Skip to main content
Data Protection

Privacy Policy

This Privacy Policy explains how Sommer collects, uses, and protects your personal information. We are committed to transparency and giving you control over your data.

Last updated: January 15, 2025
Effective: January 1, 2025
GDPR & CCPA
Global Compliance
International data protection
Enterprise
Data Protection
Bank-grade security
SaaS Standard
Legal Framework
Industry best practices
100%
Transparency
Clear and comprehensive

Privacy Overview

Navigate through our comprehensive privacy policy to understand how we handle your personal information.

Introduction & Scope
In This Section
Data We Collect
Important
In This Section
+1 more topics
How We Use Your Data
In This Section
+1 more topics
Data Sharing & Third Parties
In This Section
+1 more topics
International Data Transfers
In This Section
Data Retention
In This Section
Your Privacy Rights
Important
In This Section
Cookies & Tracking
In This Section
Data Security Measures
In This Section
Children's Privacy
In This Section
Policy Updates
In This Section
Regional-Specific Provisions
In This Section

Questions or Concerns?

If you have any questions about these terms or need clarification on any section, our legal and support teams are here to help.

1. Introduction and Scope

About this Privacy Policy and our commitment to data protection

Updated: January 15, 2025

Company Information

Sommer Inc. ("Sommer," "we," "our," or "us") operates as the data controller for personal information processed through our vacation rental management platform. We are committed to protecting your privacy and handling your personal data in accordance with applicable data protection laws.

Company Details:
Sommer Inc.
123 Business St, Suite 100
San Francisco, CA 94105
United States

Policy Scope

This Privacy Policy applies to all personal information collected and processed by Sommer through:

  • Our web application platform (sommer.co)
  • Account creation and authentication processes
  • Organization and property management features
  • Team collaboration and communication tools
  • Customer support and communication channels
  • Marketing communications (with your consent)

Privacy Contact Information

For privacy-related questions, requests, or concerns, please contact us:

  • Privacy Team: privacy@sommer.co
  • Data Protection Officer: dpo@sommer.co
  • Legal Team: legal@sommer.co
  • General Support: support@sommer.co
2. Data We Collect

Comprehensive overview of personal information we collect

Important

Account and Profile Information

When you create a Sommer account, we collect:

  • Email address (required for authentication and communication)
  • Name and username for your profile
  • Profile photos uploaded via UploadThing integration
  • Bio and description text (optional)
  • Location information (if provided)
  • Authentication data from social logins (Google, GitHub)
  • Account preferences and settings

Organization Information

For organization management functionality, we collect:

  • Organization names, descriptions, and logos
  • Member lists and role assignments
  • Organization locations and contact information
  • Team collaboration data and member communications
  • Organization settings and preferences

Property and Listing Information

For vacation rental property management, we process:

  • Property titles, descriptions, and specifications
  • Property photos and image descriptions
  • Amenity selections and feature details
  • Location data and address information
  • Pricing information and currency preferences
  • Listing status and publication settings
  • Property performance and management data

Usage and Technical Data

We automatically collect technical and usage information:

  • IP addresses and device information
  • Browser type, version, and language settings
  • Operating system and device characteristics
  • Pages visited, features used, and time spent
  • Click patterns and user interaction data
  • Session information and authentication logs
  • Performance data and error reports
  • Referral sources and marketing attribution
Data Minimization Principle
We only collect personal information that is necessary for providing our vacation rental management services. We do not collect sensitive personal information unless specifically required for legitimate business purposes.
3. How We Use Your Data

Legal basis and purposes for processing personal information

Service Provision (Contractual Necessity)

We use your personal information to provide and maintain our vacation rental management platform:

  • User authentication and account management
  • Organization creation and team collaboration features
  • Property listing creation, editing, and management
  • Photo upload and storage via UploadThing integration
  • Platform functionality and feature delivery
  • Customer support and technical assistance

Business Operations (Legitimate Interest)

We process data for legitimate business interests, balancing our needs with your privacy rights:

  • Platform improvements and feature development
  • Performance monitoring and optimization
  • Security monitoring and fraud prevention
  • Usage analytics and product insights (anonymized)
  • Customer support quality improvement
  • Business planning and strategy development

Marketing Communications (Consent-Based)

With your explicit consent, we may use your information for:

  • Product updates and feature announcements
  • Educational content and best practices for vacation rental hosts
  • Promotional offers and service improvements
  • Industry news and platform updates
  • Surveys and feedback requests
Marketing Opt-Out
You can withdraw consent for marketing communications at any time by clicking "unsubscribe" in our emails or contacting our privacy team.
4. Data Sharing and Third Parties

When and why we share personal information with others

Service Providers (Data Processors)

We share personal information with trusted service providers who help us operate our platform:

  • UploadThing: File storage and image management services
  • Neon/PostgreSQL: Database hosting and data management
  • Auth.js/OAuth Providers: Authentication and identity services
  • Resend: Email delivery and communication services
  • Upstash Redis: Caching and rate limiting services
  • Vercel: Platform hosting and content delivery
  • Stripe: Payment processing (when implemented)

All service providers are bound by data processing agreements that ensure appropriate data protection standards.

Business Transfers

Personal information may be transferred in connection with business transactions:

  • Mergers, acquisitions, or sales of company assets
  • Corporate restructuring or reorganization
  • Bankruptcy proceedings or asset liquidation
  • Due diligence processes for potential transactions

In such cases, we will ensure appropriate data protection measures are maintained by the acquiring entity.

What We Never Share

Our Commitment

Sommer never sells, rents, or trades your personal information. We do not:

  • Sell personal data to advertisers or marketers
  • Share data with third parties for their marketing purposes
  • Provide unauthorized access to user accounts or data
  • Use personal information for purposes beyond those disclosed
  • Share data without appropriate legal basis or consent
7. Your Privacy Rights

Understanding and exercising your data protection rights

Important

GDPR Rights (EU/EEA Users)

Under the General Data Protection Regulation (GDPR), EU and EEA users have the following rights:

  • Right of Access: Request a copy of your personal data and information about processing
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of personal data ('right to be forgotten')
  • Right to Restrict Processing: Limit how we process your personal data
  • Right to Data Portability: Receive personal data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Rights Related to Automated Decision-making: Protection from automated decisions

CCPA Rights (California Residents)

Under the California Consumer Privacy Act (CCPA/CPRA), California residents have these rights:

  • Right to Know: Information about data collection, use, and sharing
  • Right to Delete: Request deletion of personal information
  • Right to Correct: Correction of inaccurate personal information
  • Right to Opt-out: No sale or sharing of personal information
  • Right to Limit: Restriction of sensitive personal information use
  • Right to Non-discrimination: No penalty for exercising privacy rights

How to Exercise Your Rights

To exercise your privacy rights, you can:

  • Email our privacy team at privacy@sommer.co
  • Use our in-app privacy settings and data export tools
  • Contact customer support through our help center
  • Submit requests through our online privacy portal (when available)
Response Timeframes
We will respond to privacy requests within 30 days for GDPR requests and as required by CCPA. We may need to verify your identity to protect your personal information from unauthorized access.
9. Data Security Measures

How we protect your personal information

Technical Safeguards

We implement comprehensive technical security measures:

  • End-to-end encryption for data transmission (TLS/SSL)
  • Encryption at rest for sensitive data storage
  • Secure database configurations with access controls
  • Regular security updates and vulnerability patches
  • Multi-factor authentication for administrative access
  • Network security monitoring and intrusion detection
  • Secure development practices and code reviews

Organizational Measures

We maintain strong organizational security practices:

  • Employee security training and access management
  • Data processing agreements with all vendors
  • Regular security audits and penetration testing
  • Incident response procedures and protocols
  • Business continuity and disaster recovery planning
  • Privacy by design principles in development
  • Compliance monitoring and documentation

Data Breach Notification

In the event of a data breach, we will:

  • Notify affected users within 72 hours when required by law
  • Report breaches to relevant supervisory authorities
  • Implement immediate containment and remediation measures
  • Conduct thorough investigation and impact assessment
  • Provide clear information about the breach and mitigation steps
  • Review and improve security measures to prevent future incidents
12. Regional-Specific Provisions

Additional privacy protections by jurisdiction

European Union (GDPR)

For EU and EEA users, additional GDPR protections include:

  • Legal basis for processing under GDPR Article 6
  • Special category data protections under Article 9
  • International transfer safeguards under Articles 44-49
  • Data Protection Officer contact: dpo@sommer.co
  • Right to lodge complaints with supervisory authorities
  • EU representative contact information (if applicable)

California (CCPA/CPRA)

California residents receive enhanced privacy protections:

  • Detailed categories of personal information collected
  • Business purposes for data collection and use
  • Third parties with whom information is shared
  • Non-discrimination policy for exercising rights
  • Authorized agent procedures for submitting requests
  • Sensitive personal information processing limitations

Other Jurisdictions

We comply with privacy laws in other jurisdictions where we operate:

  • Canada (PIPEDA) - Personal Information Protection
  • Australia (Privacy Act) - Australian Privacy Principles
  • Brazil (LGPD) - Lei Geral de Proteção de Dados
  • United Kingdom (UK GDPR) - Data Protection Act 2018
  • Other applicable regional data protection laws

Questions About Your Privacy?

If you have questions about this Privacy Policy or want to exercise your privacy rights, our team is here to help.

Get Support
Email Support
Get help from our support team
< 4 hours
Live Chat
Chat with our team in real-time
< 5 minutes
Documentation
Browse our help center
Instant
Legal & Privacy
Legal Team
Questions about terms, privacy, or compliance
legal@sommer.co
2-3 business days
Data Protection Officer
Privacy rights and data protection inquiries
privacy@sommer.co
1-2 business days
Company Information
Sommer Inc.
Vacation Rental Management Platform
123 Business St, Suite 100
San Francisco, CA 94105
United States

Additional Legal Resources

Access our complete legal documentation, policy updates, and compliance information.