1. Who we are
Plubox provides software for managing rental and hospitality operations and is operated by FOP Barkar Serhii. In this Privacy Policy, “Plubox,” “we,” “us,” and “our” refer to FOP Barkar Serhii as the operator of the Plubox service at plubox.com. Our contact address is 39 Akademika Filatova Street, office 57, Odesa, Ukraine.
For account, security, billing, and support information, Plubox generally acts as a data controller. For property, guest, staff, booking, and other operational data that a customer submits to Plubox, the customer generally acts as the controller and Plubox acts as its processor or service provider.
2. Scope
This policy applies to Plubox websites, applications, APIs, support channels, and integrations, including the optional Plubox plugin for ChatGPT. It does not replace the privacy notices of our customers, OpenAI, Google, payment providers, or other third parties whose services you choose to use.
3. Information we process
Account and identity information
We process information used to create and administer an account, such as your name, email address, authentication details, organization membership, role, language, contact details, and account preferences. If you sign in through a third-party identity provider, we receive the information that provider makes available with your permission.
Property and operational information
Customers may submit information about organizations, accounts, properties, accommodation groups, bookings, guests, staff, schedules, availability, inventory, nightly prices, restrictions, services, payments, expenses, receipts, utility payments, tasks, task photos, cleanings, equipment shortages, and operational statistics.
The exact information depends on the Plubox features and integrations a customer enables. Customers are responsible for ensuring they have a lawful basis to provide personal data to Plubox and for configuring user access appropriately.
ChatGPT plugin and integration information
When you connect the optional Plubox plugin to ChatGPT, we process OAuth authorization information, account and organization identifiers, tool requests, the parameters needed to fulfill those requests, and the Plubox records returned or changed at your direction. Depending on the workflow, this can include booking, guest, property, schedule, price, payment, expense, utility, task, cleaning, image, and statistics data.
Important: Relevant request content and tool results pass between OpenAI and Plubox so the plugin can complete your request. OpenAI processes information under its own applicable terms and privacy documentation. Do not include secrets or personal data that are not necessary for the task.
Technical and usage information
We may process IP addresses, device and browser information, dates and times of access, pages and features used, diagnostic data, security events, request identifiers, and application logs. We use this information to operate, secure, troubleshoot, and improve the service.
Support communications
If you contact us, we process your contact details, message, attachments, and any information you choose to provide. Please do not send passwords, access tokens, full payment card numbers, or other secrets in a support request.
4. How we use information
We process information to:
- provide, maintain, and administer Plubox and its integrations;
- authenticate users and enforce organization, account, and property permissions;
- retrieve information and perform actions that an authorized user requests;
- process subscriptions, payments, and service communications;
- provide customer support and investigate technical issues;
- protect users, customers, Plubox, and third parties from fraud, abuse, or security threats;
- understand performance and improve reliability and usability;
- comply with law, enforce agreements, and establish or defend legal claims.
5. Legal bases
Where applicable law requires a legal basis, we rely on performance of a contract, steps requested before entering into a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where we request it. A customer may rely on different legal bases when it controls operational data processed through Plubox.
6. How we disclose information
We may disclose information only as reasonably necessary to:
- service providers that host, secure, monitor, support, communicate for, or otherwise help us operate Plubox under appropriate contractual restrictions;
- OpenAI when an authorized user connects or uses the optional Plubox plugin for ChatGPT;
- connected services such as Google services, channel managers, payment services, or other integrations that a customer enables;
- the customer and its authorized users according to configured roles and permissions;
- professional advisers and authorities where necessary to comply with law, protect rights and safety, or handle legal claims;
- a successor organization in connection with a merger, financing, reorganization, sale of assets, or similar transaction, subject to applicable safeguards.
We do not sell or rent personal data, and we do not use Google user data for advertising.
7. Google API data
If you enable a Google integration, Plubox accesses Google user data only as authorized and uses it to provide the requested functionality. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. You can revoke Google permissions from your Google account settings.
8. Data retention
Plubox does not create a separate archive of raw ChatGPT prompts or tool responses. Data retrieved through the plugin is processed for the current request. Records created or changed at the user's direction become ordinary Customer Data and remain in the customer's Plubox account until an authorized user deletes them, the customer instructs us to delete them, or the account or contract ends, subject to legal retention duties.
OAuth access tokens expire after one hour and refresh tokens after 30 days. Disconnecting the ChatGPT integration revokes its tokens immediately; a daily purge removes revoked or expired OAuth records within 24 hours. Daily application logs are retained for up to 14 days. Where Plubox controls deletion, verified requests are applied to active systems within 30 days. Rotating backup copies may remain for up to two years, and financial, security, or legal records may remain for the period required by law; deleted data is not restored to active use from backups.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, or alteration. No system is completely secure. Customers and users must protect their credentials, use appropriate access controls, and notify us promptly if they suspect unauthorized access.
10. International processing
Plubox and its service providers may process information in countries other than the country where it was collected. Where required, we use contractual or other safeguards intended to provide an appropriate level of protection for international transfers.
11. Your rights and choices
Depending on your location and our role in processing the information, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent where processing is based on consent. You may also disconnect integrations or revoke their permissions.
If Plubox processes your information on behalf of a property manager or another customer, please direct your request to that customer first. We will assist the customer as required. You may contact us at office@plubox.com. We may need to verify your identity and authority before fulfilling a request.
12. Children
Plubox is a business service and is not directed to children. We do not knowingly collect personal data directly from children for their own use of the service. Customers are responsible for handling any guest information about minors in accordance with applicable law.
13. Changes to this policy
We may update this Privacy Policy to reflect changes to the service, law, or our practices. We will publish the updated version on this page and change the effective date. Where required, we will provide additional notice.
14. Contact us
Questions or privacy requests can be sent to office@plubox.com or mailed to Plubox, 39 Akademika Filatova Street, office 57, Odesa, Ukraine. Customer support information is available at plubox.com/support.