Skip to main content
Security

What we do with your data, how it's protected, and what we don't pretend to have.

VR Goals reads from Guesty, the live PMS connection. Accounting, operations, CRM, messaging, and contracts are native VR Goals capabilities, not external connections. Here's the posture: claims only where they're true, planned work where it is still in progress.

Security posture

Encryption in transit

Live

The VR Goals website, app and API are served over HTTPS (TLS 1.2).

Guesty OAuth connection

Live

VR Goals connects to Guesty with Guesty Open API OAuth credentials, not your Guesty login password.

Access controls

Live

Authenticated access, tenant-aware access restrictions, and server-side storage for connected Google access and refresh tokens.

Data flow

What connects, and what stays native.

Live connection
Guesty, over OAuth. The PMS stays the reservation source of truth. Other PMS platforms are not live.
Native records
Accounting, operations, CRM, messaging and contracts run in VR Goals. There is no live connection to QuickBooks, Breezeway, HubSpot, Twilio, DocuSign or PandaDoc. Imports your QuickBooks history at onboarding and replaces it when you switch.
Access
Authenticated access and tenant-aware access restrictions (Privacy Policy §9).
Residency
Information may be processed in the United States and other countries where VR Goals or its service providers operate (Privacy Policy §10).
Data handling
Retention
Personal information is retained as long as needed to provide the Service and meet legal, carrier and record-keeping obligations; the period depends on the type of record. You can request deletion (Privacy Policy §11).
Residency
Information may be processed in the United States and other countries where VR Goals or its service providers operate (Privacy Policy §10).
Production access
Authenticated access and tenant-aware access restrictions (Privacy Policy §9).
Subprocessors

Third parties that process customer data on our behalf. We review and update this list as our stack evolves.

VendorPurposeData
Google WorkspaceInternal email and document collaborationInternal communications about customer engagements
CloudflareCDN, DNS and edge (including Turnstile on public forms), transactional email delivery, and AI summaries of contact-form submissions (Workers AI)Request metadata, TLS, bot/challenge tokens; access-request emails and outbound notifications; contact-form submissions for lead summaries.
TelnyxSMS/MMS transport, 10DLC registration, and telephone numbersMessage content, delivery reports, registered brand and campaign data, telephone numbers. Named throughout /terms.
PostHogProduct analytics and session replay on the marketing site (inputs masked; not loaded under Global Privacy Control or the opt-out cookie)Page views, interactions and masked session recordings
Google Analytics (GA4)Site traffic measurement on the marketing site (not loaded under Global Privacy Control or the opt-out cookie; Google signals and ad personalization off)Page views, device and browser data, approximate location, and analytics cookies (_ga)
Incident response

Report a suspected security issue to [email protected].

Need deeper diligence?

Questions about security? Email us and we'll answer them directly.