Security and data protection
Hotels trust us with reservations, guest messages and identity documents. This page explains how we protect them, who processes them, and how you can sign our Data Processing Addendum.
Encrypted everywhere
TLS in transit and encryption at rest for the database and file storage.
Access by role and hotel
Each hotel only sees its own data; staff access follows roles you set.
Audited providers
SOC 2 Type 2 database provider; card payments via Stripe (PCI DSS Level 1).
DPA ready
A Data Processing Addendum for GDPR, UK GDPR, KVKK and CCPA.
Where your data lives
Our database, authentication and server functions run on Supabase; the website and dashboard are hosted on Vercel. Some providers are in the United States; transfers from the EEA, the UK and Türkiye are covered by Standard Contractual Clauses or other lawful mechanisms.
Payments
Card details are entered into Stripe and never reach our servers. We only see the plan, billing period and payment status.
AI and guest messages
Lio sends guest message content to our AI provider only to draft a reply. Under its commercial terms, the provider does not use this content to train its models. You decide which topics Lio answers automatically and which need your approval.
Online check-in data
Identity document images and digital signatures are treated as sensitive data, visible only to your hotel’s staff, and deleted with your account at the latest.
Retention
Guest message content is anonymised after the period you set (default 60 days); guest contact details are kept 90 days after departure; account data is deleted within 30 days of a verified deletion request.
Your roles under GDPR and KVKK
For guest data your hotel is the controller and Hostlio Pro is the processor. Our Data Processing Addendum sets out these obligations and forms part of our Terms of Service.
Subprocessors
| Subprocessor | Location | Purpose |
|---|---|---|
| Supabase, Inc. | USA | Database, authentication and server functions |
| Vercel, Inc. | USA | Website and dashboard hosting |
| Stripe, Inc. | USA | Payments and subscription billing |
| Anthropic, PBC | USA | AI processing of guest messages to draft replies |
| Meta Platforms, Inc. (WhatsApp Business Platform) | USA / Ireland | Sending and receiving WhatsApp messages |
| Channex.io Ltd | United Kingdom | Availability, rate, booking and OTA message sync |
| Make (Celonis) | EU | Contact form and internal workflow automation |
| Twilio Inc.* | USA | WhatsApp numbers and messaging billing for hotels |
| Twilio SendGrid* | USA | Transactional email |
* Planned — added to this list before they process any data
Data Processing Addendum
Our DPA applies automatically when you accept the Terms of Service. You can read and print it, or ask for a countersigned copy.
Report a security issue
If you find a vulnerability, email hello@hostliopro.com with the details. Please do not access other customers’ data or disrupt the service while testing. We reply within two business days.
More detail in our Privacy Policy and Terms of Service.
Last updated:
Keep your front desk open tonight, too.
Try it free for 7 days. No charge until your trial ends, cancel anytime.