Privacy policy
Last updated: [Pending: last-updated date]
This policy explains how casflows (https://casflows.com) processes personal data when you use the service: a tool for people who manage Airbnb listings that reads each listing's iCal calendar, organises cleanings in Google Calendar and sends reminders via Telegram.
We wrote it to be understood without a law degree. If anything is unclear, write to us and we will explain it.
Who the controller is#
- Controller: [Pending: controller's full name]
- CUIT (Argentine tax ID): [Pending: controller's CUIT (tax ID)]
- Address: [Pending: controller's postal address]
- Privacy email: privacidad@casflows.com
- Service: casflows — https://casflows.com
The controller is established in Argentina and offers the service to customers in Spain and the rest of the European Union, so we apply Regulation (EU) 2016/679 (GDPR), the Spanish Organic Law 3/2018 (LOPDGDD) and Argentine Law 25,326 on Personal Data Protection.
Our role: controller and processor#
We are the controller of your account data: that of the account holder and of anyone who accesses it (name, email, credentials, acceptance of the legal terms, billing once enabled) and the technical logs of the service.
We are a processor of the data you enter so the service can work: your cleaning staff and reception contacts, your properties, the reservations coming from the iCal feed and the cleanings. For that data you are the controller and we only process it on your instructions, under the data processing agreement included in the terms of use (Art. 28 GDPR).
If you are cleaning staff or a reception contact of someone who uses casflows, the person or company managing the accommodation is responsible for your data. You can contact them; if you write to us instead, we will help pass your request on to them.
What data we process#
| Category | Data | Source |
|---|---|---|
| Account | Name, email, password (hash only, handled by Supabase Auth), account name, time zone, language, reminder time, subscription status and trial end date. If you sign in with Google: your name, email and Google identifier. | You, when signing up or configuring the account |
| Acceptance of the legal terms | Date and time you accepted these terms, this policy and the data processing agreement. | Recorded at sign-up or when you accept a new version |
| Properties | Listing name, check-in and check-out times, time zone, notes for staff and the Airbnb iCal URL. The iCal URL is stored encrypted (AES-256-GCM) and never shown in full. | You |
| Reservations | Only the iCal event identifier (UID) and the check-in and check-out dates, plus any note you choose to add. We do not store your guests’ names, phone numbers or other guest data. | The Airbnb iCal feed you give us |
| Cleanings | Date, time window, urgency, assignee and status. | Calculated from reservations |
| Cleaning staff and reception contacts | Name, Google email (optional for reception) and, once the person links the bot themselves, their Telegram chat identifier. | You; the Telegram identifier, the person themselves when opening the bot link |
| Messages | Content, recipient, date and outcome of reminders and notices sent via Telegram (and, once enabled, by email). | Generated by the service |
| Google Calendar connection | Email of the connected Google account, OAuth refresh token (encrypted), granted scopes, the identifier of the calendar casflows creates and of the events it creates in it. | Google, when you authorise the connection |
| Technical data | IP address, browser, dates and paths of requests and errors, in server logs. | Your browser and our systems |
| Billing (once enabled) | Plan, amounts, invoices and a Stripe customer ID. Card data is handled directly by Stripe; we never see it. | You and Stripe |
We do not ask for special categories of data (health, beliefs, etc.). Please do not include them in notes, and do not write guest data in notes unless it is necessary.
Why we use it and on which legal basis#
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing your account, providing the service (syncing the iCal feed, creating cleanings, notices and calendar events) and supporting you | Performance of a contract — Art. 6(1)(b) |
| Connecting your Google Calendar and creating the casflows calendar and events in it | Consent — Art. 6(1)(a). You can withdraw it at any time by disconnecting Google from the dashboard |
| Service security, fraud and abuse prevention, and technical logs | Legitimate interest — Art. 6(1)(f) (protecting the service and its customers) |
| Improving the service with aggregated usage and error metrics | Legitimate interest — Art. 6(1)(f). You can object by writing to us |
| Sending you service communications (changes, security, trial ending) | Performance of a contract — Art. 6(1)(b) |
| Keeping proof of your acceptance of the legal terms, invoicing and complying with tax, accounting obligations or requests from authorities | Legal obligation — Art. 6(1)(c); and, to prove acceptance, legitimate interest — Art. 6(1)(f) |
Where we act as a processor (data about your staff, reception, properties and reservations), you as controller determine the legal basis; see your responsibilities.
We do not send advertising or marketing newsletters. If we ever wanted to, we would ask for your consent first.
Data we receive from Google#
Connecting Google Calendar is optional and you start it from the dashboard. We only request these scopes:
openidandemail: identify the Google account you connect and show you its email so you know which one is connected.https://www.googleapis.com/auth/calendar.app.created: create one secondary calendar owned by casflows and manage the cleaning events inside it, inviting your cleaning staff and reception contacts as attendees.
With that scope casflows cannot see, read or modify your other calendars or their events. It only accesses the calendar it creates itself.
What we do with Google data:
- We use it only to provide the feature you see in casflows: keeping your cleanings in that calendar.
- We do not use it for advertising, advertising profiles or retargeting.
- We do not sell it or share it with third parties, except with the providers needed to run the service (see recipients), when required by law, or in a corporate transaction (merger, acquisition) with the same safeguards.
- We do not use it to train artificial intelligence or machine learning models, whether general or our own.
- No human reads it, unless you give us explicit consent for a specific case (for example, support), it is necessary for security purposes (investigating abuse or an incident) or to comply with the law; otherwise only in aggregated and anonymised form for internal operations.
- The access token is stored encrypted and deleted as soon as you disconnect Google or revoke access.
casflows' use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. See the Google API Services User Data Policy.
You can disconnect Google at any time from the casflows dashboard or from your Google Account permissions. When you disconnect, we delete the token; the calendar and events already created remain in your Google account, which belongs to you, and you can delete them from Google Calendar.
If you use "Sign in with Google", Google only gives us your name, email and identifier to authenticate you; that sign-in does not grant access to your calendar.
Who we share data with#
We do not sell personal data. We only disclose it to these providers (sub-processors), under a data processing agreement and the safeguards listed, and only as needed to provide the service:
| Provider | Purpose | Data location | Safeguards |
|---|---|---|---|
| Supabase, Inc. | Database and authentication | European Union (Frankfurt, Germany) | Data processing agreement (DPA) with Standard Contractual Clauses (SCCs) for any access from the US |
| Vercel, Inc. | Application hosting and server execution | Functions in the EU (Frankfurt); US company | DPA, SCCs and/or the EU-US Data Privacy Framework (DPF) where certified |
| Cloudflare, Inc. | DNS for casflows.com (application traffic does not pass through it) | Global network; US company | DPA, SCCs and/or DPF where certified |
| Google (Google LLC / Google Ireland Ltd.) | Google Calendar API and OAuth, only if you connect Google or sign in with Google | Per Google’s infrastructure | Google API terms, SCCs and/or DPF. Google processes your Google account as an independent controller |
| Telegram (Telegram Messenger Inc. and affiliates) | Sending reminders and notices to people who link the bot | Per Telegram’s infrastructure, outside the EU | The person chooses to use Telegram when linking the bot; Telegram acts as an independent controller under its privacy policy |
| Resend (once enabled) | Transactional email delivery | European Union | DPA and SCCs |
| Stripe (once enabled) | Subscription payments and invoicing | EU (Stripe Payments Europe, Ltd., Ireland) with transfers to the US | DPA, SCCs and/or DPF. Stripe processes payment data as a controller where financial regulation requires it |
Data may also be disclosed to authorities and courts where the law requires it. We will announce any change to this list by updating this policy (and, for customers, as set out in the data processing agreement).
International transfers#
- Argentina: the controller is in Argentina, which benefits from a European Commission adequacy decision (Decision 2003/490/EC). Data may be processed or accessed from there with a level of protection recognised as adequate.
- United States: with US providers we rely on the European Commission’s Standard Contractual Clauses and/or, where the provider is certified, the EU-US Data Privacy Framework (adequacy decision of 10 July 2023), with supplementary measures such as encryption.
- Telegram: sending notices via Telegram means Telegram processes the messages on its servers; this happens because the recipient chooses that channel when linking the bot.
You can ask us for a copy of the applicable safeguards at privacidad@casflows.com.
How long we keep data#
| Data | Retention |
|---|---|
| Account and service data | While the account is active. After closing it you have 30 days to export it; then we delete it. |
| Trial accounts that do not subscribe | The trial lasts 15 days. If you do not subscribe, syncing is paused and nothing is deleted straight away; 90 days after the trial ends we delete the account, with an email notice 15 days beforehand. |
| Past reservations and cleanings | 24 months from the cleaning date, as service history; then deleted. |
| Staff and reception contacts | Until you remove them or the account is closed. The Telegram identifier is deleted when unlinked. |
| Telegram linking links | Expire after 7 days and are single-use; we only store their hash. |
| Sent messages (notice queue) | 90 days from sending. |
| Google token | Deleted as soon as you disconnect Google or we detect you revoked access. |
| Technical logs | Up to 30 days. |
| Proof of acceptance of the legal terms and billing | During the relationship and, afterwards, blocked for the limitation periods of legal claims and those required by applicable tax and commercial law. |
| Backups | Deleted data may remain for up to 30 days in encrypted backups until overwritten. |
Your rights#
You can exercise at any time, free of charge, your rights of:
- Access: find out what data about you we process and get a copy.
- Rectification: correct inaccurate or incomplete data (you can change most of it yourself in the app).
- Erasure: ask us to delete your data when it is no longer needed, among other cases.
- Restriction: ask us to pause processing in certain cases.
- Portability: receive your data in a structured, commonly used format (for example JSON or CSV).
- Objection: object to processing based on legitimate interest.
- Withdraw consent (for example, by disconnecting Google), without affecting prior processing.
Write to privacidad@casflows.com stating which right you want to exercise, from your account email if you have one. If we cannot verify your identity we will ask for the minimum information needed. We reply within one month, extendable by two further months for complex cases (we will let you know). Under Law 25,326, the right of access is free of charge at intervals of no less than six months, unless a legitimate interest is shown.
If you believe we have not handled your data properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) — aepd.es — or the supervisory authority of your EU country, and also with Argentina’s Agency for Access to Public Information (AAIP) — argentina.gob.ar/aaip —, the supervisory body for Law 25,326. We would appreciate it if you wrote to us first so we can try to resolve it.
Representative in the European Union#
The controller is not established in the EU. Where required under Article 27 GDPR, it will appoint a representative in the Union and publish their contact details here. In the meantime, you can send any query to privacidad@casflows.com.
How we protect data#
- Encryption in transit (TLS/HTTPS) for all communications.
- Encryption at rest of the database and, on top of that, application-level encryption (AES-256-GCM) of secrets: the iCal URL and the Google token.
- Isolation between customers with row-level security (RLS) in the database: each account only sees its own data.
- Least privilege: explicit per-table and per-column permissions, and internal processes only access what they need.
- Passwords stored only as hashes; single-use, expiring Telegram links; secrets never go to logs.
- Data hosted in the European Union and an incident management procedure, notifying the authority and affected people where the law requires it.
No system is infallible. Please use a strong, unique password and tell us immediately if you suspect unauthorised access.
Automated decisions#
casflows automates tasks (creating a cleaning, flagging it as urgent or sending a reminder), but it does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and it does not profile you.
Cookies and local storage#
We only use strictly necessary technical cookies for the service to work, which are exempt from consent (Art. 22.2 of the Spanish LSSI). We do not use analytics, advertising or third-party tracking cookies.
| Name | Purpose | Duration |
|---|---|---|
| sb-…-auth-token | Keep you signed in (Supabase Auth) | For the session |
| NEXT_LOCALE | Remember the language you chose | Until you close the browser |
| casflow_gcal_oauth | Protect the Google connection (encrypted, single-use OAuth security state) | 10 minutes at most |
| theme (local storage, not a cookie) | Remember light or dark theme | Until you clear it from your browser |
If we ever add non-essential cookies, we will ask for your consent first with a specific notice.
Minors#
casflows is a professional service and is not intended for anyone under 18. We do not knowingly process minors’ data; if we detect an account belonging to a minor, we will delete it. If you know of such a case, write to privacidad@casflows.com.
Changes to this policy#
We may update this policy when the service or the law changes. The last-updated date is shown above. If the change is material, we will notify you by email or in the app at least 30 days in advance and, where the law requires it, ask for your acceptance or consent again.
Contact#
For any privacy matter: privacidad@casflows.com.