Privacy

Last updated: 3 September 2026 · Effective: 3 September 2026

The short version

1. Who we are

StayBotic Ltd ("we", "us", "StayBotic") is the data controller for personal data collected through staybotic.com. Registered in England & Wales, company number 17137953, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Contact: privacy@staybotic.com.

2. What we collect

From your conversations: the messages you send the concierge, the destinations you ask about, dates, group size, budget, and any preferences you mention (vibes, dietary needs, accessibility, occasion context).

If you forward us a trip request (Business and Executive): the content of the email you forward, including the sender, subject and message body, so we can work out the trip. Forwarded mail may name people other than you, such as the traveller or the person who wrote the original request. We use it only to produce the recommendation and the trip record, we do not use it to build profiles of anyone who has not signed up, and you should not forward anything you would not want us to process.

When you create an account: name and email (handled by Clerk), saved trips, bookings, payment confirmations.

Device + connection: IP address (used for rate limiting and approximate location only, never stored alongside your messages), browser type, timezone.

Geolocation: only if you grant browser permission. Used to suggest stays near you. We never log precise coordinates.

What we don't collect: we don't track you across other sites. We don't run advertising cookies. We don't sell mailing lists.

3. How we use it

We do not use your conversations to train external AI models. AI prompts are sent to OpenAI for reply generation only. Under their API data policy, this data is not used to train their models.

4. Who we share with

We use a small set of trusted processors to operate the platform:

We don't share data with anyone else. We don't sell data. Ever.

5. How long we keep it

6. Your rights

You can:

Email privacy@staybotic.com with your request. We respond within 30 days.

7. The StayBotic add-on for Gmail and Google Calendar

This section covers the "Plan this with StayBotic" Google Workspace add-on. It is written to be read on its own, because Google requires it and because anyone installing an add-on that sits beside their inbox deserves a plain answer about what it can see.

What it can access: the single message or calendar event you have open at the moment you click the StayBotic icon, and nothing else. We deliberately request only the per-message and per-event scopes:

What it cannot access: your mailbox. We do not request gmail.readonly or any other mailbox-wide scope, so the add-on cannot search, list or read any message you have not opened it on. It cannot read your inbox in the background, and it stops having access the moment you close the panel.

What we do with it: the message or event text is sent to our servers over HTTPS, and to our AI provider, to extract the trip, meaning the destination, dates, party size, budget and the venue that matters, and to produce one recommendation. That is the only purpose.

What we do not do with it: we do not use Google user data to train or improve any AI model, ours or anyone else's. We do not sell it, transfer it for advertising, or use it to build a profile. No human at StayBotic reads it, except where you have explicitly asked us to look at a specific trip, or where the law requires it, or where it is strictly necessary to investigate a security incident or abuse.

How long we keep it: the extracted brief, meaning the destination, dates and party size, is kept with your trip so you can come back to it. The raw message body is held only for the length of the request and is not written to our database. Ask us to delete a trip and the brief goes with it.

Limited Use. StayBotic's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can remove the add-on's access at any time from your Google account permissions page, independently of your StayBotic account.

8. Cookies

We use only essential cookies (session, auth, CSRF). No advertising cookies, no third-party trackers. Geolocation is opt-in via the browser permission prompt, never via a cookie. See our cookie page for the full list.

9. Security

All connections are HTTPS. Passwords are managed by Clerk and never stored by us. Payment data is tokenised by Stripe. We never see card numbers. Server logs are scrubbed of emails, phone numbers, and other obvious identifiers before storage.

10. International transfers

Some processors (Stripe, OpenAI, Clerk) are based in the US. Transfers rely on Standard Contractual Clauses or equivalent legal frameworks. Your data is encrypted in transit and at rest.

11. Children

StayBotic is not intended for users under 16. We don't knowingly collect data from anyone under 16. If you believe a child has used the service, email privacy@staybotic.com and we'll remove their data.

12. Complaints

If you're unhappy with how we handle your data, you can complain to:

13. Changes

If we change this policy, we'll post the new version here and notify users by email if the change is significant. Continued use after a change means you accept the update.

StayBotic Ltd, registered in England & Wales, Company number 17137953. This policy is effective as of 28 August 2026. Questions: privacy@staybotic.com.