Skip to content

Legal

Privacy Policy

Last updated 2026-07-18

This policy describes how LodgeDeck ("we", "us") collects, uses and protects information when you use our website, API and MCP server (the "Service"). LodgeDeck publishes cited short-term rentalrules and lodging tax rates for a set of US cities, along with free calculators, a public JSON API and a hosted MCP server. It is not a law firm, an accountant or a tax authority, and provides no legal or tax advice.

The rules and tax dataset is not your data

The regulatory and tax reference we publish is not personal information and does not live in our database. It ships inside the application itself, is identical for every visitor, and is drawn from public sources. Looking up a city on this site, or through the API, does not create a record about you beyond the request log described below.

Information we collect

  • Account information, your name and email address (or sign-in provider identifier) when you create an account.
  • Plan and billing references, your plan, its status, and the Stripe customer and subscription identifiers that correspond to it. Payment is processed by Stripe; we never see or store your card details.
  • API keys, stored as a sha-256 hash plus a short display prefix so you can tell one key from another in your dashboard. The key value itself is never stored. It is shown once, at creation, and you can revoke it at any time.
  • An API and MCP request log, the endpoint, method, response status, timing and request identifier for calls made with your key. This is what powers quota accounting, rate limits and the inspectable log in your dashboard, so you can see what your own integrations and agents did.
  • Saved properties, the label, city, jurisdiction, use type and any notes you enter for a property you choose to save.
  • Attached calendars, the public calendar export URL you paste for a property, plus a cached reading of the bookings it contains: an identifier, start and end dates, night count and the summary line the channel published.
  • Change watches, when you watch a city's rules or tax rates, a snapshot of the cited public values as they stood, so a later change can be compared exactly rather than guessed.

That is the complete list. There is no file storage on this Service and nothing to submit beyond the fields above.

About the calendar URLs you paste

We read the public calendar export URLs you supply, on a schedule, to build your turnover view. We do not write anything back to Airbnb, Vrbo or Booking.com, and we hold no partner API access to those platforms. A calendar export URL is a capability URL: anyone holding it can read that calendar, so treat it as you would a credential. You can remove a calendar from a property at any time, which deletes both the URL and the cached bookings we read from it.

No model provider is in the request path

No part of the Service sends your data to a model or AI provider. Lookups are served from the shipped dataset and calculations run deterministically in code. Nothing you enter is used to train any model, ours or anyone else's. Our MCP server lets an AI agent you control read the same public dataset; that agent is yours, and we do not pass your account data to it beyond what your key requests.

How we use your information

  • To operate the Service: serve lookups, save your properties, read the calendars you attach, and enforce plan quotas and rate limits.
  • To send account and billing notifications, such as a password reset or a receipt.
  • To process payments for paid plans via Stripe, and to meter usage-based API calls.
  • To diagnose and fix faults, and to see which features are worth keeping.
  • To keep the Service secure and prevent abuse, including by automated and agent traffic.

We do not sell your personal information.

Data storage and security

Account, API key, request log, property, calendar and watch records are stored in Supabase (Postgres) and the Service is hosted on Vercel. Every user table is owner-scoped by Postgres Row Level Security, so a row is readable only by the account that owns it and there is no world-readable user data. All traffic runs over HTTPS. See our Security page for what we do and do not have.

Data retention and your choices

You can delete a saved property, which removes its attached calendars and their cached bookings, remove a watch, revoke an API key, or delete your account at any time. If you close your account we honour deletion requests and remove your records within a reasonable period, except where we are required to retain billing records for tax or legal purposes.

Cookies and analytics

We use a small number of cookies required to keep you signed in. That is all. There is no analytics script on this site, no session recording, no advertising tracker, and no third-party tag of any kind. The free calculators run entirely in your browser and send us nothing.

Third parties

We share data with the vendors that operate the Service on our behalf: Supabase for the database, Vercel for hosting, and Stripe for billing, each bound to use it only to provide their service to us.

Accuracy of what we publish

LodgeDeck reports publicly available short-term rental rules and lodging tax rates and cites the source of each field. It is not legal or tax advice and it does not replace your own review. Ordinances and tax rates change often and automated collection can lag, so every field shows the source it came from and a confidence flag, and unconfirmed values are marked Unverified. Confirm with the jurisdiction before you rely on a rule or rate.

Children

The Service is intended for short-term rental hosts, property managers, and the businesses and agents building on top of them, and is not directed to, or knowingly used by, children under 16.

Changes to this policy

If we make a material change to this policy, we will update the date above and, where appropriate, notify you by email.

Contact

Questions about this policy or your data, including requests to access, export or delete it, can be sent to hello@lodgedeck.com.