← tabellara.com

Privacy Policy

Effective September 16, 2026

Tabellara LLC (“Tabellara”, “we”, “us”) provides digital guest guidebooks, in-property displays, and related analytics for short-term rental hosts. This policy explains what we collect and how we use it, both for hosts with accounts and for guests who view a host’s guide. We write it in plain English on purpose; if anything is unclear, ask us.

Who is responsible for what

For your account and billing data, Tabellara is the controller. For guest usage data, for guest details collected through a host’s WiFi sign-in page, and for listing and reservation data we receive from a property platform at your request, the host is the controller and we act as the host’s processor on their instructions. Guests with questions about a guide should contact the host first; we will still help where we can.

Information we collect from hosts

When you create an account we collect your name, email address, and a password (stored as a secure hash by our authentication provider; we never see it). You also provide the content of your properties and guides: property names, addresses, WiFi details, check-in and check-out times, door codes, photos, and any text you write. You control this content and can edit or delete it at any time. We keep subscription status and invoice records; card details go directly to Stripe and never touch our servers. We also keep support correspondence you send us. If you connect a property management platform, we store the connection credentials (such as OAuth tokens) encrypted and use them only to operate that integration.

If you use Guest WiFi, you invite our service account as an administrator on your network controller, and we store what the service needs to run it: your controller’s address, site names, access point identifiers (hardware MAC addresses), device models and names, the guest networks you manage through us, and their sign-in page configuration. We access your controller only to operate the service on your instructions, and equipment nobody connects to an account is forgotten from our systems within about a day.

Information we collect from guests

When a guest opens a guide we record usage events: which guide was opened, which pages and cards were tapped, which quick links were used, an anonymous session identifier, the device type, operating system and browser family from the browser’s user agent, an approximate location (city, region, country) derived from the request at the time, and a salted, truncated hash of the IP address; our analytics store only that hash, which cannot be reversed into an address. If the guest arrived by scanning a code on a Tabellara TV, a printed QR frame, or a section or card QR code, the event records which code so the host can see which placements get used. Reading a published guide requires no login and asks for no personal details; placing a Guest Store order does, as described next.

Guest WiFi sign-ins

When a guest signs in to a host’s guest WiFi, the sign-in page collects a first and last name, an email address, a phone number if the host enables that field, and the guest’s marketing-consent choice, and records the exact consent wording the guest agreed to. The page also receives the device’s network identifier (its MAC address), which is how WiFi equipment recognizes a device; we use it to authorize the device on the host’s network for the access period, so the guest is not asked to sign in again on every connection. As with every WiFi network, the host’s own equipment keeps standard connection records while a device is connected.

Sign-in details are collected for the host: they appear in the host’s Contacts and device lists, and the host is the controller of that data, including any marketing email they send, which is governed by their consent choices and applicable law, not by this policy. We use sign-in data only to run the service on the host’s behalf: authorizing the device, opening the guidebook, keeping one contact per guest, and showing the host who is connected. We never use guests’ WiFi sign-in details for our own purposes. To opt out of a host’s marketing, use the unsubscribe mechanism in their emails or contact the host; we will help if you contact us.

One honest technical note: the sign-in page itself is served over unencrypted HTTP on the local network, because the captive-portal software built into phones and laptops widely requires that to show the page automatically; this is standard for WiFi sign-in pages. The details you submit are carried over encrypted connections from our network edge onward, and the guidebook that opens afterwards is served over HTTPS.

Guest Store orders

When a guest buys from a host’s Guest Store, the guest provides a name, an email address, an optional note, and payment details. Card details go directly to Stripe on the host’s own Stripe account and never reach Tabellara; we store the order itself: the items, amounts, status, the name and email (using the details Stripe verified at payment), the note, and, for orders placed through a per-stay link, which reservation and guest contact the order belongs to. The host is the seller in that transaction and an independent controller of the order data, which they see in their dashboard and emails and use to fulfill the sale under their own terms.

We use order data to run the store on the host’s behalf: showing the order to the host, sending the transactional emails both sides expect (order received, approved, declined, expired, refunded, and host reminders), computing the host’s store analytics, and keeping the order as a transaction record. Order records are retained as business records of the sale, including after a guide is unpublished or an item is deleted. Refunds, receipts, and disputes are handled by the host through Stripe; questions about an order or a charge go to the host first.

Tabellara TV screens

A television running Tabellara TV checks in with us about once an hour and holds a connection so changes reach it at once. From the device we collect a device identifier and network address, its make, model, and software version, the list of apps installed on it (so the host can choose which appear as tiles), whether it is on, and a short log of what the app did (updates, resets, errors) for the host’s support view. We do not collect what a guest watches, typed text, or anything from inside other apps. To work without a connection, the device keeps a copy of the host’s guide and of upcoming reservations for that property (guest first name, dates, and the codes that open the guide); that copy is replaced as bookings change and is removed when the screen is unclaimed or reset. Codes shown on the screen are per-stay links, so a scan tells the host which stay and which screen it came from. The app uses the remote’s microphone only while a guest chooses to speak an answer to the stay question; what they say is transcribed on the device and sent to the host as text, and no audio is kept. The house Google account a host signs into the television is the host’s, not ours: we never see its password, and Google’s own privacy policy covers what that account does. When a television is released from a host’s account, whether by the host, at the end of a trial, or at the end of a grace period, the app removes itself and the copy it kept, and the television is a normal Google TV again.

Tours and activities (Viator)

When a host turns on tours nearby, we fetch tours for the area from Viator using the guide’s address, and show them on the host’s screens with a code. We send nothing about the guest to Viator. A guest who scans a code passes through our redirect (which counts the scan for the host’s analytics, with the same details as any other code) and then arrives on viator.com with Tabellara’s affiliate identifier and a code for the property. From there, Viator’s privacy policy and cookies apply, and any booking is made with Viator. Viator later sends Tabellara a booking report so we can pay the host their share; it contains booking references, dates, amounts, and the property code, not the guest’s name, and we keep it as a business record of the payment.

Cookies and analytics

We use Google Analytics on our marketing website to understand traffic; it sets first-party cookies that can last up to two years and receives standard usage data subject to Google’s policies. Published guides load no Google scripts at all: guest measurement is Tabellara’s own, as described above. You can opt out of Google Analytics with Google’s browser add-on or by blocking cookies. Our own session identifier for guides is stored in the browser’s session storage and expires when the tab closes; the anonymous visitor identifier hosts see in analytics is derived from the hashed IP address, so visits from the same network show as the same visitor without identifying anyone. Signed-in hosts have an authentication cookie. We do not currently respond to Do Not Track signals.

We advertise on Google, Microsoft and Meta (Facebook and Instagram). When you create a Tabellara account after arriving from one of our ads, we send Google Analytics, Microsoft Advertising and Meta the fact of the sign-up, and Google and Meta a hashed (one-way encoded) copy of the email address you signed up with, so the ad can be credited. The hash cannot be turned back into your address, it is used only for ad measurement, and it is never used for guests: guest sign-ins on WiFi pages and guest visits to guides are not shared with any ad platform.

Service providers

We rely on a small set of processors to run the service, currently including: Supabase (database, authentication, and file storage for photos), Netlify and Railway (hosting and serverless functions), Fly.io (the network front that carries WiFi sign-in page traffic), Google Analytics (usage analytics), OpenStreetMap Nominatim (converting addresses into map coordinates), Open-Meteo (weather forecasts for a property’s area), Stripe (subscription payments, and Guest Store payments processed on each host’s own Stripe account), and Resend (transactional email such as receipts, order updates, and account notices). Photos in published guides are reachable by anyone with the guide link; photos in drafts and in your Library are private to your account.

If you connect your Airbnb account through Hospitable Connect, we receive your listing content, listing photos, and reservation data such as guest first names, party size, and stay dates. If you connect a property management platform such as OwnerRez, we receive your property and listing content and, for properties you choose to connect, the reservation and guest details your platform holds, such as guest names, stay dates, party details, contact information, and marketing preferences. We use platform data solely to provide the service to you, including personalizing guides, showing reservations, delivering per-stay guide links, and maintaining your Contacts list, and never for our own marketing. Disconnecting stops new data; content already imported into your account stays until you delete it.

When you use AI features, relevant content from your account, such as listing text, guide text, photos, and the property’s address area, is sent to our AI provider (currently xAI) through its API to produce the result: drafting and designing guides, describing photos, researching local recommendations from public sources, and translating guide text into the languages guests can read. Content is sent solely to produce those results and is subject to the provider’s API data policy; we do not allow it to be used for advertising, and we may change providers. The results are stored in your account, where you control them.

What we do not do

We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use guest data for advertising, and we never use guests’ contact details for our own purposes. The Contacts list a host maintains, whether typed in, imported from their property platform at their request, or collected through their WiFi sign-in page, belongs to the host: we store it on their behalf, display the marketing opt-out preferences their platform reports, and its lawful use is the host’s responsibility as controller. We send product and marketing email only if you opt in, and every such email has an unsubscribe link; billing and security notices are sent regardless because you need them.

Retention and deletion

Content and analytics are retained while your account is active so your guides keep working and your analytics keep their history. Deleting a guide or property removes its content; photos move to Recently deleted in your Library for 30 days, then are removed. Usage events tied to deleted guides are removed. Reservation records synced from a property platform are deleted automatically 90 days after checkout, and a guest’s personal stay link stops working shortly after checkout. WiFi sign-in records remain until the host deletes them (forgetting a device erases its sign-ins) or closes their account; the network authorization itself expires on its own. Guest contacts remain until you delete them or close your account. When you close your account we delete your content from our systems within 90 days, except records we must keep for tax, accounting, or legal reasons (invoices are kept for seven years). To close your account or request deletion, email us; we verify the request by confirming your account email.

Security

Data is encrypted in transit (TLS) and at rest, with the one captive-portal exception described under Guest WiFi sign-ins. Access to guest guides that contain sensitive details such as door codes is by unlisted link that hosts control, and those pages are excluded from search engine indexing. Host data is separated by account at the database level. If a security incident affects your personal information, we will notify you as the law requires.

Where data is stored

We store data on servers in the United States. If you use Tabellara from outside the US, your data is transferred to and processed here. For personal data from the EEA or UK we rely on standard contractual clauses with our providers.

Your rights

Wherever you live, you can ask us what personal information we hold about you, ask us to correct or delete it, and ask for a copy of your guide content. California residents have these rights under the CCPA and CPRA, will not be treated differently for exercising them, and may use an authorized agent; we respond within 45 days. Residents of the EEA and UK also have rights to restrict or object to processing, to data portability, and to complain to their supervisory authority. We process account data to perform our contract with you, analytics under our legitimate interest in running and improving the service, and marketing email only with your consent. Email support@tabellara.com to exercise any of these rights.

Children

Tabellara is for adults. We do not knowingly collect personal information from anyone under 18; if we learn that we have, we delete it.

Changes and contact

We will update this policy as the service evolves and note the effective date above; for material changes we will give reasonable notice, such as by email or in the app. Questions or requests: support@tabellara.com.