Skip to content
GuestFoyer

Legal

Privacy Policy

Last updated July 30, 2026

GuestFoyer is a digital welcome book for short-term rental hosts. This policy explains what we collect from hosts who have an account, and what happens when a guest opens a published guide. We have tried to write it in plain language.

The short version

  • Guests do not need a GuestFoyer account, and simply viewing a guide does not create an advertising or analytics profile.
  • If a guest chooses to use an enabled live-chat concierge, their contact details, messages and chat-session data are processed in the host's connected SMBcrm account.
  • We do not run advertising, analytics or third-party trackers.
  • We do not sell or rent personal information to anyone.
  • Host accounts are invite-only, and a host's content is visible only to their own workspace until they publish it.

Information from hosts

When you are invited and create an account, we store your email address, your name if you provide one, and a cryptographic hash of your password. We never store your password itself.

We store the content you create: property names, addresses, check-in and check-out times, Wi-Fi network names and passwords, the guide sections you write, your local recommendations, and any images you upload. This content belongs to you.

A note on Wi-Fi passwords. A Wi-Fi password you add to a guide is shown to anyone who opens that guide once it is published. That is the point of the feature, but it means you should treat the guest network credentials you enter as public once you publish, and should not reuse a password that protects anything else.

Information from guests

A published guide is a public web page. Guests do not sign in, do not create an account, and are not asked for personal information. We do not set analytics or advertising cookies on guest pages, and we do not build profiles of guests.

Guest guide responses are served with no-store, no-referrer and noindex headers, so they are not cached by shared caches, do not leak the guide address to sites a guest clicks through to, and are not indexed by search engines.

Like any web service, our servers write short-lived operational logs that may include an IP address, the requested path, a response status and a request identifier. These are used to keep the service running and secure, and are retained for 14 days.

Optional guest concierge and live chat

A host may enable a live-chat concierge on a published guide. If you choose to use it, the widget can ask for your name, email address or phone number and processes the messages you send, technical information needed to maintain the chat session, and the automated or human replies you receive.

The first reply may be generated by Conversation AI using a knowledge base built from that property's GuestFoyer guide. Messages can also be reviewed or answered by the host team. Do not send payment-card information, government identifiers, medical information or other sensitive personal information through the chat.

The widget and conversation record are provided through SMBcrm and its LeadConnector infrastructure. GuestFoyer stores the identifiers and synchronization status needed to connect the correct property, knowledge base, agent and widget; it does not store a separate copy of the conversation transcript.

Cookies

GuestFoyer uses exactly two first-party cookies, both strictly necessary and both limited to the signed-in host application:

  • gf_session — keeps you signed in after you log in.
  • gf_csrf — protects forms against cross-site request forgery.

We do not set advertising, analytics or marketing cookies. On a guide where the host enables live chat, the embedded provider may use cookies or browser storage that are necessary to load the widget, maintain the conversation and prevent abuse. You can avoid that processing by not using the chat and contacting the host through another available channel.

How your information is protected

  • All traffic is served over HTTPS.
  • Each workspace's data is isolated; one host cannot read another host's properties, guides or uploaded media.
  • Uploaded images are stored in private storage and are readable anonymously only while a published guide references them. When you unpublish a guide, both the guide and its images stop resolving.
  • The database is private, encrypted at rest, and not reachable from the public internet.
  • Passwords are hashed, sessions can be revoked, and repeated failed sign-in attempts are rate limited.

Who we share information with

We do not sell, rent or trade personal information. We share it only with the providers needed to run the service: Amazon Web Services, which hosts our application, database and file storage in the United States; and, when live chat is enabled and used, SMBcrm and its LeadConnector infrastructure. A guest's chat is also available to the host team responsible for that property. We may disclose information where required by law.

How long we keep things

We keep your account and content for as long as your account is active. Operational logs are retained for 14 days. If you ask us to delete your account, we will delete your workspace, its properties, guides and uploaded media.

Guest chat contact and conversation records are retained in the connected SMBcrm account according to the host's retention practices and the provider's applicable policies. Contact the host shown in the conversation, or email us, if you want to request access to or deletion of a guest-chat record.

Your choices

You can edit or delete your content at any time from your dashboard, and unpublishing a guide takes it offline immediately. To request a copy of your data or ask us to delete your account, email us at privacy@guestfoyer.com.

Guests can choose not to use the live-chat concierge and can contact the host by another available method. A guest can also use the same email address to ask about personal information processed through the chat.

Children

GuestFoyer is a tool for property hosts and is not directed at children. We do not knowingly collect personal information from anyone under 16.

Changes to this policy

If we change what we collect or how we use it, we will update this page and change the date at the top before the change goes live.

Contact

Questions about privacy: privacy@guestfoyer.com.