Staythread privacy notice
Last updated 22 July 2026.
Who looks after your information
Staythread is operated by Pike House Escapes. Contact us at bookings@pikehouseescapes.co.uk with a privacy question or request.
What we hold
We hold the account details you provide, your property and membership settings, guest directions and key-collection instructions, arrival contact numbers, chosen connection method, API request status, calendar links, imported unavailable dates, manual date blocks, connection history, plan choices and support correspondence.
Where a connected booking source supplies reservation details, Staythread may also hold the booking reference and status, stay dates, lead guest name, email, available telephone numbers, postcode, party numbers and any later address fields supplied by an approved connection. The Bookings page shows when a field was not supplied.
Property access codes
When you save a property access code, its value is encrypted in a dedicated access store using a deployment-only key that is not held in the database. It is hidden from normal account and admin history. The dated history holds a secret reference, random audit ID, property, effective range, person who recorded the change and channel result. The current code is sent to a channel only when an authorised user chooses a publish action.
Guest arrival and the Sykes browser button
Guest directions, non-secret key instructions and arrival contact numbers are held as dated property versions. If you create the private Sykes browser button, Staythread stores separate one-way hashes for the bookmark and paired browser, plus creation and last-use times. One button is active per property, it expires after 30 days and it can be replaced or turned off.
When used on the matching authorised Sykes owner page, the button first saves the complete form to Staythread. Only after that succeeds does the original page submit the same form to Sykes. Staythread separates a recognised access code into the encrypted access store and rejects code-like text that it cannot separate safely.
Sykes browser import
When Sykes asks for its normal browser security check, an authorised customer can choose a separate browser import. The customer signs in to Sykes directly and deliberately runs their private Staythread button on the Sykes Bookings page. The button sends only the cottage selector and booking list shown on that page. It does not read or send the Sykes password, cookies, browser storage, complete page or content from another Sykes page.
Staythread checks that the receiving customer is signed in, that the selected Sykes connection belongs to their account, that the request came from the Sykes website and that the form carries a valid Staythread security token. The transferred page fragments are parsed in memory and discarded. Only validated cottage, booking, guest and unavailable-date fields covered by this notice are retained.
Local connector
An authorised customer can run the optional Staythread local connector on their own computer or NAS. The Sykes sign-in, browser session and cookies remain on that device. Staythread receives the same bounded cottage selector and booking list used by Browser import, plus an accepted or failed result for a queued guest-arrival update. Raw provider markup is parsed in memory and discarded.
The device is paired with a random connector key shown once to the customer. Staythread stores a one-way hash of that key, short-lived request times, single-use request IDs, last-check and result history. The customer or operator can revoke the device at any time. The connector does not require a public NAS port.
Connection passwords
When a customer selects secure reconnect for the independent Sykes owner connection, Staythread stores the supplied email and password encrypted in a dedicated connector vault. The encryption key is held outside the database, the values are bound to that customer's connection and neither the customer account nor operator screens can display the password. A customer can clear the choice or disconnect Sykes to remove the saved details. If secure reconnect is not selected, the password is discarded after the connection attempt.
A successful sign-in can also return a temporary Sykes permission. Staythread protects that permission separately and removes it when the customer disconnects. Browser import does not copy or store that permission from the customer's browser.
What we do not put in availability feeds or attachments
The private feeds and attached calendar copies generated by Staythread contain unavailable dates only. They do not include guest names, prices, email addresses, telephone numbers, addresses, access codes or payment details.
Why we use the information
We use it to provide and secure the service, import bookings for the property operator, help prevent double bookings, support guest arrival and site-membership checks, answer support requests, manage trials and subscriptions, prevent misuse and understand how the product is working.
Membership administration
A customer can record that a property requires site membership, email the joining link to a lead guest and, after recording the guest's agreement, send the minimum available details to an authorised membership contact chosen by that customer. Staythread does not use those details for club marketing.
Suppliers and transfers
We use hosting, email and operational suppliers where needed to run Staythread. Booking channels receive information only when you approve and use a connection with that channel. Membership details are sent only when the customer chooses the action and has configured the recipient. Each recipient's own privacy terms also apply.
How long we keep it
We keep active account information while you use the service. Imported guest details have a removal date based on the stay's departure and the retention period set by the Staythread owner. Customers can remove guest details sooner from the Bookings page while leaving the booking reference and dates needed for availability records. Arrival and access-code versions remain in the property audit history until the account is closed or the operator removes the property. After closure, we retain only what is reasonably needed for legal, security, support and accounting purposes, then delete or anonymise it.
Your choices
You can ask for a copy, correction or deletion of personal information, or object to certain uses. Some records may need to be kept where the law requires it. You can also complain to the UK Information Commissioner's Office.
Security
Accounts use password protection and private feed tokens. Keep account details, browser buttons, private feed links and property access codes confidential, and contact us promptly if you think any of them has been exposed.