Privacy Policy
Last updated: September 25, 2026
1. Who we are
Starry is a trade name of Zincan LLC, a limited liability company registered in North Carolina, United States ("Starry", "we", "our", "us"). Starry is software for short-term rental management companies.
This policy covers the Starry web console, the Starry mobile apps for iOS and Android, the AI assistant, the account-less job and chat links we send by text message and email, the public API, and the websites we host for our customers on their own domains ("Starry Sites") — together, the "Services".
Questions? Email privacy@starry.help.
2. Whose data this is — read this part first
Almost everything in Starry was put there by a management company about somebody else. There are two very different relationships here and it changes who you should contact.
- If you are a Starry customer — a management company and its staff — we hold your data for you, and this policy describes what we do with it.
- If you are a guest, an owner, a cleaner or a contractor whose details are in a company's Starry account, that company decides what is collected about you, what it is used for, and how long it is kept. We process it on their instructions. Ask them first. If you come to us we will help, but we will usually have to refer you back to them, because it is their record and we cannot change it on our own initiative.
- If you visited a website we host for a customer — a Starry Site — the analytics and any form you filled in belong to that company. Section 6 explains what is collected.
3. Information we collect
3.1 Information you provide about yourself
- Account details. Name, email address, phone number, profile photo, and language preference when you create an account or accept an invitation.
- Company details. Company name, industry, website, phone, logo, service regions, staff and their trades, and availability.
- Payment setup. If you connect Stripe to take card payments, Stripe collects your business and bank details directly. We store the resulting account identifier and status, not your bank details or full card numbers.
3.2 Information you provide about other people and places
This is the bulk of what is in Starry, and it is sensitive. It includes:
- Property data — addresses, unit details, and access information: door codes, lockbox and alarm notes, and access photographs. Access information is shown to the people assigned work at that property, which can include contractors with no Starry account, over a personal link.
- Reservation and guest data — guest name, email address, phone number, party size, dates, confirmation code, payout amount and notes, entered by a company or pushed through the API.
- Crew contact details — the phone numbers and email addresses a company uses to send somebody their work.
- Job content — checklists, notes, blocking reasons, and photographs taken inside properties as proof that work was completed.
- Messages — the content of conversations in Starry channels with staff, crew, guests and customers, including messages delivered by text message and email and replies ingested back into the thread.
3.3 Information we collect automatically
- Device and usage data. IP address, device model, OS version, app version, crash reports and performance metrics, collected via Sentry to diagnose errors.
- Location. On mobile, with your permission, we use location to show where field staff are on a company's team map and to record where a job was worked. You can revoke this at any time in your device settings. We do not track anybody who has not been added to a company as staff.
- Push notification tokens. When you enable notifications we receive a token from Apple or Google (via Expo) so we can deliver job and chat updates.
- Cookies and similar. Session cookies and local storage to keep you signed in, remember your language, and remember your light/dark preference. Auth forms use Cloudflare Turnstile to tell people from bots.
3.4 Information from third parties
If you sign in with an OAuth provider or are invited to a company, we receive basic profile information (name, email, profile image) from that source.
4. How we use information
- Provide, operate, secure and maintain the Services.
- Turn a company's reservations into turnover work, calculate the window a crew can be inside a unit, schedule it, and get it in front of the person assigned to it.
- Deliver messages, job links and notifications by in-app message, push, text message and email, on a company's behalf.
- Run the AI assistant when somebody in a company asks it something — see section 5.
- Host and serve customers' Starry Sites to the public.
- Improve the Services — debug crashes, diagnose performance problems, and develop new features.
- Detect, prevent and respond to fraud, security incidents and abuse.
- Comply with legal obligations and enforce our terms.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use customer content to train general-purpose AI models.
5. The AI assistant
Starry includes an AI assistant that reads a company's data and takes actions in it. It is not an optional add-on and it is not limited to chat: it can list and change properties, reservations, jobs, crew and site pages.
- What is sent. When somebody asks the assistant something, the request and the relevant parts of that company's data are sent to our model providers to produce an answer or perform the action. The assistant works inside one company at a time and inside the permissions of the person using it.
- Who the providers are. Text runs on Anthropic. Voice runs on xAI, which processes the audio of the conversation. Both are under contract and neither uses this content to train their models.
- What is kept. Conversations and the actions the assistant took are stored in the company's account so there is a record of what was asked and what changed. Outbound actions are recorded as approvals, with who approved them.
- Guests are not talking to the assistant. A message drafted for a guest is reviewed and approved by a person at the management company before it sends.
6. Starry Sites and their visitors
We host websites for our customers, often on the customer's own domain. If you are a member of the public visiting one:
- We record page views and a count of unique visitors so the company can see whether their site is working. This is aggregated into daily totals.
- If you fill in a contact or quote form, what you typed — usually your name, contact details and your message — goes to that company as a lead. They decide what happens to it next.
- If you pay through a site, the payment is processed by Stripe for that company. We do not hold your card details.
- The company whose site you visited is the one to contact about any of it. We will help you reach them.
7. How we share information
We share personal information only in these circumstances:
- Within a company's own account, as that company has set it up — for example showing a property's door code and access notes to the person assigned a job there, or showing a guest's message to the staff on that thread.
- With service providers who operate parts of the Services on our behalf under confidentiality and data-protection obligations:
- Amazon Web Services — hosting, database and file storage, including job photographs
- Stripe, Inc. — payment processing and payouts
- Twilio — text-message delivery of job links, chat links and notifications
- Postmark — email delivery
- Expo (EAS) — mobile builds and push notification delivery
- Sentry — crash and performance monitoring
- Cloudflare — bot protection on authentication forms
- Let's Encrypt — TLS certificates for customers' custom domains
- Anthropic — the assistant's language model
- xAI — the assistant's realtime voice
- For legal reasons — to comply with subpoenas, court orders or other legal process, or to protect our rights or the safety of users.
- In a business transfer — as part of a merger, acquisition or sale of assets, with notice to you where required by law.
8. Data retention
We keep personal information for as long as the company that put it there keeps it, and as long as we need it to provide the Services, meet legal and accounting obligations and resolve disputes. Job photographs and message history are part of a company's operational record and are retained with it. Some records (invoices, payment logs, security and audit logs) may be retained for up to seven years to satisfy U.S. tax, accounting and security requirements.
Job and chat links expire on their own and can be revoked at any time by the company that sent them.
9. Security
We use industry-standard safeguards including TLS in transit, encryption at rest for database backups, OAuth2 with PKCE for authentication, scoped API tokens, per-company data isolation, audit logging, and strict access controls on production systems. Job and chat links are unguessable, personal, time-limited and revocable.
No system is perfectly secure. If we become aware of a breach that affects you we will notify you, or the company whose account holds your data, as required by applicable law.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete or port your personal information, to object to or restrict processing, and to withdraw consent.
If you have a Starry account, you can:
- Update your profile and language in Settings.
- Delete your account from the Starry mobile app under Privacy & security, or by emailing privacy@starry.help.
- Revoke location or notification permissions in your device settings.
- Reply
STOPto any text message.
If you do not have an account — you are a guest, an owner or a contractor whose details a company entered — contact that company first, for the reasons in section 2. Email us and we will help you reach them.
California residents have additional rights under the CCPA / CPRA (right to know, right to delete, right to correct, right to opt out of sale or share — Starry does not sell or share for cross-context behavioural advertising). Residents of the EEA and UK have rights under the GDPR / UK GDPR.
11. Children
Starry is business software and is not directed to children under 16. We do not knowingly collect information from them. If you believe a child has provided us with personal information, contact privacy@starry.help and we will delete it.
12. International transfers
Starry is based in the United States and our infrastructure and our providers are primarily in the United States. If you use the Services from outside the U.S., your information will be processed in the U.S. subject to U.S. law. We take appropriate safeguards for cross-border transfers where required.
13. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, give prominent notice in the app or by email before the changes take effect.
14. Contact
Questions, requests or complaints? Email privacy@starry.help or write to:
Zincan LLCAttn: Privacy
North Carolina, United States