Privacy Policy
Last updated: August 14, 2026 · Effective: August 14, 2026
1. Who We Are
KynStay is a product of Tilted Labs LLC, a California limited liability company. When we say "KynStay," "we," "our," or "us" in this policy, we mean Tilted Labs LLC operating as KynStay.
We are the data controller for the personal information we collect through the KynStay platform. This means we decide how and why your personal information is processed.
2. Information We Collect
2.1 Account information you provide
When you create an account, we collect:
- Name and email address
- Phone number (optional)
- Password (stored only in hashed form—we cannot see your actual password)
- Profile photo (optional)
- Currency preference (USD, GBP, or EUR)
2.2 Property information
If you list a property, we collect:
- Property address, description, photos, and pricing
- Availability and booking calendar data
- Property access information you choose to provide, such as WiFi credentials, lock codes, emergency contacts, and check-in instructions
2.3 Booking information
When bookings are made through the platform, we collect:
- Check-in and check-out dates, guest count, and booking notes
- Pricing details (base rate, cleaning fees, discounts)
- Payment status and payment method — either a method you tell us you paid by (e.g., Venmo, Zelle, bank transfer) or, where the host accepts cards, a record of the card payment described in Section 2.6
- A history of any modifications to bookings, including who made the change and what was changed
2.4 Information from third-party sign-in
If you sign in using Google or Apple, we receive your name, email address, and profile picture from that provider. We do not receive your password from these services.
2.5 Information collected automatically
- IP address—used for security, rate limiting, and fraud prevention, and to estimate your country so we can suggest a currency. The IP addresses of your most recent and previous sign-in are stored on your account record and are visible to our administrators.
- Device and browser information—included in standard web server logs
- Session cookies—essential for keeping you logged in (see Section 4)
2.6 Information from Stripe
We use Stripe in two separate ways, and hold different information for each.
Your KynStay subscription.
When you subscribe to KynStay, your payment is processed by Stripe. We store your subscription plan, billing interval, subscription status, and a Stripe customer identifier to manage your account. We receive payment confirmations from Stripe, but we never receive or store your full credit card number. Card details are handled entirely by Stripe.
Card payments from guests to hosts.
Hosts may connect their own Stripe account so guests can pay them by card. Where a host has done that:
- If you are the host, we store the identifier of your connected Stripe account, whether Stripe has enabled it to take payments, whether you have submitted your details, and the dates you completed setup and accepted Stripe's terms. If you later disconnect, we keep the identifier of the disconnected account so we can still match up past payments.
- If you are the guest, we store Stripe's identifiers for the checkout session, the charge, the payment intent and any refund, together with the amount, the currency and the fee Stripe charged. As with subscriptions, we never receive or store your full card number.
Card payments are taken on the host's own Stripe account, not ours — KynStay never receives or holds the money. An important consequence for guests is described in Section 5.
3. How We Use Your Information
We process your information for the following purposes. Where required by UK and EU data protection law, we have identified the lawful basis for each.
| Purpose | Lawful basis |
|---|---|
| Provide and operate the KynStay platform (accounts, listings, bookings) | Performance of contract |
| Process subscription payments via Stripe | Performance of contract |
| Set up a host's connected Stripe account, and enable guests to pay that host by card | Performance of contract |
| Record and reconcile card payments and refunds against the right booking | Performance of contract |
| Send transactional emails (booking confirmations, payment reminders, subscription notices) | Performance of contract |
| Authenticate your identity (password, magic link, or OAuth sign-in) | Performance of contract |
| Geocode property addresses to display on maps | Legitimate interest |
| Secure the platform, prevent fraud, and enforce rate limits | Legitimate interest |
| Comply with tax, legal, and regulatory obligations | Legal obligation |
Where we rely on legitimate interest, we have assessed that our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interest (see Section 8).
4. Cookies and Similar Technologies
We use only essential cookies that are strictly necessary to operate the platform:
- Session cookie—keeps you logged in while you use KynStay
- CSRF token—protects against cross-site request forgery attacks
- Remember-me cookie—keeps you signed in between visits (only if you choose this option)
We do not use analytics cookies, advertising cookies, or third-party tracking cookies. We do not use any tools that track your activity across other websites.
5. Who We Share Your Information With
We share your information only with the following parties, and only to the extent necessary:
| Recipient | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing, subscription management, tax calculation | USA |
| ActiveCampaign, LLC (Postmark) | Transactional email delivery | USA |
| Google LLC | OAuth sign-in authentication | USA |
| Apple Inc. | OAuth sign-in authentication | USA |
| Hetzner Online GmbH | Server hosting and infrastructure | Germany (EU) |
| OpenStreetMap / Nominatim | Property address geocoding (address data only, no user identifiers) | Various |
| Functional Collective, Inc. (Sentry) | Error tracking and performance monitoring (no personally identifiable information is sent) | USA |
We also share information in these circumstances:
- Other users: Property details (descriptions, photos, pricing, availability) are visible to guests you invite. Booking details are visible to both the host and guest involved.
- Your host, if you pay by card: A card payment is taken on the host's own Stripe account, which makes that host the merchant of record for your payment — not KynStay. The host therefore sees the transaction in their own Stripe dashboard, including whatever Stripe shows them about it, and they — not we — decide how long they keep it and who else they let see it. Stripe's own privacy notice and your host's own practices govern that copy of the data. If you would rather not have a payment recorded on a host's Stripe account, use one of the host's manual payment methods instead.
- Legal requirements: We may disclose information when required by law, regulation, court order, or governmental request.
- Business transfers: If KynStay is acquired or merged with another company, your information may be transferred as part of that transaction. Where that happens, the acquiring company's privacy policy would apply to your information from the date we post that change here.
We do not sell your personal information. We have never sold personal information, and we have no plans to do so.
6. International Data Transfers
Your data is stored on servers located in Germany (EU), operated by Hetzner Online GmbH. Some of your data is also transferred to service providers in the United States (Stripe, Postmark, Google, and Apple) as described in Section 5.
Where data is transferred outside the European Economic Area (EEA) or the United Kingdom, we rely on the following safeguards:
- EU-US Data Privacy Framework—where the recipient is certified under the framework
- Standard Contractual Clauses (SCCs)—approved by the European Commission
- UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs—for transfers from the UK
You can request further information about the safeguards we use by contacting us at privacy@kynstay.com.
7. How Long We Keep Your Information
| Data type | How long we keep it |
|---|---|
| Account data (name, email, phone, avatar) | Deleted immediately when you delete your account. There is no grace period and no recovery window — deletion is permanent as soon as you confirm it. |
| Property listings and photos | Deleted when you remove the property or delete your account |
| Booking and payment records | Kept while your account is open, and deleted with it. We otherwise keep them for as long as needed to run the booking, resolve disputes about it, and meet our tax and accounting obligations — we do not currently enforce a fixed maximum period. |
| Server and security logs | Kept for as long as needed to investigate security and abuse. We do not currently enforce a fixed maximum period. |
| Stripe webhook events | 2 years, then automatically deleted |
| Invitation records | Kept while the invitation is outstanding and afterwards as a record that it was sent; deleted with the account that sent it. We do not currently enforce a fixed maximum period. |
| In-app notifications | 90 days after you read them, then automatically deleted (unread ones are kept until read or until your account is deleted) |
Where a row above says we do not enforce a fixed maximum period, that is a statement of what our systems do today, not a claim that we keep the data forever by design. We are working to put automatic limits on each of these; until we do, we would rather tell you the criterion we actually apply than publish a period we do not keep to. You can ask us to delete your data at any time — see Section 8.
8. Your Privacy Rights
8.1 Rights for all users
Regardless of where you live, you can:
- Access the personal information we hold about you
- Correct inaccurate information in your account
- Delete your account and associated data
- Export your data in a portable format
8.2 Additional rights for UK and EU residents
Under the UK GDPR and EU GDPR, you also have the right to:
- Restrict processing of your personal information in certain circumstances
- Data portability—receive your data in a structured, commonly used, machine-readable format
- Object to processing based on our legitimate interests
- Withdraw consent at any time where consent is the basis for processing
- Lodge a complaint with a supervisory authority—in the UK, this is the Information Commissioner's Office (ICO)
We will respond to rights requests within one month. If a request is complex, we may extend this by up to two further months, and we will let you know.
8.3 Additional rights for California residents
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the right to:
- Know what personal information we collect, use, and disclose
- Delete personal information we hold about you
- Opt out of the sale or sharing of personal information—we do not sell or share your personal information as defined by the CCPA
- Non-discrimination—we will not treat you differently for exercising your privacy rights
To exercise any of these rights, contact us at privacy@kynstay.com. We may need to verify your identity before processing your request.
9. Children's Privacy
KynStay is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we discover that we have collected information from a person under 18, we will delete their account and data promptly. If you believe a minor has provided us with personal information, please contact us at privacy@kynstay.com.
10. Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of all data in transit using HTTPS/TLS
- Password hashing using bcrypt (we never store plaintext passwords)
- Rate limiting and automatic account lockout after repeated failed login attempts
- No storage of credit card data—all card information is handled by Stripe using PCI-compliant tokenization
- Filtering of sensitive parameters (passwords, tokens, email addresses) from server logs
While we work to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to following industry best practices and promptly addressing any security issues.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we post the updated policy on this page and change the "Last updated" date at the top.
Where a change materially affects your rights, we will say so on this page. Because we do not currently send you an individual notice of changes, please check this page from time to time. Your continued use of KynStay after a change means you accept the updated policy; if you do not agree with a change, you may stop using KynStay and close your account, as described in our Terms of Service.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us:
Email: privacy@kynstay.com
Entity: Tilted Labs LLC, California, USA
UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: ico.org.uk
Phone: +44 0303 123 1113