Data Security
Last updated June 1, 2026
Protecting the data hotels and their guests trust us with is core to StayOS. This page summarizes the safeguards we apply.
Encryption
Data is encrypted in transit using TLS and encrypted at rest by our infrastructure provider. Access to production systems is restricted and logged.
Isolation
Every workspace's data is scoped to its organization with row-level security, so one customer can never read another's data.
Access control
Role-based permissions limit what each teammate can see and do. Cleaners and maintenance staff never see payments or guest financials. Administrative access to infrastructure follows least-privilege principles.
Payments
Card payments are handled by a PCI-DSS-compliant payment processor. StayOS does not store full card numbers.
Reporting an issue
If you believe you have found a security vulnerability, please email security@stayos.app. We investigate every report.
Questions about this policy? Email privacy@stayos.app.