TeratakHub

Privacy Policy

Last updated: 2 October 2026

This policy explains what information TeratakHub holds, why, and what you can do with it. Who operates TeratakHub is set out in section 1 of the Terms of Service.

1. What we collect

Owners and staff: name, email address, phone number, your language choice, and the business information you enter — units, rates, bookings and invoices.

Guests: the details an owner records, or that a guest enters in a booking request — name, phone number, email address, and IC or passport number if the owner records it. Guests who leave a review give a star rating and an optional comment.

When someone sends a booking request or joins the waitlist, we keep a one-way hash of their IP address for up to 24 hours to limit repeated submissions. The IP address itself is not stored.

These two forms also use Cloudflare Turnstile to block automated submissions. Turnstile runs only after you start filling in the form, and Cloudflare processes technical information from your browser for this check.

We do not use advertising or analytics trackers.

2. Why we use it

Only to run the service: to show your bookings and calendar, to send booking and reminder emails, to prepare invoices, and to bill your subscription and booking commission.

Owners decide which guest details to record. We store them for the owner and do not use them for anything else.

3. What is shown publicly

A unit's booking page shows only what the owner publishes: unit details, photos, rates, available dates and approved reviews. Reviews show the rating, comment and date — never the guest's name.

Photos an owner uploads are public files that anyone with the link can open. Before a photo is stored it is converted, and the location data (GPS) and other camera information inside the file are removed.

The owner's WhatsApp number appears on the booking page only if the owner turns that on.

Guest IC or passport numbers are never shown on any public page.

Calendar links shared with Airbnb, Booking.com or Google Calendar contain booked dates only — no guest names or prices. The guest guide opened from a unit's QR code shows only that unit's name and the guide the owner wrote.

4. Where data is stored and who processes it

Data is stored in a Supabase database. The website runs on Cloudflare. Emails are sent through Resend. Subscription payments are handled by CHIP. These providers process data only to provide their part of the service.

Each owner can see only their own data; access is enforced in the database itself. Payment account details and payout bank details are encrypted before they are stored.

5. Cookies

We use a login cookie to keep you signed in, and a cookie that remembers your language choice for one year. We do not use advertising cookies.

6. Export, retention and deletion

You can export your bookings, guests and units as CSV at any time, including after you cancel.

After you cancel, your data is kept. If your account stays inactive for 90 days, your data is deleted, and we notify you before that happens.

Billing records (invoices and commission) are kept for our accounts, but the owner's name, email address and phone number on them are removed.

Contact