Legal
Privacy notice
Using this site means telling us something about your health. That deserves a plain account of where it goes, so this notice leads with that rather than with cookies.
The short version of the part that matters
What you tell us you react to is visible to you, and to a host only on a stay where you ticked the box to share it. It is never in a search result, never in an analytics table, never in public copy, and never sold or given to an advertiser. The same is true of anything you write in a review about having had a reaction, and of the contents of your messages.
What we hold
- Your account. Name, email address, and optionally a phone number and a short bio. Your password is stored only as a bcrypt hash; nobody here can read it.
- Your sensitivity profile. The triggers you selected, an optional severity, and any notes you wrote. This is health information and it is treated as such throughout — see below.
- Stays. Bookings, the price breakdown as it was agreed, payments and refunds, cancellations and their reasons.
- What you wrote. Messages to hosts, reviews, guarantee claims, support requests.
- Use of the site. Which listings were viewed and which searches returned nothing. Searches that return nothing are how we decide which hosts to go and recruit, so an empty search is not wasted.
Health information, specifically
Four fields in this system are health-adjacent, and all four are fenced:
- your sensitivity profile;
- whether a review recorded that you had a reaction, and its note;
- the bodies of your messages;
- what you wrote on a Clear Air Guarantee claim.
These are visible to you; to the counterparty on a booking where sharing was agreed; and to an administrator during a dispute or a claim, because a claim cannot be reviewed without reading it. They do not appear in search results, in any analytics aggregate, or in public listing copy — that is a rule the queries enforce, not a policy we intend to follow.
When you share your profile with a host, they see the list of triggers and nothing else: not your notes, not your severity, not your history on other stays.
What we use it for
- Ranking what you see. Your triggers are scored against the amenities each host declared, so results are ordered by how well a property matches you specifically. This happens on our server, for you, and produces no record anyone else can read.
- Running a stay. Taking payment, telling your host what they need to host you, refunding you.
- Keeping the standard honest. Guarantee claims and reports are read by someone here so a listing can be corrected or taken down.
- Measuring the marketplace. Which property attributes affect price and occupancy, computed over listings — never over people, and never using anything from the four fields above.
Who else sees it
- Your host, on a stay you booked: your name, dates, party size, any message you sent, and your triggers only if you shared them.
- Payment processing. Card details are handled by the payment provider and never stored on our servers; we keep the last four digits and the brand so you can tell your cards apart.
- Identity verification, for hosts only, through a provider that checks a government document. Guests are never asked for one.
- Nobody else. We do not sell personal information and we do not share it with advertisers.
Email and messages
Mail about a stay you are on — a confirmation, a cancellation, a refund, a password reset — is transactional and cannot be switched off by a preference, because a guest who muted email and then arrives at a cancelled booking has been failed by us rather than by their own settings. Everything else is a preference you control on your account page, and every message carries a one-click unsubscribe that suppresses the address entirely.
The body of a message from a host is never put in the notification email — only that one arrived. Message bodies are health-adjacent under our own rules and mail is not a confidential channel.
How long we keep it
Bookings, payments and refunds are kept as long as we are required to keep financial records. Your profile and sensitivity profile are kept until you delete them or the account. Sessions expire after 30 days, and every one of them ends the moment you reset your password.
Your control over it
- Change or clear your sensitivity profile at any time from your account. Clearing it stops it being used for ranking, immediately.
- Stop sharing with hosts by unticking the box; it applies to future bookings, since a host you already told cannot unlearn it.
- Sign out everywhere from your account page, in one action.
- Ask for a copy, or for deletion, through help and support. Where a record has to be kept for financial reasons we will say which and why rather than refusing in general terms.
Cookies
One cookie, cas_session. It holds an opaque session token, it is httpOnly so no script can read it, and it exists to keep you signed in. There is no advertising cookie and no third-party tracker on this site.