Hyatus Living · Reporting Portal
Effective date: July 17, 2026 · Version 2026-07
This Privacy Policy describes how Hyatus Living (“Hyatus”, “we”, “us”) collects, uses, stores, and protects information in the Hyatus Living financial reporting portal (the “Portal”). The Portal is an internal reporting application used by authorized Hyatus personnel and invited collaborators to review expenses, revenue, reservations, and financial models for Hyatus operating properties.
Account information. When you are invited to the Portal we collect your name and email address. If you sign in with a password, it is stored only as a one-way hash; if you sign in with Google, we store your Google account identifier. We also store your role, page-access grants, theme preference, and sign-in sessions.
Financial data from QuickBooks. With an administrator’s authorization, the Portal connects to our QuickBooks Online company via OAuth and imports business financial data — expenses, vendors, classes, accounts, deposits, and related ledger records — to power the reports in the Portal. QuickBooks connection tokens are stored encrypted (AES-256-GCM) at rest.
Reservation and revenue data. The Portal reads reservation and revenue data from Hyatus property-management systems (read-only replicas of booking and pricing systems). The Portal projects only the non-PII fields it needs — such as unit, dates, rates, channel, and company — and does not copy guest names, contact details, identity documents, or payment instruments.
Bank account data via Plaid. When bank connections are enabled, we will use Plaid Inc. (“Plaid”) to gather your data from financial institutions. By connecting a financial institution account, you grant Hyatus Living and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution. You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with Plaid’s End User Privacy Policy, available at plaid.com/legal. Bank connection tokens and transaction data received through Plaid will be stored encrypted at rest using the same AES-256-GCM standard applied to our QuickBooks connection.
Technical and consent data. We keep sign-in sessions, consent records (which policy version you accepted, when, and the browser user agent), and standard service logs needed to operate and secure the Portal.
We use the information we collect to:
We do not sell personal information and we do not use it for advertising.
Portal data is stored in managed, access-controlled databases (our primary Postgres database, plus read-only replicas of reservation systems). Data is encrypted at rest — through provider-managed storage encryption, and additionally at the application level (AES-256-GCM) for sensitive integration secrets such as QuickBooks and future Plaid connection tokens. Data in transit is protected with TLS. Access inside the Portal is limited by role-based access controls, page-level grants, and per-user data scoping, and sign-in sessions are validated against the database on each request.
We retain information only as long as needed for the purposes above:
You may request access to, correction of, export of, or deletion of your personal information at any time by emailing privacy@hyatus.com. Deletion requests are honored for account data we control; some business financial records may be retained where accounting or legal obligations require it. You may also withdraw consent to this policy, but because the Portal processes business financial data, withdrawing consent may require closing your Portal account.
We rely on a small set of processors to run the Portal: Intuit QuickBooks (accounting data), Plaid (bank connections, when enabled), Google (optional sign-in), managed database and hosting providers (including Neon, MongoDB Atlas, and Vercel), and transactional email delivery. Each processes data under its own privacy terms and only as needed to provide its service to us.
If we make material changes to this policy, we will update the version above and ask you to review and accept the new version the next time you use the Portal.
Questions about this policy or about how your information is handled can be sent to privacy@hyatus.com.