Privacy

Privacy policy

The short version: journal guests never make accounts, we collect almost nothing, we sell nothing, and every page appears only with its author's consent. Approved partner referrals are measured without an advertising cookie or a browsing profile.

Who is responsible

Workbird LLC operates StayPage and is the controller for host account data. For the content of a journal, the host runs the book: they choose moderation, hide pages, and answer for what their journal displays, while StayPage stores and serves it on their behalf. Whoever you are, the support chat on any page reaches the person responsible.

What we collect from hosts

An email address for passwordless sign-in, an organization name, and billing details handled entirely by Stripe; card numbers never touch our servers. If a host arrives through an approved compensated partner link, we also keep the partner, an opaque referral identifier, and the resulting commission ledger. We do not give the partner the host's journal content, card details, or browsing history.

What we collect from guests

Only what a guest chooses to put on their page: words, photos, a signature. Guests never create accounts and never give us an email address for a journal page. The editor stores a private editing key in an HttpOnly cookie and local browser storage. The complete private edit link also carries that key after the # so the guest can move the editor to another browser. Browser fragments are not sent to our server as part of the page URL or in referrers. We do not store guest IP addresses in readable form; a salted hash that rotates daily is kept briefly for abuse prevention and cannot be turned back into an address.

What we collect in support chat

If you contact support through the site, we collect the name and email address you enter, your messages, any photos you choose to share, delivery and read times, and brief online-presence timestamps. We also keep a rotating salted hash of the network address used to start the chat for abuse prevention. Support chat is separate from journal guest pages.

Why we may lawfully use it

Where the law asks us to name a basis: we process host data to perform our contract with the host, guest pages on the guest's consent and audience choice given when the page is finished, and the abuse-prevention hashes on our legitimate interest in keeping journals safe. Support conversations are processed to answer the request you chose to send and to keep that exchange reliable and secure. We never process anything for advertising, profiling, or resale, so no basis is needed for those; there is nothing to base.

Consent and audience choice

A guest page joins a journal only after the guest chooses either Public journal or Homeowner only and confirms that choice. A public page may be read by future guests and anyone with its journal link. A homeowner-only page stays in the same home and year but is available only to the account owner or a person explicitly granted owner access to that home. No confirmation, no finished page. We record the choice and its time. A homeowner cannot later turn a private page public without fresh consent from the guest.

Partner referrals

An approved partner link creates one random first-party referral identifier. It contains no email address, IP address, user-agent, or readable customer information and travels only through the landing, passwordless sign-in, and first account setup. We use it to credit the referring partner if that new organization becomes a paying customer. The partner may receive a disclosed commission at no added cost to the customer. The first valid referral claimed by a new organization is final; existing accounts cannot be reassigned by clicking another partner link.

Cookies

Only functional ones: a session cookie for signed-in hosts, the guest editing key, a support-chat key, and a PIN cookie where a journal requires one. No advertising trackers, no third-party analytics cookies, no affiliate cookie, and nothing that follows anyone around the internet. A guest's draft recovery key is also kept in that browser's local storage. The complete private edit link can restore access in another browser. The full list, lifetimes included, lives in the cookie policy. We do not respond to Do Not Track signals because there is no tracking to turn off.

Who can see what

Public journal pages are visible to anyone with the journal link, or to anyone with the PIN where the host requires one. Homeowner-only pages do not appear in the public journal, public search surfaces, public year counts, or public share links; only the account owner or an explicitly granted owner of that home can read them in the signed-in dashboard. Organization administrators who are not owners cannot read them. Drafts are available only to a browser holding the private editing key, whether it created the draft or received the complete private edit link. Owners can hide or delete pages in their journals, and hiding also quarantines the page's photos. Support conversations and their photos are visible only to the visitor holding that conversation's private key and authorized StayPage superadmins.

Where your data lives

StayPage runs on a small set of processors, each seeing only what it needs: Supabase stores the database and photos, Stripe processes payments, Resend delivers our email, and Netlify serves the site. Data is processed in the United States; if you use StayPage from elsewhere, you are sending it there, protected by our contracts with those processors. We do not sell personal data and we do not run third-party advertising.

How we protect it

Everything travels over HTTPS. Database access is fenced by row-level security so a host's session can only ever read its own organization. Guest editing keys are stored server-side as cryptographic hashes. A journal PIN is stored server-side in retrievable form because the host may print it beside the QR code and rotate it; public journal reads never receive it, and a successful PIN check stores an HMAC cookie rather than the PIN itself. Draft and homeowner-only photos live in private storage and are served through short-lived signed links to authorized viewers. Photos move to public storage only after the guest chooses Public journal and any required host approval is complete. The moderation trail is append-only. No system is perfect; if a breach ever affects you, we tell you quickly and plainly.

Your rights

Wherever you live, we honor the strong set: access, correction, export, deletion, and objection. Hosts can export every journal from the dashboard, as a keepsake PDF or a full JSON archive, without asking anyone. If a page shows you and you want it gone, use the Report link on that page and choose the privacy reason, or use the support chat on any page; the host is notified immediately and we can remove content permanently, including photos. Deletion means deletion: the page, its photos, and the storage objects behind them. We answer within thirty days and never charge for it.

If you are in New Zealand

StayPage is built in the United States, and the New Zealand Privacy Act 2020 covers an overseas business that serves people in New Zealand. So if you are a New Zealand host or guest, these extra promises apply on top of everything above. You can ask to see the personal information we hold about you and to have it corrected; we answer within the twenty working days the Act sets, and we never charge. Your information travels to our United States processors under contracts that require protection comparable to the New Zealand Act. If a privacy breach ever causes you serious harm or is likely to, we tell you and the New Zealand Privacy Commissioner as soon as practicable. Our privacy officer keeps these promises and answers through the support chat on any page. If we get it wrong, you can complain for free to the Office of the Privacy Commissioner at privacy.org.nz.

Retention

Unpublished drafts and their uploads are deleted automatically after fourteen days of inactivity. If a subscription ends, journals become read-only and are retained for at least twelve months, with email warnings before any scheduled deletion. Nothing is ever deleted by a billing state alone. Completed support conversations, including their private photos, are deleted after ninety days. Uncompleted support conversations with no activity are deleted after one hundred twenty days, and abandoned pending support uploads are deleted after twenty-four hours. An unclaimed referral is deleted ninety days after its attribution window expires. Claimed referral and commission records are retained with the related account and billing ledger so earnings, refunds, and disputes can be reconciled.

Children

StayPage is not directed at children under 13 and we do not knowingly collect their personal information. Family pages are written by adults or under a host's and guardian's watch; if a child's information was published without a guardian's okay, tell us and it comes down.

Changes and contact

If this policy changes in a way that matters, we email hosts first and note the date below. Anything unclear, or any request about your data: use the support chat on any page.

Last updated August 2026