Last updated: 19 May 2026. This policy is provided for transparency and should be reviewed by legal counsel before relying on it commercially.
Who we are
LetPilot provides holiday-rental management software. This policy covers the LetPilot website, web app, mobile app and backend API operated at letpilot.co.
Data we collect
- Account data: name, email, password (stored hashed), business/tenant name.
- Operational data you enter: properties, bookings, guest details you record (name/email/phone), tasks, messages, pricing.
- Device data for notifications: a push token, if you enable notifications.
- Diagnostics: crash and error reports (via Sentry) — technical context only, with personal-data scrubbing enabled.
We do not sell personal data and do not use third-party advertising trackers.
How we use it
To provide the service: authentication, syncing bookings and calendars, operational notifications, owner statements, and payment processing via Stripe (we do not store card numbers).
Sub-processors
Stripe (payments) and Sentry (error monitoring), and — only if you connect them — Xero, Twilio, PriceLabs, Minut, RemoteLock, Mailgun and Bunny. Data shared is limited to what each integration requires.
Retention & deletion
Financial records are retained for accounting and audit purposes. Request account deletion at privacy@letpilot.co; we delete or anonymise personal data within 30 days except where retention is legally required.
Your rights
You may request access, correction, export or deletion of your personal data by emailing privacy@letpilot.co. We respond within applicable statutory timeframes (e.g. UK/EU GDPR where it applies).
Security
Encryption in transit (TLS), credentials encrypted at rest, breached-password rejection and login throttling. No system is perfectly secure; report vulnerabilities to security@letpilot.co.
Contact
LetPilot — privacy@letpilot.co