HostHub

Privacy Policy

隐私政策

Effective August 1, 2026 · 生效日期 August 1, 2026

  1. 1. Two different roles两种不同角色

    This policy covers two things that are easy to confuse. For the account of the landlord or property manager who signs up, we decide why and how the data is used — we are the controller. For everything they then put into HostHub about their guests, tenants and staff, they decide and we only act on their instructions — they are the controller and we are their processor.
    本政策涵盖两件容易混淆的事。对于注册的房东或物业管理者的账号数据,由我们决定使用目的与方式,我们是控制者。对于他们随后存入 HostHub 的房客、租客与员工信息,由他们决定,我们仅按其指示行事:他们是控制者,我们是其处理者。

    If you are a guest or tenant and want to know what a particular host holds about you, ask that host. We will help them answer, but the data is theirs to explain.
    如果你是房客或租客,想了解某位房东持有你的哪些信息,请直接联系该房东。我们会协助其回复,但数据由其负责说明。

  2. 2. What we collect我们收集的信息

    As controller, for your account:
    作为控制者,就你的账号:

    • Your name, email address and a bcrypt hash of your password. We never store the password itself.
      你的姓名、邮箱地址,以及密码的 bcrypt 哈希值。我们从不存储密码原文。
    • Your timezone, language and display preferences.
      你的时区、语言与显示偏好。
    • Billing status and your Stripe customer and subscription identifiers. Card numbers are entered on Stripe's own forms and never reach our servers.
      计费状态,以及你在 Stripe 的客户与订阅标识。卡号在 Stripe 页面输入,不经过我们的服务器。
    • Usage counters — how many AI calls, emails and pricing lookups your account has made this month — used to apply plan limits.
      用量计数:本月的 AI 调用、邮件与定价查询次数,用于执行套餐额度。
    • Credentials you choose to store for services you connect, such as a Hostex API key or your own Stripe key.
      你为所接入服务自愿保存的凭据,例如 Hostex API 密钥或你自己的 Stripe 密钥。
    • Technical records needed to run the service: an activity log of actions taken in your account, and error reports.
      运行服务所需的技术记录:账号内操作的活动日志与错误报告。

    As processor, on your instructions, HostHub stores whatever you enter about:
    作为处理者,按你的指示,HostHub 会存储你所录入的:

    • Guests and tenants: name, email, phone, WeChat id, guest count, stay dates, payments, deposits, notes, uploaded identity-verification status, signed contracts and message history.
      房客与租客:姓名、邮箱、电话、微信号、入住人数、入住日期、付款、押金、备注、身份验证状态、已签署合同与消息记录。
    • Staff and cleaners: name, contact details, assigned tasks and uploaded cleaning photos.
      员工与清洁人员:姓名、联系方式、指派的任务与上传的清洁照片。
    • Owners in profit-sharing arrangements: name, contact details and ledger entries.
      分成业主:姓名、联系方式与账目记录。
  3. 3. Why we use it使用目的

    • To provide the service you asked for — the legal basis is performance of our contract with you.
      为提供你所请求的服务,法律依据为履行与你订立的合同。
    • To take payment and prevent fraud — performance of contract, and our legitimate interest in being paid.
      为收取费用与防范欺诈,依据为履行合同,以及我们收取款项的正当利益。
    • To keep the service secure and diagnose faults — our legitimate interest in a working, safe product.
      为保障服务安全与排查故障,依据为我们维持产品可用与安全的正当利益。
    • To email you about your account, and — only if you opt in — about the product. You can unsubscribe from the latter at any time.
      就你的账号事项向你发送邮件;仅在你选择订阅时发送产品相关邮件。后者可随时退订。
    • To meet legal obligations such as tax records.
      为履行税务记录等法定义务。

    We do not sell personal data, we do not use it for advertising, and we do not use your content to train AI models.
    我们不出售个人信息,不用于广告,也不使用你的内容训练 AI 模型。

  4. 4. Who else touches the data其他数据接触方

    We use these providers to run HostHub. Each is bound by a contract limiting them to processing on our instructions. Items marked optional only apply if you turn that feature on.
    我们使用以下服务商运行 HostHub。各方均受合同约束,仅可按我们的指示处理数据。标注“可选”的项目仅在你启用相应功能时适用。

    • Vercel Inc. — Application hosting and file storage (Vercel Blob). All data in transit; uploaded photos, documents and signed contract PDFs at rest.
      Vercel Inc. — 应用托管与文件存储(Vercel Blob)。全部传输中的数据;上传的照片、文件与已签署合同 PDF。
    • Neon Inc. — Managed PostgreSQL database. All account, property, booking, guest and message records.
      Neon Inc. — 托管 PostgreSQL 数据库。全部账号、房源、订单、房客与消息记录。
    • Stripe, Inc. — Subscription billing, and guest payments where the customer connects their own Stripe account. Billing contact and payment details. Card numbers are entered on Stripe's own forms and never reach our servers..
      Stripe, Inc. — 订阅计费;若客户接入自有 Stripe 账户,则用于收取房客款项。账单联系人与支付信息。卡号在 Stripe 页面输入,不经过我们的服务器。。
    • Anthropic PBC (optional) — The AI assistant, note parsing, message drafting and pricing suggestions. Only the text sent to a given feature — typically a booking note, a guest message or a pricing question.
      Anthropic PBC(可选) — AI 助理、备注解析、消息草拟与定价建议。仅限该功能所发送的文本,通常为订单备注、房客消息或定价问题。
    • Hostex (optional) — Channel management: calendars, reservations and guest messages. Reservation and guest data for the customer's own Hostex account, using the customer's own API key.
      Hostex(可选) — 渠道管理:日历、预订与房客消息。客户自有 Hostex 账户的预订与房客数据,使用客户自己的 API 密钥。
    • The customer's chosen SMTP provider (optional) — Outbound email: contracts, invoices, reminders and confirmations. Recipient address and message content, including attached PDFs.
      The customer's chosen SMTP provider(可选) — 外发邮件:合同、发票、提醒与确认。收件地址与邮件内容,包括附件 PDF。
    • Functional Software, Inc. (Sentry) (optional) — Error monitoring. Error reports with request bodies, cookies and query strings stripped, and the user reduced to an account id.
      Functional Software, Inc. (Sentry)(可选) — 错误监控。错误报告;请求体、Cookie 与查询串已剔除,用户仅保留账号 ID。

    We will tell you before adding a new provider that processes personal data. We may also disclose data if the law compels us, and will tell you unless we are forbidden from doing so.
    新增处理个人信息的服务商前,我们会事先告知你。若法律强制要求,我们也可能披露数据,除非被禁止告知,否则会通知你。

  5. 5. Where the data is数据存放地

    Our database and file storage run in North America, and some providers above operate globally. Where personal data leaves its home region, transfers rely on the mechanisms that region recognises — for the EEA and UK, the Standard Contractual Clauses.
    我们的数据库与文件存储位于北美,上述部分服务商在全球运营。当个人信息离开其所在地区时,我们依据该地区认可的机制进行传输;就欧洲经济区与英国而言,为标准合同条款(SCC)。

  6. 6. How long we keep it保存期限

    Account data is kept while your account is open. When you delete a record in HostHub it goes to the recycle bin and can be restored; deleting it there removes it.
    账号数据在账号存续期间保留。你在 HostHub 中删除的记录会进入回收站并可恢复;在回收站中删除即移除。

    After you close your account you have 30 days to export. We then delete your data, except for backups that expire on their own cycle and records we must keep for tax or legal reasons.
    账号关闭后你有 30 天可导出数据。此后我们将删除你的数据,但备份会按其自身周期自然过期,法律或税务要求保留的记录除外。

  7. 7. How it is protected安全措施

    • Traffic is encrypted in transit; the database and file storage are encrypted at rest by our providers.
      传输过程加密;数据库与文件存储由服务商进行静态加密。
    • Passwords are stored only as bcrypt hashes. Sessions use signed, http-only cookies.
      密码仅以 bcrypt 哈希存储。会话使用签名的 http-only Cookie。
    • Every query is scoped to the account that owns the row, and that isolation is covered by an automated test suite that runs against two separate tenants.
      每次查询都限定在拥有该数据的账号范围内,并由针对两个独立租户运行的自动化测试套件持续验证隔离性。
    • Error reports are scrubbed before they leave our servers: request bodies, cookies and query strings are removed, sensitive headers redacted, and the user reduced to an account id.
      错误报告在离开服务器前已脱敏:移除请求体、Cookie 与查询串,屏蔽敏感请求头,用户仅保留账号 ID。

    No system is perfectly secure. If a breach affects your data we will tell you without undue delay and, where required, within 72 hours of becoming aware.
    没有系统是绝对安全的。若发生涉及你数据的泄露,我们将不无故迟延地通知你;在法律要求的情形下,将在知悉后 72 小时内通知。

  8. 8. Your rights你的权利

    Depending on where you live, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or send it to another provider. You may also withdraw consent where we relied on it, and complain to your data protection authority.
    视你所在地区而定,你可要求我们提供数据副本、更正、删除、限制或反对使用,或转移至其他服务商。你也可撤回此前给予的同意,并向当地数据保护机构投诉。

    Most of this you can do yourself in the app. For anything else, email platinumtravelca@gmail.com. We answer within 30 days and do not charge for it.
    多数操作你可在应用内自行完成。其他事项请邮件联系 platinumtravelca@gmail.com。我们将在 30 天内答复,且不收取费用。

  9. 9. CookiesCookie

    We set two cookies, both necessary: one holds your signed session so you stay logged in, and one remembers your language. We do not use advertising or analytics cookies, which is why there is no cookie banner.
    我们仅设置两个必要 Cookie:一个保存你的签名会话以保持登录,一个记住你的语言。我们不使用广告或分析类 Cookie,因此没有 Cookie 弹窗。

  10. 10. Children未成年人

    HostHub is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16 as an account holder.
    HostHub 是商务工具,不面向儿童。我们不会在知情的情况下收集未满 16 周岁者作为账号持有人的信息。

  11. 11. Changes政策变更

    If we change this policy materially we will tell you by email or in the app before it takes effect. The date at the top always reflects the current version.
    如本政策发生实质性变更,我们将在生效前通过邮件或应用内告知你。页面顶部日期始终对应当前版本。

  12. 12. Contact联系方式

    PLATINUM TRAVEL INC., 2980 Number 3 Rd, Richmond, BC V6X 2B3. Privacy enquiries: platinumtravelca@gmail.com.
    PLATINUM TRAVEL INC.,2980 Number 3 Rd, Richmond, BC V6X 2B3。隐私相关咨询:platinumtravelca@gmail.com。

The English text is the governing version; the Chinese is provided for convenience. 中文译文仅供参考,以英文版为准。
PLATINUM TRAVEL INC. · 2980 Number 3 Rd, Richmond, BC V6X 2B3 · platinumtravelca@gmail.com