Privacy Policy
Last updated: October 5, 2026
In short
- baandi collects only what it needs to answer guests and alert a host's team.
- We do not sell personal information, show ads or use tracking cookies.
- Guest messages are sent to an AI provider to write and check replies, with long numbers hidden first.
- You can ask us to show, correct or delete your information by writing to fayeem@recrewit.ai.
- 1. Who we are
- 2. Who this policy covers
- 3. What we collect
- 4. How we use it
- 5. How AI is used
- 6. The services it passes through
- 7. Where it is kept
- 8. How long we keep it
- 9. How we protect it
- 10. Your rights
- 11. How to delete your data
- 12. Children
- 13. Changes to this policy
- 14. Contact
1. Who we are
baandi is a service of SH LLC, a New York company ("we", "us"). baandi helps hosts of short-term rentals answer their guests: it drafts replies from a knowledge base the host's team has approved, asks the team when it does not know, and alerts the team on WhatsApp.
baandi is an independent third party and is not endorsed by or associated with Airbnb, Inc. or its affiliates.
2. Who this policy covers
- Visitors to this website.
- Hosts and their team members, who sign in to the baandi portal and may use baandi on WhatsApp.
- Guests whose messages a host handles with baandi.
For guest information, the host decides why and how it is used, and we handle it on the host's behalf and on the host's instructions. If you are a guest and have a question about your information, please ask your host first; we help the host answer you.
3. What we collect
From visitors to this website
We do not use analytics, advertising or tracking cookies on this website, and its lettering is served from the website itself. The company that hosts it for us, Cloudflare, receives the technical details that every web request carries, such as your IP address, your browser type and the time. If you write to us, we receive your email address and what you wrote.
If you press "Request access" and leave your email address, we save that address and the time, and it is emailed to the people at SH LLC who answer requests. We use it only to write to you about baandi, and we keep it until you ask us to delete it.
From hosts and their team members
- Your sign-in. Your email address and a password. The password is kept by our sign-in provider in a scrambled form that we cannot read. We also see when you last signed in.
- Your details. Your first and last name, your WhatsApp number, the ID WhatsApp uses for that phone, when you confirmed the number, and who added you to the team.
- What you do in the portal. The replies you write or approve, the knowledge base entries you add, change or approve (your email is recorded with each change), and a log of who was added to or removed from the team.
- The knowledge chat. Every message in the chat is kept with the email of the person who wrote it, and the whole team can read past chats. A message that looks like a door code is not kept.
- Files you attach. A screenshot, picture, PDF or text file you import, or a picture you add to the knowledge chat, is read by the AI and then discarded. Only the draft entries or the answer made from it are saved.
- The microphone. The microphone in the knowledge chat uses your browser's own speech recognition. The sound does not come to us, but your browser may send it to its maker to turn it into text.
- WhatsApp. When you write to the baandi number, we note your number and the time. The words you write to the assistant are not stored: they are sent to the AI provider once, with long numbers hidden, to write the answer. One exception is a fact you tell the assistant and choose to offer as a knowledge base entry: it is stored so it can become a draft, and decided or day-old suggestions are deleted the next time you offer one.
- Alerts. For each WhatsApp alert we record what it was about, who it went to, when, and whether it arrived. The text of the alert is not stored.
- In your browser. The portal keeps your sign-in in your browser's storage so you stay signed in, and a note that you have seen the Knowledge guide. It sets no cookies.
If a phone number that is not on any team writes to the baandi WhatsApp number, we note the number and the time, do not answer, and delete the note after 30 days.
About guests, on a host's behalf
- The booking. The guest's first name, the number of guests, the dates of the stay, the booking's status, the unit, and the booking site's own reference numbers. baandi does not ask for or store a guest's last name, phone number or email address.
- The conversation. The messages the guest and the host's team write to each other, in full, with their times. If a message has an attachment, we store a link to it on the booking site and do not download the file.
- The reply's reasons. What the AI understood the guest to be asking, the reply it drafted, and the result of each check.
Today baandi answers test guests in its own simulator, and no booking site is connected. Before Airbnb and VRBO are connected through Hospitable, we will update this policy to list the booking details Hospitable sends.
4. How we use it
- To provide baandi: drafting and sending replies, alerting the team, and keeping the knowledge base.
- To let the right people sign in and to keep the service secure.
- To measure what the AI costs and how well it works. For each AI call we record the model, its size and its cost.
- To answer you when you write to us.
We do not sell personal information, we do not share it for advertising, and we do not use your information or your guests' messages to train AI models.
5. How AI is used
baandi uses Claude, an AI model made by Anthropic, and no other AI provider. Before any text goes to the AI, long numbers are hidden: anything that looks like a door code, any other number of four or more digits, and shorter numbers in a sentence about a lock. Times, dates and prices are kept.
What is sent depends on the task:
- A guest reply. The unit's name, the stage of the booking, the guest's first name, the approved knowledge base entries for that unit, and up to the last 12 messages of the conversation. A second, independent AI check then sees the entries used, the guest's messages and the reply.
- The knowledge chat. The list of units, every knowledge base entry, up to 30 earlier messages of that chat, your new message, and any picture you attach.
- Import. The text you paste, with sentences that mention a door code removed first. A picture or a PDF is sent as it is, because a number inside a picture cannot be hidden beforehand, so please keep door codes out of the files you import.
- The WhatsApp assistant. Your message, and what it looks up to answer you: the calendar, guests' first names, recent messages and knowledge base entries.
Replies sent without a person. A reply reaches a guest without a person reading it first only when the host has chosen Automatic mode, has switched on "Send automatically when a guest asks" for every entry the reply uses, and every safety check passes. Refunds, cancellations, complaints, prices and other sensitive topics always wait for a person. Replies are sent in the host's name and are not labelled as written by AI.
Anthropic's commercial terms state that it does not train its models on what is sent through its service.
6. The services it passes through
We use these companies to run baandi, and each receives only what its job needs:
| Service | What it does for us | What it receives |
|---|---|---|
| Supabase | The database, sign-in and our server code | Everything listed in section 3 that we store |
| Anthropic | The AI that drafts and checks | The text described in section 5 |
| Meta (WhatsApp) | Alerts and the assistant on WhatsApp | Team members' WhatsApp numbers, what they and the assistant write, and each alert: the unit, the guest's first name, the stay dates, and the first line of the guest's message with long numbers hidden |
| Resend | Sends sign-in codes, invitations and requests for access by email | The email address, the code or the invitation, the name and email of the person who invited you, and the address of someone who asked for access |
| Cloudflare | Hosts this website and the portal's pages | The technical details of each web request, such as the IP address |
| Google Fonts | Supplies the lettering inside the portal (not on this website) | The IP address and browser type of a signed-in team member's browser |
| Hospitable | Will connect Airbnb and VRBO | Nothing yet; it is not connected |
We may also disclose information when the law requires it, or to a company that takes over baandi, which would have to keep to this policy.
7. Where it is kept
Our database is in the United States. If you are in another country, your information is sent to and handled in the United States, whose privacy laws may differ from yours.
8. How long we keep it
- Guest bookings and conversations are kept while the host uses baandi, so the history behind each reply stays available. They are deleted when the host asks us to, or after the host stops using baandi.
- Knowledge base entries moved to the Trash can be restored for 30 days and are then removed from use for good. The record of a deleted entry and its earlier versions is kept, so the reason behind a past reply can still be explained.
- A team member who is removed has their name and WhatsApp number deleted. The log of team changes keeps their email, and their sign-in record stays with our sign-in provider until we are asked to delete it.
- Sign-in codes stop working after one hour.
- Notes of WhatsApp messages from numbers that are on no team are deleted after 30 days.
- Test data from the simulator is deleted when the host presses "Delete all test data".
Deleted information may stay in our database provider's backups for a short time, until those are replaced.
9. How we protect it
- Only people on a host's Team list can sign in, and a first or forgotten password needs a 6-digit code sent to that person's email.
- Everyone on a Team list can see that host's conversations and knowledge base, so a host should add only people they trust.
- The database refuses direct access. Everything goes through our server code, which checks who is asking first.
- What arrives from WhatsApp is checked to be really from Meta before it is used.
- Information is encrypted on its way to and from baandi, and in the database.
- The text of messages is never written to our server logs.
No service can promise perfect security. If we learn that your information was exposed, we will tell the people affected without undue delay.
10. Your rights
Wherever you live, you can ask us to show you the information we hold about you, to correct it, to give you a copy, or to delete it. We do not treat anyone differently for asking, and we answer within 30 days.
- If you live in California or another US state with a privacy law: we do not sell personal information and do not share it for advertising. We handle guest information as a service provider to the host.
- If you live in the European Economic Area or the United Kingdom: we handle hosts' and team members' information to carry out our agreement with the host and for our legitimate interest in running a secure service, and we handle guest information as a processor for the host. You may also object to or ask us to limit a use of your information, and you can complain to your local data protection authority.
If you are a guest, please send your request to your host. If you send it to us, we pass it to the host and help them answer.
11. How to delete your data
- Write to fayeem@recrewit.ai from the email address you use with baandi. If you wrote to the baandi WhatsApp number, tell us that phone number. If you are a guest, tell us which host you stayed with.
- We may ask one question to make sure the request is really from you.
- We delete your information within 30 days and write back when it is done.
We keep only what the law requires us to keep, and the plain record that a deletion was asked for and done. A host can also remove a team member on the Team screen at any time.
12. Children
baandi is made for businesses and adults. We do not knowingly collect information from children under 16, and if you believe a child has given us information, write to us and we will delete it.
13. Changes to this policy
When we change this policy we change the date at the top. If a change affects how your information is used in an important way, we tell hosts by email before it takes effect.
14. Contact
SH LLC
Email: fayeem@recrewit.ai