Ridgeline ← Back to app

Privacy Policy

Effective Date: July 12, 2026 · Replaces the version effective April 1, 2026

Plain English Summary

1. Who This Applies To

This Privacy Policy applies to all users of Ridgeline, including design partners and early access participants. "You" refers to anyone who accesses the Product via a login link or any other access method. Ridgeline is designed for rental property operators — including short-term, mid-term, and long-term rental operators — and this policy applies regardless of property type.

If you are a virtual assistant, co-host, or staff member using Ridgeline on behalf of an operator: your activity in the Product is logged and may be reviewed by that operator. You retain the rights described in Section 9 over your own data.

2. What We Collect

Account data: Your email address and operator identity, used to authenticate access and scope your data to your properties.

Property data: Vendor names, contact details, and roles; device and amenity records; operational procedures and policies associated with your account.

Operational logs: Incidents, notes, and decisions you create or that are generated through your use of the Product.

Usage data: Queries you submit to Ridgeline, session activity, and response data. This includes the content of your conversations with Ridgeline.

Integration data: If you connect a property management system (currently Hospitable), Ridgeline reads reservation, guest, property, and messaging data from it under your authorization. That connection is yours: it runs on your own account with that provider, under your agreement with them, and you can disconnect it at any time.

Guest-related data: Names, complaints, stay context, and other guest details you enter as part of operational logging or that arrive through a connected integration. See Section 10 for how this is handled.

3. Who Controls What

Two kinds of data exist in Ridgeline, with different responsibility:

Data you control. Everything you bring in or create deliberately — property records, vendor records, procedures, incident logs, and guest data (whether typed in or pulled from a connected integration). You are the data controller; Ridgeline processes it on your behalf to run the Product.

Data Ridgeline derives. Records the system creates by operating — query logs, learned operational patterns, classifier signals, and aggregated insights. Ridgeline is the data controller for these, and is responsible for handling them under this policy.

The practical test: if you deleted your account and walked away with your data, whatever Ridgeline would still be responsible for is what Ridgeline controls.

4. How We Use Your Data

We process your data because it is necessary to deliver the service you signed up for: operating Ridgeline, generating responses specific to your properties, maintaining your operational logs and knowledge base, and authenticating your access. For the records Ridgeline derives (Section 3), we process them under our legitimate interest in delivering and improving the Product.

Product development: We may use operational data — including property details, log entries, and query patterns — to improve Ridgeline's responses and features. Where this involves reading identifiable content (such as individual message bodies), access is gated by an internal access policy and logged; product analytics is performed on aggregated or anonymized data wherever possible.

AI training and evaluation: Any use of your data to train or evaluate AI models happens only after true anonymization — removing or aggregating information until it can no longer reasonably be traced back to you, your properties, or your guests. Replacing names with codes is not enough; we hold ourselves to the stronger standard. You may opt out of this use entirely by emailing privacy@ridgelineoms.com. Data in the sensitive categories described in Section 11 is never used for training in any form.

5. What We Don't Do

We do not sell your data. We do not share your identifiable data with third parties for marketing, advertising, or any purpose unrelated to operating the Product. We do not use your data to contact your guests or vendors directly.

6. Where Your Data Lives

Your data is stored in Ridgeline's own database (PostgreSQL), hosted on Railway infrastructure in the United States, and encrypted in transit and at rest. Procedure playbook content is stored in Notion, which also holds a time-limited read-only backup of operational data from Ridgeline's 2026 storage migration. Backups follow the hosting providers' backup policies.

7. Third-Party Service Providers

Ridgeline uses a small number of third-party providers ("sub-processors") to operate the Product. The authoritative, current list — including each provider's purpose and location — is maintained at ridgelineoms.com/legal/sub-processors. We provide at least 30 days' notice before adding or replacing a sub-processor, as described on that page.

A note on the AI provider

When you submit a query, the query and the property context needed to answer it — procedures, vendor details, operational history — are sent to Anthropic's API to generate a response. Ridgeline currently uses Claude, developed by Anthropic, and is required by Anthropic to disclose this. Under Anthropic's API terms, this data is not used to train Anthropic's models and is retained only for abuse detection.

8. Data Retention and Deletion

While your account is active: your property data, logs, and derived records are retained for the life of the account. Query logs and learned operational patterns are kept for the account lifetime because the Product reasons over them to give you specific, personalized answers — deleting them on a timer would degrade the service you are paying for.

When you delete your account (or request deletion): a 30-day soft-delete window starts, during which the deletion can be reversed. After 30 days, your identifiable data is permanently deleted — including property records, logs, and the derived records tied to your account.

What survives deletion: aggregated and truly anonymized patterns that can no longer be traced to you. Backup copies age out on the hosting providers' backup schedules.

9. Your Rights

You can exercise any of these rights at any time, whether you are an operator, a staff member, or a guest whose data an operator has entered:

Send requests to privacy@ridgelineoms.com. We respond within 30 days.

10. Guest Data

When guest information enters Ridgeline — typed in as part of operational logging or pulled from a connected integration — you are the data controller for that information and Ridgeline processes it on your behalf. You are responsible for ensuring your collection and use of guest data complies with applicable privacy laws, including any obligations to your guests.

Guest identities are additionally protected inside Ridgeline's derived records: guest-identifiable details are removed when a guest requests deletion, before any pattern is aggregated across operators, and before any internal access for purposes other than supporting you.

11. Sensitive Data

Special category data (health information, religious or political affiliation, biometric data, and similar categories under GDPR Article 9): Ridgeline does not intentionally collect or process it. If it appears incidentally in free text — a chat message, a log note — it stays in that text only: it is not extracted into structured fields, not used as training signal, and not propagated into derived insights. You are responsible for any special category data you choose to enter.

Operational credentials (WiFi passwords, lock codes, alarm codes, payment details): treated as restricted. They are stored as structured property records, never appear in Ridgeline's derived records or logs, and are only resolved into a response at the moment you need them.

12. Data Security

Your data is encrypted in transit and at rest, and access is scoped to your operator identity. No system is completely secure and we cannot guarantee absolute security of data transmitted to or stored in the Product. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or product notice. Changes to the sub-processor list follow the 30-day notice commitment described at ridgelineoms.com/legal/sub-processors. Continued use of the Product after notice constitutes acceptance of the updated policy.

14. Children

Ridgeline is not intended for users under 18 years of age. We do not knowingly collect data from anyone under 18, and you are responsible for not entering data about minors into the system.

15. Governing Law

This Privacy Policy is governed by the laws of the State of New Jersey.

16. Contact

Privacy questions or data requests: privacy@ridgelineoms.com