Where the data lives
- Application servers on Fly.io in the Amsterdam region.
- Database on Neon Postgres in the EU.
- Photos in Google Cloud Storage and Firebase Storage.
- Messaging providers — Telegram, Twilio (SMS and WhatsApp), MailerSend for email, CYTA for SMS in Cyprus — each receives what it needs to deliver a message and nothing else.
- Payments through Stripe; Lemon never sees card numbers.
What Lemon holds, and what it deliberately does not
- Host and team accounts: name, email, organisation, timezone.
- Cleaners: name, contact number or Telegram identity, fee, availability, and a record of messaging consent (when, how, from which device).
- Bookings from iCal: dates, a platform label, the calendar UID, and a guest name only if the feed contains one (Airbnb sometimes does, Booking.com never does).
- Bookings from a PMS: scrubbed at ingest. Lemon keeps the dates, status, platform and a reservation reference, not the guest's contact details.
- Forensic snapshots of calendar feeds are kept for 30 days and then deleted.
Your rights and the legal basis
The privacy policy at /privacy sets out the legal bases (contract, legitimate interest, legal obligation), retention, processors, and how to exercise access, correction, portability and erasure rights under the GDPR and Cyprus Law 125(I)/2018. The data controller is Red Tribe Media Ltd, Limassol, Cyprus.
Audit trail
Every booking-affecting decision the sync makes is a row with a kind, a reason and before/after state; every outbound message is a row with its delivery status. When a host asks "why did this happen", the answer is a query, not a guess.