GuestVet LogoGuestVet
Get early access
Legal

Privacy Policy

Effective date: June 25, 2026 · Last updated: June 25, 2026

This Policy covers everyone who uses GuestVet. Sections 11–14 contain additional rights and disclosures for individuals in the European Economic Area (EEA), United Kingdom, and California. Because GuestVet uses AI to analyze information about guests, please read Section 6 (Automated Decision-Making) and Section 12 (Individuals You Research) carefully.

1. Overview and Scope

Swix Labs LLC, the company that operates GuestVet (“GuestVet”, “we”, “us”, or “our”), runs a guest-research platform for short-term rental hosts. This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and the rights and choices available to you. It applies to our website, waitlist, applications, and — when launched — the full Service.

We are not a consumer reporting agency under the U.S. Fair Credit Reporting Act (FCRA), and our reports are not “consumer reports.” By using GuestVet you agree to this Policy. If you do not agree, please do not use the Service.

2. Who We Are (Data Controller)

For the purposes of the EU and UK GDPR and other applicable data-protection laws, the controller of personal data processed about our website visitors, waitlist members, and account holders is:

Swix Labs LLCContact: legal@guestvet.com

Where you use the Service to research an individual, you determine the purposes of that research and act as an independent controller for the data you submit and the report you receive; we act as a separate controller for the limited processing needed to operate, secure, and improve the Service. See Section 12.

3. Information We Collect

Information you provide directly

  • Email address — collected when you join our waitlist or create an account.
  • Account details — name and password when you subscribe. We do not collect or store full payment-card numbers ourselves; payments are processed by our third-party payment processor, Stripe (see below).
  • Search queries — names, profile links, or other identifiers you submit to generate a report.
  • Communications — emails, support requests, survey responses, and feedback you send us.

Information collected automatically

  • Log and usage data — IP address, pages and features used, search counts, referring URLs, and timestamps.
  • Device and browser data — browser type, operating system, device type, language, and screen resolution.
  • Cookies and similar technologies — see Section 9.

Information about individuals you research

To produce a report, we collect and analyze publicly available information about the individual you query — such as public reviews, ratings, and profile details published on third-party platforms. We do not knowingly collect special-category data (e.g., data revealing race, health, religion, or sexual orientation) for this purpose, and our outputs are limited to conduct-based signals. See Section 12.

4. How We Use Information and Our Legal Bases

Under the GDPR and UK GDPR, we must have a lawful basis for each processing activity. We rely on the following:

Purpose
Legal basis
Provide the Service, your account, and reports you request
Performance of a contract (Art. 6(1)(b))
Send transactional, security, and service messages
Performance of a contract; legal obligation (Art. 6(1)(c))
Send early-access and marketing emails (you may opt out anytime)
Consent, or legitimate interests in promoting the Service (Art. 6(1)(a)/(f))
Process payments and keep financial/tax records
Contract; legal obligation (Art. 6(1)(b)/(c))
Secure the Service; detect, prevent, and investigate fraud and abuse
Legitimate interests in keeping the Service safe (Art. 6(1)(f))
Analyze and improve the Service and our models using aggregated/de-identified data
Legitimate interests (Art. 6(1)(f))
Comply with law and enforce our Terms
Legal obligation; legitimate interests (Art. 6(1)(c)/(f))

Where we rely on legitimate interests, we balance those interests against your rights and freedoms; you may object as described in Section 11. Where we rely on consent, you may withdraw it at any time without affecting prior processing. We do not sell your personal information, and we do not use your data to train third-party AI models without your explicit consent.

5. How We Share Information

We share personal data only as described here:

  • Service providers (processors) — vetted vendors that host our infrastructure and deliver email, customer support, and analytics on our behalf, under contracts requiring them to protect your data and use it only for us.
  • Payment processor — when you subscribe, your payment-card details are collected and processed directly by Stripe, Inc. under its own terms and privacy policy. We receive only limited transaction data (such as a confirmation, the last four digits of your card, and billing country); we never receive or store your full card number.
  • Legal and safety — authorities or other parties when required by law, court order, or lawful request, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of GuestVet, our users, or the public.
  • Business transfers — in a merger, acquisition, financing, or sale of assets, your data may be transferred subject to this Policy; we will notify you of any change in control or use.

We do not share the individual queries you run (the names or profiles you research) with other GuestVet users or sell them to any third party, except as required by law.

6. Automated Decision-Making and Profiling

GuestVet uses automated processing, including AI models, to analyze public information and generate sentiment signals, risk indicators, and a summary score about an individual. This constitutes profiling under Article 4(4) of the GDPR.

GuestVet does not make decisions on your behalf. Our outputs are decision-support only and are designed to be reviewed by a human (you) who exercises independent judgment before accepting or declining a booking. We require, through our Terms, that you not use a report as the sole basis for a decision that produces legal or similarly significant effects on an individual without meaningful human involvement, consistent with Article 22 of the GDPR. Individuals who are the subject of a report have the rights described in Sections 11 and 12, including the right to obtain human review of, and to contest, an automated assessment.

7. International Data Transfers

GuestVet is based in the United States and may process data in the U.S. and other countries. If you access the Service from the EEA, UK, or elsewhere, your data may be transferred to countries whose data-protection laws differ from your own.

For transfers of personal data from the EEA, UK, or Switzerland to countries not covered by an adequacy decision, we implement appropriate safeguards, primarily the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with supplementary technical and organizational measures. You may request a copy of the relevant safeguards by emailing legal@guestvet.com.

8. Data Retention

We keep personal data only for as long as necessary for the purposes set out in this Policy, after which we delete or de-identify it. In general:

  • Account data — for the life of your account and for a limited period afterward to meet legal, tax, and dispute-resolution needs.
  • Search-query and report logs — up to 12 months for security and abuse prevention, then deleted or anonymized.
  • Waitlist email — until you unsubscribe or request deletion.
  • Transaction records — the limited billing data we receive from Stripe, kept as required by applicable tax and accounting law (typically up to 7 years). Full card details are held by Stripe, not by us.

You may request deletion at any time as described in Section 11.

9. Cookies and Tracking

We use cookies and similar technologies to keep you signed in, remember preferences, and understand usage. We use:

  • Essential cookies — required for core functionality (e.g., authentication, security). These cannot be disabled.
  • Analytics cookies — help us measure and improve the Service using aggregated data.
  • Marketing cookies — help us measure the effectiveness of our waitlist and campaigns.

Where required by law, we request your consent for non-essential cookies via our cookie banner, and you can change your choices at any time. Most browsers also let you refuse or delete cookies; doing so may affect functionality. We honor Global Privacy Control (GPC) signals where legally required.

10. Data Security

We use industry-standard technical and organizational measures to protect personal data, including encryption in transit (TLS) and at rest, access controls, least-privilege practices, logging, and periodic security reviews. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by applicable law (under the GDPR, generally within 72 hours of becoming aware).

11. Your Rights (EEA, UK, and Globally)

Depending on where you live, you may have some or all of the following rights regarding your personal data. Under the GDPR and UK GDPR you have the right to:

  • Access — obtain confirmation of, and a copy of, the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted (the “right to be forgotten”), subject to legal exceptions.
  • Restriction — limit how we process your data in certain circumstances.
  • Portability — receive data you provided in a structured, machine-readable format and have it transmitted to another controller where technically feasible.
  • Object — object to processing based on legitimate interests, and to direct marketing at any time.
  • Human review — obtain human intervention in, express your view on, and contest decisions based on automated processing (see Section 6).
  • Withdraw consent — withdraw consent at any time where processing is based on consent, without affecting prior processing.

To exercise any right, email legal@guestvet.com. We will respond within the timeframe required by law (generally one month under the GDPR; 45 days under the CCPA), and may need to verify your identity first. You will not be discriminated against for exercising your rights.

Right to complain: if you are in the EEA or UK, you also have the right to lodge a complaint with your local data-protection authority — for example, your national supervisory authority in the EEA, or the UK Information Commissioner’s Office (ICO) at ico.org.uk. We would, however, appreciate the chance to address your concerns first.

12. Individuals You Research (Data Subjects)

If you are an individual who has been the subject of a GuestVet report, this section is for you. GuestVet analyzes information that has been made public by you or by others on third-party platforms in order to provide decision-support to a host considering a booking. We rely on legitimate interests (Article 6(1)(f)) for this limited processing, balanced against your rights, and we restrict outputs to conduct-based signals rather than personal characteristics.

You have the right to access, correct, delete, restrict, or object to this processing, and to obtain human review of any automated assessment, by contacting legal@guestvet.com. Where you object, we will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed to establish, exercise, or defend legal claims. We do not maintain a public, standing profile of any individual; reports are generated on demand at a host’s request and retained only as described in Section 8.

13. California Residents (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act, including the rights to know, access, delete, and correct personal information, and to opt out of the “sale” or “sharing” of personal information and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we do not use sensitive personal information for purposes that trigger the right to limit.

To submit a verifiable consumer request, email legal@guestvet.com with the subject line “California Privacy Request.” You may use an authorized agent. We will not discriminate against you for exercising your rights. We honor opt-out preference signals (such as GPC).

14. EU/UK Representative

Where GuestVet is required under Article 27 of the EU GDPR or UK GDPR to designate a representative in the EU or UK, our appointed representative’s contact details will be published here and can be obtained by emailing legal@guestvet.com. Until a representative is formally appointed, you may direct all GDPR inquiries to our Data Protection Officer at that address.

15. Minors

The Service is not directed to anyone under 18, and we do not knowingly collect personal data from individuals under 18. If we learn that we have collected such data, we will delete it promptly. If you believe a minor has provided us data, contact legal@guestvet.com.

16. Changes to This Policy

We may update this Policy from time to time. We will post the updated version here, revise the “Last updated” date, and, for material changes, provide notice by email or a prominent notice on the Service at least 14 days before the change takes effect. Your continued use after the effective date constitutes acceptance of the updated Policy.

17. Contact Us

For any question or request regarding this Policy or your personal data, contact our Privacy team:

Swix Labs LLC — Privacy TeamContact: legal@guestvet.com