Who we are. Sona is a white-label guest-experience platform operated by Sonastay LLC ("Sona," "we," "us"). We provide hotels with a browser-based guest app and staff dashboard. This policy explains how we handle personal information across two roles: as the operator of our own website, and as a service provider that processes guest data on behalf of the hotels who use our platform.
Our website & prospects (we are the controller). When you visit sonastay.com, request a demo, or book a call, we decide how your information is used and this policy governs it directly.
Hotel guest data (we are a processor). When a hotel runs our platform, guests enter information into an app branded as that hotel. The hotel is the data controller; Sona processes that data only to provide the service, under the hotel's instructions and our agreement with them. Guests should also review the hotel's own privacy notice.
We do not process payment card numbers. The hotel remains the merchant of record; any charge-to-room or payment is handled by the hotel, not by Sona.
We do not sell personal information, and we do not use guest data to serve advertising.
The in-app concierge is powered by a third-party AI provider (Anthropic). It is designed to answer only from the hotel's verified facts and to hand off to staff for anything else. Guest messages processed by the concierge are handled under our subprocessor terms and are not used to train third-party models.
Guest personal information is automatically expired approximately five days after checkout — a privacy feature built into the platform. Website/prospect contact information is kept only as long as needed for the purpose it was collected or as required by law, after which it is deleted or anonymized.
We rely on a small set of vetted providers to run the platform, including hosting, database, DNS, email, and AI services (currently Supabase, Netlify, Cloudflare, Microsoft 365, and Anthropic). Each is bound by contractual data-protection terms and may process data only to provide their service to us.
We use industry-standard safeguards including encryption in transit, row-level access controls that isolate each hotel's data, per-person staff logins, and least-privilege access. No system is perfectly secure, but we work to protect information and to respond promptly to any issue.
Depending on where you live, you may have rights to access, correct, delete, or restrict use of your personal information. For website/prospect data, contact us at privacy@sonastay.com and we will respond within a reasonable time. For guest data held on a hotel's behalf, please contact that hotel (the controller); we will assist the hotel in fulfilling valid requests.
We use only the cookies and similar technologies needed to run the site and understand basic, aggregate usage. We do not use cookies for third-party advertising, and we do not sell personal information.
Our platform is intended for hotel operations and adult guests. It is not directed to children, and we do not knowingly collect personal information from children.
We operate from the United States and may process information in the U.S. and in the locations of our service providers. Where required, we put appropriate safeguards in place for cross-border transfers.
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to affected hotels.
Sonastay LLC
Privacy: privacy@sonastay.com · General: hello@sonastay.com
Katy, Texas, USA