Skip to content

Legal

Privacy Policy

Version 2026-09-29 · Effective

For your Butler account and our own business records, we decide how information is used. Information about guests, callers, owners and tradespeople belongs to the property manager, and we handle it on their instructions. Our systems are in Sydney; our AI, phone and transcription providers process some information in the United States. We do not sell personal information and use no tracking cookies.

Contents
  1. 01Who we are
  2. 02Our two roles
  3. 03Information we collect about users
  4. 04Customer Data we process for property managers
  5. 05AI and other providers
  6. 06Where information goes
  7. 07The Butler app for iOS
  8. 08Browser and device storage
  9. 09Security
  10. 10How long we keep information
  11. 11Your rights
  12. 12Breaches, children and changes

01Who we are

Butler is provided by Blackbox Studios Limited (New Zealand company number 9368525, NZBN 9429053095091), trading as Butler, of Auckland, New Zealand. Our privacy officer can be reached at privacy@butlerhost.com. We are a New Zealand business, so the Privacy Act 2020 applies to everything we do. Where the GDPR or the Australian Privacy Act applies, we follow it too.

02Our two roles

  • Account Data is your account, your devices, telemetry, acceptance records, support and billing contacts, and visits to our website. We are the agency (controller) for it, and this policy explains how we use it.
  • Customer Data is the information a property manager puts into Butler or connects to it: guests, callers, property owners, tradespeople and its staff's work records (timesheets, photos, chat). The property manager is the agency (controller). We hold it as their agent (Privacy Act section 11) and processor (GDPR Article 28), only to provide Butler, under the Terms of Service. If it is about you, contact the property manager first; we will help them respond.

03Information we collect about users

Account
Details: Name, work email and role, created by your organisation's owner or manager. Your password is held only by our authentication provider (Supabase), in hashed form. — Why: To give you access and apply your role
Devices
Details: Push token (Apple) and app version. For Voice, a calling token registered directly with Twilio and an optional backup mobile number. — Why: Notifications and calls
Usage and diagnostics
Details: From the app: random account and install identifiers, device model, operating system and app version, screens opened, actions taken and request timings. Never names, emails, message text or guest details. From our API: request route, timing, result and IP address. — Why: To keep Butler working and secure
Acceptance records
Details: Document version, time, user, organisation, IP address and browser or device details when you accept our terms — Why: Evidence of the agreement
Support and billing
Details: What you send us; your organisation's billing contacts, orders and invoices. Card details go straight to our payment provider. — Why: Support and invoicing

We use this information to run, secure and improve Butler, to invoice, and to meet legal obligations. Where the GDPR applies, our basis is the contract with your organisation, our legitimate interest in running the service, or a legal obligation.

04Customer Data we process for property managers

Guests
Examples: Name and contact details, booking dates, messages and translations, AI drafts, call recordings and transcripts, reviews, access codes issued for the stay, vehicle registration, parking, extras and charges, damage and bond records and photos — Source: The manager's PMS and booking channels, guest portal, connected mailbox, calls and staff
Callers
Examples: Phone number, matched booking, recording and transcript — Source: Calls through Butler
Property owners
Examples: Name, statements and bank account details for payouts — Source: The manager's PMS
Tradespeople
Examples: Name, email, job details, and photos and notes uploaded through job links — Source: The manager and the tradesperson
The manager's staff
Examples: Timesheets, timers, pay requests, photos and chat — Source: The staff member's use of Butler

What each person in an organisation can see depends on the role its owners give them. Payment-card details are never stored.

05AI and other providers

Butler sends messages, booking context and property information to Anthropic (drafting, translation and extraction) and OpenAI (search embeddings), both in the United States, under commercial terms that do not allow training on our data. Call audio is recorded by Twilio and transcribed by AssemblyAI in the United States, and is not used to train their models. A person reviews AI drafts before anything is sent. Butler makes no decisions with a legal or similarly significant effect and performs no biometric identification.

06Where information goes

Our database, files and telemetry are hosted in Sydney, Australia (Supabase and Fly.io). The providers above process data in the United States. We rely on the EU adequacy decision for New Zealand, on the EU-US Data Privacy Framework where a provider is certified (Twilio, AssemblyAI, Google and Fly.io) and on standard contractual clauses otherwise (Anthropic, OpenAI and Supabase). Push notifications go through Apple. Where a property manager connects Gmail, we read that mailbox under Google's API policies. Services the manager chooses (its PMS, guest portal, smart locks and its own Stripe account) are governed by the manager's own contracts. We tell organisation owners 30 days before adding a provider. We do not sell personal information.

07The Butler app for iOS

The app asks for the camera (photos and videos of cleans, lockboxes, issues and damage), the microphone (calls and video sound) and notifications. It collects your name, email and phone number (the Voice backup number), messages you send, photos, videos and audio you record, other content you enter, your user and device IDs, and usage and diagnostic data, all linked to your account and never used for tracking or advertising. Messages, photos and call audio are shared with the third-party AI providers in section 5. Photos are re-encoded before upload, which removes location metadata; videos and PDFs are uploaded as they are.

08Browser and device storage

The web console uses no tracking cookies, analytics or third-party scripts. It keeps your sign-in session, a display preference and any files waiting to upload in your browser's storage. Sign out on shared devices.

09Security

Data is encrypted in transit and at rest. Access is role-based and scoped to your organisation, connected-service credentials are encrypted, changes are audit-logged, and the database is backed up daily. No system is completely secure, so we cannot guarantee it.

10How long we keep information

Customer Data
For the life of the organisation's subscription. Exported or deleted on the organisation's instruction, and deleted within 60 days after a 30-day export window when the subscription ends; backups expire within a further 35 days.
Telemetry and logs
90 days
Acceptance records
7 years after the organisation's account ends
Account, billing and support records
The life of the account, then 7 years for financial and legal records
Call audio and transcripts
Held by our telephony and transcription providers under their retention terms, and deleted on the organisation's instruction.

Deleting your account. Ask in Settings in the Butler app, or email privacy@butlerhost.com. Deletion is processed after 14 days unless you cancel by signing in. Your organisation's owners and managers are notified, and your login, profile, preferences and device tokens are removed. Work records stay with your organisation.

11Your rights

You can ask to see and correct personal information we hold about you, and we respond within 20 working days. Where the GDPR or Australian law applies you can also ask us to erase, restrict or hand over your information. For Customer Data, ask the property manager; we will assist them. To complain, contact privacy@butlerhost.com first, then the Office of the Privacy Commissioner (privacy.org.nz) or your local authority (the ICO, an EU authority or the OAIC).

12Breaches, children and changes

If a breach affects Customer Data we notify the organisation within 48 hours of becoming aware of it. For Account Data we notify the Privacy Commissioner and affected people where the Act requires. Butler is a business tool used by organisations and their staff, and is not directed at children. We may update this policy, and you will be asked to acknowledge the current version when you next sign in.

Contact: privacy@butlerhost.com · https://butlerhost.com · https://console.butlerhost.com