Privacy Policy
Last updated: 1 July 2026.
This Privacy Policy explains how Occupancy Guard ("we", "us", "our") collects,
uses, and shares information when you use the Occupancy Guard mobile application and related
services (the "Service"). Occupancy Guard is operated by Erbacci LTD ("Erbacci"),
the controller of personal data described below. Contact:
info@erbacciltd.com.
1. What Occupancy Guard does
Occupancy Guard is a tool for short-term-rental (STR) hosts. It watches a Ring video doorbell
at the entrance of a property you own or manage and counts how many guests
arrive, comparing that to the number booked. It produces occupancy notifications and
timestamped arrival snapshots you can use as evidence in a booking or chargeback dispute.
Occupancy Guard is an occupancy-awareness tool, not a security, alarm, or eviction
system, and it does not identify individuals.
Occupancy Guard is designed for external, entrance-only monitoring. It is never
intended for indoor use, and it does not perform facial recognition or biometric identification.
2. Information we collect
2.1 Information you provide
- Account identifiers from Ring. When you sign in with your Ring account,
we receive your Ring user ID and the email address associated with your Ring account.
- Property configuration. Property name, address, time zone, an optional
listing URL, and the Ring doorbell/camera(s) you select.
- Booking details. Booked guest count, check-in and check-out times,
platform (e.g. Airbnb, VRBO), an optional confirmation code, guest name, and notes that you
enter to define a booking window.
- Preferences. Snooze settings and any events you mark "not interesting."
2.2 Information we receive from Ring
- Event metadata. Doorbell press / motion metadata: camera identifier,
timestamp, and a reference to the snapshot frame.
- Snapshot images. A still frame from the entrance doorbell/camera,
processed by Amazon Rekognition (object pre-filter) and Anthropic Claude (running on Amazon
Bedrock) to produce a headcount only — the number of people at the entrance,
whether a person is at the threshold, and a time-of-day estimate. The vision model is
instructed to count, not identify; it does not describe, recognize, or
enroll any person.
2.3 Information we generate
- Occupancy classifications — the structured JSON output of the vision
model (a headcount, not an identity).
- Arrival and occupancy records — distinct arrivals within a booking window,
peak occupancy, and any over-occupancy or unauthorized-arrival flags.
- Evidence snapshots — the still frame stored for an arrival, together with
a SHA-256 hash of the exact image bytes so the snapshot can be shown to be untampered.
- Notification records — which alerts we attempted, to which devices, and
the outcome.
- Diagnostic logs — error traces and performance metrics, scoped to internal
use.
2.4 Information from your device
- Push notification tokens (APNs / FCM) so we can deliver alerts.
- Device metadata — OS version, app version, locale — used for compatibility
and analytics.
- Stable per-install device identifier generated by the app on first launch.
Not linked to any advertising identifier.
We do not collect: faces, faceprints, or other biometric identifiers; audio;
location data outside the camera's fixed entrance view; contact list, calendar, or other
unrelated device data.
3. Guest privacy and consent
Occupancy Guard records at the entrance of a property you own or manage. You are
responsible for lawfully operating the Ring doorbell and for notifying your guests that the
entrance is monitored by a video doorbell. Many jurisdictions and booking platforms
(including Airbnb and VRBO) require hosts to disclose the presence and location of any
exterior recording device in the listing and/or at the property. Occupancy Guard counts
arrivals and does not identify individuals, but you remain the party responsible for guest
notice and consent where the law requires it.
4. How we use information
- Count arrivals at your entrance and compare them to your booking to surface
over-occupancy, unauthorized, or early arrivals.
- Produce timestamped arrival snapshots you can assemble into an evidence packet for a
booking or chargeback dispute.
- Send you notifications according to your tier and preferences.
- Maintain your account, including subscription state.
- Improve the Service by analysing aggregate accuracy metrics. Snapshots are not used
to train third-party models.
- Comply with legal obligations and respond to lawful requests.
We do not sell your personal information. We do not "share" personal
information for cross-context behavioural advertising as defined under CCPA/CPRA.
5. How we share information
- Amazon Web Services — infrastructure provider (storage, compute, vision
model invocation).
- Anthropic, via the Amazon Bedrock service, for vision model inference.
Snapshots are not retained by the model provider beyond the inference call.
- Apple and Google, for push notification delivery.
- Resend — transactional email provider, for delivery of sign-in one-time
codes and occupancy-alert emails. Resend receives the recipient's email address and the
message content (which may include a short-lived link to a snapshot); it does not
receive Ring camera media files or account tokens.
- Ring (Amazon), for OAuth identity and subscription webhooks.
- Law enforcement or regulators, where required by valid legal process.
6. Retention
| Data | Retention |
| Account record | Until account deletion |
| Properties & bookings | Until account deletion (bookings expire after the retention window below) |
| Event / arrival timeline (free tier) | 30 days |
| Event / arrival timeline (premium tier) | 90 days |
| Snapshot images | Up to 90 days; purged on account deletion within 24h |
| Push notification audit log | 30 days |
| Diagnostic / error logs | 30 days |
7. Your rights
You may have the right to access, correct, delete, port, or restrict processing of your
personal information. Exercise these rights from inside the app
(Settings → Delete account) or by emailing
info@erbacciltd.com. We respond within 30 days.
We do not discriminate against you for exercising these rights.
If you are a California resident, you have rights under the CCPA/CPRA including the
right to know, delete, correct, and opt out of "sale" or "sharing" (we do neither).
8. Security
- Encryption in transit (TLS) and at rest (AWS managed encryption).
- HMAC signature verification on all incoming webhooks.
- Short-lived JWT session tokens stored in iOS Keychain / Android Keystore.
- Least-privilege IAM policies on every backend component.
9. Children
The Service is not directed to children under 13. We do not knowingly collect personal
information from children under 13. If you believe we have, contact us and we will
delete the information.
10. International transfers
The Service is operated from the United States and offered only in the United States. If you
access it from outside the US, your information is transferred to and processed in the US.
11. Changes to this policy
We may update this Privacy Policy. If changes are material, we will notify you in-app
before they take effect.
12. Contact
Erbacci LTD, the data controller · info@erbacciltd.com
Registered office: Strovolou 77, Strovolos Center, Office 301, Strovolos 2018, Nicosia, Cyprus (Company No. HE 457237).