Staging: test data only, nothing here is real.
DRAFT — not legal advice. This was generated from the app’s actual data practices as a starting point and has not been reviewed by an attorney. Review and finalize it with counsel before relying on it. Bracketed items like [LEGAL ENTITY] are placeholders to fill in.

Privacy Policy

Last updated: [EFFECTIVE DATE]

This policy explains what StayLane (“we,” “us”) collects, why, who we share it with, how long we keep it, and the choices you have. StayLane is operated by [LEGAL ENTITY — e.g., StayLane, Inc.].

1. The short version

StayLane helps engaged couples and event hosts arrange hotel room blocks with hotel sales teams. To do that we collect the details you give us about your event and your contact information. We use a small set of trusted service providers to run the product. We do not sell personal data. You can ask us to access or delete your data at any time using the contact below.

2. Who this policy covers

  • Couples / hosts — the account holder who plans the event.
  • Hotel staff / partners — sales reps who receive and respond to requests.

3. Information we collect

Depending on how you use StayLane, we collect:

  • Account & identity — name, email, phone, and (for contracting) legal name and mailing address.
  • Event details — event name and dates, venue and location, guest count, room needs, budget, and hotel preferences.
  • Hotel-contact details — names, emails, phones, and roles of hotel sales staff, and signer details on contracts.
  • Deal records — requests for proposals, hotel proposals, messages between parties, and contract documents.
  • Communications — emails we send on your behalf or to you, including their recipients and contents.
  • Technical data — log and security data such as timestamps, rate-limiting identifiers, access tokens/links, and error diagnostics.

4. How we collect it

  • Directly from you — at sign-up, during intake, and as you use the dashboard.
  • From hosts — who enter event and venue information.
  • From hotels — who submit proposals and contract terms.
  • Automatically — basic technical and security data generated as you use the service.

5. How we use it

  • Run the service — match you with hotels, send requests for proposals, and generate and route contracts.
  • Communicate — send transactional emails (proposals, signing links, confirmations, reminders) and respond to support requests.
  • Keep it working and safe — debugging, fraud and abuse prevention, rate limiting, and security.
  • Improve the product and meet legal obligations.

We do not sell your personal data, and we do not use it for third-party advertising.

6. Legal bases (where applicable)

Where data-protection law (such as the GDPR) applies, we process personal data to perform our contract with you, for our legitimate interests in operating and securing the service, with your consent where required, and to comply with legal obligations. [Confirm the applicable bases and jurisdictions with counsel.]

7. Automated processing & AI

Some of our processing uses a third-party AI provider (Anthropic): reading the replies hotels send to a request for proposals, summarizing hotel reviews, and enriching hotel listings. The content of those hotel replies and listings is sent to that provider. Your intake answers are not — the intake is a form we process ourselves. We do notsend your guests’ personal details to the AI provider. The provider processes this data on our behalf and retains it only for a limited period (currently around 30 days) for trust-and-safety purposes. AI output is assistive and may be imperfect — always review terms before signing.

8. Service providers we share data with

We share data with a small set of processors that run the product on our behalf. They may only use it to provide their service to us:

  • Supabase — database, authentication, and file storage (all stored data).
  • Resend — sending transactional email (recipient addresses and message contents). Note: once an email is sent, it cannot be recalled from a recipient’s inbox.
  • Anthropic — reading hotel replies and enriching hotel listings (see section 7).
  • Google (Places) — venue and hotel lookup/geocoding (venue and location text; no guest names).
  • Error monitoring — diagnostics for reliability; may incidentally include identifiers present in an error.
  • Railway — application hosting/infrastructure.

We may also disclose data to comply with law, enforce our terms, or protect rights, safety, and security; and we may transfer data as part of a merger, acquisition, or sale of assets. [Add or remove processors here as the stack changes, and confirm data-processing agreements are in place with counsel.]

9. How long we keep it

We keep personal data for as long as your account is active and as needed to provide the service, resolve disputes, and meet legal obligations, after which we delete or anonymize it. Because guest data is the most sensitive and is not tied to a guest account, we aim to keep it only as long as needed to arrange the block. [Set specific retention periods with counsel — e.g., delete event/guest data X months after the event; purge old email logs on a schedule.] You can request earlier deletion at any time (section 10).

10. Your rights & choices

Depending on where you live, you may have the right to access, correct, delete, export, or object to/restrict the processing of your personal data, and to withdraw consent. To exercise any of these, contact us at [PRIVACY CONTACT — e.g., privacy@staylaneblocks.com]. We will verify your request and respond within the time required by applicable law. We will not discriminate against you for exercising these rights.

Deletion / erasure:on a verified request we permanently delete the account and its associated data — events, requests, proposals, contracts, and contract files. Guests’ data is deleted as part of the host’s event or account deletion.

11. Limits of deletion

Some data is held by the providers in section 8 and cannot be fully retrieved by us: emails already delivered cannot be un-sent (Resend); the AI provider holds its own short-term copy (Anthropic); and venue lookups were processed by Google. Where a provider supports it, we will pass along a deletion request. We may also retain limited records where the law requires (for example, certain transaction records).

12. Security

We protect data with encryption in transit, access controls, and role-based restrictions, and we limit access to the people who need it. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. [Describe additional safeguards and any breach-notification commitments with counsel.]

13. Cookies, sessions & links

We use cookies and similar technologies that are necessary to sign you in and keep you signed in. We also use unguessable links and codes (for example, magic sign-in links and hotel response links) to let you access the right information without an account. [If any non-essential/analytics cookies are added, disclose them and add a consent mechanism where required.]

14. Children

StayLane is intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact [PRIVACY CONTACT — e.g., privacy@staylaneblocks.com] and we will delete it.

15. International users

We operate from the United States, and data we process may be stored and processed there or in other countries where our providers operate. [If you serve EU/UK users, add the relevant transfer mechanism and representative details with counsel.]

16. Changes to this policy

We may update this policy from time to time. We will revise the “last updated” date above and, for material changes, take additional steps where required by law.

17. Contact

Questions or requests: [PRIVACY CONTACT — e.g., privacy@staylaneblocks.com] ([LEGAL ENTITY — e.g., StayLane, Inc.]). See also our Terms of Service.