TapStay

Privacy Policy

How TapStay handles Host information, Guest Portal operational data and optional Guest analytics.

Last updated: September 6, 2026 · Version 2026-09-06

For product access controls and platform protections, see Security at TapStay.

1. Who operates TapStay

TapStay is operated by Eyal Hayout, an individual operator based in Israel.

You can reach the operator at contact@tapstay.app.

Privacy questions are handled directly by the operator at the contact address above.

2. Scope

This Policy explains what information TapStay handles when a Host uses the TapStay application and when a Guest opens a property's Guest Portal.

It does not cover the practices of the properties themselves, of listing platforms, or of third-party websites and services you reach from TapStay.

3. Information Hosts provide

To create and run a Host account and a Guest Portal, TapStay handles information such as:

  • account email and authentication identity (email/password, Google or Apple sign-in)
  • profile information you choose to add
  • property information and content: property name and type, full property address, media, welcome videos
  • check-in and check-out information, house rules, checkout instructions, FAQ and custom sections
  • Host contact phone where supplied
  • listing platform and listing URL where supplied
  • Wi-Fi network name (SSID) and Wi-Fi password where supplied
  • reservation and stay records you create
  • plaque-order information, including shipping information where applicable
  • Trial and Early Pilot entitlement records

Account information, property information and property address are required to provide the service — without them a Guest Portal cannot be created or resolved. Optional fields (for example welcome video, FAQ, contact phone, Wi-Fi) are voluntary: if you do not provide them, the related section simply does not appear to Guests, and the rest of the service continues to work.

TapStay does not collect payment card details. No payment provider is active today.

4. Guest Portal operational data

When a Guest taps the plaque or scans the QR code, TapStay performs the operations necessary to show the Portal:

  • resolving the permanent property Guest Portal URL
  • short-lived operational access and session handling, resolved on the server
  • checkout-completion records when a Guest reports checkout
  • browser/device sessionStorage used to keep a Concierge conversation continuous during the visit

The permanent plaque, QR code and slug identify the property. They do not permanently identify a Guest or a reservation.

These necessary operations are not analytics, and the Guest Portal does not require analytics consent in order to work.

5. Optional analytics

Optional analytics are switched OFF unless a Guest chooses “Allow analytics”. A Guest may instead choose “Continue without analytics”, which keeps analytics off and is remembered for 180 days before the choice can be offered again, or “Not now”, which dismisses the prompt for the current browser session only.

Core Guest Portal functionality remains available without optional analytics. A Guest can also delete the analytics collected during the current visit; deleting also switches optional analytics off.

TapStay does not extrapolate or estimate analytics for Guests who do not consent, and does not measure all Guests.

When optional analytics is allowed, TapStay may measure:

  • an analytics session
  • page views and Portal interactions
  • section impressions and actions
  • Around You category use
  • rendering of place recommendation lists and qualifying place impressions
  • Google Maps actions, Website actions and Call actions

A measured action is an interaction only. It is not proof of a purchase, booking, sale, conversion or revenue. Internal QA traffic and suspected bot traffic may be excluded from internal reporting.

6. Location

Guest location is used only when the Guest asks for it. It requires both TapStay's own location permission screen and the browser/device permission.

If the Guest grants permission, the coordinates may be used ephemerally within the server request that ranks nearby places. Guest coordinates are not persisted as Guest-location analytics, and TapStay does not keep a history of Guest GPS positions.

To return nearby results, TapStay's server may send the coordinates and the relevant search context (for example the category being browsed and a search radius) to Google Maps / Places. Wi-Fi credentials are never sent to Google.

Property-level city and country, and structural place identity, may be retained.

7. Around You and Google services

TapStay uses Google services for functionality such as Around You, nearby discovery, Maps and place functionality, and property address autocomplete, geocoding and timezone resolution where applicable.

Structural place information that TapStay may retain includes:

  • Google Place ID
  • the place category (for example restaurant, café or pharmacy)
  • city and country

Business display information such as names, ratings, website addresses, phone numbers, formatted addresses and photos is resolved live when needed rather than kept as a permanent internal record for reporting.

8. AI Concierge

The TapStay Concierge uses an AI service provider. The current provider is OpenAI. It is used to produce Concierge responses and, where applicable, phrasing for nearby places.

What may be sent to the provider for a Concierge request:

  • a redacted stay fact sheet
  • the Guest's question
  • limited recent chat context

TapStay minimizes and redacts information before sending it, and specifically excludes sensitive operational credentials such as Wi-Fi. Because Guests type free text, a message may still contain personal information — so TapStay does not claim that the provider receives no personal data. Please avoid typing sensitive personal details into the Concierge.

TapStay makes no claim here about provider-level training, retention duration or special data-control settings.

9. Internal Intelligence and Anthropic

TapStay produces an internal Intelligence report for the operator. Anthropic (Claude) is used to interpret that report.

Claude receives only TapStay's privacy-allowlisted aggregate Intelligence Snapshot. The data sent to Anthropic is designed and validated by TapStay to exclude Guest identifiers, Host identifiers, property identifiers, session identifiers, exact property coordinates, raw Concierge messages, Wi-Fi credentials and tokens.

The full Intelligence Snapshot and the generated report are not stored in the database. Only operational run and delivery telemetry is stored.

TapStay makes no claim here about Anthropic provider-level training or retention settings.

10. Wi-Fi credentials

Hosts may store a Wi-Fi network name (SSID) and Wi-Fi password for their property. TapStay stores them because the product needs to display them.

They are shown only to eligible Guests according to the current stay access rules, and they are not sent to OpenAI.

11. How information is used

TapStay uses information to:

  • create and secure Host accounts
  • build, host and display Guest Portals
  • resolve stay access and checkout completion
  • provide Around You and Concierge features
  • send authentication and transactional email
  • operate Trial and Early Pilot entitlements
  • keep the service secure and prevent abuse
  • produce aggregate internal measurement where a Guest allowed optional analytics
  • measure public marketing and Host site traffic, and advertising performance, only where a visitor allowed the matching optional marketing choice

12. Service providers

TapStay relies on the following categories of providers:

  • Lovable / Lovable Cloud and Supabase — hosting, application infrastructure, database, authentication, storage and deployment, and Lovable's own visitor/project analytics telemetry (page hits) for the hosted site
  • Google Maps / Places — maps, nearby discovery, address autocomplete, geocoding and timezone
  • OpenAI — the AI Concierge
  • Anthropic — interpretation of the internal aggregate Intelligence Snapshot
  • Lovable Emails on notify.tapstay.app — authentication and transactional email
  • Resend on reports.tapstay.app — delivery of TapStay Intelligence report emails and PDF attachments
  • Google Analytics — optional traffic, page and event measurement data from the public marketing and Host site, only after Analytics is allowed in the marketing privacy choices; TapStay does not send its own account identifiers to Google Analytics
  • Meta — optional advertising measurement (the Meta Pixel) on the public marketing and Host site, only after Advertising measurement is allowed in the marketing privacy choices

Lovable Emails remains the provider for authentication and transactional email. Resend is used only for the delivery of TapStay Intelligence report emails and their PDF attachments. No payment provider is used, because no payment is processed today. If an additional email or payment provider becomes active, this Policy will be updated accordingly. Lovable's visitor/project analytics telemetry is platform telemetry that runs as part of the hosting platform; it is separate from Google Analytics and Meta, and it is not controlled by the marketing privacy choices. TapStay does not claim here that any specific retention, training or transfer arrangement with these providers has been verified.

13. International processing

TapStay uses international technology providers, so information may be processed outside Israel depending on provider infrastructure. TapStay does not claim here that any specific international-transfer legal mechanism has been signed or verified.

14. Retention

Retention is enforced by an automated retention engine. Current rules:

  • operational sessions: deleted 7 days after expiry or revocation
  • raw optional analytics: 180 days
  • checkout completions: 730 days
  • property stay history: 730 days
  • plaque shipping personal information: minimized 180 days after the plaque order is closed

Trial and Early Pilot entitlement records, and the current mock billing records, are kept for as long as the Host account exists and are removed when the account is deleted.

Place identifiers and privacy-minimized aggregate measurement — which contain no Guest, session or property identifiers, in line with the exclusions described in the Internal Intelligence section — may be kept for longer for statistical and business measurement.

15. Backups

The infrastructure provider takes automatic daily snapshots with an approximately 14-day rolling window; snapshots expire automatically. Selective deletion of a single person's data from an individual backup snapshot is not supported.

This means that after live deletion, information may remain recoverable in provider-managed backup snapshots for a limited period until those snapshots expire.

16. Security

TapStay applies controls such as:

  • access controls and row-level security in the database
  • server-only secrets
  • data minimization and redaction before AI requests
  • automated retention
  • automated privacy validation of internal reporting
  • separation between necessary operational data and optional analytics

No system can guarantee absolute security, and TapStay does not claim that it can.

17. Data export and account deletion

Hosts can download a copy of their data from the account area at any time.

Hosts can also request account deletion. Deletion has a 7-day safety window and can be cancelled during that window. After the window, TapStay deletes the authentication user and the owned live data according to the implemented workflow, subject to the limited backup persistence described above and to other valid retention requirements.

18. Privacy rights

You may contact contact@tapstay.app to exercise applicable privacy rights.

Under Israeli privacy law you may request access to personal information held about you, and you may request correction where information is inaccurate, incomplete, unclear or out of date.

Some categories of information may need to be retained for legal, security or operational reasons, so a request to delete cannot be guaranteed for every category in every situation.

19. Choices and consent

Guests control optional analytics from the privacy screen inside the Guest Portal, and can change that choice at any time.

A Host's acknowledgement of this Privacy Policy at signup is a separate matter from a Guest's optional analytics consent; the two are recorded and managed separately.

On the public marketing and Host site, a privacy banner offers “Accept all”, “Reject optional” and “Manage choices”. Analytics (Google Analytics) and Advertising measurement (the Meta Pixel) stay off unless the matching choice is allowed, and the choices can be reopened at any time from the Privacy page. Lovable's visitor/project analytics telemetry is part of the hosting platform and is not controlled by this banner.

These marketing-site choices are a separate system from the Guest Portal's optional analytics consent. Allowing or rejecting one has no effect on the other.

TapStay uses only the browser storage the service needs: sessionStorage in the Guest Portal to keep a Concierge conversation continuous during a visit and to remember a “Not now” privacy choice for the current browser session, local browser storage to remember a “Continue without analytics” choice and Host draft content such as the property wizard, the sign-in session storage used by the authentication provider to keep a Host signed in, local browser storage for the marketing privacy choices (key “tapstay:marketing-consent:v1”, holding only the choices made and the date and version of the decision — no name, email or identifier), and a temporary local marker tied to the account identifier, used only to avoid counting the same signup twice in measurement, kept for up to 48 hours in the browser and never sent to the analytics or advertising providers.

20. Changes to this Policy

TapStay may update this Policy. Each version carries a version number and a last-updated date. Material updates may require renewed acceptance, and earlier acceptance records are preserved unchanged.

21. Contact

Eyal Hayout — contact@tapstay.app