This Privacy Policy explains how Airelay collects, uses, shares, and protects personal data when you use our smart-lock access-automation platform, websites, and related services (collectively, the "Service"). It also describes the rights you have over your personal data and how to exercise them. Please read it alongside our Terms of Service.
Airelay operates the Service and is responsible for the personal data described in this policy. For any privacy matter you can reach us at privacy@airelay.app. Where this policy refers to "we", "us", or "our", it means Airelay.
As a controller. When you sign up for an account, contact us, visit our website, or pay for the Service, we decide why and how your personal data is processed. For that data, Airelay is the data controller.
As a processor. Our customers are typically property managers, hotels, and vacation-rental operators. When they use Airelay to manage access to their properties, they upload or sync reservation and guest information into the platform. We process that data only on their instructions and on their behalf. For that data, our customer is the controller and Airelay is the processor. The terms of that processing are set out in our Data Processing Agreement, available on request.
When a customer connects a channel manager (such as Lodgify, Superhote, Guesty, Hostaway, or Hostify) or a device cloud (such as Shelly, SwitchBot, Ring, Fingerbot, or Home Assistant), we receive the data needed to sync properties, reservations, and device state. We only request the scopes required to provide the Service.
Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing and operating the Service, including syncing devices and generating guest access | Performance of a contract; legitimate interests; or processing on a customer's documented instructions |
| Account creation, authentication, and security | Performance of a contract; legitimate interests in keeping accounts secure |
| Billing, invoicing, and fraud prevention | Performance of a contract; legal obligation |
| Customer support and service communications | Performance of a contract; legitimate interests |
| Improving reliability, diagnosing faults, and preventing abuse | Legitimate interests |
| Marketing emails to existing customers and prospects | Consent, or legitimate interests where permitted (you can opt out at any time) |
| Complying with legal and regulatory obligations | Legal obligation |
We do not sell personal data, and we do not use guest or reservation data for advertising.
We share personal data only in these situations:
We use a small number of trusted providers to deliver the Service. They process data only on our instructions and under contractual confidentiality and security obligations. Our core infrastructure provider is Render, which hosts our application and PostgreSQL database in Frankfurt, Germany (EU). We also use a payment processor for billing and an email provider for transactional and service messages.
Separately, the channel managers and device clouds a customer chooses to connect (Lodgify, Superhote, Guesty, Hostaway, Hostify, Shelly, SwitchBot, Ring, Fingerbot, Home Assistant) act as independent recipients of the data exchanged with them. An up-to-date list of sub-processors is available on request at privacy@airelay.app.
Our primary hosting is in the EU (Frankfurt). Where a sub-processor or connected service processes data outside the European Economic Area, we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses, so that your data continues to receive an equivalent level of protection.
We keep personal data only as long as needed for the purposes described in this policy:
We use technical and organisational measures appropriate to the risk, including encryption of data in transit (TLS), hashed and salted passwords, scoped multi-tenant isolation, authenticated and CSRF-protected sessions, access controls, and audit logging. No system can be guaranteed perfectly secure, but we work continuously to protect personal data and will notify affected users and regulators of a personal-data breach where the law requires.
Depending on where you live, you may have the right to:
To exercise any of these rights, email privacy@airelay.app. We will respond within the timeframe required by law (generally within one month). If your data is processed by Airelay on behalf of a customer (for example, guest data), we will refer your request to that customer as the controller.
Our websites and portal use only the cookies necessary to operate the Service, such as authentication and security cookies (including the session and CSRF tokens). We do not use third-party advertising cookies. Where any non-essential analytics are used, we will request consent in line with applicable law.
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Continued use of the Service after an update means you accept the revised policy.
For any question or request about this policy or your personal data, contact our privacy team at privacy@airelay.app. We aim to respond within five business days.
Email our privacy team and we'll respond within five business days.
Email privacy@airelay.app