AllInGuide
← Back to websiteLast updated: 21 September 2026

Privacy policy

This notice explains which data AllInGuide processes to provide the website, host area and digital guest guides.

Data processed

  • Account data: email, name, sign-in method and technical session data.
  • Property and guide content entered by the host, including images, Wi-Fi, check-in, services and local recommendations.
  • Essential usage data: guide views, assistant questions, technical information and IP address when needed for security and rate limiting.
  • Billing data and Stripe identifiers required to manage subscriptions; full card data is not stored by AllInGuide.

Purposes

  • Provide and protect accounts, guides, publishing and billing.
  • Run AI assistant, AI setup and requested search features.
  • Prevent abuse, fraud and unauthorized access.
  • Provide operational statistics and maintain service reliability.

Service providers

  • OpenAI may receive the minimum guide context needed when AI features are used; application requests are configured with store=false.
  • Google is used for Google Sign-In and, when requested by the host, Google Places.
  • Stripe handles checkout, payments, invoices, customer portal and subscription status.
  • The infrastructure/VPS provider processes data required to host the application and database.

Retention

  • Assistant questions and answers: up to 90 days.
  • Guide view events: up to 365 days; session identifiers are removed after 30 days.
  • AI setup drafts: up to 30 days; AI counters and technical usage data: up to 90 days.
  • Admin audit IP addresses: removed after 90 days; admin audit records: up to 730 days.
  • Technical Stripe webhook events: up to 400 days. Expired tokens and obsolete sessions are removed automatically.

Control of your data

Users can update their profile and delete their account from the Account area. Deletion first cancels any Stripe subscription and then removes the account and linked database data. Some technical records already detached from the account may remain for the stated retention period.

Security

AllInGuide uses HttpOnly authentication cookies, CSRF protection, rate limits, expiring sessions, separated secrets and authorization checks. No security measure can eliminate every risk.

Controller and privacy contact

Informazioni legali da completare.
Configura NEXT_PUBLIC_LEGAL_ENTITY_NAME e NEXT_PUBLIC_PRIVACY_EMAIL prima dell’uso commerciale; indirizzo e identificativo fiscale sono opzionali se non applicabili.