Cabinly Privacy Policy
Last updated: 19 September 2026
This Privacy Policy explains how we process personal data in connection with the use of the Cabinly website and application, available at cabinly.io (the “Service” or “Cabinly”).
We want this document to be clear. If anything is unclear, email us at wecare@cabinly.io.
1. Data Controller
The controller of your personal data is:
Enlive Michał Michańczyk, ul. Długosza 4/1, 80-547 Gdańsk, Poland, Tax ID (NIP): 9571001658, Business Reg. (REGON): 221589533, contact e-mail: wecare@cabinly.io (the “Controller”, “we”, “us”).
We have not appointed a Data Protection Officer. For all matters relating to personal data, contact us at wecare@cabinly.io.
2. Who this Policy applies to
Cabinly is a tool for short-term rental property owners (“Hosts”) that lets them create their own booking page, accept payments and manage a calendar. Two groups of people interact with the Service:
- Hosts – people who create a Cabinly account and use the application. In relation to their data, we act as the controller.
- Guests – people who make a booking or get in touch through a booking page created by a Host. Guest data entered while handling a booking is generally processed by us as a processor on behalf of the Host – see section 10.
3. Data we process
3.1. Host (user) data
- Account data: name or company name, e-mail address, password (stored encrypted).
- Property data: property name and description, location, photos, prices, calendar availability, booking page content.
- Billing and payment data linked to a Stripe account (payments are handled by Stripe – see section 8).
- Technical data: IP address, device and browser type, system logs, cookie and analytics data.
- Correspondence: the content of messages you send us.
3.2. Guest (booker) data
- Booking data: name, e-mail address, optionally phone number, stay dates, number of guests, booking notes.
- Payment data: handled directly by Stripe. We do not store full payment card numbers.
- AI assistant (“Leo”) conversations: the content of questions and answers in the chat on the booking page.
- Technical data: IP address, device data, cookies.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running an account, providing the Cabinly service | Art. 6(1)(b) – performance of a contract |
| Handling bookings and payments | Art. 6(1)(b) – performance of a contract |
| Publishing posts to a connected Facebook Page and Instagram account | Art. 6(1)(b) – performance of a contract |
| Contact and handling enquiries | Art. 6(1)(b) and (f) – our legitimate interest |
| Security, fraud prevention, logs | Art. 6(1)(f) – our legitimate interest |
| Analytics and product development | Art. 6(1)(f) – our legitimate interest |
| Marketing (e.g. newsletter, product updates) | Art. 6(1)(a) – consent |
| Legal obligations (e.g. tax, accounting) | Art. 6(1)(c) – legal obligation |
| Establishing, exercising or defending claims | Art. 6(1)(f) – our legitimate interest |
Providing data is voluntary but necessary to use the Service – without certain data we cannot create an account or process a booking.
5. AI assistant “Leo”
The Service includes an AI-based assistant (“Leo”) that answers Guests’ questions about a property and their booking. Conversation content may be processed by a third-party AI model provider acting as our processor (OpenAI). Please do not enter sensitive data or information that is not needed to handle a booking into the chat.
6. Facebook and Instagram publishing
Cabinly is adding the option for a Host to connect their Facebook Page and Instagram account and publish posts from Cabinly. The feature is in development and awaits Meta’s App Review. If you connect them, this section applies.
When you connect Facebook or Instagram, we process:
- Meta access tokens for the connection (stored encrypted),
- the ID and name of the connected Facebook Page and the ID and username of the connected Instagram account,
- the content of posts you create or schedule in Cabinly: text, the photos you choose, the publish time, and – after publishing – the post ID and link.
We do not collect your Facebook password, your private messages or your friend list.
We use this data only to publish posts to your Page and Instagram account on your instruction and to show you the status of those posts. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
Post content goes to Meta Platforms Ireland Limited, which publishes it on Facebook and Instagram; from then on Meta’s own privacy policy applies to it. Photos being published are stored with Cloudflare. When you use AI-generated post text or photo analysis, the text and photos are sent to OpenAI.
Access tokens are kept until you disconnect the account – they are deleted at that moment – or until they expire. Post history is kept while your Cabinly account exists, or until you delete it.
To delete this data, disconnect Facebook and Instagram in the Cabinly app settings or write to wecare@cabinly.io. Step by step: Deleting your Facebook and Instagram data. Your other rights are described in section 12.
7. Cookies and tracking technologies
The Service uses cookies and similar technologies to:
- ensure the Service works correctly (essential cookies),
- analyse how the Service is used and record sessions – only with your consent (PostHog, servers in the European Union). Recordings are masked: we capture the layout, clicks and scrolling, without field contents and without text.
- visit statistics – only with your consent (Google Analytics 4, deployed through Google Tag Manager). We collect page views and events about how the Service is used: clicks on call-to-action buttons, playing the product demo, and changes to the savings calculator. Page views carry the address together with its campaign parameters (utm_source and the like), which is how we tell where a visit came from.
We do not run cookie-based marketing and we do not place advertising cookies on the Service.
Your decision is stored in a cookie named cabinly_consent (valid for one year, on the .cabinly.io domain). It covers the whole of Cabinly – this website, the owner panel and the property booking pages – so it is asked once rather than separately in each of them. PostHog cookies (ph_*) appear only after consent is given; before your decision nothing is sent to PostHog.
Google Analytics works the same way: the Google Tag Manager container is fetched at the moment consent is given, so before your decision we send nothing to Google and set none of that service’s cookies. After consent, _ga and _ga_* cookies appear (valid for up to two years, on the .cabinly.io domain), used only to tell one visit from the next for statistics. We use Google Consent Mode in its basic form, and the advertising consents (ad_storage, ad_user_data, ad_personalization) stay permanently denied. Google Signals is turned off, Analytics is not linked to Google Ads, and we do not run remarketing. When you withdraw consent we delete the _ga* cookies from your device.
You can change your choice at any time through the “Cookie settings” link in the footer, and through your browser settings. Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out beforehand.
8. Recipients and processors
We share data with trusted providers that help us deliver the Service, in particular:
- Stripe – payment processing (Stripe acts as an independent controller for payment data under its own privacy policy),
- hosting and server infrastructure provider – OVHcloud (OVH SAS, France); our servers are located in Germany,
- e-mail and communication providers – Resend (transactional messages sent by the Service; EU region, Ireland) and Google Workspace (correspondence with us),
- AI model provider – OpenAI (the Leo assistant, and AI-generated post text and photo analysis for Facebook and Instagram publishing),
- Meta Platforms Ireland Limited – publishing posts to a connected Facebook Page and Instagram account (Meta’s own privacy policy applies to published content),
- Cloudflare – storage of photos being published to Facebook and Instagram,
- analytics tools providers – PostHog (EU region) and Google Ireland Limited (Google Analytics 4 and Google Tag Manager),
- providers of accounting, legal and IT services.
We do not sell your personal data.
9. Transfers outside the EEA
Our server infrastructure is located in Germany, within the European Economic Area. Transactional mail and analytics run in their providers’ EU regions. Some of our other providers (Stripe, OpenAI, Meta, Cloudflare, Google Workspace, and Google Ireland Limited for Google Analytics) may process data outside the EEA, in particular in the United States; for the Google entities this is based on the adequacy decision for the EU–US Data Privacy Framework. In such cases, transfers are based on appropriate safeguards, in particular the Standard Contractual Clauses approved by the European Commission, or on an adequacy decision. You can request a copy of the safeguards by writing to wecare@cabinly.io.
10. Processing of Guest data on behalf of Hosts
For Guest data entered through a Host’s booking page, the Host is the controller of that data and Cabinly processes it on their behalf as a processor. The terms of this arrangement are set out in the data processing agreement that forms part of the Terms accepted by the Host. Cabinly processes Guest data solely to provide the service to the Host and in line with the Host’s documented instructions.
11. Retention periods
- Account and property data – for the duration of the contract (while the account exists), and afterwards for as long as needed for settlements and the limitation of claims.
- Booking and payment data – for the period required by law (including tax and accounting rules), typically up to 5 years from the end of the year in which settlement took place.
- Facebook and Instagram access tokens – until you disconnect the account (they are then deleted) or they expire; post history – while the account exists or until you delete it.
- Data processed based on consent – until consent is withdrawn.
- Technical data and logs – up to 12 months, unless longer is needed for security or claims.
12. Your rights
You have the right to:
- access your data and obtain a copy,
- rectify inaccurate or incomplete data,
- erase data (“right to be forgotten”),
- restrict processing,
- data portability,
- object to processing based on our legitimate interest,
- withdraw consent at any time (without affecting the lawfulness of processing before withdrawal),
- lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warszawa) or your local supervisory authority.
To exercise these rights, write to wecare@cabinly.io. We respond without undue delay and no later than within one month.
13. Security
We apply appropriate technical and organisational measures to protect data against unauthorised access, loss or destruction – including encrypted connections (HTTPS), access controls and encrypted password storage. However, no method of transmission or storage is 100% secure.
14. Children’s data
The Service is not directed at persons under 16, and we do not knowingly collect their data. If you believe a child’s data has been provided to us, write to wecare@cabinly.io and we will delete it.
15. Changes to this Policy
We may update this Policy, for example as the Service evolves or the law changes. We will notify you of material changes on the Service or by e-mail. The current version is always available at cabinly.io. The last update date is shown at the top of this document.
Cabinly is in an early stage of development (alpha). The scope of data processed and the list of providers may change as the product evolves – we will update this document accordingly.