Privacy
Privacy policy.
This policy explains what personal data Staylist collects, why we collect it, how long we keep it, and the rights you have over it. It is written to meet GDPR standards and applies to visitors and customers wherever you are.
Last updated 14 August 2026
Who is responsible for your data
Staylist Pty Ltd — Sydney, Australia — is the data controller for the personal data described here. We are an Australian company and we serve hosts internationally, including in the European Economic Area and the United Kingdom.
Privacy contact: contact@staylist.company. Our founder, Paul King, is accountable for privacy questions and answers them personally.
What we collect, why, and on what legal basis
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address and password hash (account) | To create your account, verify your email, sign you in and contact you about your account. | Contract — we cannot provide the service without it. |
| Property details you enter (name, location, sleeps, bedrooms, property type, house rules, tone) | To generate a listing pack that matches your place. | Contract. |
| Property photos you upload | To read your property and generate listing content from what is actually visible. | Contract. |
| Generated listing packs and their history | So you can return to, copy, export and regenerate your packs. | Contract. |
| Generation run records (time, plan, model used, hashed IP for demo runs) | To enforce plan quotas and the demo's three-runs-a-day limit, and to debug failures. | Legitimate interests — preventing abuse and keeping a free tier viable. |
| Lead form submissions (email, message, which form) | To reply to your enquiry. | Consent, given when you submit the form. |
| Billing data (plan, subscription status, payment identifiers) | To charge the correct amount and manage your subscription. Card numbers are handled by our payment processor, never by us. | Contract and legal obligation (tax and accounting records). |
| Aggregate analytics (page views, non-identifying id) | To understand which pages help hosts. | Consent — off unless you accept analytics cookies. |
| Security and error logs | To keep accounts safe and fix breakages. | Legitimate interests — service security and reliability. |
How your photos are processed
When you generate a listing pack, the photos you upload are sent to OpenAI's API, where a vision-capable model reads them and returns the listing text. This is the core of the service — without sending the photos there is nothing to describe.
We do not use your photos to train our own models, and we do not have any models of our own to train. We use OpenAI's API under terms where submitted content is not used to train their models. Photos are not sold, licensed, or shared with any other third party, and no human at Staylist browses your library for any purpose other than a support request you have asked us to look into.
Your photos stay yours. They are stored in private storage scoped to your account, and you can delete a property — and its photos — at any time from your dashboard.
Who else processes your data
We keep the list short and each provider is a processor acting on our instructions: OpenAI (listing generation from photos and basics), our cloud database, authentication and file storage provider, our application hosting and content delivery provider, our payment processor for paid plans, and our email delivery provider for verification and account email.
How long we keep things
| Data | Retention |
|---|---|
| Account record | For as long as your account exists, then deleted within 30 days of account deletion. |
| Property photos | Until you delete the property or your account, then removed from storage within 30 days. |
| Generated listing packs | Until you delete them or your account; deleted with the account within 30 days. |
| Generation run records | 12 months, then deleted. Demo runs keep only a hashed IP, never the address itself. |
| Lead form submissions | 24 months after our last exchange, then deleted. |
| Billing and invoice records | 7 years, as Australian tax and accounting law requires. |
| Security and error logs | 90 days. |
| Analytics records | 14 months. |
Your rights
Wherever you live, you can ask us to: give you a copy of your data (access), fix data that is wrong (correction), delete your data (deletion), send you your data in a portable machine-readable format (portability), restrict how we use it, or object to processing we base on legitimate interests. Where processing relies on consent, you can withdraw it at any time — including cookie consent, via the cookie policy page.
Email contact@staylist.company and we will respond within 30 days. We never charge for a request and never require a form or a phone call. You can also delete your account yourself in settings. We do not make automated decisions with legal effects about you, and we do not sell personal data.
Security
Data is encrypted in transit (TLS) and at rest. Photos live in private buckets that are not publicly listable; access is row-level-scoped so one account cannot read another's properties, packs or files. Passwords are salted and hashed by our authentication provider. Server-side keys — including our OpenAI key — are stored as secrets and never shipped to the browser. Access to production data is limited to the people who need it and protected by multi-factor authentication. If a breach ever affects your data, we will notify you and the relevant regulator without undue delay and, where the law requires it, within 72 hours.
International transfers
We are based in Australia and our providers operate in Australia, the European Union and the United States, so your data crosses borders. For transfers of EEA or UK data outside those regions we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) in our contracts with each provider, together with encryption in transit and at rest. Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle your data consistently with the Privacy Act 1988.
Children
Staylist is a tool for property hosts and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe we have, email us and we will delete it.
Complaints
Please raise it with us first at contact@staylist.company — most things are a misunderstanding we can fix quickly.
If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC), the regulator for the Privacy Act 1988, at oaic.gov.au.
If you are in the EEA, you may instead complain to the data protection supervisory authority of the country where you live or work — the list is maintained at edpb.europa.eu. UK visitors can complain to the Information Commissioner's Office.
Changes to this policy
If we change how we handle data we will update this page and the date at the top, and for material changes we will email account holders before the change takes effect.
Staylist Pty Ltd · Sydney, Australia · contact@staylist.company · © 2026
Footnote: these pages are plain-language templates written for Staylist, not legal advice. If your situation is unusual — a specific regulator, a large portfolio, an enterprise contract — have a qualified lawyer in your jurisdiction review them.