Back
DE|IT|EN

Privacy Policy

Last updated: April 2026 · Applies to guestflow.io

1. Controller

The data controller for this platform is GuestFlow, operated by Deborah Salcher, South Tyrol / Alto Adige, Italy. Privacy inquiries: deborah.salcher@gmail.com

2. Data we process

CategoryDataLegal basis
Operator account dataEmail address, name, business details, Stripe payment dataArt. 6(1)(b) GDPR (Contract performance)
Guest conversation dataChat messages, guest profile (e.g. family, dog), language, session ID (anonymous UUID)Art. 6(1)(f) GDPR (Legitimate interest)
Technical logsIP address (rate-limiting only, not permanently stored), server logs without PIIArt. 6(1)(f) GDPR (IT security)

3. Purposes of processing

4. Retention periods

5. Sub-processors

ProviderPurposeLocation
SupabaseDatabase hostingEU/EEA
VercelWeb hosting and Edge RenderingUSA (SCCs)
AnthropicClaude AI APIUSA (SCCs)
StripePayment processingEU
UpstashRedis rate-limitingEU

US transfers rely on Standard Contractual Clauses (SCCs) under Art. 46 GDPR. See Anthropic Privacy Policy.

6. Your rights

Contact: deborah.salcher@gmail.com

7. Technical and organisational measures

8. Cookies and local storage

GuestFlow uses sessionStorage in the guest chat (anonymous UUID). No tracking or advertising cookies are set. The dashboard uses Supabase authentication cookies (technically necessary for login).

Last updated: April 2026.