Privacy
Privacy policy
How the Haven app and website handle account details, enquiries, service records and uploaded media. Updated 29 September 2026.
Your Haven account
Haven uses your account ID, name, contact details, account role and password verification data to provide sign-in and appropriate access. Stay records, meal orders and support tickets are used to coordinate the services you request. Access is limited according to account responsibilities. Public rooms, meals and contact pages can be used without signing in.
When you contact us
We save the details you submit, including your name, reply contact, stay preferences and message, so our team can respond. Enquiries are stored in Haven and copied to a private Google Sheets report for follow-up. Starting a form does not send its contents to analytics.
The Android app
The Android app does not load Google Analytics, Cloudflare's website analytics script or third-party live-chat scripts. Optional website analytics are disabled in the packaged app. Account, enquiry, upload and support requests still reach Haven when you use those features. The app does not request access to your contacts, microphone or device location, or broad access to your photo library. You choose individual photos or videos through the system file picker.
Storage and external services
Haven uses Cloudflare to serve its API and MongoDB Atlas to store account and service records. Enquiries are also copied to a private Google Sheets report. Uploaded listing media uses configured Google Drive storage or Haven's database fallback. Network providers process connection information, including IP addresses, to deliver and protect requests. Opening WhatsApp or email hands your selected message to that service; it is not sent until you choose to send it there.
Your analytics choice
Choose Allow analytics to help us understand public page visits, searches, selected areas, contact clicks, chatbot topics and website performance. These events use a random session reference and limited details such as device category, country and referring website. We do not include your name, contact details, passwords or message text in these events.
Google Analytics
When enabled, Google Analytics follows the same opt-in choice. It helps us understand traffic sources and which public website steps lead to enquiries. We do not use it to record activity inside signed-in accounts or send it the contact details you submit.
Simple traffic and speed reports
Cloudflare provides aggregate reports about public page visits, referring websites and loading performance without analytics cookies or individual visitor profiles. These reports are separate from the detailed analytics you can choose to allow.
Changing your choice
Use Analytics preferences in the website footer to allow or decline detailed analytics at any time. Choosing Essential only keeps search, enquiries and account access available. Your browser's Do Not Track or Global Privacy Control preference also turns detailed analytics off.
How long reports are kept
The private Google Sheets report keeps a rolling view of up to 20,000 website events and 5,000 enquiries. Copies of individual analytics events in Haven's database expire 30 days after successful export. Events waiting to reach the report remain queued. Business enquiry and service records are kept separately for ongoing follow-up and are not erased when a report reaches its limit.
Support questions and account access
Questions sent to website chat help us improve our answers; detected contact details and credentials are removed from that question log. Analytics receives only a topic or action, not the conversation text. Haven limits access to guest, property and team records according to each person's responsibilities.
Property photos and videos
Photos and videos submitted for listings are stored for Haven's review and displayed in approved listings. Files may contain metadata supplied by your device. Upload only material you have permission to use, and avoid including private documents or other people's personal information.
Local storage and security
The app stores a sign-in token on your device so you can return to your account; signing out removes it and clears loaded account records. Recent help conversations are kept in session storage, with detected contact details and credentials removed. Requests to Haven's API use HTTPS. Automated redaction is not a guarantee, so never put passwords or private documents into chat.
Account deletion and retention
Account and service records are kept for service administration and follow-up; they do not follow the analytics event expiry described above. Request account deletion through Account settings in the app or the account-deletion page on this website, without needing to sign in. The team verifies ownership before deleting the account and associated personal data, including applicable copies held by service providers. Any records retained for a legitimate security, dispute or legal reason must be explained as part of the request, including the applicable retention period. Submitting a request does not itself delete an account or cancel an active service.
Contact about your information
For privacy questions, corrections or deletion requests, contact Haven at [email protected] or use the support form below. Do not send your password. The team will confirm the next steps after verifying your request.