Legal

Privacy Policy

Effective Date: June 1, 2026  ·  Last Updated: June 1, 2026

1. Introduction and Scope

StAI Flow, Inc. ("StAI Flow," "we," "our," or "us") is a software company that develops and operates a hospitality and property operations management platform (the "Service") available at staiflow.app. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, with whom we share it, and the choices and rights available to you. This policy applies to all users of the Service, including property owners, administrators, managers, and staff members, as well as visitors to our marketing website. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy and consent to the practices described herein. If you are using the Service on behalf of a business or organization, you represent that you have the authority to bind that organization to this policy.

2. Information We Collect

2.1 Account and Identity Information

When you or your organization creates an account or profile, we collect:

  • Full name, username, and email address
  • Job title, department, and property/site assignments
  • Profile photo (if voluntarily provided)
  • Employee start date, hire date, and manager relationships
  • Role and permission assignments within the platform
  • Skills, certifications, and training records

2.2 Operational and Business Data

As you and your team use the Service to manage operations, we store:

  • Maintenance tickets, work orders, and preventative maintenance records
  • Housekeeping job assignments, room statuses, and completion data
  • Scheduling records, shift assignments, time entries, and labor reports
  • Pool chemical logs, safety inspections, and compliance records
  • Inventory counts, usage logs, purchase orders, and stock levels
  • Incident reports, corrective actions, and safety findings
  • Lost and found items, guest waivers, and action requests
  • Food service orders, menu data, and event records
  • Expense records, vendor information, and contract details
  • Floor plan layouts, asset locations, and facility maps

2.3 Communication and Collaboration Data

When you use communication features within the Service:

  • In-app direct messages and group conversations
  • Push-to-talk (PTT) audio recordings and AI-generated transcripts
  • Panic alert activations, timestamps, and GPS/location data
  • Files, photos, and documents uploaded to the platform
  • Notifications sent and received, including read receipts

2.4 Usage, Device, and Technical Data

We automatically collect certain technical information when you access the Service:

  • IP address, browser type, browser version, and operating system
  • Device type, device identifiers, and mobile network information
  • Pages visited, features accessed, and navigation paths
  • Session start and end times, login and logout events
  • Search queries, filter selections, and in-app actions
  • Error logs, crash reports, and performance metrics
  • Referring URLs and referring sources

2.5 Authentication and Security Data

To secure your account we collect and store:

  • Bcrypt-hashed password credentials (passwords are never stored in plain text)
  • TOTP-based multi-factor authentication (MFA) secrets
  • Time-limited, single-use password reset tokens
  • Login history including timestamps, IP addresses, and device fingerprints
  • Failed login attempt counts and account lockout records

2.6 Billing and Payment Data

When your organization subscribes to the Service:

  • Billing contact name, email address, and phone number
  • Subscription plan, billing cycle, and usage metrics
  • Payment processing is handled by Stripe, Inc. We do not store full credit card numbers. Stripe may share last four digits and card brand for receipt purposes.
  • Invoice history and payment status records

2.7 Information from Third-Party Integrations

If you connect third-party services to the platform (such as Google Drive), we may receive data from those services as authorized by you, strictly limited to what is necessary to provide the integration functionality.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: Provide, operate, maintain, and improve all features and modules of the Service.
  • Authentication and Access Control: Authenticate users, enforce role-based permissions, and prevent unauthorized access.
  • Operational Workflows: Power job assignments, scheduling, shift management, notifications, and cross-department coordination.
  • Analytics and Reporting: Generate operational dashboards, KPI summaries, compliance reports, and AI-powered insights.
  • Compliance and Audit: Maintain immutable audit logs to support regulatory compliance, internal accountability, and dispute resolution.
  • Communications: Deliver in-app notifications, emergency alerts, push-to-talk broadcasts, and administrative announcements.
  • Safety and Emergency Response: Enable panic alert systems, incident reporting workflows, and emergency shutoff dashboards.
  • Customer Support: Respond to support tickets, troubleshoot issues, and improve documentation.
  • Platform Improvement: Analyze aggregate usage patterns to improve features, fix bugs, and optimize performance.
  • Billing and Account Management: Process payments, generate invoices, manage subscriptions, and detect fraud.
  • Legal Obligations: Comply with applicable laws, respond to lawful government requests, enforce our terms, and protect legal rights.
  • Security: Detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activity.

4. Legal Basis for Processing (EEA and UK Users)

If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases to process your personal data:

  • Contract Performance: Processing necessary to provide the Service under our agreement with your organization.
  • Legitimate Interests: Processing for security, fraud prevention, product improvement, and operational analytics, where our interests are not overridden by your rights.
  • Legal Obligation: Processing required to comply with applicable laws and regulations.
  • Consent: Where you have explicitly consented, such as for optional communications or certain integrations. You may withdraw consent at any time.

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share information only as follows:

  • Within Your Organization: Data is accessible to authorized users within your organization based on configured role permissions. Site-level isolation ensures staff at one property cannot access data from another.
  • Service Providers and Subprocessors: We engage trusted third-party vendors including cloud infrastructure providers, email delivery services, payment processors (Stripe), analytics platforms, and AI service providers. All subprocessors are bound by data processing agreements requiring them to protect your data.
  • Integrations You Enable: If you connect a third-party service, we share only the minimum data necessary to provide that integration, and only with your authorization.
  • Legal Compliance and Protection: We may disclose information when required by law, subpoena, court order, or government authority, or when we believe disclosure is necessary to protect the safety, rights, or property of StAI Flow, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, financing, reorganization, or sale of assets, customer data may be transferred as part of that transaction. We will provide notice before your data becomes subject to a different privacy policy.
  • Professional Advisors: We may share information with lawyers, auditors, insurers, and other professional advisors under confidentiality obligations.
  • With Your Explicit Consent: We may share your information for any other purpose with your prior written consent.

6. Data Retention

We retain personal information for as long as your account is active or as needed to fulfill the purposes outlined in this policy. Our general retention periods are:

  • Account and Profile Data: Retained for the duration of the active subscription plus 90 days following termination, after which it is deleted or anonymized.
  • Operational Records: Maintenance tickets, jobs, inspections, and similar records are retained for a minimum of 2 years to support compliance, audits, and reporting.
  • Audit Logs and Activity History: Retained for 3 years.
  • Communication Data: Messages, PTT recordings, and notifications are retained for 1 year, unless a longer retention period is required by applicable law or an active legal hold.
  • Billing and Financial Records: Retained for 7 years in accordance with financial recordkeeping regulations.
  • Backup Copies: Encrypted backups may persist for up to 90 days after the primary data deletion date.
  • You may request deletion of your personal data at any time (see Section 8). Certain data may be retained longer if required by legal obligations or to resolve disputes.

7. Security Measures

We implement and maintain a comprehensive set of administrative, physical, and technical safeguards to protect your data:

  • Role-Based Access Control (RBAC): Over 50 granular permission levels control precisely what each user can view and perform.
  • Site-Level Data Isolation: Multi-tenant architecture enforces strict data separation between properties and organizations.
  • Multi-Factor Authentication (MFA): TOTP-based MFA is available to all users and can be enforced as mandatory by administrators.
  • Encryption in Transit: All data is encrypted in transit using TLS 1.2 or higher (HTTPS) on all endpoints.
  • Encryption at Rest: Sensitive data including passwords and authentication tokens is encrypted or cryptographically hashed at rest.
  • Audit Logging: All sensitive operations are logged with user identity, timestamps, IP address, and action details.
  • Automated Security Monitoring: We monitor systems for anomalous access patterns, unauthorized activity, and potential breaches.
  • Vulnerability Management: We conduct regular security reviews and apply patches promptly.
  • Data Breach Response: We maintain an incident response plan and will notify affected customers without undue delay in the event of a confirmed data breach, and no later than required by applicable law (72 hours under GDPR).

8. Your Privacy Rights

Depending on your location and applicable law, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention obligations.
  • Right to Data Portability: Request an export of your data in a structured, commonly used, machine-readable format (JSON or CSV).
  • Right to Restriction of Processing: Request that we limit processing of your personal data in certain circumstances.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right Not to Be Subject to Automated Decisions: You have the right not to be subject to a decision based solely on automated processing that produces significant legal or similarly significant effects.
  • To exercise any of these rights, contact us at support@staiflow.app. We will respond within 30 days. We may need to verify your identity before processing your request.

9. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected, the purposes for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information we maintain about you.
  • Right to Opt Out of Sale or Sharing: We do not sell personal information or share it for cross-context behavioral advertising. If this changes, we will provide a "Do Not Sell or Share My Personal Information" mechanism.
  • Right to Limit Use of Sensitive Personal Information: You may direct us to limit our use of sensitive personal information to what is necessary to provide the Service.
  • Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
  • To submit a California privacy request, email support@staiflow.app with "California Privacy Request" in the subject line.

10. Cookies and Tracking Technologies

We use the following technologies to operate and improve the Service:

  • Strictly Necessary Cookies: Required for user authentication, maintaining secure login sessions, and CSRF protection. These cannot be disabled.
  • Functional Cookies and Local Storage: Used to persist user preferences such as theme settings, default site, sidebar layout, and app state between sessions.
  • Service Workers: Enable offline functionality and background sync for field operations staff.
  • Performance and Analytics: We may use aggregate, anonymized analytics to understand feature adoption and platform performance. No individual behavioral profiling is performed.
  • We do not use third-party advertising cookies, cross-site tracking pixels, or behavioral profiling for advertising purposes.
  • Most browsers allow you to control cookies through browser settings. Disabling strictly necessary cookies may impair the functionality of the Service.

11. International Data Transfers

StAI Flow is headquartered in the United States. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States or other countries where our service providers operate, which may have different data protection laws than your country of residence. Where we transfer personal data from the EEA, UK, or Switzerland to countries that have not received an adequacy decision, we use appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms. By using the Service, you consent to the transfer of your information to the United States and other countries as described in this policy.

12. Children's Privacy

The Service is a business-to-business platform intended for use by adults in professional settings. It is not directed to, and we do not knowingly collect personal information from, individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). If we become aware that we have inadvertently collected personal information from a child, we will promptly delete it. If you believe a child has submitted personal information to us, please contact us immediately at support@staiflow.app.

13. Third-Party Links and Integrations

The Service may contain links to third-party websites or enable integrations with third-party services such as Google Drive, Stripe, or other platforms. This Privacy Policy applies solely to data processed by StAI Flow. Third-party services have their own privacy policies, and we encourage you to review them before connecting such services. StAI Flow is not responsible for the privacy practices or content of any third-party services.

14. Do Not Track

Some browsers offer a "Do Not Track" (DNT) signal. Because there is no consistent industry standard for responding to DNT signals, our Service does not currently respond to DNT browser settings. We do not track users across third-party websites.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated by posting the updated policy with a new "Effective Date" and, where appropriate, by sending an in-app notification or email to account administrators at least 30 days before the changes take effect. Your continued use of the Service after the effective date of the revised policy constitutes acceptance of the changes. If you do not agree with the changes, you should discontinue use of the Service before the effective date.

16. Contact Us

For privacy-related inquiries, to exercise your data rights, or to report a concern, please contact us:

StAI Flow, Inc.

Email: support@staiflow.app

Website: staiflow.app

If you are located in the EEA or UK and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

We aim to respond to all privacy requests within 30 days. For complex requests, we may extend this by an additional 60 days with prior notice.