Privacy policy
Effective 7 September 2026. Auro MGT LLC, Miami, Florida, operates HoztSync.
What we collect
Account data: your email address and name, and the role you hold in an organisation. We sign you in with one-time codes, so we store no passwords.
Operational data entered by the Customer: properties, reservations, guest names and contact details the Customer enters, calendar feeds, forwarded booking emails, financial records, tasks, photos, messages and files.
Technical data: IP address, browser, and timestamps in server logs, kept for security and debugging for up to 30 days. Consent records for services a guest orders include the time and IP address of acceptance.
How we use it
To provide the Service to the Customer and the people the Customer gives access to; to send the emails and notifications the Service exists to send (sign-in codes, invitations, statements, approval requests, alerts); to reconcile financial records; and to keep the Service secure. We read forwarded booking emails with an automated language model to extract booking facts; those emails are stored for the Customer's records and are not used to train models.
Who sees it
Within an organisation, administrators see everything; owners see only their properties' calendars, money and approvals; staff see tasks and stays without financial amounts; guests see only their own stays. Every table is protected by row-level security enforced in the database.
We share data only with the providers that run the Service under contract: Supabase (database and storage, United States), Vercel (hosting), Resend (email), Stripe (payments; card details never touch our servers), and Anthropic (automated reading of booking emails). We do not sell data.
Your choices
You can edit your name and see your access from the Account page. Guests can ask the host, or us, to remove their profile. Customers can export and delete their organisation's data. Write to privacy@hoztsync.com for any request; we answer within 30 days.
Retention and security
Data is kept while the Customer's account is active and for 30 days after cancellation, then deleted, except records required by law. Data is encrypted in transit and at rest. Access by our staff is limited to what support requires and is logged.
Children
The Service is for adults managing or staying at properties. We do not knowingly collect data from children under 13.
Changes
We will post changes here and, for material ones, email Customers 30 days ahead.