BaanHost Privacy Policy
Who we are
BaanHost is a property-management app for villas, bungalows and guesthouses, operated by Baan Paro Mruen, Koh Phangan, Thailand ("we"). This policy explains what data the app handles and how.
Two kinds of people
- Account holders — owners, managers and staff who sign in to the app. The data we keep about them is listed under "What account data the app stores" below.
- Guests — the people who stay at a property. Their details are entered by the property's staff, who are the data controller for that information. BaanHost processes it on the property's behalf.
What account data the app stores
- Sign-in details — your email address, display name, role and a hashed password, used to sign you in and to show who did what in your organization. If you sign in with Google or Apple, we also store the account identifier that Google or Apple provides, used only to recognise you when you sign in again.
- Subscription purchases — for each subscription bought for your organization: the platform (App Store or Google Play), the product, the transaction numbers, the purchase and expiry dates, the status and whether it renews automatically. We use these to know which plan your organization has paid for, to restore purchases and to answer billing questions. We receive only the verified transaction details from the store; we never see your card number or other payment details.
- Devices for push notifications — if you allow notifications: the device's push token, platform (iOS or Android), app language, app version and when the device was last active, together with the notification types you have switched on or off. We use these only to deliver the notifications you chose, in your language.
What guest data the app stores
Name, phone, email, nationality, identity-document type and number, date of birth, booking dates, payments and notes — only what the property's staff choose to enter, what a guest submits on the property's online check-in page, direct booking page or payment page, and bookings that the property imports from its connected channels (through Channex or iCal calendar links). When staff scan a passport in the app, the image is read on the device and deleted immediately. If a guest uploads a passport photo or signs on the online check-in page, that image and signature are stored privately for the property, used only for check-in and the guest registration that local law requires, and erased with the rest of the guest's personal data. If a guest reports a payment on the property's payment page, the report and any transfer slip image they upload are kept in the property's private storage, visible only to its staff. Housekeeping photos taken in the app show rooms, not people. No location tracking, no advertising identifiers, no contacts access.
Guest payments
When a property turns on online payments, guests who pay by card or by scanning a QR code on the property's payment page are processed by Omise. Card details are entered into Omise's own payment form and never pass through our servers, and the money goes directly to the property's own Omise account. We store only the Omise payment reference, method, amount and status.
Where data lives
On servers in Singapore (Amazon Web Services), encrypted in transit. Nightly backups are stored privately in the same region. Crash and error reports go to Sentry (EU data centre) and contain technical details only — never guest names, contact details or document numbers.
How long we keep it
Each property sets its own retention period for guest personal data (default three years after the guest's last check-out). After that the guest's name, contact details, document number and notes are automatically erased; booking and payment records are kept without personal identifiers. Staff can erase an individual guest's personal data at any time from the app.
If a trial ends without a subscription, or a subscription ends and its 7-day grace period passes, the organization becomes read-only. Its data is then kept for 90 days; renewing within that time restores full access with all data intact. After 90 days, the organization and all of its data may be permanently deleted.
Your rights
- Account holders can change their details and password in the app, and delete their account from the round avatar at the top right of the app (Delete account). Deleting the last owner account deletes the whole property's data.
- Property owners can export all of their data as a ZIP of CSV files from More → Privacy & data.
- Guests who want to know what a property holds about them, or want it erased, should contact the property; we will help the property fulfil the request.
Deleting your BaanHost account
You can delete your BaanHost account at any time, in the app or by email. You do not need the app installed to ask.
- In the app: sign in, tap the round avatar at the top right, choose Delete account, enter your password and confirm. The account is deleted immediately. If you signed up with Google or Apple and have never set a password, first set one with Forgot password? on the sign-in screen, or ask us by email.
- By email: write to [email protected] from the email address you sign in with, say that you want your account deleted and give the name of your organization. We reply to confirm and delete the account within 30 days.
If you use the same email address in more than one organization, you have a separate account in each. Delete each one in the app after switching to that organization, or tell us by email which ones to delete.
What is deleted: your name, email address, password, Google or Apple sign-in, settings and the devices registered for notifications. If you are the organization's only owner, the whole organization is deleted as well: its properties and rooms, bookings, guest records (including passport photos and signatures), payments and finance records, documents, housekeeping photos, messages and activity log.
What is kept: if the organization still has another owner, the bookings, payments and other records you entered stay with it, because they are the organization's business records. Apple and Google keep their own records of subscription purchases under their own policies. Data in our backups is deleted automatically within 90 days.
Sharing
We do not sell data and do not share it with advertisers. Service providers that process data for us:
- Amazon Web Services — hosting, file storage and backups.
- Cloudflare — network security.
- Sentry — error reporting.
- Resend — sending email, such as sign-up codes, account notices and the messages a property sends to its guests by email.
- Google Firebase Cloud Messaging — delivering push notifications.
- Channex — channel synchronisation: it sends a property's availability and rates to the booking channels it connects and passes the bookings from those channels, including guest details, back to the property.
- Google and Apple — sign-in with Google or Apple when you choose it, app distribution, and subscription billing: subscriptions in the iPhone and iPad app are charged through Apple's App Store, and in the Android app through Google Play.
Website visitors
If you join the waiting list on baanhost.com, we store your email address and language so that we can tell you when the app is available. If you sign up on the website, we store your organization's name, your name, your email address and a hashed password to open your account, and email you a verification code. We use these details only to contact you about BaanHost and to set up your account — never for advertising.
Support access
To investigate a problem you report, BaanHost support staff may sign in to your organization with the same view as your owner account. Each session requires a stated reason, expires after one hour, and every action during it is recorded in your organization's audit log as performed by BaanHost support. Access is limited to what is needed to resolve your request.
Contact
[email protected] — Baan Paro Mruen, Koh Phangan, Surat Thani, Thailand.