Tavvolo Privacy Policy

Last Updated: November 12, 2025

Tavvolo, Inc. ("Tavvolo," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our community-specific vacation rental platform, including our website, mobile applications, and related services (collectively, the "Service").

Please read this Privacy Policy carefully. By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with this Privacy Policy, you may not access or use the Service.

1. Information We Collect

1.1 Information You Provide to Us

Account Information: When you register for an account, we collect your name, email address, phone number, password, and profile photo (optional).

Identity Verification: Through our integration with Stripe Identity, we collect government-issued identification documents (such as driver's licenses or passports), photos for facial recognition, and biometric data necessary for identity verification. Stripe Identity processes this information according to their privacy policy.

Property Listings: If you are a Host, we collect property addresses, descriptions, photos, amenities, house rules, pricing, availability calendars, and other property-related information.

Payment Information: Payment card information, bank account details, and billing addresses are collected and processed by Stripe, our payment processor. We do not store full payment card numbers on our servers, but we may store the last four digits for your reference.

Communications: We collect the content of messages you send through the Service, including messages between Hosts and Guests, customer support inquiries, and reviews.

User-Generated Content: We collect photos, reviews, ratings, comments, and other content you submit to the Service.

Preferences and Settings: We collect information about your preferences, communication settings, notification preferences, and account settings.

1.2 Information Collected Automatically

Device Information: We automatically collect device type, operating system, unique device identifiers, mobile network information, and device settings.

Usage Information: We collect information about your interactions with the Service, including pages viewed, links clicked, features used, search queries, booking history, and time spent on the Service.

Location Information: With your permission, we collect precise geolocation data from your mobile device. We may also derive approximate location from your IP address.

Log Information: Our servers automatically record information including IP addresses, browser type and language, access times, pages viewed, app crashes, and system activity.

Cookies and Similar Technologies: We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your browsing activities and preferences. For more information, see Section 6 below.

1.3 Information from Third Parties

Social Media: If you connect your account to social media services, we may receive information from those services, such as your profile information and friend lists, in accordance with their privacy settings.

Background Checks: If you consent, we may receive information from third-party background check providers.

Other Users: We may receive information about you from other users, such as when they invite you to the platform, include you in a booking, or write reviews about their experience with you.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process transactions and send related information, including confirmations, receipts, and invoices
  • Verify your identity and prevent fraud, spam, and abuse
  • Send you technical notices, updates, security alerts, and administrative messages
  • Respond to your comments, questions, and customer service requests
  • Send you promotional communications, newsletters, and marketing materials (with your consent where required)
  • Personalize and customize your experience, including showing you relevant property listings and content
  • Monitor and analyze trends, usage, and activities in connection with the Service
  • Detect, investigate, and prevent fraudulent transactions and other illegal activities
  • Facilitate communication between Hosts and Guests
  • Enforce our Terms of Service and other policies
  • Comply with legal obligations and resolve disputes
  • Carry out any other purpose described to you at the time the information was collected

3. How We Share Your Information

We may share your information in the following circumstances:

3.1 With Other Users

When you make or accept a booking, we share relevant information with the other party, including names, contact information, property addresses, and booking details. Your public profile information may be visible to other users of the Service.

3.2 With Service Providers

We share information with third-party service providers who perform services on our behalf, including:

  • Payment Processing: Stripe processes all payment transactions and identity verification
  • Cloud Hosting: Supabase provides our database and backend infrastructure
  • Communication Services: Email and SMS providers deliver transactional and marketing communications
  • Analytics: Analytics providers help us understand how users interact with the Service
  • Customer Support: Customer support platforms help us respond to your inquiries

These service providers are contractually obligated to protect your information and use it only for the purposes for which it was disclosed.

3.3 For Legal Reasons

We may disclose your information if required by law or in response to valid legal requests, including:

  • To comply with a subpoena, court order, or other legal process
  • To respond to lawful requests from government authorities
  • To protect our rights, property, or safety, or that of our users or the public
  • To investigate, prevent, or take action regarding illegal activities, suspected fraud, or potential threats

3.4 Business Transfers

If we are involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

3.5 With Your Consent

We may share your information with third parties when you give us consent to do so, such as when you authorize third-party integrations or participate in promotional activities.

3.6 Aggregated or De-Identified Information

We may share aggregated or de-identified information that cannot reasonably be used to identify you, such as statistics about Service usage or demographic trends.

4. Data Retention

We retain your information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce our agreements, and for other legitimate business purposes. The retention period varies depending on the type of information:

  • Account Information: Retained for the duration of your account plus a reasonable period thereafter
  • Transaction Records: Retained for at least 7 years to comply with tax and financial regulations
  • Communications: Retained for a reasonable period to resolve disputes and provide customer support
  • Marketing Data: Retained until you unsubscribe or request deletion
  • Verification Data: Identity verification data is retained according to Stripe's retention policies and applicable regulations

5. Data Security

We implement reasonable administrative, technical, and physical security measures to protect your information from unauthorized access, use, disclosure, alteration, and destruction. These measures include:

  • Encryption of data in transit using TLS/SSL
  • Encryption of sensitive data at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication requirements
  • Employee training on data protection and security practices
  • Monitoring for unauthorized access or suspicious activity

However, no system is completely secure, and we cannot guarantee the absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials.

6. Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar technologies to collect information about your browsing activities and preferences. These technologies help us:

  • Remember your preferences and settings
  • Authenticate your account
  • Analyze Service usage and performance
  • Deliver targeted advertising
  • Prevent fraud and enhance security

Types of cookies we use:

  • Essential Cookies: Required for the Service to function properly
  • Preference Cookies: Remember your settings and choices
  • Analytics Cookies: Help us understand how you use the Service
  • Advertising Cookies: Used to deliver relevant ads and measure campaign effectiveness

Most web browsers automatically accept cookies, but you can modify your browser settings to decline cookies. However, disabling cookies may affect your ability to use certain features of the Service. Mobile device users can manage tracking through device settings.

7. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

7.1 Access and Portability

You have the right to access your personal information and request a copy in a portable format. You can access most of your information through your account settings.

7.2 Correction and Update

You have the right to correct inaccurate information or update incomplete information. You can update most information through your account settings.

7.3 Deletion

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, pending transactions, or fraud prevention). To request deletion, contact us at privacy@tavvolo.com. Note that some information may be retained in backup systems for a limited period.

7.4 Objection and Restriction

You have the right to object to or restrict certain processing of your information, including for direct marketing purposes. You can opt out of marketing communications using the unsubscribe link in emails or by updating your communication preferences in account settings.

7.5 Withdraw Consent

Where we rely on your consent to process information, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.

7.6 Lodge a Complaint

You have the right to lodge a complaint with a data protection authority about our collection and use of your personal information.

To exercise any of these rights, contact us at privacy@tavvolo.com. We will respond to your request within the timeframe required by applicable law (typically 30 days). We may request additional information to verify your identity before processing your request.

8. Children's Privacy

The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@tavvolo.com, and we will delete such information from our systems.

9. International Data Transfers

Your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws different from your country. By using the Service, you consent to such transfers. We implement appropriate safeguards to protect your information when it is transferred internationally, including standard contractual clauses and other mechanisms approved by regulatory authorities.

10. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell
  • Right to Delete: Request deletion of personal information, subject to certain exceptions
  • Right to Opt-Out: Opt out of the sale or sharing of personal information. We do not sell personal information in the traditional sense, but sharing with third parties for targeted advertising may be considered a "sale" under CCPA
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Limit: Limit the use and disclosure of sensitive personal information
  • Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights

To exercise these rights, contact us at privacy@tavvolo.com or call [phone number]. You may designate an authorized agent to make requests on your behalf.

11. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

Legal basis for processing: We process your information based on:

  • Contract: Processing necessary to perform our contract with you
  • Consent: Where you have given explicit consent
  • Legitimate Interests: For our legitimate business interests, such as fraud prevention and service improvement
  • Legal Obligation: To comply with legal requirements

Data Protection Officer: For questions about our GDPR compliance, contact our Data Protection Officer at dpo@tavvolo.com.

12. Third-Party Links and Services

The Service may contain links to third-party websites, applications, and services that are not operated by us. This Privacy Policy does not apply to those third-party services. We are not responsible for the privacy practices of third parties, and we encourage you to review their privacy policies before providing them with any information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Privacy Policy with a new "Last Updated" date. Material changes will be communicated through email notification or a prominent notice on the Service. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@tavvolo.com

Data Protection Officer: dpo@tavvolo.com

Customer Support: support@tavvolo.com

Website: www.tavvolo.com

Mailing Address: Tavvolo, Inc., [Address to be determined]

* * *

By using Tavvolo, you acknowledge that you have read and understood this Privacy Policy.