Bondmako
HomeLegal

Legal / BondMako legal

Privacy Policy

This company-wide policy explains what BondMako collects across StayOS and related products, why we collect it, who processes it, how long we keep it, and how you can request access, correction, or deletion. BondMako does not sell personal data.

Effective 2 August 2026 · Last updated 4 August 2026 · privacy@bondmako.com

Bondmako does not sell personal data.

On this page
  1. 1. Who we are (controller)
  2. 2. Scope and who this policy covers
  3. 3. We do not sell personal data
  4. 4. What we collect
  5. 5. StayOS — product-specific processing
  6. 6. Why we collect and use data
  7. 7. Legal bases (where GDPR / similar laws apply)
  8. 8. Who processes data (processors and infrastructure)
  9. 9. Sharing and third-party protections
  10. 10. Retention and deletion
  11. 11. Your rights — access, correction, deletion, and consent withdrawal
  12. 12. Security measures
  13. 13. International transfers
  14. 14. Children
  15. 15. Cookies and similar technologies
  16. 16. Other Bondmako products
  17. 17. Changes to this policy
  18. 18. Contact

1. Who we are (controller)

Bondmako (“Bondmako”, “we”, “us”, or “our”) operates hospitality and business operating software, including StayOS and related Bondmako products.

For privacy questions, data-subject requests, and complaints about personal data processing, contact privacy@bondmako.com. For general legal notices, contact legal@bondmako.com. Operational support may also reach support@bondmako.com.

This Privacy Policy applies company-wide across Bondmako products unless a product-specific notice states otherwise. Product sections below describe additional processing unique to that product.

2. Scope and who this policy covers

This policy covers personal data we process when you create an account, sign in, invite staff, operate a hotel property, use mobile or desktop apps, contact support, or otherwise use Bondmako services.

It covers account holders, employees and contractors invited into a workspace, managers and administrators, and — where hotel operators enter guest or reservation information — guest-related data processed on behalf of the hotel customer.

Where a hotel or other business customer uses StayOS to process guest data, that customer typically acts as an independent controller of guest data. Bondmako processes that data as a service provider / processor to deliver the hotel operating system, except where we determine purposes and means ourselves (for example authentication, security, billing of the Bondmako account, or product telemetry).

3. We do not sell personal data

Bondmako does not sell personal data. We do not rent or trade personal data for monetary consideration.

We do not share personal data with third parties for their independent advertising or marketing purposes.

We only disclose personal data as described in this policy: to authorised workspace users, to infrastructure and service providers who process data on our instructions, when required by law, to protect rights and safety, or in connection with a corporate transaction subject to appropriate protections.

4. What we collect

Account and identity data: name, email address, authentication credentials or tokens, role and permission assignments, workspace membership, and profile display details.

Staff and workplace data: staff profiles, property access grants, department or role lane, invitation and acceptance records, and operational language preferences where configured.

Hotel / property context: property identifiers, property settings, business date and operational configuration needed to run the property workspace.

Operational activity: actions taken in the product (for example check-in/out workflows, housekeeping task updates, folio or cashier events where enabled, messaging, approvals, configuration changes) and related audit evidence.

Device and session data: device type, app version, OS version, IP address, session tokens, approximate location derived from network where needed for security, crash or diagnostic signals, and security logs.

Communications: support messages, invitation emails, delivery status for transactional email, and related correspondence.

Guest and reservation data entered by authorised hotel users (StayOS and related hospitality modules): guest names and contact details, reservation and stay records, room assignments, folio/payment references entered into the system, identification or document references where the hotel enables those features, and other hospitality operating data the hotel chooses to store.

We do not require you to provide more data than needed to operate the relevant product functions. Some fields are optional; others are required for authentication, security, or a specific operational workflow.

5. StayOS — product-specific processing

StayOS is Bondmako’s hotel property operating system (web, Capacitor Android shell, and native iOS where published). It is designed for authorised hotel staff, not for public guest self-service as a consumer social app.

StayOS collects and processes: staff account details; staff profiles; hotel/property access; role and permission assignments; invitations; operational activity across front desk, housekeeping, maintenance, night audit, revenue, and related desks where enabled; device/session data for sign-in and security; and guest/reservation/folio data entered by authorised users.

Why StayOS processes this data: authenticate users; run hotel operations; enforce role and property scope; maintain security and audit trails; deliver invitation and operational email; provide support; improve reliability and service quality; and meet legal or contractual obligations.

Hotel customers remain responsible for lawful collection of guest data, notices to guests where required, retention choices configured in property settings, and internal staff access policies. StayOS Settings → Privacy & Retention controls are operational policy settings for the property; they do not replace this Privacy Policy.

Mobile apps may open this Privacy Policy in Safari or an in-app browser from Settings → Privacy & Legal. The canonical public URL is https://bondmako.com/privacy.

6. Why we collect and use data

Authentication and account administration.

Providing hotel and business operating features you request.

Security monitoring, fraud and abuse prevention, and incident response.

Auditing, accountability, and configuration change evidence.

Customer support and service communications.

Service improvement, reliability, diagnostics, and product quality (including aggregated or de-identified analysis where feasible).

Compliance with applicable law, regulatory requests, and enforcement of terms.

7. Legal bases (where GDPR / similar laws apply)

Contract performance: to provide the Bondmako services you or your organisation subscribe to.

Legitimate interests: securing the platform, preventing abuse, improving reliability, and operating internal administration — balanced against your rights and expectations.

Legal obligation: where we must retain or disclose records.

Consent: where we ask for it (for example certain optional communications or local consent flows). You may withdraw consent where processing is consent-based, without affecting prior lawful processing.

Hotel customers may have separate legal bases for guest data they enter into StayOS; Bondmako processes that data to provide the service under the customer relationship.

8. Who processes data (processors and infrastructure)

Bondmako personnel and authorised contractors under confidentiality and access controls.

Infrastructure and service providers that process data on our instructions, which may include: cloud hosting and content delivery; authentication and database providers (including Supabase); transactional email delivery (for example Resend or other configured mail transports); monitoring, logging, and error diagnostics; payment processors where billing features are used; and app distribution platforms (Apple App Store / TestFlight, Google Play) according to their terms when you install our apps.

These providers may only process personal data as needed to deliver their services to Bondmako, under contractual protections appropriate to the service.

We do not authorise processors to sell your personal data or to use it for their own unrelated marketing.

9. Sharing and third-party protections

Within your workspace: data is visible to users granted access by your organisation’s administrators, according to roles and property scope.

Service providers: as described above, under processing agreements / equivalent protections where required.

Legal and safety: if required by law, court order, or to protect Bondmako, our users, guests, or the public from harm, fraud, or security threats.

Corporate events: in connection with merger, acquisition, financing, or asset transfer, subject to continuing confidentiality and privacy commitments.

App platforms: Apple and Google may receive limited account, device, and crash information as part of distributing and securing mobile applications.

10. Retention and deletion

We retain personal data only as long as needed for the purposes above, including providing the service, maintaining security and audit records, resolving disputes, enforcing agreements, and meeting legal, tax, and accounting requirements.

Retention varies by record type. Operational and audit logs may be kept longer than day-to-day profile fields when needed for security and accountability.

When an account or workspace is closed, or when a validated deletion request is completed, we delete or de-identify personal data in active systems within a reasonable period, except where retention is required by law or needed for security, fraud prevention, or dispute resolution.

Backups may persist for a limited period before being overwritten according to our backup rotation.

Hotel-configured retention settings in StayOS (for example guest or document retention preferences) guide property operations but do not override mandatory legal holds.

11. Your rights — access, correction, deletion, and consent withdrawal

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data; to object to certain processing; and to withdraw consent where processing is based on consent.

To exercise these rights, email privacy@bondmako.com with the subject line “Privacy Request”, and include the email on your Bondmako / StayOS account, the product you use, and whether you seek access, correction, deletion, or another right.

We may need to verify your identity before fulfilling a request. If you are a hotel employee, some requests may need to be coordinated with your employer (the hotel workspace administrator), especially where data is controlled by the hotel.

You may also use in-app Settings → Privacy & Legal → Request account/data deletion, which opens this section and provides the contact path.

You may lodge a complaint with your local data-protection authority where applicable.

12. Security measures

We apply technical and organisational measures designed to protect personal data, including encryption in transit, access controls and role-based permissions, authentication controls, audit logging for sensitive administrative actions, least-privilege operational access, and monitoring for abuse and anomalies.

No method of transmission or storage is perfectly secure. You must protect your devices, credentials, and staff access. Administrators should promptly revoke access for users who leave the organisation.

If we become aware of a personal-data breach affecting you, we will notify you and/or regulators as required by applicable law.

13. International transfers

Bondmako may process and store data in the European Union and/or other countries where our providers operate.

Where personal data is transferred internationally, we use appropriate safeguards required by applicable law, such as contractual protections (including Standard Contractual Clauses where applicable) and provider security commitments.

14. Children

Bondmako products, including StayOS, are business and hospitality operations tools. They are not directed to children and are not intended for use by individuals under 16 as end consumers.

Guest records for minors may appear only where a hotel lawfully records them as part of a stay. Hotels are responsible for lawful handling of such records.

15. Cookies and similar technologies

We use cookies and similar technologies that are necessary for authentication, session security, preference storage (for example language), and core product operation.

We do not use advertising cookies or third-party advertising pixels to sell or target ads based on your Bondmako usage.

Native mobile apps primarily use secure local storage and tokens rather than browser cookies; equivalent session and security technologies apply.

16. Other Bondmako products

Owner, EmployeeOS, Concierge and future Bondmako apps reuse this company Privacy Policy. They may process additional account, workforce, messaging, or operations data needed for those products under the same principles: no sale of personal data; purpose limitation; security; and rights of access, correction, and deletion.

If a product requires a materially different notice, we will publish an addendum linked from that product and update the effective date here.

17. Changes to this policy

Effective date: 2 August 2026. Last updated: 4 August 2026.

We may update this Privacy Policy to reflect legal, operational, security, or product changes. When we do, we will revise the effective date on this page.

If a change is material, we will provide additional notice where required (for example in-product notice, email to account owners, or App Store / Play release notes).

Continued use of the services after the effective date of an update constitutes notice of the updated policy, except where applicable law requires express consent.

18. Contact

Privacy / data-protection requests: privacy@bondmako.com

Legal notices: legal@bondmako.com

Operational support: support@bondmako.com

Public Privacy Policy URL: https://bondmako.com/privacy

Canonical URL: https://bondmako.com/privacy

Bondmako home · All legal documents · Terms of Service · Request access, correction, or deletion