Skip to main content

Privacy

Privacy policy.

This policy explains what personal data Staylist collects, why we collect it, how long we keep it, and the rights you have over it. It is written to meet GDPR standards and applies to visitors and customers wherever you are.

Last updated 14 August 2026

Who is responsible for your data

Staylist Pty LtdSydney, Australia — is the data controller for the personal data described here. We are an Australian company and we serve hosts internationally, including in the European Economic Area and the United Kingdom.

Privacy contact: contact@staylist.company. Our founder, Paul King, is accountable for privacy questions and answers them personally.

What we collect, why, and on what legal basis

DataWhy we collect itLegal basis
Email address and password hash (account)To create your account, verify your email, sign you in and contact you about your account.Contract — we cannot provide the service without it.
Property details you enter (name, location, sleeps, bedrooms, property type, house rules, tone)To generate a listing pack that matches your place.Contract.
Property photos you uploadTo read your property and generate listing content from what is actually visible.Contract.
Generated listing packs and their historySo you can return to, copy, export and regenerate your packs.Contract.
Generation run records (time, plan, model used, hashed IP for demo runs)To enforce plan quotas and the demo's three-runs-a-day limit, and to debug failures.Legitimate interests — preventing abuse and keeping a free tier viable.
Lead form submissions (email, message, which form)To reply to your enquiry.Consent, given when you submit the form.
Billing data (plan, subscription status, payment identifiers)To charge the correct amount and manage your subscription. Card numbers are handled by our payment processor, never by us.Contract and legal obligation (tax and accounting records).
Aggregate analytics (page views, non-identifying id)To understand which pages help hosts.Consent — off unless you accept analytics cookies.
Security and error logsTo keep accounts safe and fix breakages.Legitimate interests — service security and reliability.

How your photos are processed

When you generate a listing pack, the photos you upload are sent to OpenAI's API, where a vision-capable model reads them and returns the listing text. This is the core of the service — without sending the photos there is nothing to describe.

We do not use your photos to train our own models, and we do not have any models of our own to train. We use OpenAI's API under terms where submitted content is not used to train their models. Photos are not sold, licensed, or shared with any other third party, and no human at Staylist browses your library for any purpose other than a support request you have asked us to look into.

Your photos stay yours. They are stored in private storage scoped to your account, and you can delete a property — and its photos — at any time from your dashboard.

Who else processes your data

We keep the list short and each provider is a processor acting on our instructions: OpenAI (listing generation from photos and basics), our cloud database, authentication and file storage provider, our application hosting and content delivery provider, our payment processor for paid plans, and our email delivery provider for verification and account email.

How long we keep things

DataRetention
Account recordFor as long as your account exists, then deleted within 30 days of account deletion.
Property photosUntil you delete the property or your account, then removed from storage within 30 days.
Generated listing packsUntil you delete them or your account; deleted with the account within 30 days.
Generation run records12 months, then deleted. Demo runs keep only a hashed IP, never the address itself.
Lead form submissions24 months after our last exchange, then deleted.
Billing and invoice records7 years, as Australian tax and accounting law requires.
Security and error logs90 days.
Analytics records14 months.

Your rights

Wherever you live, you can ask us to: give you a copy of your data (access), fix data that is wrong (correction), delete your data (deletion), send you your data in a portable machine-readable format (portability), restrict how we use it, or object to processing we base on legitimate interests. Where processing relies on consent, you can withdraw it at any time — including cookie consent, via the cookie policy page.

Email contact@staylist.company and we will respond within 30 days. We never charge for a request and never require a form or a phone call. You can also delete your account yourself in settings. We do not make automated decisions with legal effects about you, and we do not sell personal data.

Security

Data is encrypted in transit (TLS) and at rest. Photos live in private buckets that are not publicly listable; access is row-level-scoped so one account cannot read another's properties, packs or files. Passwords are salted and hashed by our authentication provider. Server-side keys — including our OpenAI key — are stored as secrets and never shipped to the browser. Access to production data is limited to the people who need it and protected by multi-factor authentication. If a breach ever affects your data, we will notify you and the relevant regulator without undue delay and, where the law requires it, within 72 hours.

International transfers

We are based in Australia and our providers operate in Australia, the European Union and the United States, so your data crosses borders. For transfers of EEA or UK data outside those regions we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) in our contracts with each provider, together with encryption in transit and at rest. Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle your data consistently with the Privacy Act 1988.

Children

Staylist is a tool for property hosts and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe we have, email us and we will delete it.

Complaints

Please raise it with us first at contact@staylist.company — most things are a misunderstanding we can fix quickly.

If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC), the regulator for the Privacy Act 1988, at oaic.gov.au.

If you are in the EEA, you may instead complain to the data protection supervisory authority of the country where you live or work — the list is maintained at edpb.europa.eu. UK visitors can complain to the Information Commissioner's Office.

Changes to this policy

If we change how we handle data we will update this page and the date at the top, and for material changes we will email account holders before the change takes effect.

Staylist Pty Ltd · Sydney, Australia · contact@staylist.company · © 2026

Footnote: these pages are plain-language templates written for Staylist, not legal advice. If your situation is unusual — a specific regulator, a large portfolio, an enterprise contract — have a qualified lawyer in your jurisdiction review them.