Privacy Policy

Last updated: July 22, 2026

This Privacy Policy explains how S’living GmbH (“JamesBnB”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use:

  • our marketing website at https://jamesbnb.com (the “Website”);
  • our web application for property managers (the “Web App”);
  • our mobile application for property managers (the “Mobile App”); and
  • related services such as waitlist signup, onboarding, guest messaging assistance, channel sync, and support

(together, the “Service”).

JamesBnB is a business tool for hosts and property managers. It is not a consumer guest app.

1. Controller

The controller responsible for processing under this Privacy Policy is:

S’living GmbH
Geißstr. 13
70173 Stuttgart
Germany

Email: [email protected]

2. Roles for guest and booking data

When you connect a mailbox, messaging channel, or listing platform and we process guest names, contact details, booking details, or message content on your behalf, we generally act as a processor and you (the property manager / host account holder) act as the controller of that guest data.

We act as an independent controller for:

  • your JamesBnB account and authentication data;
  • waitlist and marketing lead data;
  • product, security, and operational logs needed to run and improve JamesBnB;
  • billing and commercial correspondence (if and when paid plans apply); and
  • support communications with you.

You are responsible for having a lawful basis to collect and process guest personal data and for providing any required notices to guests under applicable law (including GDPR where it applies).

3. Categories of personal data we process

Depending on how you use the Service, we may process:

3.1 Account and profile data

  • name, email address, password (stored as a one-way hash);
  • company / property-manager profile details (for example company name, phone, address, city, country);
  • preferred language and product settings (for example training mode, notification preferences);
  • authentication session data (web cookies / mobile tokens), login timestamps, and device/user-agent information used for security.

3.2 Waitlist and marketing data

If you join the waitlist, we may collect:

  • full name, email, optional phone number;
  • country, property count range, weekly guest-question range;
  • platforms used, time-cost answers, feedback willingness;
  • optional listing URL;
  • consent to contact you about early access, product feedback, and onboarding;
  • bot-protection signals (for example Cloudflare Turnstile).

3.3 Connected mailbox and channel credentials

To sync bookings and messages, you may connect:

  • Google / Gmail or Google Workspace OAuth tokens; and/or
  • IMAP/SMTP credentials; and/or
  • WhatsApp Business / Meta Embedded Signup connection data (including tokens and business/phone identifiers).

We store connection secrets in encrypted form where applicable. OAuth tokens from Google are used to access the connected mailbox as authorized by you and are not returned to your browser after setup.

3.4 Property, listing, and knowledge data

  • property and listing metadata (names, platform IDs/URLs, locations, images, status);
  • scraped or imported listing content used to answer guest questions;
  • knowledge-base content you store (for example Wi‑Fi details, check-in instructions, house rules).

Do not store secrets in knowledge bases unless necessary for guest operations; you remain responsible for what you instruct James to share with guests.

3.5 Guest, booking, and conversation data (processed for you)

When channels are connected, we may process:

  • guest identifiers and profile data (name, email, phone / WhatsApp number, platform user IDs, language, country);
  • booking details (dates, status, confirmation codes, guest counts, prices, special requests, platform);
  • conversation and message content (guest, host/manager, and AI-assisted messages), including translations and drafts;
  • conversation events, escalations, approvals, and related operational metadata;
  • embeddings / vector representations of messages and property knowledge used for search and retrieval;
  • calendar / iCal data linked to listings where configured.

3.6 Device, notification, and technical data

  • IP address, browser/app type, operating system, approximate request metadata;
  • Mobile App push tokens and notification permission status;
  • Web App session cookies necessary for login and CSRF protection;
  • crash/diagnostic or server logs needed to operate the Service.

We do not currently use third-party advertising pixels or product analytics SDKs in the Web App or Mobile App. Optional Website analytics (if configured) run only after cookie consent, as described in Section 6.

3.7 Support and communications

Content you send us by email or in-product support, and our replies.

We process personal data for the following purposes and legal bases under Art. 6 GDPR:

PurposeExamplesLegal basis
Provide the ServiceAccount creation, login, sync, messaging, AI drafts, translations, push alertsArt. 6(1)(b) contract; for guest data processed for you, Art. 6(1)(b)/(f) as applied by you as controller, and Art. 28 processing on your documented instructions
Security and abuse preventionAuthentication, CSRF, Turnstile, fraud/abuse monitoringArt. 6(1)(f) legitimate interests; Art. 6(1)(b) where necessary for the Service
Product improvement and qualityDebugging, reliability, AI quality monitoring (including LLM traces)Art. 6(1)(f) legitimate interests
Waitlist / early-access contactEmails about access, onboarding, feedbackArt. 6(1)(a) consent
Legal complianceResponding to lawful requests, retaining records where requiredArt. 6(1)(c) legal obligation
Corporate transactionsMerger, acquisition, restructuring diligenceArt. 6(1)(f) legitimate interests

You may withdraw consent for waitlist/marketing contact at any time by emailing [email protected]. Withdrawal does not affect prior lawful processing.

5. Artificial intelligence processing

JamesBnB uses AI models (currently Google Vertex AI / Gemini) to:

  • draft and send guest replies (subject to your settings, including training/approval modes);
  • enhance manager-written messages;
  • translate messages for display or delivery;
  • power the in-app manager assistant;
  • summarize or structure listing/knowledge content.

Message content, booking/property context, and related instructions may be sent to these AI providers solely to provide the Service.

We also use observability tooling (LangSmith) in production to trace AI runs for reliability, debugging, and quality. Traces may include prompts, tool inputs/outputs, and model responses that contain personal data from conversations.

Embeddings used for retrieval may be generated with local/self-hosted models in our infrastructure.

Important: AI outputs can be incomplete or incorrect. You remain responsible for reviewing critical guest communications according to your operating procedures and channel settings.

6. Cookies and similar technologies

On the Website, we show a cookie banner so you can Accept all, Reject non-essential, or Customize your choices before optional cookies run. You can change your mind anytime via Cookie settings in the website footer.

We store your choice locally in your browser (necessary preference storage).

  • Necessary — required to operate the Website securely and provide requested features. This includes remembering your cookie preferences and bot-protection technologies used on forms (for example Cloudflare Turnstile). These do not require consent under EU ePrivacy rules when strictly necessary for the service you request.
  • Analytics — optional measurement cookies/scripts (for example Google Analytics, when configured) that help us understand Website traffic and improve content. Analytics run only after you consent.

We do not currently use advertising or marketing pixels on the Website. If we add new optional categories later, we will update the banner and this Policy.

Where Google Analytics is enabled and you consent, we configure Google Consent Mode so analytics storage remains denied until consent is granted, and we request IP anonymization.

Web App and Mobile App

The Web App uses necessary cookies for authentication and security, including access/refresh session cookies and a CSRF cookie. These are required to keep you signed in and to protect account actions. The Mobile App uses secure on-device token storage instead of browser cookies.

We do not currently use third-party advertising pixels or product analytics SDKs in the Web App or Mobile App.

You can block cookies in your browser, but the Web App will not work correctly without necessary auth cookies.

7. How we share personal data

We share personal data only as needed to operate the Service:

7.1 Service providers (processors / subprocessors)

Depending on configuration, this may include:

  • infrastructure and hosting providers in the EU;
  • Google (Vertex AI / Gemini; Gmail API when you connect Google mail);
  • LangSmith (AI tracing / observability);
  • Meta / WhatsApp (when you connect WhatsApp);
  • Expo, Apple Push Notification service, and Firebase Cloud Messaging (mobile push delivery);
  • Cloudflare (Website hosting / edge and Turnstile bot protection);
  • email/SMTP providers you configure for outbound channel replies.

7.2 Channel platforms

When you use Airbnb, Booking.com, WhatsApp, email, or similar channels through JamesBnB, message and booking data is exchanged with those platforms according to your configuration and their terms.

We may disclose data if required by law, to protect rights and safety, or in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.

We do not sell personal data.

8. International transfers

Primary application databases and application hosting for JamesBnB are located in the European Union.

Some subprocessors (for example Google AI services, LangSmith, Meta, Expo/Apple/Google push infrastructure, or Cloudflare) may process data in the United States or other countries outside the EEA/UK/Switzerland. Where required, we rely on appropriate transfer mechanisms such as the EU Standard Contractual Clauses and additional safeguards offered by those providers.

9. Retention

We retain personal data only as long as needed for the purposes described in this Policy, unless a longer period is required by law.

Sensible defaults we apply:

  • Account data: for the life of the account, then deleted or anonymized within 30 days after confirmed account deletion, except records we must keep longer (for example security or legal claims);
  • Guest messages, bookings, embeddings, and AI conversation state: while your account remains active and the related integrations are connected, and for a limited period afterward needed for backups, dispute handling, or deletion workflows;
  • Push tokens: while notifications are enabled / the device remains registered; tokens should be deactivated when notifications are disabled or on request;
  • Waitlist / marketing leads: until you withdraw consent or we close the waitlist program, and then for a short administrative period;
  • Logs and security records: typically up to 12 months, unless needed longer for investigations or legal obligations;
  • AI traces (LangSmith): retained according to our observability configuration and provider settings, limited to what is needed for reliability and quality.

Exact backup cycles may mean residual copies persist for a short additional period before deletion completes.

10. Your rights

If the GDPR or similar laws apply to you, you may have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase data (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a supervisory authority.

For Germany, you may contact your local data protection authority; S’living GmbH is based in Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg).

How to exercise rights / delete or export data

There is currently no fully self-serve account-deletion or export flow in the apps. To request access, export, correction, or deletion of your account and related JamesBnB-controlled data, email [email protected] from the email address associated with your account.

We aim to respond within 30 days. We may need to verify your identity and distinguish:

  • data we control (account, waitlist, logs); from
  • guest data we process for you (which we will delete/return according to your instructions and technical feasibility, subject to legal retention duties).

Deleting a conversation inside the product removes that conversation from your workspace where supported; it is not a full account erasure.

11. Security

We use commercially reasonable technical and organizational measures, including encrypted transport (HTTPS), hashed passwords, encrypted storage of selected secrets (mailbox/WhatsApp tokens), access controls, and environment separation.

No method of transmission or storage is perfectly secure. You are responsible for protecting your login credentials and the mailboxes/channels you connect.

12. Children

The Service is for business users aged 18 or older. We do not knowingly collect personal data from children under 18. If you believe a minor has provided data, contact us and we will delete it.

The Service may link to third-party sites or rely on third-party platforms (Airbnb, Booking.com, Meta, Google, Apple, Expo, and others). Their privacy practices are governed by their own policies.

14. Changes

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. For material changes, we may also notify you by email or in-product notice where appropriate.

15. Contact

Questions about privacy or this Policy:

S’living GmbH
Geißstr. 13
70173 Stuttgart
Germany

Email: [email protected]