Maison Labs, Inc.

Privacy Policy

Updated Aug 26, 2026

Maison (“Maison,” “we,” “us,” or “our”) provides an AI hotel-concierge service that reads guest messages sent to a hotel's mailbox and drafts a concierge reply from that same mailbox. This Privacy Policy explains what data we collect, how we use it, how we store and protect it, who we share it with, and the choices and rights you have. It applies to the Maison service and website at https://maison.cx and is written to satisfy the Google API Services User Data Policy, including its Limited Use requirements (affirmed in Section 5).

Who our customer is. Our direct customer is the hotel/hospitality operator (“Operator”) that connects its mailbox to Maison. Guests correspond with the hotel by email; Maison processes those messages on the Operator's behalf. For data-protection purposes the Operator is the controller and Maison acts as its processor/service provider.

Legal entity. Maison is operated by Maison Labs, Inc.

1. What data we collect

  • a. Google user data (the connected hotel mailbox). Message bodies, threads, and history of the connected hotel mailbox, plus the OAuth access + refresh tokens that authorize access. We do not access any third-party or personal mailboxes.
  • b. Microsoft mailbox data (Outlook). Equivalent data via Microsoft Graph for Operators on Outlook.
  • c. Guest email content. Whatever personal information a guest includes in their message to the hotel (name, email, travel dates, requests).
  • d. Forwarded email — removed. The earlier SES forwarding path was decommissioned (July 2026); hotel mail is read directly via the Gmail API / Microsoft Graph and no forwarded copies are stored.
  • e. Operator account/config data. Connected mailbox address, channel configuration, connection status.
  • f. Website/support data. What you send us at support@maison.cx.

2. Google user data — scopes and exactly what we access

Scope Access it grants Why Maison needs it
gmail.modify Read message bodies, threads, and history of the connected hotel mailbox, and modify message labels (read/unread state) Read the inbound guest message to generate an accurate concierge reply, and mark a guest email as read only after the agent has replied — unanswered mail stays unread as the hotel staff's work queue. No deletion, no settings changes, no filters.
gmail.send Send mail as the connected hotel mailbox Send the concierge reply from the hotel's own mailbox. A separate grant from read.

gmail.send allows sending only. Maison requests exactly these two scopes and no others; the only label operation performed under gmail.modify is marking an answered guest email as read. Maison never deletes mail, never changes mailbox settings, and never creates filters or forwarding rules.

Exactly what is accessed: message bodies/threads + mailbox history, and read/unread label state; the OAuth access + refresh tokens (stored encrypted, Section 3); only the single hotel mailbox the Operator connects — never any other Google account.

3. How we use, store, and secure the data

Use: read the inbound message (gmail.modify); draft the reply via Google Gemini through Maison's llm-service for stateless inference only (never used to train/fine-tune/improve any model, never for advertising, never sold); optional human review by the Operator before sending (their own mailbox, with their consent); send the reply (gmail.send / Microsoft Graph); mark the answered guest email as read (gmail.modify) — unanswered mail stays unread for hotel staff. Used only to provide/improve these user-facing features.

Store + secure: OAuth tokens encrypted at rest with AES-256-GCM in Postgres (client_channels), never logged; guest content processed transiently to make one reply (not a long-term archive on the inference path); active conversation state in DynamoDB auto-expires after 7 days; the durable conversation log (guest message + agent reply, reviewable by the hotel in its console) is retained for the duration of the Operator's service relationship; TLS in transit.

4. Sharing and subprocessors

We do not sell data, do not use it for advertising, do not use it to train/fine-tune/improve any AI model. Subprocessors:

Subprocessor Purpose Data involved
Google Gmail API + Gemini (stateless inference) Mailbox content + OAuth tokens; guest content sent to Gemini for inference only
Microsoft Graph / Outlook access Mailbox content + OAuth tokens (Outlook path)
AWS Hosting + storage (Postgres, DynamoDB, S3) Encrypted tokens, session logs

No other third parties except to comply with law or in a merger/acquisition (with continued protection).

5. Limited Use — Google API Services User Data Policy

Maison's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Maison affirms:

  1. Use of Google user data is limited to providing/improving prominent user-facing features — reading the inbound guest message and drafting/sending the concierge reply.
  2. No transfer of Google user data except to provide/improve those features, comply with law, or in a merger/acquisition with user consent.
  3. No use or transfer of Google user data for advertising (incl. retargeting/personalized/interest-based).
  4. No humans read Google user data unless: (a) with the user's affirmative agreement for specific messages; (b) necessary for security (investigating abuse); (c) to comply with law; or (d) aggregated for internal operations. Operator review of a drafted reply occurs on the Operator's own mailbox with their affirmative agreement, consistent with (a).

Google user data is never used to train, fine-tune, or improve any generalized or non-personalized AI/ML model. All inference is stateless, solely to generate the reply.

6. Data retention and deletion

  • Active conversation/session state auto-expires after 7 days (DynamoDB TTL); message-processing status records (metadata only, no message content) after 30 days; site-diagnostic events after 90 days.
  • No forwarded email is stored — the legacy SES forwarding path was decommissioned (July 2026).
  • Guest content on the inference path is transient — processed once to generate the reply; the durable record is the conversation log, retained for the duration of the Operator's service relationship and deleted on account deletion.
  • OAuth tokens retained only while the connection is active.

Disconnecting a mailbox (any time) → Maison erases the stored tokens and revokes access. Account deletion → Maison purges associated data (request via support@maison.cx / engineering@maison.cx). Guest deletion requests go to the hotel (Operator), who may route to Maison at support@maison.cx.

7. Your rights and controls

Connection control (disconnect any time); human oversight (review before send); access/correction/deletion/restriction rights depending on location (contact support@maison.cx). No discrimination for exercising rights.

8. Security incidents

If we become aware of a security incident affecting Google user data or other personal data, we respond per applicable law and notify affected parties as required. Report concerns to security@maison.cx.

9. Changes

We may update this policy; material changes update the “Last updated” date with notice where appropriate.

10. Contact

Product: https://maison.cx · General/privacy/deletion: support@maison.cx · Engineering: engineering@maison.cx · Security: security@maison.cx