Moche-AIBack to site

Legal Center

  • Overview
  • Terms of Service
  • Privacy Policy
  • Refund & Billing
  • Data Processing Addendum
  • Master Service Agreement
  • Security
  • Subprocessors
  • Acceptable Use
  • AI Policy
  • Open-Source Notices
  • Cookies
  • Support & Data Rights

Data Processing Addendum

Version 1.1.0 · Last updated August 4, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies where Moche-AI processes personal data on a customer’s behalf (GDPR Art. 28). By accepting during signup or checkout, the customer (“Controller”) and Moche-AI (“Processor”) agree to these terms.

1. Roles & scope

The Controller determines the purposes and means of processing property and guest data. The Processor processes such data only on documented instructions from the Controller, including for international transfers, unless required by law.

2. Processor obligations

  • Process only on the Controller’s documented instructions.
  • Ensure personnel are bound by confidentiality.
  • Implement the technical & organizational measures in Schedule 2.
  • Assist the Controller with data-subject requests and security/DPIA obligations.
  • Delete or return personal data at the end of the engagement, subject to legal retention.
  • Make available information necessary to demonstrate compliance.

3. Breach notification

The Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal-data breach affecting the Controller’s data, with the information reasonably available. See our Security Overview and internal security-incident runbook.

4. Subprocessors

The Controller authorizes the use of the subprocessors listed in Schedule 3. We impose data-protection obligations on each subprocessor no less protective than this DPA and remain liable for their performance. We will give notice of intended changes and allow a reasonable objection right.

5. International transfers

For transfers outside the EEA/UK, the parties incorporate the EU Standard Contractual Clauses and the UK IDTA/Addendum, with the Processor as “data importer” where applicable.

6. CCPA service-provider terms

To the extent the CCPA/CPRA applies, Moche-AI acts as a service provider: we do not sell or share personal information and do not retain, use, or disclose it except to provide the Service or as permitted by the CCPA.

Schedule 1 — Processing details

Subject matterProvision of the AI guest-concierge and Property Brain.
DurationFor the term of the subscription.
Nature & purposeStorage, retrieval, embedding, and AI-based answering of property/guest content.
Data subjectsThe Controller’s guests and staff.
Data categoriesProperty content, guest questions/answers, hashed guest contact identifiers.

Schedule 2 — Technical & organizational measures

The measures in our Security Overview (access control, encryption in transit and at rest, logging & monitoring, vulnerability management, incident response, vendor management, and data protection including PII redaction before external AI routing) are incorporated here by reference.

Schedule 3 — Authorized subprocessors

VendorPurposeData processedRegionTransferRetentionStatus
SupabasePrimary application database (Postgres + pgvector), authentication, file storageHost account & profile data, property/brain content, guest identities (hashed contacts), embeddingsEU (Frankfurt) / US — project-dependentSCCsFor the life of the account; deleted on erasure request (billing/legal records retained)Active
VercelApplication hosting, edge network, serverless computeRequest metadata, IP addresses, logsUS / global edgeSCCsTransient; logs per Vercel retention policyActive
StripePayment processing and subscription billingHost billing contact, payment card data (held by Stripe, never by us), invoicesUS / EUSCCsPer Stripe policy and tax/accounting law (typically 7+ years for financial records)Active
OpenAIAI subprocessor — text embeddings (text-embedding-3-small), guest-intent classification, and the fallback path for all chat completions if model routing is unavailableGuest questions and property knowledge context (PII redacted before external routing where applicable)USSCCsAPI inputs/outputs retained up to 30 days for abuse monitoring, then deleted (no training on API data)Active
OpenRouterAI model router — directs completion requests to a task-appropriate model (currently Google Gemini 2.5 Flash for guest answers, OpenAI GPT-4o-mini and Meta Llama 3.1 for background extraction/classification) with automatic failover between modelsPrompt content only, with personal data programmatically redacted before the request leaves our infrastructure: guest questions and the relevant property knowledge context. A post-redaction check blocks the external request entirely if personal data is still detected. No guest identity, contact details, or account data are sent.US (routes to model providers in the US/EU)SCCsZero-Data-Retention enforced on every request: prompts and responses are not logged or retained by OpenRouter, and any downstream model provider that would collect or train on the data is refused (the request fails closed and falls back to our primary provider instead)Active
ResendTransactional email delivery (host notifications, escalations)Host email address, notification contentUSSCCsDelivery logs per Resend policyActive
TwilioSMS delivery for guest verification one-time codesGuest phone number, one-time verification codeUS / globalSCCsMessage logs per Twilio policyActive
FirecrawlHost-initiated URL ingestion (fetch & extract public listing/content pages)URLs submitted by the host and the fetched page contentUSSCCsTransient; extracted content stored in the host’s Property BrainActive
SentryApplication error monitoring and performance tracingError events, stack traces, request metadata (PII scrubbed where feasible)US / EUSCCsPer Sentry retention settings (typically 90 days)Active
CloudflareBot mitigation (Turnstile) on guest verification and edge protectionIP address, challenge token, request metadataGlobal edgeSCCsTransient challenge dataActive
MapboxAddress autocomplete/geocoding, nearby place discovery, and static map images on the host dashboardProperty address strings and coordinates entered by the host, plus the host browser’s request metadata (IP, referrer) when a static map image loads. No guest identity or guest message content is sent.USSCCsQuery logs per Mapbox policy; results cached in the host’s own property recordsActive
PostHogProduct analytics (host-side usage; no guest PII sent)Pseudonymous host user id, product events, page viewsUS / EU (cloud region dependent)SCCsPer PostHog project retention settingsActive
Trigger.devBackground job orchestration (async task execution and retries outside the request/response cycle)Task payloads we choose to send. Jobs are designed to carry row/record ids only, never guest PII directly — the job re-reads any needed data from Supabase using the service role at execution time.USSCCsRun logs and payloads retained per Trigger.dev account settingsActive
Amazon Web Services (S3)Private object storage for host-uploaded files and images, accessed only via short-lived presigned URLs so bytes never transit our app serversProperty-related images and documents the host uploads. Objects are stored under a per-property key prefix; no object is publicly accessible (all public access blocked, TLS-only bucket policy, server-side encryption at rest).US (us-east-2)SCCsObjects retained until deleted by the host or removed per bucket lifecycle policy (noncurrent versions expire after 90 days)Active
Terms of ServicePrivacy PolicyRefund & BillingData Processing AddendumMaster Service AgreementSecuritySubprocessorsAcceptable UseAI PolicyOpen-Source NoticesCookiesSupport & Data Rights

Built in Somerville, MA