Shared Holiday Homes logo

Privacy Policy

This Privacy Policy explains how Shared Holiday Homes collects, uses, and shares information when you use our website and software.

Effective date: 5 August 2026

1. Scope

This policy covers the Shared Holiday Homes marketing site, free tools, authenticated application, and related communications. It should be read with our Terms of Service.

2. Who we are

The service is operated by Shared Holiday Homes. Privacy questions and requests: support@sharedholidayhomes.com .

Security concerns or suspected vulnerabilities can also be reported to support@sharedholidayhomes.com with enough detail for us to investigate (please do not include passwords or unnecessary personal data in the initial report).

3. Information we collect

Account and profile

When you sign up or are invited, we collect information such as name, email address, authentication identifiers, and role within a property workspace. Sign-in is handled by Firebase Authentication (email/password and Google, as offered).

Property and collaboration content

Content you and other members add to a property — for example bookings, rooms, tasks, documents, guides, settings, and communications metadata — is stored so the product can work for your group. That content may include personal data about members or guests that you choose to enter.

Billing

Subscription and payment processing are handled by Stripe. We receive subscription status and related billing metadata needed to unlock paid features. Card details are processed by Stripe; we do not store full payment card numbers on our servers.

Usage and diagnostics

We collect product analytics and technical telemetry to understand how the service is used and to fix problems. Primary analytics are provided by PostHog (page views, selected product events, exception capture, and optionally session replay configured with input masking). Firebase may also provide limited analytics or crash-related signals depending on environment.

We aim to keep analytics privacy-safe: typed product events should not include names, emails, addresses, passwords, notes, or free-form form payloads. Demo and certain internal accounts may be excluded from product analytics capture.

Device and technical data

Like most web services, we process IP address, browser type, device information, approximate location derived from IP, referrers, and similar technical logs via our hosting and security providers as needed to operate the service.

4. How we use information

  • Provide, secure, and improve the service
  • Authenticate users and manage invitations and roles
  • Process subscriptions, trials, and invoices
  • Send transactional email (for example invitations and notices)
  • Understand product usage and diagnose errors
  • Comply with law and enforce our Terms

5. Sharing and subprocessors

We share data with service providers that help us run the product. Key processors today include:

  • Firebase (Google) — Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, and related infrastructure
  • Stripe — payments, subscriptions, and customer billing portal
  • PostHog — product analytics, page views, exception capture, and session replay (with masking defaults)
  • Email and hosting infrastructure used to deliver the website, application, and transactional messages

We do not sell personal information. We may disclose information if required by law, to protect rights and safety, or in connection with a business transfer (with appropriate safeguards).

A formal Data Processing Agreement (DPA) and public subprocessors list for business customers may be published separately later.

6. International transfers

Our providers may process data in countries other than where you live, including the United States and other regions where Firebase, Stripe, or PostHog operate. Where required, we rely on appropriate transfer mechanisms offered by those providers. Details are subject to counsel review as we formalise compliance documentation.

7. Retention

We retain account and property data while your workspace is active and for a reasonable period afterward for backups, disputes, and legal obligations. Billing records may be retained as required by tax and accounting rules. Analytics data is retained according to our PostHog project settings and operational needs.

8. Security

We use industry-standard controls offered by our cloud providers, authentication, and access roles within the product. No method of transmission or storage is perfectly secure. Report suspected security issues to support@sharedholidayhomes.com .

9. Your rights

Depending on where you live (including under GDPR, UK GDPR, or CCPA-style laws), you may have rights to access, correct, delete, export, or restrict certain personal data, and to object to or opt out of certain processing. To make a request, email support@sharedholidayhomes.com . We may need to verify your identity and the scope of the request.

If you are a member of someone else’s property workspace, some content may be controlled by the property owner or admins; we may need to coordinate with them for certain requests.

10. Cookies and tracking

We use cookies and similar technologies that are needed for the product to function, plus analytics technologies described below.

  • Authentication and session — Firebase Auth and related session storage keep you signed in and secure the application.
  • Preferences — for example theme preference stored in the browser, and limited UI state (such as sidebar open/closed) that may use a cookie or local storage.
  • Analytics — PostHog may set cookies or use local storage to distinguish visitors/sessions, capture page views and product events, and (when enabled in our PostHog project) record sessions with input masking. Autocapture of DOM clicks is disabled in our client configuration; we prefer explicit product events. Analytics is disabled on local development hostnames.
  • Payments — Stripe may use cookies or similar technologies on checkout and billing portal pages they host.

We do not currently show a separate cookie-consent banner. If we expand non-essential tracking or operate in jurisdictions that require a different consent approach, we will update this section and the product accordingly. You can control cookies through your browser settings; blocking essential cookies may prevent sign-in or core features from working.

11. Children

The service is intended for adults organising shared property use. It is not directed at children under 16, and we do not knowingly collect personal information from children.

12. Changes

We may update this Privacy Policy by posting a new version at this URL and revising the effective date. Material changes will be highlighted in the product or by email where appropriate.

13. Contact

Privacy, security, and data requests: support@sharedholidayhomes.com