Moche-AIBack to site

Legal Center

  • Overview
  • Terms of Service
  • Privacy Policy
  • Refund & Billing
  • Data Processing Addendum
  • Master Service Agreement
  • Security
  • Subprocessors
  • Acceptable Use
  • AI Policy
  • Open-Source Notices
  • Cookies
  • Support & Data Rights

Privacy Policy

Version 1.2.0 · Last updated August 4, 2026

This Privacy Policy explains how Moche-AI collects, uses, discloses, and protects personal data. It applies to hosts (our customers) and to guests who interact with a host’s AI concierge. It is written to align with the EU/UK GDPR and the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”).

1. Our roles

We act as a controller for host account, billing, and marketing data, and as a processor for the property content and guest data we handle on a host’s behalf. Host processing terms are in our Data Processing Addendum.

2. Data we process

CategoryExamplesSource
Host accountName, email, phone, business nameYou
Billing metadataPlan, status, period — not card numbersStripe
Property contentDocuments, FAQs, recommendations you uploadYou
Guest interactionsQuestions asked, AI answers, escalationsGuests
Guest verificationPhone/booking identifiers stored as irreversible hashesGuests
TechnicalIP, device/user-agent, product analytics eventsAutomatic

3. Legal bases (GDPR)

  • Contract — to provide the Service you sign up for.
  • Legitimate interests — security, fraud prevention, product analytics, and service improvement, balanced against your rights.
  • Consent — for non-essential cookies/marketing where required; withdrawable at any time.
  • Legal obligation — tax, accounting, and compliance record-keeping.

4. AI processing & third parties

Guest questions and relevant property content are processed by AI models to generate answers. Model requests are routed through OpenRouter, an AI model gateway, which forwards them to the underlying model provider — currently OpenAI (GPT-4o mini), Google (Gemini 2.5 Flash), and Meta (Llama 3.1). Text embeddings used for search and retrieval are generated by OpenAI directly. We select the model per task for cost and quality reasons and may change models; the current register of providers is always published on the Subprocessors page.

Personal data is redacted from content before it is sent to any external model provider (see our Security Overview), and we seek Zero-Data-Retention terms where a provider offers them. We do not permit these providers to use your content or your guests’ content to train their models.

5. International transfers

Where personal data is transferred outside the EEA/UK, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum / IDTA, together with supplementary measures as appropriate.

6. Sale / sharing of personal information

We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.

7. SMS & WhatsApp messaging

If you opt in during signup or in Dashboard → Settings and verify a mobile number, Moche-AI may send you account and guest-related messages by SMS and/or WhatsApp — for example new guest questions, escalations that need your attention, verification codes, and maintenance or billing alerts. Guests who opt in may likewise receive messages relating to their stay.

  • Consent is optional. Opting in to messaging is never a condition of creating an account or using the Service.
  • Message frequency varies based on account activity and guest interactions.
  • Message and data rates may apply from your mobile carrier.
  • Opt out any time by replying STOP to a text message, or by turning messaging off in Dashboard → Settings. Reply HELP for help, or contact us at Support & Data Rights.

We do not sell, rent, or share mobile opt-in information or phone numbers with third parties or affiliates for their own marketing or promotional purposes.Phone numbers collected for SMS/WhatsApp are used solely to deliver the messages described above and are handled by our messaging processor, Twilio (see the Subprocessors page), for the sole purpose of message delivery.

8. Your rights

Subject to applicable law you may access, correct, delete, port, or object to/restrict processing of your personal data, and (CCPA/CPRA) opt out of sale/sharing and limit use of sensitive personal information. Hosts can export or delete their data in-app from Dashboard → Profile, or contact us via Support & Data Rights. We do not discriminate against you for exercising these rights.

9. Retention

We keep personal data only as long as needed for the purposes above or as required by law. Billing and legal-acceptance records are retained for statutory periods even after account deletion (see the data-rights section).

10. Contact

See Support & Data Rights for our privacy contact.

Terms of ServicePrivacy PolicyRefund & BillingData Processing AddendumMaster Service AgreementSecuritySubprocessorsAcceptable UseAI PolicyOpen-Source NoticesCookiesSupport & Data Rights

Built in Somerville, MA