Skip to content
Airbnb Safety Checklist

Privacy Policy

Last updated: 19 September 2026

This policy explains how Airbnb Safety Checklist (“we”, “us”) handles personal data when you use Airbnb Safety Checklist (the “Service”). We have designed the Service to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable US state privacy laws.

1. Who we are

Airbnb Safety Checklist, 880 N St # 301, Anchorage, Alaska 99501, United States, is the controller of personal data about our account holders, website visitors and people who request our free resources. Contact us at hanaweb2020@gmail.com.

Hosts' data about their assignees. When a host adds a cleaner, co-host or other person to a checklist, and that person completes it (entering their name, taking photos and adding notes), the host decides why and how that information is used. For that data the host is the controller and we act as the host's processor. Questions about that data should go to the host first; we will help them respond.

2. What we collect

  • Account data: name, email address, password (stored only as a secure hash), and — if you sign in with Google — your Google account name, email and profile image.
  • Property and checklist data: property names, addresses, amenities, checklists, due dates and notes.
  • Assignee data: the name and email a host enters, the name the assignee types, completion times, notes and photo proof.
  • Photos: images uploaded as proof of a safety check. Our app re-encodes photos on the device where possible, which removes embedded location (GPS) metadata.
  • Billing data: your plan, subscription status and customer reference. Card details are collected and processed by Dodo Payments, our merchant of record — we never see them.
  • Technical data: IP address, browser type and timestamps, used for security, rate limiting and session management.
  • Marketing data: if you request our free checklist, your email address and whether you agreed to receive marketing.

3. Why we use it and our lawful basis

PurposeLawful basis (UK GDPR)
Providing the Service, including checklists, photo storage, reports and notificationsContract
Processing assignee data on a host's behalfAs processor, on the host's instructions
Billing, tax and accounting recordsContract; legal obligation
Security, fraud and abuse preventionLegitimate interests
Sending the free checklist you requestedLegitimate interests
Marketing emailsConsent (withdraw any time)
Optional analyticsConsent via our cookie banner

4. Photos of people

The Service is designed to photograph equipment, not people. Hosts must tell assignees not to photograph guests or their belongings, and must not use the Service to record guests.

5. Who we share data with

We use carefully selected service providers (sub-processors), each bound by a data processing agreement:

  • Hosting and database infrastructure (our virtual private server provider)
  • Object storage for photos and reports (Cloudflare R2 or equivalent, where configured)
  • Resend — transactional email delivery
  • Dodo Payments — payment processing and tax (merchant of record)
  • Google — only if you choose “Continue with Google”
  • Plausible Analytics — only if you accept analytics cookies

When a host shares a report link, anyone with that link can view the report until the host disables it. We do not sell personal data or share it for cross-context behavioural advertising.

6. International transfers

Some providers process data outside the UK. Where they do, we rely on UK adequacy regulations (including the UK–US data bridge where the recipient is certified) or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.

7. How long we keep data

Photo proof and reports are kept for 2 years by default (hosts can choose 1–7 years). See our Data Retention Policy for every category.

8. Your rights

Under UK GDPR you have the right to:

  • access your personal data and receive a copy;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to processing;
  • data portability — download your data from Settings → “Export my data”;
  • withdraw consent at any time, without affecting earlier processing.

You can delete your account at any time in Settings. To exercise any right, email hanaweb2020@gmail.com; we respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk). US residents may have similar rights under their state's law and can use the same contact details.

9. Security

Data is encrypted in transit (TLS). Photos and reports are stored in private storage and only served to authorised users through short-lived links. Passwords are hashed, access to production systems is restricted, and every photo is fingerprinted so tampering can be detected.

10. Children

The Service is for adults running rental businesses and is not directed at anyone under 18.

11. Changes

We'll post updates here and, for significant changes, notify account holders by email.

Airbnb Safety Checklist is an independent resource and is not affiliated with, endorsed by, or sponsored by Airbnb, Inc.