Privacy Policy
Last updated: September 14, 2026
1. Data controller
The data controller of personal data is SEEDFLOW, SAS, operator of the WonderGuest service, available at wonderguest.app, registered office: 24 rue Lombard, 33300 Bordeaux, European Union (SIREN 989 468 426).
Contact: support@wonderguest.app
This policy covers the WonderGuest application (app.wonderguest.app and the mobile apps), the published guidebooks and the marketing website wonderguest.app. It applies wherever you are located, including in the United States.
2. Data collected
As part of using the Service, we collect the following categories of data:
2.1 Registration and profile data
- Email address
- First and last name (via manual entry or automatically retrieved when logging in via Google or Apple)
- Preferred language and theme
- Authentication data: we do not store any password; authentication relies on a one-time code (OTP) sent by email, or on the OAuth protocols of Google and Apple
2.2 Usage data
- Information about your accommodations (address, description, photos, GPS coordinates)
- Guidebook content (texts, images, links, custom blocks)
- Guidebook viewing statistics (number of views, QR code scans)
- Interaction events in the application (navigation, user actions) collected through our product analytics tool
- Technical logs and diagnostic data in case of error (stack traces, device, application version)
2.3 Payment data
Payment information (bank card number) is processed directly by Stripe, our PCI-DSS-certified payment provider. WonderGuest does not store any bank data. We only keep the Stripe customer and subscription identifiers needed to manage your account.
2.4 Guest data (guidebook visitors)
Guests do not create an account. Depending on the features the host has enabled, the following data may be collected when a guest uses a published guidebook:
- Check-in form answers: first and last name, arrival and departure dates, arrival time and, if the host asks for them, number of guests and children, means of transport, pets, telephone number, language, occasion, special requests and answers to the host’s custom questions
- Extras store orders: name, email address, telephone number, postal address, stay dates, items ordered, requested date and time, comments; the payment itself is made through a Stripe payment link and WonderGuest does not receive the card number
- Email address, if the guest provides it through a form embedded in the guidebook
- Anonymized browsing data (QR code scan, guidebook viewing)
For this data, the host is the data controller and WonderGuest acts as a processor on the host’s instructions, under the Data Processing Agreement. Guests who have a question about their data should contact the host first; we forward any request we receive directly to the host concerned.
2.5 Visitors of the marketing website
- Contact form: name, email address and message, sent to us by email through Resend and kept for as long as needed to answer you
- Audience measurement through Plausible Analytics, Vercel Analytics and Vercel Speed Insights: pages viewed, referrer, country, browser and device type, without cookies and without tracking across other websites
- Advertising measurement through the Meta Pixel: pages viewed, IP address, browser data and pixel cookie identifiers, sent to Meta Platforms to measure our Facebook and Instagram campaigns and build advertising audiences
- Campaign attribution: the parameters of the link you arrived from (utm tags, referral code, gclid, fbclid), kept in a first-party cookie for 30 days and passed to the application if you sign up
The Cookie Policy lists the cookies concerned and how to refuse them.
3. Processing purposes
Your data is processed for the following purposes:
| Purpose | Legal basis |
|---|---|
| Managing your account and providing the Service | Performance of the contract (ToU) |
| Authentication (OTP email, Google, Apple) | Performance of the contract |
| Billing and subscription management via Stripe | Performance of the contract |
| Service improvement and usage analysis | Legitimate interest |
| Detection and correction of technical errors | Legitimate interest |
| Service-related communications (transactional emails) | Performance of the contract |
| Onboarding and marketing emails about the Service | Legitimate interest, with an unsubscribe link in every email |
| Measurement of our advertising campaigns (Meta Pixel) | Legitimate interest |
| Referral program | Performance of the contract |
| Compliance with our legal obligations (billing, retention) | Legal obligation |
4. Retention period
| Data category | Retention period |
|---|---|
| Account and profile data | Duration of the subscription + 30 days after account deletion |
| Guidebook content and guest data | Duration of the subscription + 30 days after account deletion |
| Billing data | 10 years (legal obligation) |
| Analytics data (PostHog) | 24 months |
| Error logs (Sentry) | 90 days |
| Contact form messages | As long as needed to answer, then deleted |
| Attribution cookie (marketing website) | 30 days |
| Local storage data (session, preferences) | Until logout or deletion by the user |
5. Subprocessors and third-party services
We use the following subprocessors to operate the Service and the marketing website:
| Service | Function | Data processed | Location |
|---|---|---|---|
| Supabase | Hosting, database, authentication, file storage | All Service data | Switzerland (AWS, Zurich region) |
| Stripe | Payment and subscription management | Email, name, payment data | European Union / United States (certified) |
| Resend | Sending of transactional, onboarding and guest emails, and of contact form messages | Email, name, email content | United States |
| PostHog | Product analytics and usage events | User identifier, email, interaction events, device data | European Union |
| Sentry | Error monitoring and diagnostics | Technical data, IP address, user identifier | European Union (DE region) |
| OAuth authentication, Google Maps URL resolution | Google profile data (email, name) | United States (standard contractual clauses) | |
| Apple | Sign In with Apple authentication | Apple profile data (email, name) | United States (standard contractual clauses) |
| Vercel | Hosting of the marketing website, audience measurement (Vercel Analytics, Speed Insights) | IP address, request logs, pages viewed (aggregated) | United States |
| Plausible | Cookieless audience measurement on the marketing website | Pages viewed, referrer, country, browser and device type | European Union |
| Meta Platforms | Advertising measurement and audiences (Meta Pixel on the marketing website) | Pages viewed, IP address, browser data, pixel cookie identifiers | United States |
6. Local storage
The application uses local storage on your device (AsyncStorage on mobile, localStorage on the web) for the following items:
- Authentication session (Supabase tokens)
- User preferences (language, theme, onboarding progress)
- Pending referral code
This data is not transmitted to third parties and remains on your device. It is deleted upon logout or uninstallation of the application.
7. Data made public
When you publish a guidebook, the following information becomes publicly accessible via a unique URL:
- The content of the guidebook (texts, images, accommodation information)
- The guidebook URL (wonderguest.app/l/[token])
- The associated QR codes (wonderguest.app/q/[token])
No personal data of the host (email, name, account information) is exposed publicly through these URLs.
8. Your rights
8.1 Rights under the GDPR
In accordance with the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: obtain a copy of your personal data
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: request the deletion of your data
- Right to portability: receive your data in a structured, machine-readable format
- Right to object: object to the processing of your data based on legitimate interest
- Right to restriction: request restriction of processing in certain cases
To exercise these rights, contact us at support@wonderguest.app. We will respond within 30 days.
You may also lodge a complaint with the CNIL: www.cnil.fr
8.2 Residents of the United States
We do not sell personal data. On the marketing website, the Meta Pixel shares browsing data with Meta Platforms for advertising measurement, which some state laws, including the California Consumer Privacy Act (CCPA), treat as “sharing” or “targeted advertising”. You can limit it by blocking the pixel cookies in your browser and through your Meta ad preferences, as described in the Cookie Policy. The application itself does not share data for advertising.
Where a United States state privacy law applies to WonderGuest, residents of that state may, subject to verification of their identity:
- know what personal data we collect, use and disclose, and receive a copy of it;
- request the correction or the deletion of their data;
- opt out of the sale of their data, of its sharing for targeted advertising and of profiling with legal or similarly significant effects (we do none of these in the application);
- not be discriminated against for exercising these rights;
- appeal our decision on a request by replying to our answer; we will explain the outcome of the appeal and, where required, how to contact your state attorney general.
Requests can be sent to support@wonderguest.app, by you or by an agent you have authorized in writing. We answer within 45 days. We use the data you provide in a request only to verify and fulfil it.
Under the California “Shine the Light” law, we confirm that we do not disclose personal data to third parties for their own direct marketing purposes.
9. Security
We implement the following technical and organizational measures to protect your data:
- Encryption in transit (TLS/HTTPS) for all communications
- Encryption at rest of data stored in Supabase
- Passwordless authentication (OTP, OAuth) reducing credential-related risks
- Row Level Security (RLS) policies at the database level, ensuring that each user only accesses their own data
- Strict separation of production and development environments
- API keys and secrets managed through secure environment variables
Our Security page gives more detail. If a security incident affects your personal data, we inform you and the competent authorities as required by applicable law, including United States state breach notification laws.
10. International data transfers
Service data is stored in Switzerland, a country covered by a European Commission adequacy decision. Some of our subprocessors (Google, Apple, Stripe, Resend, Vercel, Meta Platforms) may process data in the United States. These transfers are covered by:
- The EU-US Data Privacy Framework, where the provider is certified
- Standard contractual clauses (SCCs) adopted by the European Commission
- The certifications and contractual commitments of each provider
PostHog, Sentry and Plausible process data in the European Union. If you use the Service from the United States, your data is transferred to and stored in Europe as described above.
11. Children’s privacy
The Service is intended for adults. Accounts may only be created by persons of legal age, and the Service is not directed to children under 13. We do not knowingly collect personal data from a child under 13; if you believe that we have, contact us and we will delete it.
12. Marketing emails
After you create an account, we may send you onboarding and marketing emails about the Service. Every such email contains an unsubscribe link, and opting out takes effect within 10 business days. Transactional emails (one-time codes, receipts, service notices) are not affected by this choice.
13. Do Not Track and Global Privacy Control
Our websites do not currently respond to “Do Not Track” or Global Privacy Control browser signals. Third parties listed in section 5 may collect data about your activity across websites through the Meta Pixel, as described in section 2.5.
14. Changes
This policy may be updated. Any material change will be notified by email or through the Service at least 15 days before it takes effect. The last updated date is shown at the top of this document.
15. Contact
For any question relating to the protection of your personal data, you can contact us at: support@wonderguest.app