Resort Buggy

Built with privacy first.

Resort Buggy protects your property's data and your guests' data with TLS encryption in transit, encrypted storage at rest, role-based access, per-property data isolation, EU hosting, and encrypted nightly off-box backups — and tells you plainly what we do and don't do.

Last updated: 2026-07-10

How we protect your data

Encryption in transit and at rest

All traffic is encrypted in transit with TLS (certificates via Let’s Encrypt). The production database lives on a LUKS-encrypted volume (AES-256), and nightly off-site backups are client-side encrypted before they leave the server — encryption keys are never stored with the data they protect. Access to the database is restricted to the application over a private network.

Access controls

Token-based authentication (JWT) with strict role separation — guests, drivers, and admins each see only what their role allows. Guest access codes expire automatically at checkout and can be revoked instantly.

Multi-tenant isolation

Every database query is scoped to your property’s ID at the application layer. Your guests, drivers, rides, and maps are never visible to another property — your data is yours.

Backup & recovery

Automated daily database backups copied off-box, with 30-day retention, so your operational history survives hardware failure or loss of the server.

Privacy

We collect the minimum needed to dispatch a buggy — and nothing more.

What we collect

  • Guest name and room/villa identifier (provided by your property)
  • Access codes for guests, drivers, and admins
  • Pickup and dropoff selections, ride history
  • GPS location while the app is actively in use
  • A push notification token, only if the user opts in

What we don't

  • No payment or billing data from guests — rides are complimentary
  • No email addresses or phone numbers from guests
  • No tracking across other apps or websites, no ad networks
  • No analytics in the guest app — on the marketing site, analytics load only if you opt in
  • Push notification payloads carry only ride status — never guest personal data

Where data lives

All data is hosted on Hetzner Cloud in the European Union. It does not leave the EU for processing or storage.

Export & deletion

You can request a full export or deletion of your property's data at any time — email [email protected]. Details in our Privacy Policy.

Compliance & certifications

We're an early-stage company and we won't pretend otherwise: here is exactly where we stand today, and where we're headed.

Today

  • GDPR-aligned practices: minimal collection, EU hosting, export and deletion on request
  • Encryption in transit (TLS) and at rest (LUKS-encrypted database volume, AES-256), role-based access, per-property data isolation
  • Daily off-box backups, client-side encrypted before upload, 30-day retention
  • Data Processing Agreement (DPA) with a public sub-processors list and downloadable PDF

Roadmap — not yet attained

  • SOC 2 Type I — targeted within 12 months of general availability
  • ISO 27001 — planned as we grow beyond our founding partners
  • Lawyer-reviewed legal pack — our DPA is published, formal legal review pending

Incident response

If you report a security concern, we acknowledge it within 24 hours.

If a breach affecting your data is confirmed, we notify you within 72 hours with what happened, what data was involved, and what we're doing about it.

Security contact: [email protected]

Responsible disclosure

Found a vulnerability? We want to hear about it. Email [email protected] with steps to reproduce, and we'll respond within 24 hours.

Safe harbor: we will not pursue legal action against researchers who test in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before public disclosure. We don't run a paid reward program yet, but we credit researchers who want to be named.

Prefer to keep it in-house?

For privacy-first properties, a self-hosted deployment on your own infrastructure can be arranged on the Private Island tier — scoped and set up together with our team as a bespoke engagement. You retain full control of your operational data.

Live service status is always public at status.resortbuggy.com.

Have a security question?

Security questionnaires, procurement reviews, or anything we didn't cover here — we answer them personally.