Privacy Policy
Last updated: June 30, 2026
1. Introduction
Lighthouse is a property management platform built for short-term rental hosts in Nigeria. We help you manage bookings, track guests, generate guest portals, and understand your property performance — all in one place.
We take your privacy seriously. This policy explains what data we collect, how we use it, and the choices you have. We aim to be clear and direct — no walls of legal text.
2. What Data We Collect
We collect only what is necessary to run the platform:
Host account information
- Name and email address (from sign-up)
- Phone number and business name (if you add them to your profile)
Guest information entered by hosts
- Guest name, email address, and phone number
- Nationality
Booking and stay details
- Check-in and check-out dates
- Property, revenue, and booking source
- Booking status and stay history
Reviews and feedback
- Ratings and written comments submitted via the guest portal
- The date and property the review relates to
Service requests
- Requests submitted by guests during their stay (e.g. housekeeping, maintenance)
- Request status and resolution notes
3. How We Use Your Data
We use the data collected to:
- Operate the host dashboard and keep your records up to date
- Generate secure guest portal links so guests can view their stay details
- Calculate analytics such as occupancy rate, revenue per guest, and repeat guest percentage
- Enable host-to-guest communication (e.g. the mailto link on guest profiles)
- Display stay history, review summaries, and service request logs
We do not use your data for advertising, profiling, or any purpose beyond operating the platform.
4. Data Storage
All data is stored securely using Supabase, a PostgreSQL-based cloud database provider. Data is encrypted at rest and in transit using industry-standard TLS encryption. Supabase infrastructure is hosted on AWS and meets SOC 2 Type II standards.
Your data is stored in a dedicated database with access controls that ensure only authorised users can read or modify it.
5. Data Sharing
We do not sell, rent, or share your personal data or your guests' data with any third parties for commercial purposes.
Each host can only see their own data. We use Supabase Row Level Security (RLS) policies so that every query is automatically scoped to the authenticated user — it is not possible for one host to access another host's guests, properties, bookings, or reviews.
We may disclose data if required by Nigerian law or a valid legal order, and only to the minimum extent required.
6. Cookies
We use essential session cookies only. These cookies keep you logged in while you use the platform and expire when your session ends or you sign out.
We do not use tracking cookies, advertising cookies, or any third-party analytics cookies. We do not load Facebook Pixel, Google Analytics, or similar tracking scripts.
7. Guest Data
Guest information (name, contact details, nationality) is entered into Lighthouse by the host — not directly by the guest. Guests do not create accounts on Lighthouse and do not interact directly with the dashboard.
Guests can request access to or removal of their personal information by contacting their host directly. The host can then update or delete the guest record from the dashboard. If a guest believes their data is being misused, they may contact us at support@lighthousehost.io.
8. Data Retention
Your data is retained for as long as your account is active. If you delete your account from Settings → Danger Zone, all of your data — including guest records, stays, reviews, service requests, and property information — is permanently deleted. This action cannot be undone.
You may also delete individual guest records, stays, or properties at any time from within the dashboard.
9. Your Rights
As a Lighthouse user, you have the right to:
- Access the personal data we hold about you
- Correct any inaccurate information
- Request deletion of your account and all associated data
- Export or receive a copy of your data on request
To exercise any of these rights, contact us at support@lighthousehost.io. We will respond within 14 business days.
10. Security
We take reasonable steps to protect your data:
- Passwords are never stored in plain text — authentication is handled by Supabase Auth, which hashes passwords using bcrypt
- All sessions are encrypted and transmitted over HTTPS
- Guest portal links are tied to a specific stay ID and are only useful during the active stay period — they contain no persistent authentication token
- Row Level Security ensures no cross-account data leakage at the database level
No system is completely immune to security risks. If you discover a vulnerability, please report it responsibly to support@lighthousehost.io.
11. Contact
For any questions or concerns about this privacy policy or how your data is handled, please contact us:
Lighthouse · Built for Nigerian short-term rental hosts · Last updated June 30, 2026