Privacy Policy

Effective Date: May 2026 · Updated: 30 August 2026

1. Introduction

This Privacy Policy explains how Hostli Ltd. ("Hostli") processes personal data. It covers our marketing website (www.hostli.ai) and our application (app.hostli.ai). On the marketing website we are the Data Controller. In the application we act as a Data Processor on behalf of our client hotels, who are the Controllers for their guest data. This Policy complies with the Israeli Protection of Privacy Law (PPL) 5741-1981 and its Amendment 13, the Privacy Protection Regulations (Instructions for Data Transferred to Israel from the EEA) 2023, and the EU General Data Protection Regulation (GDPR) where applicable. The detailed obligations we accept toward our hotel customers as a processor (including security measures, sub-processor list, retention timelines, and international transfer mechanisms) are set out in our Data Processing Agreement at /en/legal/dpa.

2. Our Role: Controller or Processor

Marketing website (www.hostli.ai): Hostli is the Data Controller for data collected directly from website visitors and prospects (contact form submissions, demo requests, analytics events). Hostli application (app.hostli.ai): each hotel is the Data Controller for guest data uploaded to or generated within the platform. Hostli is the Data Processor. The hotel is responsible for ensuring it has the legal right and necessary consent to collect that guest data and share it with Hostli. Hostli processes such data only on the hotel's documented instructions, as set out in our Data Processing Agreement at /en/legal/dpa.

3. What We Collect

From marketing website visitors: contact information you provide (name, work email, phone, hotel name) and technical metadata (IP address, browser/device, pages viewed) collected with your consent where required. From hotel guests, processed on behalf of the hotel: contact information uploaded by the hotel (name, email, phone), public Facebook/Instagram comments on the hotel's posts, and public reviews of the hotel that we aggregate to support analytics and AI features. From hotel staff: account information (name, work email, phone for authentication), and login and audit events. A complete description of categories, purposes, and processing operations for guest data is in Annex 1 of our DPA at /en/legal/dpa.

If you contact us by messaging our WhatsApp business number, we receive the phone number the message was sent from, the WhatsApp profile name you have set, the content of your message, and the time it arrived. Where you reached us from an advertisement, Meta also supplies a click identifier and the advertisement's headline. We derive your country from the dialling prefix of the number. Where the profile name appears to be that of a business, we may send it together with the phone number to our AI provider (Google Vertex AI) to identify the business before we reply. We do not ask for, and do not need, any further personal information in order to respond.

To understand which pages and which campaigns lead people to contact us, the message your device pre-fills when you tap a WhatsApp button on this site includes a short reference code (the letters HL followed by eight characters) on its own line at the end. When the message reaches us we use that code to associate your enquiry with the visit it came from, including the pages viewed, the referring source and any campaign parameters, and with the visit information collected by Google Analytics for that session. The code is visible in your message before you send it and you are free to delete it. If you do, we will handle your enquiry exactly as we otherwise would; it simply will not be associated with an earlier visit.

4. Who We Share Data With

We share data with third parties only as necessary to deliver the service. These recipients fall into the following categories: advertising and messaging platforms (e.g., Meta, Google), cloud hosting and infrastructure, managed database and object storage, AI model providers, and transactional communication providers. Our detailed, current list of sub-processors (including each vendor, the data they receive, and the legal mechanism for any international transfer) is provided to our hotel customers as part of their service agreement, and active customers receive 30 days’ advance notice of changes. Audience sync with Meta: when the hotel uses Hostli's audience-sync feature, hashed email addresses are transmitted to Meta to create a Custom Audience. Under Meta's Customer List Custom Audiences Terms, Meta processes the hashed list solely to perform the match (on the hotel's instructions and as a processor, with Hostli acting as the hotel's processor) and deletes the uploaded list once the match is complete. Meta's subsequent delivery of ads using the resulting audience is governed by Meta's own advertising terms, under which Meta acts as an independent controller. The hotel, as the upstream Controller, is responsible for ensuring guests have been informed of this processing in the hotel's own guest-facing privacy notices. Connected Google accounts (Google API Services): When a hotel connects its Google account to the Hostli application, the hotel authorises Hostli (acting as the hotel's processor, on its documented instructions) to access specific Google data through Google's APIs: Google Business Profile (business.manage) to read the hotel's reviews and publish replies and posts; Google Ads (adwords) to create, manage, and report on the hotel's advertising campaigns; Google Analytics (analytics.readonly, read-only) to read the hotel's GA4 property list and traffic and conversion metrics; and Google Search Console (webmasters.readonly, read-only) to read the hotel's verified sites and organic search performance. Hostli uses this data solely to provide and improve the marketing-automation features the hotel has enabled. Hostli does not sell this data, does not use it to serve advertising to anyone else, transfers it only as needed to provide the service, with the hotel's consent, or as required by law, and limits human access to it. Where the hotel enables AI-assisted features, this data may be processed by our AI sub-processor (Google Gemini on Google Cloud Vertex AI) to generate the hotel's own content and recommendations; under Google's terms this data is not used to train generalised AI models, and any retention of prompt data is limited to short-term abuse monitoring. OAuth access and refresh tokens are encrypted at rest. The hotel may disconnect at any time from within the Hostli application or by revoking access in its Google Account security settings (https://myaccount.google.com/permissions), which immediately ends Hostli's access. Hostli's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Google Analytics: we use Google Analytics to measure use of this marketing website. Google receives visit information (pages viewed, referring source, campaign parameters, approximate location derived from IP address, and device and browser type) and, for enquiry events, the pseudonymous hashed identifier and non-identifying attributes described in Section 7. Google does not receive your name, email address, phone number or the content of any message you send us. Google acts as our processor for this purpose under the Google Ads Data Processing Terms, with EU Standard Contractual Clauses where applicable.

5. How Long We Keep Data

We retain personal data only as long as necessary to deliver the service, comply with legal obligations, or as instructed by the hotel customer. Specific retention timelines for categories of data processed on behalf of hotels are set out in Annex 1 of our DPA at /en/legal/dpa. Marketing leads are retained for the duration of the commercial relationship plus a reasonable archival period not exceeding two years. Hotel guests may request deletion of their personal data ("Right to be Forgotten") by contacting [email protected] or by directing the request to the hotel (Controller).

6. Your Rights

Under the Israeli PPL, the GDPR where applicable, and other relevant laws, you have the right to: access the personal data we hold about you, rectify inaccurate or incomplete information, erase your personal data where retention is no longer required, restrict processing in certain circumstances, port your data to another service in a machine-readable format, object to processing for direct marketing purposes, and withdraw consent at any time where processing is based on consent. For guest data held by Hostli on behalf of a hotel, please direct your request to the hotel (the Controller). Alternatively, you may contact us at [email protected] and we will forward the request to the relevant hotel without unreasonable delay. For data we hold as Controller (marketing leads, website visitors, hotel staff accounts), please contact [email protected]. We will respond within 30 days (Israeli PPL) or one month (GDPR Art. 12), extendable by a further two months for complex requests. We maintain technical and organisational measures appropriate to the risk of processing; the specific measures we apply when processing data on behalf of hotels are set out in Annex 2 of our DPA at /en/legal/dpa.

7. Cookie Policy

We use Strictly Necessary cookies (required for authentication and core functionality). To understand site usage we use Vercel Web Analytics (a cookieless, privacy-preserving tool that sets no cookies, does not track visitors across sites, and collects only aggregated, anonymised data, so it runs without a separate cookie opt-in) and Google Analytics 4, which loads under Google Consent Mode v2 with analytics storage denied until you opt in. Targeting cookies for advertising attribution are set only with your consent. Explicit opt-in consent is required for all cookie-based non-essential technologies, aligning with the Israeli Privacy Protection Authority's 2024 consent interpretations and EU ePrivacy guidance. You can withdraw consent at any time via the cookie banner or your browser settings.

Some measurement takes place on our servers rather than in your browser. When you visit this site, use one of our free tools, or send us an enquiry, we record that interaction in our own systems and transmit a pseudonymous summary of it to Google Analytics from our servers. We do this for three purposes: to measure which pages and campaigns lead people to contact us, so that we spend our marketing budget where it works; to understand how our tools and pages are used so that we can improve them; and to protect this site and its forms against automated abuse, spam and flooding, for which we retain a salted, irreversible hash of the IP address a request came from.

Our lawful basis for this processing is our legitimate interests (Article 6(1)(f) GDPR) in measuring and improving our own service and in keeping our systems secure, a purpose the GDPR expressly recognises in Recital 49. These server-side events set no cookies and store no identifiers on your device, which is why they fall outside the consent requirement in Article 5(3) of the ePrivacy Directive that governs the cookie-based measurement described above. The summary carries a salted, irreversible hash of your phone number or email address in place of the identifier itself, together with non-identifying attributes such as country, dialling code, device type, campaign and an indication of message length. It never contains your name, phone number, email address or the content of your message, and is sent with advertising consent signalled as denied and ad personalisation disabled.

Your right to object: you have the right to object to this processing at any time on grounds relating to your particular situation (Article 21(1) GDPR). Write to [email protected] and we will stop processing your data for these purposes unless we can demonstrate compelling legitimate grounds that override your interests. Your choice in the cookie banner governs cookie-based measurement in your browser; it does not by itself stop this separate server-side processing, which you can end by objecting or by asking us to erase your data under Section 6.

8. Law Enforcement & Government Requests

Hostli may disclose personal data to law enforcement or government authorities only when legally required. We review every request to verify it is legally valid, properly scoped, and issued by a competent authority before any data is disclosed. We will challenge or reject requests we believe to be overbroad, vague, or otherwise unlawful. We disclose only the minimum data necessary to comply with the specific legal obligation and do not provide bulk or unrestricted access to user data. We maintain records of all government data requests, our responses, the legal basis relied upon, and the parties involved. We will notify affected users of a data request unless prohibited by law or court order from doing so.

9. International Data Transfers

Hostli is headquartered in Israel and processes data primarily within Israel and the European Union. Some processing takes place in the United States via our sub-processors. Israel benefits from a European Commission adequacy decision, so transfers from the EEA to Hostli in Israel require no additional mechanism. Where we or our sub-processors transfer EEA personal data to the United States or other third countries, we rely on appropriate safeguards (EU Standard Contractual Clauses, EU-US Data Privacy Framework where applicable, and supplementary technical measures). The specific transfer mechanism for each sub-processor is provided to our hotel customers as part of their service agreement.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. The current version is always available at https://www.hostli.ai/privacy. Material changes will be communicated to active customers via email or in-app notification at least 30 days before they take effect.

11. Contact

For privacy inquiries, to exercise your rights, or to submit a data subject request, contact us at [email protected]. For security incidents or suspected vulnerabilities: [email protected]. Data subjects who are not satisfied with our response may contact the Israeli Privacy Protection Authority (Reshut HaGanah Al HaPrivatsiut) or, for EEA residents, their local data protection supervisory authority.