Privacy policy
Alpy AI (“Alpy”, “we”) is the commercial name under which NEXPA SERVICES operates an operations platform for short-term rental operators: a channel manager, a unified guest inbox, message automation, cleaning and supplier coordination. This policy explains what personal data we process, why, on what legal basis, and the rights you have. It is written for three audiences: account holders and their team members (the businesses that use Alpy), the guests of those businesses, and suppliers who work through Alpy.
1. Who is responsible
Alpy and Alpy AI are the commercial names (noms commerciaux) of NEXPA SERVICES - SASU (société par actions simplifiée unipersonnelle) registered in France, SIREN 994 579 530
40 B Allée des Chênes, 13410 Lambesc, France
Contact: yam@alpyai.com · Website: https://alpyai.com
Alpy is a multi-tenant service. Two roles apply, and they matter for your rights:
- For account data (your login, profile, team, billing and usage of Alpy) we are the data controller.
- For guest and booking data that a rental business brings into Alpy (reservations, guest names and contact details, messages, WhatsApp conversations, cleaning notes) that business is the data controller and Alpy acts as its data processor, on its instructions and under a data-processing agreement. If you are a guest, the business you booked with is your first point of contact; we will assist them, and you, with any request.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account & team | Name, email, phone, language, role and permissions, login events and device/IP of sign-ins, notification preferences | You, your account owner, Google Sign-In if you use it |
| Properties | Listing details, addresses, photos, rates, availability, access details (door codes, Wi-Fi) you choose to store | You, your connected channel manager / PMS |
| Reservations & guests | Guest name, email, phone, stay dates, party size, booking reference and amounts, channel of origin | Booking channels (via the channel manager), your own brand websites, manual entry |
| Messages | Guest conversations from booking channels; WhatsApp Business conversations (message text, media descriptions, timestamps, delivery receipts, the guest’s WhatsApp phone number and profile name, and - if you connect an existing WhatsApp Business app number - the chat history and contact names Meta syncs to us); automated messages Alpy sends on your behalf | Meta (WhatsApp Business Platform), booking channels, you |
| Operations | Cleaning tasks, photos, issues reported, supplier assignments and prices | You, your suppliers, your cleaners |
| Technical | Server logs (IP address, user agent, request paths, timestamps), error reports, a session cookie | Automatically |
We do not process card numbers: payments to Alpy and guest payments on your own sites are handled by payment providers; Alpy records only the status and amounts you choose to mirror.
3. Why, and on what legal basis
- Providing the service - running your calendar, inbox, automations and operations (performance of a contract, Art. 6(1)(b) GDPR; for guest data, the instructions of the controller).
- Guest messaging - delivering messages you write or automate to guests on the channels they used to reach you, including WhatsApp. Business-initiated WhatsApp messages use Meta-approved templates and are sent only to guests who have given the business their number for this purpose; the business remains responsible for the lawful basis of each communication.
- Security and integrity - sign-in protection, abuse prevention, logs (legitimate interest, Art. 6(1)(f)).
- Legal obligations - accounting and tax retention, responding to lawful requests (Art. 6(1)(c)).
- Service communications - onboarding, security and operational notices to account holders (contract / legitimate interest). We do not send marketing email without consent.
4. WhatsApp Business Platform
When a business connects a WhatsApp number to Alpy, the connection is made through Meta’s WhatsApp Business Platform (Cloud API), using Meta’s Embedded Signup or the business’s own Meta app. Alpy then receives, from Meta, the messages guests send to that number and the delivery receipts for messages sent, and sends replies and approved templates through Meta. Where the business chooses to keep using the WhatsApp Business phone app alongside Alpy (“coexistence”), Meta also forwards to Alpy the messages typed on the phone, up to six months of existing conversations, and the phone’s contact names, so that both places show the same conversation. Alpy stores these conversations in the business’s account only; tenants never see each other’s conversations. Meta’s own processing is governed by the WhatsApp Business Terms and Meta Privacy Policy. Access tokens Meta issues to Alpy for a business are stored encrypted and are revoked when the business disconnects WhatsApp in Alpy or removes Alpy’s access in Meta Business Manager.
5. Who we share data with
We use a small number of processors, each bound by contract and, where outside the EU/EEA, by appropriate safeguards (EU standard contractual clauses or an adequacy decision):
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application and database, encrypted backups | Germany (EU) |
| Meta Platforms Ireland Ltd | WhatsApp Business Platform (messages, webhooks, Embedded Signup) | EU / USA |
| Channex.io | Channel manager connectivity to booking channels (Booking.com, Airbnb, Expedia and others) | EU / USA |
| Postmark (ActiveCampaign) | Transactional email | USA |
| Cloudinary | Property photo storage and delivery | EU / USA |
| Sign-in with Google (if used), Maps and Places, optional message translation | EU / USA | |
| Your own connected providers | Your PMS, your email sender, your payment provider - connected by you, under your own agreements | Varies |
We share data with booking channels and your connected systems only to do what you asked (push a rate, answer a guest, sync a booking). We do not sell personal data and we do not use guest data for advertising.
6. Retention
- Account data: for the life of the account and up to 12 months after closure, then deleted or anonymised, except what accounting law requires us to keep (10 years for invoices in France).
- Reservations and guest conversations: for as long as the business keeps them in Alpy; businesses can archive and delete conversations, and deleting the account deletes its data.
- Server logs: 90 days. Encrypted backups: 30 days rolling.
- WhatsApp credentials: until disconnected, then deleted immediately.
7. Security
Data is encrypted in transit (TLS) and at rest for backups and stored credentials; provider tokens are encrypted with a key held outside the database. Access is role-based and account-scoped - every query is bound to the account it belongs to. Sign-ins are rate-limited and new-device sign-ins are notified. Webhooks from Meta and other providers are authenticated by signature before anything is stored.
8. Your rights
Under the GDPR you may ask for access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to yam@alpyai.com; we answer within one month. If you are a guest, we will also route your request to the business that holds your booking, which is the controller of that data. You may lodge a complaint with the CNIL (cnil.fr) or your local supervisory authority. See also our data deletion instructions.
9. Cookies
Alpy uses one strictly necessary session cookie to keep you signed in, and no advertising or third-party analytics cookies on the application. Our public pages load fonts from Google Fonts.
10. Children
Alpy is a business tool and is not directed at children; we do not knowingly collect data from anyone under 16.
11. Changes
We will post changes here and update the date above; material changes are announced to account holders by email.