back to nightdesk.cc

Privacy Policy

Last updated: June 2026

1. Introduction

Nightdesk operates the revenue intelligence platform at nightdesk.cc ("Service"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and your rights regarding that data.

We built Nightdesk for independent hotel and hostel operators who trust us with their business data. This policy is written to be honest and clear.

2. Information We Collect

Account Registration

When you create an account, we collect your full name, email address, and password. Passwords are hashed by Supabase -- we never see or store your plaintext password.

Property Details

During onboarding you provide your property name, type (hotel, hostel, glamping, etc.), timezone, and currency. This is used to configure your reports.

Revenue Data You Upload

The core of the Service involves uploading historical revenue and booking data via CSV or XLSX. This typically includes occupancy records, ADR, RevPAR, booking dates, and aggregate revenue figures. This data belongs to you and is used only to generate your forecasts and reports.

Usage Data

We collect information about how you interact with the Service -- features used, import history, timestamps of key actions. This helps us identify problems and prioritize improvements.

Error and Diagnostic Data

Sentry captures diagnostic information when errors occur -- browser type, OS, the page where the error happened, and stack traces. Revenue data and passwords are not captured in error reports.

What we do NOT collect

  • Payment card numbers or CVV -- Stripe handles this entirely and we never see it
  • Personal data belonging to your guests or customers
  • Advertising or behavioral tracking data
  • Social login data -- we do not offer Google, Facebook, or Apple login

3. How We Use Your Information

DataPurposeGDPR Basis
Name, email, passwordAccount creation and managementContractual necessity
Property detailsConfigure the Service for your propertyContractual necessity
Revenue data (CSV uploads)Generate forecasts, briefs, rate recommendationsContractual necessity
Usage dataDiagnose bugs, improve the ServiceLegitimate interest
Error / diagnostic dataIdentify and fix application errorsLegitimate interest
Email addressSend transactional emails and daily morning briefsContractual necessity
Server logsSecurity and abuse preventionLegitimate interest

We do not use your data for advertising, profiling, or any purpose beyond providing and improving the Service. Nightdesk does not currently use uploaded operator data to train machine learning or AI models. If this changes, we will provide advance notice and an opt-out opportunity before any such use begins.

4. Service Providers We Share Data With

We share your information only with the providers below, all of which process data on our behalf under contractual obligations. We do not sell your personal information. We do not share data with advertisers or data brokers.

Payment processing. When you enter payment details they go directly to Stripe -- we never receive or store your card number. Stripe is PCI-DSS certified.

Delivers your daily morning briefs and transactional emails (account confirmations, billing receipts). Your email is shared with Resend solely for delivery.

Database and authentication. Stores your account data, property details, and uploaded revenue data. Hosted on AWS us-west-2 (Oregon). Data encrypted at rest and in transit.

Application error tracking. Receives diagnostic reports when errors occur. Revenue data and passwords are not included in error payloads.

Hosting and serverless functions. Processes standard server request logs including IP addresses for security and performance.

We may also disclose your information if required by law, court order, or valid government request. In the event of a merger or acquisition, your data may transfer as part of that transaction with advance notice to you.

5. Data Retention

Data TypeRetentionReason
Account data, property details, revenue dataActive account + 90 days after cancellationService provision, then deletion
Billing records7 yearsLegal and tax obligations
Error logs (Sentry)90 daysDebugging and security
Server logs (Vercel)30 daysSecurity and abuse prevention
Support emails2 years from last contactCustomer service continuity

You may request earlier deletion by contacting support@nightdesk.cc.

6. Data Security

We implement the following measures to protect your data:

  • All data transmitted between your browser and our servers is encrypted via HTTPS/TLS
  • Data stored in Supabase is encrypted at rest on AWS us-west-2
  • Passwords are hashed using bcrypt via Supabase -- we never store or see plaintext passwords
  • Payment card data is handled entirely by Stripe and is never stored on Nightdesk infrastructure
  • Access to production data is restricted to authorized personnel
  • Sentry monitors for application errors and anomalies in real time

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at support@nightdesk.cc.

7. Your Rights Under GDPR (EEA and UK Residents)

If you are located in the European Economic Area or United Kingdom, you have the following rights:

  • Right of Access -- Request a copy of the personal data we hold about you
  • Right to Rectification -- Correct inaccurate or incomplete data
  • Right to Erasure -- Request deletion of your personal data
  • Right to Restrict Processing -- Ask us to limit how we use your data
  • Right to Data Portability -- Receive your data in a machine-readable format
  • Right to Object -- Object to processing based on legitimate interests
  • Right to Withdraw Consent -- Withdraw consent at any time where processing is consent-based
  • Right to Lodge a Complaint -- Contact your local Data Protection Authority

To exercise these rights, email support@nightdesk.cc. We will respond within 30 days.

8. Your Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights:

  • Right to Know -- what personal information we collect, use, and share
  • Right to Delete -- request deletion of your personal information
  • Right to Opt-Out of Sale or Sharing -- we do not sell or share personal information for advertising
  • Right to Non-Discrimination -- we will not penalize you for exercising your rights
  • Right to Correct -- request correction of inaccurate personal information

Categories of personal information collected in the past 12 months: identifiers (name, email), commercial information (subscription and billing history), internet/network activity (usage logs, error reports), and professional information (property name and type). We do not sell any of these categories.

To exercise your rights, contact support@nightdesk.cc.

9. Cookies

Nightdesk uses only essential cookies required for authentication and session management.

Cookie TypePurposeDuration
Essential / Auth (Supabase)Login session and authentication stateSession / up to 7 days
Essential / CSRFCross-site request forgery protectionSession

We do not use advertising cookies, cross-site tracking cookies, Google Analytics, Meta Pixel, or any third-party analytics scripts.

10. Children's Privacy

The Service is intended for adult business operators and is not directed at individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact support@nightdesk.cc and we will delete it.

11. International Data Transfers

Your data is primarily stored in the United States (AWS us-west-2, Oregon). If you access the Service from outside the US, your information will be transferred to and processed in the US. For EEA and UK users, we rely on Data Processing Agreements incorporating Standard Contractual Clauses (SCCs) approved by the European Commission with our service providers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 14 days before changes take effect. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact

For privacy questions or to exercise your data rights:

Nightdesk
support@nightdesk.cc

Terms of ServiceNightdesk Home