Information we collect
Booking information can include first and last name, email address, phone number, stay dates, guest count, reservation records, payment status, and processor transaction references. We do not store raw credit or debit card numbers or CVV. Configured processors, including Braintree and/or Stripe, process or tokenize card information.
Guest-portal and check-in information can include guest-access tokens, ETA, occupancy details, house-rule and agreement acknowledgements, and private arrival details such as door-code, Wi-Fi, parking, and check-in instructions. Those private details are encrypted at rest and released only through valid time-limited guest access. Optional identification upload is not part of the current booking flow and would only be collected if separately enabled.
How information is used
We use information to review availability requests, communicate about a possible or confirmed stay, provide guest access when enabled, fulfill check-in and cleaning operations, prevent fraud or abuse, maintain security and audit records, and meet applicable legal or accounting obligations. An availability request is not a reservation and does not activate payment.
Calendar synchronization uses configured external calendar URLs as a read-only advisory source. The weather feature requests forecast information from the weather service. The Local Guide may link to third-party locations but does not create advertising profiles.
Service providers and automation
Depending on configuration, providers may include Hostinger for hosting and email, Supabase/Postgres for data storage, Clerk for owner authentication, Telegram for private host notifications, calendar providers, and payment processors for future enabled payment flows. Host operational automation may run through protected scheduled endpoints.
The host AI Draft control is designed to create text for owner review only. No external host-draft AI provider is currently configured by the application, so inquiry content is not transmitted externally for that feature. If an external provider is configured in the future, this policy should be updated before guest content is transmitted. Drafts remain stored with the inquiry until sent, replaced, or cancelled; sending always requires a separate owner action.
Retention and privacy choices
Information is retained while needed for inquiry handling, stay operations, security, dispute resolution, and applicable accounting or legal obligations. Retention settings and privacy requests are owner-reviewed; deletion is not automatic. You may request access, correction, or deletion through the Privacy Choices page. We may need to verify the request and may retain information where required or reasonably necessary.
Shell By The Shore does not sell personal information. The site does not currently use advertising profiling cookies. Essential authentication and security technologies may be used where needed.
Contact
Questions and privacy requests may be sent to stay@shellbytheshore.com.
