01What we collect
Partners: application, identity, business, contact, tax-status, connected-account readiness, and agreement acceptance records. An acceptance stores the typed name, time, version, hash, and IP address. Guests: the guide sets a first-party cookie with a random 30-day session identifier and stores property attribution, chosen preferences, listing activity, and optional feedback. When a guest requests a booking, we also collect the name, phone, email, booking details, accepted-policy version, and technical evidence needed to operate, support, and defend that booking. Payments: for an opt-in partial-payment offer we store Stripe identifiers, status, amounts, refunds, disputes, settlement, and reconciliation records. Stripe-hosted Checkout receives the card details; PostcardPerks does not receive or store full card numbers or security codes. Photos uploaded through PostcardPerks are delivered through our site. When an operator supplies a link to a photo hosted on another site, that site may receive the browser information needed to return the image.
02How we use it
We use this information to operate the guide and booking flow, respond to partner applications, lock capacity, attribute bookings to the referring property, send contracts and receipts, process refunds and disputes, pay eligible host shares, reconcile Stripe and the journal, prevent abuse, support guests and partners, meet reporting duties, and improve recommendations. We do not sell personal information and do not send marketing to guests.
03Retention & choices
Guest sessions expire after 30 days of inactivity and are removed with non-booking activity after the operating retention period. Booking, payment, refund, dispute, settlement, tax, journal, and agreement records are kept for the period needed for accounting, legal, dispute, fraud-prevention, and platform-reporting duties. To request access, correction, or deletion, or to clear a non-booking guest session, email hello@postcardperks.com. Some financial and contract records cannot be deleted while a retention duty applies.
04Service providers
Railway processes hosting and database information. Stripe processes connected-account onboarding, hosted checkout, payments, refunds, disputes, and partner transfers for the payment cohort. Email and SMS providers process transactional booking messages. The activity vendor receives the guest and booking information needed to provide the activity and collect the stated balance. These providers receive access for their stated role.
Questions or requests: hello@postcardperks.com.