Who we are and what this policy covers
Supalobby is a unified inbox for accommodation hosts. It collects the messages a host receives on WhatsApp, Instagram, Facebook Messenger, email and booking platforms into one place, suggests replies with the help of an AI assistant, and sends the replies the host approves.
In this policy, “Supalobby” and “we” refer to the operator of the service. This policy explains what personal data we process when you use the Supalobby application at supalobby.vercel.app, the website chat widget a host can embed on their own site, and the voice assistant, and how we protect it.
Supalobby is a business tool. It is not directed at children and we do not knowingly collect data from anyone under 16.
Hosts, guests and us
Hosts are the businesses and people who create a Supalobby account and connect their channels. For host account data we are the data controller.
Guests are the people who message a host. Guest data belongs to the host’s relationship with the guest. For guest data we act as the host’s data processor: we store and display it only to provide the inbox and act only on the host’s instructions. The host decides what happens to it and is the data controller.
If you are a guest and have questions about how a host handles your data, contact that host first. You can also write to us and we will forward your request to the host and help them answer it.
What we collect
Host account data
Email address, a password hash managed by our authentication provider, organisation name, language and theme preferences, and sign-in records.
Channel connections
Identifiers for the accounts a host connects, such as WhatsApp Business Account and phone number ids, Instagram account id and username, Facebook Page id, and mail server addresses, together with the credentials needed to use them: OAuth tokens, app passwords or session tokens. Credentials are encrypted before they are stored.
Guest conversations, by channel
- WhatsApp. The guest’s phone number and profile name, message text, media, reactions, delivery and read status. When a host connects a number that is also used in the WhatsApp Business app, Meta can also synchronise up to six months of earlier conversation history and the host’s WhatsApp contacts.
- Instagram. The guest’s Instagram-scoped id, username, name and profile picture where available, direct messages, shared media, reactions, story replies and story mentions, and the existing conversation threads imported when the account is connected.
- Facebook Messenger. The guest’s Page-scoped id, name and profile picture where available, messages and delivery status.
- Email. Sender and recipient addresses, subject, message body, attachments and the headers used to thread replies. We read a host’s mailbox for guest messages only; newsletters and other unrelated mail are filtered out and not kept.
- Booking platforms (Slowhop, Aloha Camp). Booking references, guest names, stay dates and the messages exchanged, read through the host’s own account on those platforms.
- Airbnb and Booking.com. We parse the notification emails those platforms send to the host to extract guest messages and reservation details. We do not connect to Airbnb or Booking.com directly.
- Website chat. Messages typed into a host’s website widget and a random thread token stored in the visitor’s browser so the conversation survives a page reload. No account is required.
- Voice assistant. The text transcript of each turn of a call handled by a host’s voice assistant. Audio is processed by our speech provider and is not stored by Supalobby.
Content the host adds
Property details, availability rules, knowledge base entries, samples of the host’s own past replies used to learn their writing style, and AI assistant settings.
Technical data
Server logs, incoming webhook payloads as received from channel providers, background job records and AI request traces. We keep these only to run and debug the service.
How we use it
- Provide the inbox. Receive, store, thread and display conversations, and recognise the same guest across channels when identifiers such as a phone number or email address match.
- Send messages. Deliver the replies a host writes or approves to the guest’s channel.
- Suggest replies. Generate draft answers and, where a host enables it, automatic answers, as described in the next section.
- Run the service. Authentication, security, abuse prevention, debugging and support.
- Meet legal obligations and respond to lawful requests.
We do not sell personal data, use it for advertising, or build profiles of guests for any purpose other than showing the host their own conversation history.
Our legal bases under the GDPR are performance of our contract with the host (Article 6(1)(b)), our legitimate interest in running a secure and reliable service (Article 6(1)(f)) and compliance with legal obligations (Article 6(1)(c)). For guest data we act on the host’s documented instructions.
AI assistance
Supalobby uses large language models to draft replies. When a guest message arrives, the conversation, the host’s knowledge base and property details, and live availability from the host’s booking system are sent to our AI provider to produce a suggested reply.
On messaging channels such as WhatsApp, Instagram, Messenger, email and booking platforms, the suggestion is shown to the host, who edits, approves or dismisses it. Nothing is sent on those channels without a person’s decision. On the host’s own website chat and voice assistant, the host can choose to let the assistant answer immediately.
A host can ask Supalobby to learn their writing style. This uses the host’s own past replies and produces a short style description. It does not use guests’ messages as examples.
Our AI providers process data under contract, use it only to return a response, and do not train their models on it. We keep a record of each AI request and response for debugging for up to 90 days.
Meta platform data: WhatsApp, Instagram and Messenger
When a host connects WhatsApp, Instagram or Facebook Messenger, we receive data through Meta’s APIs: the WhatsApp Business Platform, the Instagram API with Instagram Login and the Messenger Platform. The host grants us access through Meta’s own consent screens and can revoke it at any time.
We use Meta platform data only to display the host’s conversations, show who the guest is, and deliver the host’s replies. We comply with the Meta Platform Terms and Developer Policies, the WhatsApp Business Messaging Policy and the Messenger and Instagram messaging policies. In particular we:
- only message people who have messaged the host first or otherwise consented, within the messaging windows those platforms allow;
- never use Meta platform data for advertising, never sell it, and never share it with anyone other than the service providers listed in this policy;
- request only the permissions needed for messaging and remove our access when a host disconnects;
- delete Meta platform data for a person on request, and when a host disconnects a channel or deletes their account, as described under Deleting your data.
If you remove Supalobby from your Facebook or Instagram settings, Meta calls our deauthorisation endpoint and we revoke the stored credentials for that account at once. If you ask Meta to delete your data, Meta calls our data deletion endpoint: we erase what we hold for that account and return a confirmation code, which you can check any time at /data-deletion. Meta’s own handling of your data is described in the Meta Privacy Policy.
Where data is stored
Our primary database and file storage are in the European Union (Ireland). Some service providers operate in the United States. Where personal data leaves the European Economic Area we rely on the European Commission’s Standard Contractual Clauses or the EU-US Data Privacy Framework, depending on the provider.
How long we keep it
| Data | Kept for |
|---|---|
| Guest conversations, attachments and call transcripts | Until the host deletes them or closes the account |
| Channel credentials | Until the host disconnects the channel, then deleted at once |
| Raw webhook payloads, job records and AI traces | Up to 90 days |
| Host account data | Until account deletion, then removed within 30 days |
| Backups | Expire within 30 days of the data being deleted |
| Records of deletion requests | 12 months, to show the request was carried out |
Security
- All connections, including those to channel providers, are encrypted in transit.
- Channel credentials are encrypted at rest with a key held outside the database.
- Hosts can only see their own organisation’s data, enforced by database row-level security.
- Every incoming webhook is verified against the provider’s signature before it is processed.
- We request the narrowest platform permissions that the service needs, and credentials never reach the browser.
No system is perfectly secure. If we learn of a breach affecting your data we will notify you and, where required, the supervisory authority without undue delay.
Your rights
Under the GDPR you can ask to access the personal data we hold about you, have it corrected or erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. Hosts can exercise most of these rights directly in the app; for anything else, write to us. Guests should contact the host they messaged, and we will help the host respond.
You can complain to a supervisory authority. Ours is the Polish Personal Data Protection Office (Urząd Ochrony Danych Osobowych, uodo.gov.pl). You may also complain to the authority where you live.
Deleting your data
You can have your data deleted in any of the ways below. Every request gets a confirmation code, and you can check its status at /data-deletion. We complete requests within 30 days; copies in backups expire within a further 30 days.
Hosts
- Disconnect a channel in Settings › Integrations. Its credentials are revoked and deleted at once; the conversations stay in your inbox until you delete them.
- Delete individual conversations from the inbox.
- Email us to close your account. Everything in your organisation is deleted.
Guests and anyone else
Email kontakt@wilczavilla.pl with the channel and the identifier we would know you by: your phone number, Instagram username, email address or Facebook name, and, if you know it, the host you messaged. We confirm receipt, delete the data and send you a confirmation code you can quote later.
Facebook and Instagram users
Requesting deletion through your Facebook or Instagram settings sends a signed request from Meta to our data deletion endpoint. We delete the data we hold for that account automatically and return a confirmation code, which Meta shows to you. Removing the app without a deletion request revokes our access but keeps the host’s conversation history until the host deletes it.
A host who deletes a conversation in Supalobby may still hold copies in their own channel apps, for example the WhatsApp Business app or their mailbox. Those copies are outside our control.
Changes and contact
We will post any changes to this policy here and update the date at the top. For material changes to how we handle host or guest data we will notify hosts by email before they take effect.
Data controller for host accounts and processor contact for guest data: Supalobby.
Email: kontakt@wilczavilla.pl