Privacy Policy
Effective date: July 16, 2026
This policy explains what personal data IONICA collects when you use ionica.world, the IONICA mobile apps, and the partner and admin portals — how we use it, who we share it with, how long we keep it, and how you can access, correct, or delete it.
1. Who we are
IONICA is operated by The Ioni Group(Miami, Florida, USA), with technical services provided by CRIZZ Global Solutions S.A.S. In this policy “we” and “IONICA” mean that entity.
2. What we collect
We only collect data that's necessary to run a booking marketplace and a partner portal. We do not show ads, and we never sell your personal data.
- Account: name, email, phone, password (hashed), profile photo. Set at sign-up or from your Google / Apple account when you use those sign-in options.
- Bookings & payment: stay dates, guest count, guest name, contact details. Card details are collected and processed by Stripe, our PCI-DSS compliant payment processor — IONICA never sees or stores card numbers. We store the Stripe reference IDs, invoice totals, and receipts for tax and accounting purposes.
- Identity verification for stays above certain thresholds: government ID photo, selfie, ID number. Used only to verify identity and to comply with lodging regulations.
- Partner financial data (owners only): monthly statements, escrow contributions, payout history, tax IDs, banking references. Required to compute payouts and issue tax documents.
- Guest messages: messages exchanged with our concierge, hosts, or across channel-manager inboxes (Airbnb, Booking.com, Vrbo, Expedia, direct email). Content is stored so you and our staff can see the conversation history.
- Device and diagnostic data: browser, OS, IP address, app version, crash reports. Crash reports are captured by Sentry to help us fix bugs — they include a stack trace and non-personal device metadata, and are automatically scrubbed of email, phone, and payment values before being sent.
- Usage patterns: pages viewed, searches performed, features used. Aggregated to improve the product; not used for advertising.
3. Why we use it (purposes & legal bases)
- Provide the service — process bookings, run the concierge, deliver messages, calculate partner payouts. Legal basis: contract performance.
- Verify identity and prevent fraud — match ID to booking, detect duplicate abuse. Legal basis: legitimate interest, and legal obligation for lodging regs.
- Issue receipts and file taxes / statements — required to operate a lodging business in Florida and to pay owners. Legal basis: legal obligation.
- Improve the product — aggregated usage patterns, crash reports. Legal basis: legitimate interest (no personal profiling).
- Transactional email (confirmations, receipts, security) — sent via Resend. Legal basis: contract performance. Marketing email requires opt-in and is always opt-out from within the message.
4. Who we share it with
We share the minimum necessary with providers who process data on our behalf under a written data-processing agreement:
- Stripe (payment processing) — handles cards, refunds, partner transfers. PCI-DSS Level 1.
- Supabase (database + authentication) — hosts our account records, bookings, messages, and files (identity docs, attachments). Servers in the United States.
- Resend (transactional email delivery) — sends confirmations, receipts, notifications.
- Sentry (error monitoring) — receives scrubbed crash reports so we can fix bugs. No personal messages, emails, phone numbers, or payment values are sent.
- Rentals United — channel manager for bookings that originate on Airbnb, Booking.com, Vrbo, Expedia, and other OTAs. Guest name, dates, guest count, and message content flow between IONICA and RU for those bookings only.
- Google / Apple(sign-in only) — if you sign in with Google or Apple, they verify you and pass us your email and basic profile info. We don't receive your password.
- Property owners receive the information needed to host a stay: guest name, arrival / departure dates, guest count, and any messages you send them directly.
- Government or law-enforcement when required by valid legal process (warrant, subpoena, or a specific regulatory request in the jurisdiction of the stay).
We do not sell personal data.We do not run advertising on the platform and don't share your data with advertising networks.
5. How long we keep it
- Active accounts: for as long as the account exists.
- Deleted accounts: we complete profile deletion within 30 days of an accepted request. See ionica.world/account-deletion.
- Booking and payment records: retained for the period required by tax and lodging regulations — typically 7 years in Florida — even after account deletion. Sensitive card data is not stored (held only by Stripe).
- Partner statements and payouts: retained for the tax period required by the partner's jurisdiction.
- Crash reports: retained by Sentry for 90 days, then automatically purged.
6. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your account and personal data — subject to legal retention obligations for booking / payment records. Request deletion here.
- Objectto processing that isn't strictly necessary to run the service.
- Data portability — export a machine-readable copy of your account data.
- Withdraw consent for anything you previously opted in to (e.g. marketing emails).
To exercise any right, email privacy@ionica.world (or admin@ionica.world) from the email address on your account. We respond within 30 days.
7. Security
Data is encrypted in transit (HTTPS/TLS) and at rest on our providers' infrastructure. Passwords are hashed with bcrypt via Supabase Auth. Access to production data is restricted to a small number of engineers and logged. Payment card data is handled exclusively by Stripe under PCI-DSS Level 1.
No system is perfectly secure. If you believe your account has been compromised, email privacy@ionica.world immediately.
8. Children
IONICA is intended for adults. We don't knowingly collect data from anyone under 18. If we learn a minor has created an account, we delete it.
9. International transfers
Our processors (Stripe, Supabase, Resend, Sentry) host data in the United States. If you access IONICA from outside the U.S., your data is transferred to the U.S. under standard contractual protections.
10. Changes
We'll update this policy from time to time. Material changes will be announced by email at least 30 days before they take effect. The effective date at the top of the page reflects the current version.
11. Contact
Privacy questions, data requests, deletion:
privacy@ionica.world or admin@ionica.world
The Ioni Group, Miami, Florida, USA
Política de privacidad (Español)
Fecha de vigencia: July 16, 2026
Esta política resume qué datos personales recopila IONICA cuando usas ionica.world, las apps móviles y los portales de socios y administración; para qué los usamos, con quién los compartimos, cuánto tiempo los guardamos y cómo puedes acceder, corregir o eliminarlos. El texto en inglés es la versión oficial — esta traducción existe para tu conveniencia.
Qué datos recopilamos
Cuenta (nombre, correo, teléfono, contraseña cifrada, foto). Reservas y pagos (fechas, huéspedes, contactos). Las tarjetas las procesa Stripe — IONICA nunca ve ni guarda números de tarjeta. Verificación de identidad para estancias con umbrales específicos (foto ID, selfie). Datos financieros para socios (estados de cuenta, retenciones, historial de payouts, ID fiscal). Mensajes con conserjería y anfitriones. Datos de dispositivo e informes de fallos (Sentry) para arreglar bugs, sin correos ni teléfonos ni valores de pago. No mostramos publicidad ni vendemos tus datos personales.
Con quién compartimos
Solo lo mínimo necesario con proveedores bajo contrato: Stripe (pagos), Supabase (base de datos + autenticación), Resend (correo transaccional), Sentry (informes de fallos), Rentals United (para reservas que vienen de Airbnb, Booking.com, Vrbo, Expedia y otros canales), y Google / Apple si usas sus opciones de inicio de sesión. Compartimos con propietarios lo indispensable para hospedarte (nombre, fechas, huéspedes) y con autoridades solo cuando la ley lo exija.
Tiempo de retención
Cuentas activas: mientras exista la cuenta. Cuentas eliminadas: el perfil se borra dentro de 30 días desde una solicitud aceptada. Registros de reservas y pagos: retenidos por el período requerido por la ley fiscal y de hospedaje (típicamente 7 años en Florida) incluso después de eliminar la cuenta. Informes de fallos: 90 días en Sentry.
Tus derechos
Acceso, corrección, eliminación (sujeto a retención legal), oposición, portabilidad de datos, y retiro de consentimiento. Escríbenos a privacy@ionica.world (o admin@ionica.world) desde el correo asociado a tu cuenta. Respondemos en 30 días. Para eliminar tu cuenta: ionica.world/account-deletion.
Contacto
The Ioni Group, Miami, Florida, USA · privacy@ionica.world · admin@ionica.world