the platform, prevent fraud, and enforce rate limits | Legitimate interest |
| Comply with tax, legal, and regulatory obligations | Legal obligation |
Where we rely on legitimate interest, we have assessed that our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interest (see Section 8).
4. Cookies and Similar Technologies
We use only essential cookies that are strictly necessary to operate the platform:
- Session cookie—keeps you logged in while you use KynStay
- CSRF token—protects against cross-site request forgery attacks
- Remember-me cookie—keeps you signed in between visits (only if you choose this option)
We do not use analytics cookies, advertising cookies, or third-party tracking cookies. We do not use any tools that track your activity across other websites.
5. Who We Share Your Information With
We share your information only with the following parties, and only to the extent necessary:
| Recipient | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing, subscription management, tax calculation | USA |
| ActiveCampaign, LLC (Postmark) | Transactional email delivery | USA |
| Google LLC | OAuth sign-in authentication | USA |
| Apple Inc. | OAuth sign-in authentication | USA |
| Hetzner Online GmbH | Server hosting and infrastructure | Germany (EU) |
| OpenStreetMap / Nominatim | Property address geocoding (address data only, no user identifiers) | Various |
| Functional Collective, Inc. (Sentry) | Error tracking and performance monitoring (no personally identifiable information is sent) | USA |
We also share information in these circumstances:
- Other users: Property details (descriptions, photos, pricing, availability) are visible to guests you invite. Booking details are visible to both the host and guest involved.
- Legal requirements: We may disclose information when required by law, regulation, court order, or governmental request.
- Business transfers: If KynStay is acquired or merged with another company, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
We do not sell your personal information. We have never sold personal information, and we have no plans to do so.
6. International Data Transfers
Your data is stored on servers located in Germany (EU), operated by Hetzner Online GmbH. Some of your data is also transferred to service providers in the United States (Stripe, Postmark, Google, and Apple) as described in Section 5.
Where data is transferred outside the European Economic Area (EEA) or the United Kingdom, we rely on the following safeguards:
- EU-US Data Privacy Framework—where the recipient is certified under the framework
- Standard Contractual Clauses (SCCs)—approved by the European Commission
- UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs—for transfers from the UK
You can request further information about the safeguards we use by contacting us at privacy@kynstay.com.
7. How Long We Keep Your Information
| Data type | Retention period |
|---|---|
| Account data (name, email, phone, avatar) | Duration of your account, plus 30 days after deletion |
| Property listings and photos | Deleted when you remove the property or close your account |
| Booking records | 7 years after booking completion (tax and legal obligations) |
| Payment records | 7 years (tax and legal obligations) |
| Server and security logs | 90 days |
| Stripe webhook events | 2 years (operational audit) |
| Invitation records | 1 year after acceptance or expiry |
| In-app notifications | 90 days after read (unread preserved until read or account deletion) |
8. Your Privacy Rights
8.1 Rights for all users
Regardless of where you live, you can:
- Access the personal information we hold about you
- Correct inaccurate information in your account
- Delete your account and associated data
- Export your data in a portable format
8.2 Additional rights for UK and EU residents
Under the UK GDPR and EU GDPR, you also have the right to:
- Restrict processing of your personal information in certain circumstances
- Data portability—receive your data in a structured, commonly used, machine-readable format
- Object to processing based on our legitimate interests
- Withdraw consent at any time where consent is the basis for processing
- Lodge a complaint with a supervisory authority—in the UK, this is the Information Commissioner's Office (ICO)
We will respond to rights requests within one month. If a request is complex, we may extend this by up to two further months, and we will let you know.
8.3 Additional rights for California residents
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the right to:
- Know what personal information we collect, use, and disclose
- Delete personal information we hold about you
- Opt out of the sale or sharing of personal information—we do not sell or share your personal information as defined by the CCPA
- Non-discrimination—we will not treat you differently for exercising your privacy rights
To exercise any of these rights, contact us at privacy@kynstay.com. We may need to verify your identity before processing your request.
9. Children's Privacy
KynStay is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we discover that we have collected information from a person under 18, we will delete their account and data promptly. If you believe a minor has provided us with personal information, please contact us at privacy@kynstay.com.
10. Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of all data in transit using HTTPS/TLS
- Password hashing using bcrypt (we never store plaintext passwords)
- Rate limiting and automatic account lockout after repeated failed login attempts
- No storage of credit card data—all card information is handled by Stripe using PCI-compliant tokenization
- Filtering of sensitive parameters (passwords, tokens, email addresses) from server logs
While we work to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to following industry best practices and promptly addressing any security issues.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and by posting a notice on the platform at least 30 days before the changes take effect. Your continued use of KynStay after the notice period means you accept the updated policy. If you do not agree with the changes, you may close your account before they take effect.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us:
Email: privacy@kynstay.com
Entity: Tilted Labs LLC, California, USA
UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: ico.org.uk
Phone: +44 0303 123 1113