Sona ← Back to sonastay.com

Privacy Policy

Effective August 11, 2026 · Last updated August 11, 2026

Who we are. Sona is a white-label guest-experience platform operated by Sonastay LLC ("Sona," "we," "us"). We provide hotels with a browser-based guest app and staff dashboard. This policy explains how we handle personal information across two roles: as the operator of our own website, and as a service provider that processes guest data on behalf of the hotels who use our platform.

1. The two ways we handle data

Our website & prospects (we are the controller). When you visit sonastay.com, request a demo, or book a call, we decide how your information is used and this policy governs it directly.

Hotel guest data (we are a processor). When a hotel runs our platform, guests enter information into an app branded as that hotel. The hotel is the data controller; Sona processes that data only to provide the service, under the hotel's instructions and our agreement with them. Guests should also review the hotel's own privacy notice.

2. Information we collect

From website visitors and prospects

Guest information processed for hotels

We do not process payment card numbers. The hotel remains the merchant of record; any charge-to-room or payment is handled by the hotel, not by Sona.

3. How we use information

We do not sell personal information, and we do not use guest data to serve advertising.

4. AI concierge

The in-app concierge is powered by a third-party AI provider (Anthropic). It is designed to answer only from the hotel's verified facts and to hand off to staff for anything else. Guest messages processed by the concierge are handled under our subprocessor terms and are not used to train third-party models.

5. Data retention

Guest personal information is automatically expired approximately five days after checkout — a privacy feature built into the platform. Website/prospect contact information is kept only as long as needed for the purpose it was collected or as required by law, after which it is deleted or anonymized.

6. Service providers (subprocessors)

We rely on a small set of vetted providers to run the platform, including hosting, database, DNS, email, and AI services (currently Supabase, Netlify, Cloudflare, Microsoft 365, and Anthropic). Each is bound by contractual data-protection terms and may process data only to provide their service to us.

7. Security

We use industry-standard safeguards including encryption in transit, row-level access controls that isolate each hotel's data, per-person staff logins, and least-privilege access. No system is perfectly secure, but we work to protect information and to respond promptly to any issue.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or restrict use of your personal information. For website/prospect data, contact us at privacy@sonastay.com and we will respond within a reasonable time. For guest data held on a hotel's behalf, please contact that hotel (the controller); we will assist the hotel in fulfilling valid requests.

9. Cookies and analytics

We use only the cookies and similar technologies needed to run the site and understand basic, aggregate usage. We do not use cookies for third-party advertising, and we do not sell personal information.

10. Children

Our platform is intended for hotel operations and adult guests. It is not directed to children, and we do not knowingly collect personal information from children.

11. International users

We operate from the United States and may process information in the U.S. and in the locations of our service providers. Where required, we put appropriate safeguards in place for cross-border transfers.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to affected hotels.

13. Contact

Sonastay LLC
Privacy: privacy@sonastay.com · General: hello@sonastay.com
Katy, Texas, USA