Privacy Policy
Birch Smart Home · Effective 7 September 2026
1. Who we are
This Privacy Policy explains how Birch Stays Ltd (“Birch Stays”, “we”, “us”, “our”) collects, uses, shares and protects personal data when you use the Birch Smart Home service, including when you connect a Google account so we can control heating in a managed holiday let.
Birch Stays Ltd is the data controller. We are a private limited company registered in England and Wales under company number 13824705. Our registered office is 76 Duddy Road, Disley, Stockport, England, SK12 2GB. Contact: hello@birchstays.com.
2. What this policy covers
This policy covers personal data processed when you:
- authorise Birch Smart Home to access a Google Nest / Google Home household via Device Access;
- invite a Birch slot Gmail to a Google Home household so we can manage heating for a stay;
- use Birch staff tools to connect, sync or unlink thermostats and related devices.
Guest bookings on birchstays.com and the owner portal at owner.birchstays.com have their own privacy notices.
3. Google user data we access
When you (or a Birch operator acting with the household’s permission) complete Google’s Partner Connections Manager flow, we request the Smart Device Management scope https://www.googleapis.com/auth/sdm.service. Through Google’s Device Access / SDM APIs we may receive:
- the Google account email used to authorise the connection;
- Google Home structure (household) identifiers and display names;
- device identifiers, types and names (typically thermostats and related HVAC devices);
- device traits and state (for example mode, ambient temperature, heat setpoint);
- OAuth access and refresh tokens needed to keep the connection working.
We do not request camera, doorbell or microphone device access. We do not use Google user data for advertising.
4. How we use that data
We use Google Nest / SDM data only to:
- list homes and devices so they can be linked to a Hostfully property;
- run booking-driven heating (for example pre-heat before check-in, eco or away after check-out);
- show current heating status to authorised Birch staff;
- keep the OAuth connection alive and diagnose faults.
Google API Services User Data Policy — Limited Use
Birch Stays’ use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve user-facing heating automation for properties we manage. We do not sell it. We do not use it for advertising. We do not transfer it to others except as needed to operate the service (for example encrypted storage with our hosting providers), to comply with law, or with your direction. Human access is limited to security, support and operations where it is necessary to provide the service.
5. Other data we process
Alongside Google data we may store:
- Birch staff account details for people who sign in to this admin app;
- property identifiers from Hostfully, used to match a home to a holiday let;
- workflow and execution logs (setpoints sent, success or failure);
- technical logs such as IP address and time of admin access, for security.
6. Lawful bases
- Consent — you grant Device Access when you complete Google’s permission screen.
- Contract / legitimate interests — operating heating for a property Birch manages, and keeping the service secure.
- Legal obligation — where we must retain or disclose records.
7. Who we share data with
Tokens and device state are stored in our database (encrypted at rest for secrets) and processed by our cloud hosting providers. We may share information with professional advisers, or with regulators or law enforcement when required by law. We do not sell personal data.
8. International transfers
Google and some hosting providers process data outside the UK, including in the United States. Where we transfer personal data outside the UK we use an appropriate safeguard under UK data protection law (for example adequacy or the UK IDTA / UK Addendum to the EU SCCs).
9. Retention
We keep connected-account tokens and device records for as long as the property remains connected. If you disconnect, we delete or anonymise Google tokens and stop calling the SDM API. Operational logs are kept only as long as needed for support, security and debugging, then deleted or anonymised.
10. Your rights and how to disconnect
You can:
- revoke Birch’s access in Google Account → Third-party access and/or Partner Connections Manager;
- ask Birch to unlink the home in this admin app;
- exercise UK GDPR rights (access, rectification, erasure, restriction, objection, portability) by emailing hello@birchstays.com.
You may also complain to the ICO at ico.org.uk.
11. Security
We use HTTPS, access-controlled staff logins with two-factor authentication, and encryption of stored OAuth secrets. No method of transmission or storage is completely secure.
12. Changes
We may update this policy. The current version will be published at this URL. Material changes will be noted by updating the effective date above.
See also our Terms of Service.