Privacy Policy

Last updated: April 10, 2026

Bedly (“we”, “our”, “us”) operates the Bedly booking management platform (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service, in compliance with the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (nFADP/DSG), and other applicable data protection laws.

1. Data Controller

Bedly
Switzerland
Email: privacy@bedly.io

2. Data We Collect

2.1 Property Manager Data (Account Holders)

  • Account information: Name, email address, password (hashed), phone number
  • Property information: Property name, address, description, photos, settings
  • Usage data: Login timestamps, features used, pages visited
  • Payment data: Processed by Stripe — we do not store credit card details

2.2 Guest Data (Processed on Behalf of Property Managers)

  • Booking information: Name, email, phone, check-in/check-out dates, booking reference
  • Identity documents: Passport/ID photos uploaded for verification (stored encrypted, auto-deleted after checkout + 30 days)
  • Communication: Messages exchanged through the platform

2.3 Automatically Collected Data

  • IP address, browser type, device type
  • Cookies and similar technologies (see our Cookie Policy)

3. How We Use Your Data

PurposeLegal Basis (GDPR)
Provide and maintain the ServiceContract performance (Art. 6(1)(b))
Process bookings and paymentsContract performance (Art. 6(1)(b))
Send transactional emailsContract performance (Art. 6(1)(b))
AI-powered features (message suggestions, concierge)Legitimate interest (Art. 6(1)(f))
Improve the Service and fix bugsLegitimate interest (Art. 6(1)(f))
Comply with legal obligations (e.g., tax records)Legal obligation (Art. 6(1)(c))
Marketing communications (only with consent)Consent (Art. 6(1)(a))

4. AI Processing

Our Service uses AI (powered by Anthropic Claude) for:

  • Generating suggested replies to guest messages
  • Answering guest questions through the AI concierge
  • Generating property descriptions and translations

AI processing is performed server-side. Data sent to the AI provider is not used for training their models. We have a Data Processing Agreement with Anthropic that ensures GDPR compliance.

5. Data Sharing

We share personal data only with:

RecipientPurposeLocation
SupabaseData storage & authenticationEU (AWS Frankfurt)
VercelApplication hostingEU/US
StripePayment processingEU/US
ResendTransactional emailsUS
AnthropicAI featuresUS

For US-based processors, we rely on Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework where applicable.

6. Data Retention

  • Account data: Retained while account is active + 30 days after deletion
  • Guest booking data: Retained as required by tax law (typically 10 years for financial records)
  • Identity documents: Auto-deleted 30 days after check-out
  • Messages: Retained while account is active
  • Demo accounts: Auto-deleted after 24 hours

7. Your Rights

Under GDPR and nFADP, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Delete your data (“right to be forgotten”)
  • Restrict processing
  • Port your data to another service
  • Object to processing based on legitimate interest
  • Withdraw consent at any time

To exercise your rights, email us at privacy@bedly.io. We will respond within 30 days.

8. Data Security

  • All data encrypted in transit (TLS 1.3) and at rest
  • Row Level Security (RLS) policies isolate data between tenants
  • Authentication via Supabase Auth with secure session cookies
  • Rate limiting on all API endpoints
  • Input validation with Zod schemas

9. International Transfers

Some of our processors are located outside Switzerland/EU. We ensure adequate protection through Standard Contractual Clauses, adequacy decisions, or the EU-US Data Privacy Framework.

10. Children's Privacy

Our Service is not directed to individuals under 16. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or a notice in the Service.

12. Contact

For privacy inquiries: privacy@bedly.io

You also have the right to lodge a complaint with a supervisory authority: