Legal

Privacy Policy

Last updated: June 16, 2026

1. Introduction

GuestFlow (“we,” “us,” or “our”) is a product of WEP. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our website, dashboard, booking pages, and related services (collectively, the “Service”).

2. Roles: hosts vs. guests

Hosts (podcasters who create GuestFlow accounts) are generally the data controllers for guest information collected through their booking pages.

GuestFlow acts as a data processor for guest data submitted through host booking flows, and as a data controller for host account data, billing, and platform analytics.

3. Information we collect

We may collect the following categories of information:

  • Account information — name, email address, password hash, profile details, and authentication tokens when you register or sign in.
  • Show and booking configuration — podcast names, descriptions, branding, availability rules, event types, intake questions, and integration settings.
  • Guest information — names, emails, optional mobile numbers, bios, social links, intake answers, timezone, consent records, and booking history submitted through public booking pages, invite links, or embed widgets.
  • Communications — confirmation emails, email and SMS reminders, prep packs, and lifecycle messages sent through the Service.
  • Usage and device data — log data, browser type, pages viewed, and feature usage for security and product improvement. Booking page analytics store a hashed visitor id (derived from IP and user agent), optional UTM or source parameters, referrer host, device class, and coarse location from the hosting platform. Raw IP addresses are not stored for widget analytics.
  • Payment information — billing name, email, and subscription status. Full payment card numbers are processed by Stripe and not stored on our servers.
  • Integration data — calendar busy times, OAuth tokens for connected services (Google Calendar, Zoom), and webhook payloads where enabled.

4. How we use information

  • Provide, operate, maintain, and improve the Service
  • Process bookings, send confirmations, reminders, and host-configured automations
  • Generate AI episode briefs when enabled by the host
  • Enforce plan limits, prevent fraud, and secure accounts
  • Process subscriptions and communicate billing updates
  • Respond to support requests and legal obligations
  • Analyze aggregated usage to improve product design

6. Sharing and subprocessors

We share information with service providers who help us operate GuestFlow. We do not sell personal information. Key subprocessors include:

  • Supabase — database, authentication, and file storage
  • Stripe — payment processing and subscription management
  • Resend — transactional email delivery
  • Twilio — SMS recording reminders when a host enables them and a guest provides a mobile number
  • AI providers — episode brief generation when enabled
  • Google / Zoom — calendar and meeting integrations when connected by hosts

We may also disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition with appropriate safeguards.

7. Data retention

We retain account and booking data while your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Hosts may export or request deletion of data through dashboard settings or by contacting support. Backup copies may persist for a limited period after deletion.

8. Security

We implement technical and organizational measures including encryption in transit (TLS), row-level security on database access, access controls, and regular security reviews. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

9. Your rights

Depending on your location, you may have rights to:

  • Access a copy of your personal data
  • Correct inaccurate information
  • Delete your data, subject to legal exceptions
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with a supervisory authority

Guests should contact the podcast host first for booking-related data requests. Hosts and users may contact support@guestflow.app to exercise rights.

10. Cookies and similar technologies

We use essential cookies and local storage for authentication sessions and security. We may use analytics cookies to understand product usage. You can control non-essential cookies through your browser settings; disabling essential cookies may limit Service functionality.

11. International transfers

We may process data in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for transfers from the EEA/UK.

12. Children

GuestFlow is not directed to children under 16. We do not knowingly collect personal information from children. Contact us if you believe we have collected data from a child.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. Continued use after changes become effective constitutes acceptance of the revised policy.

14. Contact us

GuestFlow · support@guestflow.app
See also our Terms of Service.