Privacy Policy
This Privacy Policy explains how Sommer collects, uses, and protects your personal information. We are committed to transparency and giving you control over your data.
Privacy Overview
Navigate through our comprehensive privacy policy to understand how we handle your personal information.
Questions or Concerns?
If you have any questions about these terms or need clarification on any section, our legal and support teams are here to help.
About this Privacy Policy and our commitment to data protection
Company Information
Sommer Inc. ("Sommer," "we," "our," or "us") operates as the data controller for personal information processed through our vacation rental management platform. We are committed to protecting your privacy and handling your personal data in accordance with applicable data protection laws.
Company Details:
Sommer Inc.
123 Business St, Suite 100
San Francisco, CA 94105
United States
Policy Scope
This Privacy Policy applies to all personal information collected and processed by Sommer through:
- Our web application platform (sommer.co)
- Account creation and authentication processes
- Organization and property management features
- Team collaboration and communication tools
- Customer support and communication channels
- Marketing communications (with your consent)
Privacy Contact Information
For privacy-related questions, requests, or concerns, please contact us:
- Privacy Team: privacy@sommer.co
- Data Protection Officer: dpo@sommer.co
- Legal Team: legal@sommer.co
- General Support: support@sommer.co
Comprehensive overview of personal information we collect
Account and Profile Information
When you create a Sommer account, we collect:
- Email address (required for authentication and communication)
- Name and username for your profile
- Profile photos uploaded via UploadThing integration
- Bio and description text (optional)
- Location information (if provided)
- Authentication data from social logins (Google, GitHub)
- Account preferences and settings
Organization Information
For organization management functionality, we collect:
- Organization names, descriptions, and logos
- Member lists and role assignments
- Organization locations and contact information
- Team collaboration data and member communications
- Organization settings and preferences
Property and Listing Information
For vacation rental property management, we process:
- Property titles, descriptions, and specifications
- Property photos and image descriptions
- Amenity selections and feature details
- Location data and address information
- Pricing information and currency preferences
- Listing status and publication settings
- Property performance and management data
Usage and Technical Data
We automatically collect technical and usage information:
- IP addresses and device information
- Browser type, version, and language settings
- Operating system and device characteristics
- Pages visited, features used, and time spent
- Click patterns and user interaction data
- Session information and authentication logs
- Performance data and error reports
- Referral sources and marketing attribution
Legal basis and purposes for processing personal information
Service Provision (Contractual Necessity)
We use your personal information to provide and maintain our vacation rental management platform:
- User authentication and account management
- Organization creation and team collaboration features
- Property listing creation, editing, and management
- Photo upload and storage via UploadThing integration
- Platform functionality and feature delivery
- Customer support and technical assistance
Business Operations (Legitimate Interest)
We process data for legitimate business interests, balancing our needs with your privacy rights:
- Platform improvements and feature development
- Performance monitoring and optimization
- Security monitoring and fraud prevention
- Usage analytics and product insights (anonymized)
- Customer support quality improvement
- Business planning and strategy development
Legal Compliance (Legal Obligation)
We may process your data to comply with legal requirements:
- Compliance with data protection laws (GDPR, CCPA, etc.)
- Response to legal requests, court orders, and subpoenas
- Tax and financial record keeping requirements
- Industry regulation compliance
- Law enforcement cooperation when legally required
Marketing Communications (Consent-Based)
With your explicit consent, we may use your information for:
- Product updates and feature announcements
- Educational content and best practices for vacation rental hosts
- Promotional offers and service improvements
- Industry news and platform updates
- Surveys and feedback requests
When and why we share personal information with others
Service Providers (Data Processors)
We share personal information with trusted service providers who help us operate our platform:
- UploadThing: File storage and image management services
- Neon/PostgreSQL: Database hosting and data management
- Auth.js/OAuth Providers: Authentication and identity services
- Resend: Email delivery and communication services
- Upstash Redis: Caching and rate limiting services
- Vercel: Platform hosting and content delivery
- Stripe: Payment processing (when implemented)
All service providers are bound by data processing agreements that ensure appropriate data protection standards.
Business Transfers
Personal information may be transferred in connection with business transactions:
- Mergers, acquisitions, or sales of company assets
- Corporate restructuring or reorganization
- Bankruptcy proceedings or asset liquidation
- Due diligence processes for potential transactions
In such cases, we will ensure appropriate data protection measures are maintained by the acquiring entity.
Legal Requirements
We may disclose personal information when legally required:
- Court orders, subpoenas, and legal process
- Law enforcement investigations and requests
- Regulatory compliance and government audits
- Protection of rights, property, and safety
- Prevention of fraud and criminal activity
Understanding and exercising your data protection rights
GDPR Rights (EU/EEA Users)
Under the General Data Protection Regulation (GDPR), EU and EEA users have the following rights:
- Right of Access: Request a copy of your personal data and information about processing
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure: Request deletion of personal data ('right to be forgotten')
- Right to Restrict Processing: Limit how we process your personal data
- Right to Data Portability: Receive personal data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Rights Related to Automated Decision-making: Protection from automated decisions
CCPA Rights (California Residents)
Under the California Consumer Privacy Act (CCPA/CPRA), California residents have these rights:
- Right to Know: Information about data collection, use, and sharing
- Right to Delete: Request deletion of personal information
- Right to Correct: Correction of inaccurate personal information
- Right to Opt-out: No sale or sharing of personal information
- Right to Limit: Restriction of sensitive personal information use
- Right to Non-discrimination: No penalty for exercising privacy rights
How to Exercise Your Rights
To exercise your privacy rights, you can:
- Email our privacy team at privacy@sommer.co
- Use our in-app privacy settings and data export tools
- Contact customer support through our help center
- Submit requests through our online privacy portal (when available)
How we protect your personal information
Technical Safeguards
We implement comprehensive technical security measures:
- End-to-end encryption for data transmission (TLS/SSL)
- Encryption at rest for sensitive data storage
- Secure database configurations with access controls
- Regular security updates and vulnerability patches
- Multi-factor authentication for administrative access
- Network security monitoring and intrusion detection
- Secure development practices and code reviews
Organizational Measures
We maintain strong organizational security practices:
- Employee security training and access management
- Data processing agreements with all vendors
- Regular security audits and penetration testing
- Incident response procedures and protocols
- Business continuity and disaster recovery planning
- Privacy by design principles in development
- Compliance monitoring and documentation
Data Breach Notification
In the event of a data breach, we will:
- Notify affected users within 72 hours when required by law
- Report breaches to relevant supervisory authorities
- Implement immediate containment and remediation measures
- Conduct thorough investigation and impact assessment
- Provide clear information about the breach and mitigation steps
- Review and improve security measures to prevent future incidents
Additional privacy protections by jurisdiction
European Union (GDPR)
For EU and EEA users, additional GDPR protections include:
- Legal basis for processing under GDPR Article 6
- Special category data protections under Article 9
- International transfer safeguards under Articles 44-49
- Data Protection Officer contact: dpo@sommer.co
- Right to lodge complaints with supervisory authorities
- EU representative contact information (if applicable)
California (CCPA/CPRA)
California residents receive enhanced privacy protections:
- Detailed categories of personal information collected
- Business purposes for data collection and use
- Third parties with whom information is shared
- Non-discrimination policy for exercising rights
- Authorized agent procedures for submitting requests
- Sensitive personal information processing limitations
Other Jurisdictions
We comply with privacy laws in other jurisdictions where we operate:
- Canada (PIPEDA) - Personal Information Protection
- Australia (Privacy Act) - Australian Privacy Principles
- Brazil (LGPD) - Lei Geral de Proteção de Dados
- United Kingdom (UK GDPR) - Data Protection Act 2018
- Other applicable regional data protection laws
Questions About Your Privacy?
If you have questions about this Privacy Policy or want to exercise your privacy rights, our team is here to help.
Additional Legal Resources
Access our complete legal documentation, policy updates, and compliance information.