Updated 20 August 2026
Privacy
Entrio is based in Toronto. This page says what the software collects, who else ever sees it, and what it does not do — which is most of it.
Who this is
Entrio is operated by Cullan Liang, a sole proprietor in Toronto, Ontario, Canada. For anything about your information, or to ask for a copy or a correction, write to privacy@entrio.ca. A person reads it.
Three kinds of people
Hosts hold an Entrio account and pay for it. Guests never do — they open a link their host sends and read a page. Cleaners don’t either: a host who uses the turnovers feature invites them by email, and they answer through a link of their own.
Information about guests and cleaners belongs to the host who put it there. Entrio holds it on their behalf and does not use it for anything of its own. A guest or cleaner asking to see or delete their details should ask their host, who can act on it in the app; if that isn’t possible, write to us and we will help.
What we collect from hosts
Your name, your business name, your email address, and a password that is stored only as a hash — the plain password is never written down anywhere, including in our logs.
Everything you type about a property: its name, address, check-in and check-out times, entry code and instructions, wi-fi, house rules, guidebook, recommendations, cleaning checklists, photographs, and the calendar link you paste. Plus your subscription status and the Stripe identifiers that go with it.
If you connect a channel manager (today, Hospitable), we hold the access token you paste and use it to read your listings, your bookings and the guest contact details the manager already holds for you — and, when you switch the messages on, to post your welcome and pre-arrival messages into a booking’s own thread. Disconnecting deletes the token and stops all of it.
If you turn notifications on, we store a push subscription for that device so requests, cleans and guest milestones can reach it. The same is true for a cleaner who turns notifications on from their schedule page.
What we hold about guests
A guest’s name, email address, phone number, stay dates, party size, and any notes their host writes. Some of it arrives from the host, some the guest types into their own page when they introduce themselves. We also count how many times a guest has stayed with that host, which is what produces the “returning guest” welcome.
Calendar links carry dates, not names — Airbnb withholds the guest, so a booking reads “Awaiting guest” until the guest opens their link and fills their details in. A connected channel manager fills in what it already knows: the guest’s name, and their email and phone where the platform shares real ones.
For a host’s cleaners we hold what the host enters — a name and an email address — plus the invitations sent, the yes or no that came back, and the record of which cleans they did.
Guest activity, when a host turns Insights on
On the plan that includes it, a host can switch on a first-party measurement of how their guest pages are used: which tabs are opened, which guide sections are read, which extras are looked at and asked for, which recommendations are tapped, whether the entry code was copied and the review button pressed — with a timestamp, whether the device was a phone or a computer, and roughly how long the page stayed open.
When the checkout-reminder email is also on, it takes part in the same measurement: the email carries a one-pixel image served by our own server that notes when it was opened, and its button passes through our server on the way to the guest’s page so the click is counted. Both are first-party, both are gated by the same switch, and when Insights is off the email carries neither.
Each visit to the page carries a random number that exists only in that open tab’s memory, so the host can tell separate visits apart. It is never written to the device and dies when the tab closes — it cannot recognise a device coming back.
What it never records: no IP address, no location, no cookie, no browser fingerprint, nothing typed. Collection happens on our own server, is shown only to that host, and is never shared with or sent to anyone else. The host’s own visits to guest pages are not counted. Activity records are deleted automatically after six months, and deleting a booking deletes its activity with it. When the switch is off — or the plan doesn’t include it — nothing is collected at all.
Identity checks, when a host uses them
On plans that include identity checks, a guest may be asked to verify who they are before their entry code appears. That happens entirely inside Stripe. Their government ID and selfie are uploaded to Stripe and are never sent to Entrio, never stored on our servers, and never visible to us.
What we receive back is the outcome — verified, mismatched, failed — and the name Stripe read from the document, so a host can see whether it matches the booking.
Money
Card details never touch Entrio. Host subscriptions and guest payments for extras both run through Stripe, which collects and stores the card itself. When a guest pays a host for an extra, Stripe moves the money to the host’s own Stripe account; Entrio takes no cut of it.
Who else ever sees your information
Only the companies that run parts of the service, and only the part each one needs:
- Render hosts the application and the database, in Ohio, United States.
- Stripe subscriptions, guest payments, and identity checks.
- Resend sends the emails Entrio sends you and your guests.
- Cloudflare stores and serves your photographs, and routes mail sent to entrio.ca.
- Google Places and Anthropic receive a property's address — and, if you search for a specific place, the words you typed — when you draft Nearby recommendations. No guest information is sent to either.
- Hospitable if you connect it: we read your bookings and guests from it and post your automated messages through it, using the token you provided.
- Apple, Google and Mozilla push services carry notifications to devices that turned them on. The content is encrypted to your device — the carrier can't read it.
Nothing is sold, rented, or handed to advertisers. There is no advertising on Entrio and no arrangement under which there could be.
Because Render and Stripe operate in the United States, information is stored and processed outside Canada, where it may be reachable by foreign courts and authorities under the laws that apply there.
Cookies
Entrio sets one cookie, called entrio_session, when a host signs in. It keeps you signed in and does nothing else.
There is no advertising pixel, no session recording and no third-party tracker anywhere on this site or on a guest’s page, and no third-party analytics of any kind. The optional Insights measurement described above is first-party, cookie-free — it uses the booking link’s own token, sets nothing on the device, and never leaves our server. That is why you have never been asked to accept cookies here: the only one we set is the one required to do the thing you asked for.
Guest links
Each booking has its own web address containing a long random token. Anyone holding that link can open the page, which is what lets a guest use it without an account or a password — so treat it the way you treat the key it stands in for.
Entry codes and arrival details stay off the page until the time the host chooses. Deleting a booking in Entrio stops its link working immediately.
How long we keep it
Until you delete it, with one exception: guest activity records from Insights are removed automatically after six months. Everything else stays until its owner goes — a booking’s details (and its activity) until you delete the booking, a property’s until you delete the property. Closing your account removes your properties, bookings, guest and cleaner records, and activity with it.
Backups of the database are kept by our hosting provider for a short period and are overwritten in turn, so deleted information can survive there briefly before it is gone.
Security
Traffic to Entrio is encrypted in transit. Passwords are stored as hashes. Every request for a host’s data is scoped to that host’s account in the database layer, not by a check somebody could forget to write. Card details and identity documents are held by Stripe rather than by us, which is the strongest thing we can say about them.
No service can promise it will never be breached, and this page will not pretend otherwise. If information of yours is exposed, you will be told what happened and when.
Your rights
Under Canadian federal privacy law you may ask what personal information we hold about you, ask for a copy, ask for a correction, and complain if you think it has been mishandled. Write to privacy@entrio.ca and you will get an answer within thirty days.
If our answer doesn’t satisfy you, the Office of the Privacy Commissioner of Canada takes complaints about businesses like this one.
Changes
If what the software does changes, this page changes with it, and the date at the top moves. Material changes to how your information is used will be emailed to hosts rather than quietly posted.