Subprocessors
Last updated: October 9, 2026
Besty uses the third-party service providers listed on this page to deliver the service. Each one processes personal data on our behalf under a written contract that limits its use of the data to providing its service to us. This page is referenced by our Privacy Policy and our Data Processing Agreement.
We update this page before a new subprocessor begins processing Customer data. Customers who want to be notified of changes can email privacy@getbesty.ai with the subject “Subprocessor updates” and we will add them to the notification list.
“Guest data” means information about a Customer’s guests that Besty processes on the Customer’s behalf. “Customer data” means information about the Customer’s own account and staff. Region is where the vendor stores and processes data for Besty.
Infrastructure and hosting
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Amazon Web Services | Servers, database, file storage, secrets, backups, call transcription | All Customer and guest data | United States (us-east-1) |
| Google Cloud | AI models, analytics warehouse, file storage for some message attachments, Maps | Guest messages and attachments, booking events, listing addresses | United States |
| Microsoft Azure | AI models and translation | Guest message text | United States |
| Cloudflare | Bot protection at signup, secure tunnels to Besty-operated hardware, DNS | IP addresses; data in transit | Global |
| Besty-operated hardware (GPU server and voice fallback server, outside AWS) | Message classification; backup voice processing | Guest message text; live call audio during fallback | United States |
| Replit | Hosting for an internal analysis tool and an operator page embedded in the dashboard | Samples of guest messages and Besty replies from the last 90 days, used to draft Customer workflows; Customer session tokens for the embedded page | United States |
| Mapbox | Maps in the dashboard and mobile app | IP address, device and SDK usage data, and the map areas viewed, which can show listing locations and the last known location of Customer staff who share it | United States |
AI and language models
These providers receive the text, audio or images needed to generate a specific output and are contractually prohibited from training their models on it.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Microsoft Azure OpenAI | Message drafting, classification, summaries | Guest messages, reservation and property context, call transcripts | United States |
| Google (Gemini and Vertex AI) | Message drafting, check-in time extraction, host assistant, listing analysis | Guest messages, reservation and property context, listing photos | United States |
| OpenAI | Message embeddings, image understanding, voice assistant, website chat, translation of interface text | Guest messages, call audio, uploaded images | United States |
| Anthropic | Host assistant, offline evaluation of message samples | Customer questions and account data; samples of guest messages | United States |
| OpenRouter | Routing to additional models when primary providers are unavailable | Guest messages, inbound email | United States |
| Cerebras | Fast inference for voice assistant and some workflows | Call transcripts, guest messages | United States |
| Vellum | Prompt management and fallback routing to the providers above | Guest messages, reservation context, call transcripts | United States |
| AWS Transcribe | Call and voicemail transcription | Call audio | United States |
| Microsoft Azure Translator | Guest message translation | Guest message text | United States |
| Groq, Together AI, DeepInfra, TypeSafe | Fallback and evaluation models for the voice assistant | Call transcripts | United States |
| Deepgram | Speech to text for the voice assistant | Call audio | United States |
| Pinecone | Vector search over Customer knowledge bases | Customer content (SOPs, property information) | United States |
| Braintrust | Quality tracing for the host assistant | Customer questions and responses | United States |
| Perplexity | Market and property research | Property and market queries | United States |
Messaging, telephony and notifications
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Twilio | SMS and MMS, voice calls and recording, phone verification at signup | Guest and Customer phone numbers, message content, call audio | United States |
| Telnyx | SMS, voice calls, voicemail, recording, voice assistant audio | Guest and Customer phone numbers, message content, call audio | United States |
| Meta (WhatsApp Business Platform) | WhatsApp messaging | Guest phone numbers, message content, media | United States |
| Suiteness | Airbnb inbox connection for some Customers | Airbnb guest names and messages | United States |
| Hosttools | Airbnb listing and messaging connection operated through Besty's partner account, for Customers who connect Airbnb directly to Besty | Airbnb listings, reservations, guest names and messages | United States |
| Expo, Apple Push Notification service, Google Firebase Cloud Messaging | Mobile push notifications to Customer staff; over-the-air app updates (Expo) | Device tokens, device and app version, notification text (may include guest name and message preview) | United States |
Email delivery and mailbox connections
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Twilio SendGrid | Transactional email (password resets, signed agreements, notifications, guest emails sent through Besty) | Customer and guest email addresses, names, message content, attachments | United States |
| Google (Gmail API) | Sending and receiving email from a Customer's connected Gmail mailbox | Guest emails and attachments, mailbox access tokens | United States |
| Microsoft (Graph API) | Sending and receiving email from a Customer's connected Outlook mailbox | Guest emails and attachments, mailbox access tokens | United States or EU, per the Customer's Microsoft tenant |
| Nylas | Connecting other IMAP mailboxes | Guest emails and attachments, mailbox credentials | United States |
| Loops | Product and lifecycle email to Customers | Customer name and email | United States |
Payments and identity verification
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Stripe | Customer subscription billing; guest payments, deposits and damage waivers on behalf of Customers; Stripe Identity for guest ID verification where the Customer requires it | Customer billing details; guest name, email, payment method (card details held by Stripe), government ID images, selfie, date of birth | United States |
| Guesty Pay | Card tokenisation in the guest portal for Customers who use Guesty | Guest card details (tokenised directly with Guesty) | United States |
Property operations and access
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Seam | Smart lock and thermostat control | Access codes, check-in and check-out times, code labels | United States |
| dormakaba (Oracode) | Access codes for Kaba locks | Access codes, arrival and departure windows | United States |
| Breezeway | Cleaning and maintenance task sync for Customers who connect it | Reservation dates, property, guest name on tasks | United States |
| 1Password | Secure storage of credentials Customers give Besty for third-party portals | Customer credentials for external sites | United States |
| Kernel | Cloud browsers in which Besty staff and automations act inside Customer accounts on Airbnb and property management systems (for example, sending a reservation date change on Airbnb) | Customer usernames, passwords and one-time code secrets for those sites where the Customer provides them; logged-in browser sessions (cookies); pages viewed, which can include guest names, messages and reservation details | United States |
Support, analytics and monitoring
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Datadog | Application logging and performance monitoring | Technical logs, which can include guest names, contact details and message content | United States |
| Intercom | In-app support chat for Customers | Customer name, email, account identifier, support conversations | United States |
| HubSpot | Sales and customer relationship management | Customer business contact details, plan and usage summary | United States |
| Segment | Product analytics and booking event warehouse | Customer usage events; pseudonymous guest booking events (no names or contact details) | United States |
| Google Analytics and Google Tag Manager | Website and dashboard analytics | Page views, device and browser data, cookies | United States |
| PostHog | Visitor analytics and session replay on direct booking websites | Visitor behaviour, device, pseudonymous identifiers; session replay of booking pages, with form inputs masked except the checkout guest fields (name and contact details) and card fields never recorded | United States |
| Slack | Internal operational alerts | Guest name and booking details in upsell and sales alerts | United States |
| Linear | Internal issue tracking | Guest message content when a support issue is reported | United States |
| Notion | Internal knowledge base for Customers on the Copilot managed service | Customer SOPs, property information and owner directory pages, which can include owner and staff names and contact details | United States |
| ipapi.co | Approximate location of website chat visitors, shown to Customers in the inbox | Visitor IP address | United States |
| Meta (Custom Audiences) and Google (Customer Match) | Advertising audiences for Customers who enable the feature, so they can advertise to past guests | Hashed (one-way encoded) guest email, phone and name; the platforms cannot read the original values | United States |
Sales and marketing
These providers receive data about prospective property owners that Customers import into Besty for owner outreach. They do not receive guest data.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Lob | Printing and mailing postcards and letters to prospective property owners | Prospect names and mailing addresses; the Customer's business name and return address | United States |
| ZeroBounce | Email address validation for imported prospect lists | Prospect email addresses | United States |
Systems controlled by Customers
The following are not Besty subprocessors. They are systems the Customer has chosen and controls, and Besty exchanges data with them on the Customer’s instructions. Each has its own privacy terms with the Customer.
- Property management systems connected to Besty, including Hostaway, Guesty, Hostfully, OwnerRez, Uplisting, Lodgify, Track, Streamline, Escapia, Avantio, Beds24, Cloudbeds, Hospitable, Mews, Octorate, Smily, Rentals United, Stays.net, Staah, HomHero, HostHub and iGMS. Besty reads reservations, guest contact details and messages from the PMS and writes replies, access codes and custom fields back to it.
- Booking platforms such as Airbnb, Vrbo and Booking.com, whose messages and reservations reach Besty through the Customer's PMS or inbox connection.
- Customer-owned accounts that Besty connects to on the Customer's behalf: Customer.io, HubSpot and Instantly workspaces, Twilio accounts, Google and Microsoft mailboxes, Meta and Google Ads accounts, PriceLabs, TouchStay and Clearing.
Questions about this page: privacy@getbesty.ai