Privacy Policy
Last updated September 2, 2026
Short version: we store the minimum, encrypt the sensitive, and never sell anything.
What we store
Your account email and password hash. Your property's name, PMS identifier, room count, and your PMS API key encrypted with AES-256-GCM. From your PMS we keep reservation records without guest identity (stay dates, nightly rates, booking channel, room type, status) plus daily summaries built from them. The PMS records we keep have no fields for guest names, emails, phone numbers, or payment data. Keeping this history is what powers your trends, pickup curves, and year-over-year views even when your PMS no longer returns old data.
If you connect the Guest Inbox, we do store guest email. A reviewable inbox has to hold the message itself, so for each email a guest sends to your connected mailbox we keep the sender's email address and name, the subject line, the message text (up to 8,000 characters), and any reply sent from YieldWizard. These messages are kept for 90 days and then deleted automatically, whether or not the inbox is still syncing. Disconnecting the mailbox deletes that property's stored messages right away. The mailbox app password you connect with is stored encrypted with AES-256-GCM, is decrypted only to run your sync, and is never shown or logged.
If you connect a phone system, we keep one record per call: when it started, which desk rang, how long it rang, and whether it was answered. We store the work email of the staff member who handled the call, because it is the only thing the phone export uses to tell your team apart, and we show it as a name on your Call Desk. We do not store the caller's number, and we do not store recordings or transcripts. If Dialpad text stats are connected, we keep date, desk or person, and inbound/outbound counts. We do not store text bodies or guest phone numbers.
What we don't do
No selling of your data. No advertising trackers. Your numbers are never shown to another customer, and we do not use your data to train third-party AI models. To make the product better for every hotel on it, we analyze de-identified, aggregated operational data (things like pacing, channel mix, and pricing patterns) internally; nothing in that analysis identifies your property to anyone outside our team.
Infrastructure
Hosted on Vercel with a Neon (Postgres) database, both in US regions. Traffic is TLS-encrypted end to end.
Data Processing Agreement
When you use YieldWizard, we process property and account data as your processor so we can run the product you asked for. We do not sell that data, we do not use it to train third-party models, and we do not give another hotel your numbers. The processors we use are listed below. They see only what their job requires (for example Resend sees the email we send; Plaid sees the bank connection you chose to link).
Ask, and we will sign a written DPA that matches this page. Until that paper is signed, this section is the processing record: what we store, who else touches it, and how long Guest Inbox messages are kept.
Subprocessors
These vendors process data on our instructions. The list is current as of the date above.
- Anthropic: model calls for the Wizard and other AI features.
- OpenRouter: fallback model routing when the primary model is down.
- Resend: transactional email (welcome, alerts, owner reports).
- Twilio: SMS when you turn on texting.
- SerpAPI: search and ranking checks for Get Found.
- Plaid: bank connections you attach, read only.
If you upload a bank or card statement instead of connecting a bank, we keep the transactions (date, amount, description, and the last four digits of the account you tell us) and we do not keep the uploaded file itself, only its content fingerprint, the row count, and who uploaded it and when.
Guest Inbox is the one place we store guest email and the message body. That is required for a reviewable inbox. We keep the sender address and name, the subject, the body (up to 8,000 characters), and any reply sent from YieldWizard, for 90 days, then delete them. Disconnecting the mailbox deletes those messages right away.
Deletion
Ask, and your account, property record, encrypted credentials, and any stored guest emails are deleted. Revoking the API key in your PMS also cuts our access instantly, on your side.
Questions: reply to your invite email.