Privacy Policy
Last updated: July 24, 2026
Maravo ("we") provides an operations platform for short-term rentals. This policy explains what personal data we process, why, and the rights you have under the GDPR (EU) and the LGPD (Brazil). This document is a general summary and not legal advice.
1. Data we collect
Account data: name, email, password (stored as a salted hash — we never see the plain text), role, language preference.
Workspace data you enter: properties (addresses, Wi-Fi and lock notes, emergency contacts), tasks, checklists, expenses, income, maintenance records, documents, and photos your team uploads as proof of work.
Guest data your host enters for a stay: guest name, contact details, party size, stay dates, and payment amounts. The host is the controller of guest data; Maravo processes it on the host's behalf.
Party members: a host may record the other people on a booking (name, date of birth / age, and an infant flag) for capacity and safety.
Guest identity documents (optional): if a host asks guests to verify their identity, a guest may upload a photo of a government-issued ID. These are treated as sensitive personal data — encrypted at rest with a per-workspace key, stored separately from other photos, viewable only by the host, never used for any other purpose or shared with third parties, and automatically deleted 30 days after checkout (or sooner if the host deletes them).
Staff identity documents (optional): a cleaner or service person may upload their own ID so the host knows who enters the property. Same protections as guest IDs — sensitive, encrypted at rest, viewable only by the host, not shared, and automatically deleted 30 days after upload (or sooner if the owner or host deletes it).
Technical data: session cookie (HTTP-only, required to sign you in), IP address in server logs for security and rate-limiting, and push-notification subscriptions when you opt in.
2. Why we process it
To run the service: scheduling cleanings, tracking maintenance and expenses, generating guest pages, sending the notifications you enable.
To secure it: fraud prevention, abuse and rate limiting, audit history of workspace activity.
To bill subscriptions through our payment processor. We never store full card numbers.
3. Processors we use
Stripe (payments), Resend (transactional email), OpenAI (voice transcription and the guest concierge — only the content needed to answer), and our hosting provider (EU-region servers). Each receives only what is necessary for its function.
Meta Platforms (advertising measurement): on our public pages and signup we use the Meta Pixel to measure whether our ads work. It reports page views and signup/checkout milestones — never names, emails, or your workspace content. It does not run in the mobile apps, and it never loads if your browser sends a Global Privacy Control or Do-Not-Track signal.
AI features (such as scanning photos into your inventory) send the photos you select to the configured AI provider (OpenAI or Google) solely to generate suggestions you then review — they are not used to train models by us. AI features can be disabled at any time in Settings → AI features.
4. Retention
Your data stays for as long as your workspace is active. If you cancel your account, workspace data is permanently deleted after a 30-day grace period. You can export everything as CSV/JSON first (Settings → Data & account).
5. Your rights (GDPR / LGPD)
Access and portability: download all your data from Settings → Export.
Rectification: edit any record in the app.
Erasure: delete individual records, or cancel the account for full deletion.
Objection and restriction: contact us and we will respond within 30 days.
You may also lodge a complaint with your supervisory authority (e.g. CNPD in Portugal, ANPD in Brazil).
6. Cookies
We use a first-party session cookie to keep you signed in, plus a language preference stored in your browser. Our public marketing pages and signup also use the Meta Pixel cookie for advertising measurement (see "Processors we use"); you can opt out with a Global Privacy Control / Do-Not-Track browser signal, via Meta's ad settings, or by blocking the cookie — the product works fully without it. The logged-in product sets no other tracking cookies.
7. Contact
Data questions or requests: [email protected].