Security & connected systems
Last updated: August 19, 2026
Cabinator only works if you trust it with a read-only view of your operation. This page states plainly what we read, what we never ask for, and how to switch it off. Cabinator is a product of PCBC LLC, Mississippi, USA.
We never ask for your passwords
Connections are authorized by you through each provider's official authorization flow (OAuth) or through a provider-issued access token you generate inside that provider's own account settings. Cabinator does not ask for, display a form for, or store the ordinary password you use to sign in to another company's service. If anything ever asks you for such a password in Cabinator's name, it is not us — report it to support@cabinator.ai.
What we read from each connected system
Property management system
We read: Property records, reservation dates, nightly rates, fees, booking channel, payout and cancellation status, and guest first name plus arrival details needed to build your daily briefing.
We never read: We do not read guest payment card numbers, government identification, or message attachments.
Dynamic pricing tool
We read: Your recommended base price, minimum stay settings, and calendar-level rate recommendations, so Cabinator can compare them with your live settings.
We never read: We do not change your rates. Cabinator suggests; you approve inside your own tool.
Guest payment or deposit system
We read: Whether a payment, deposit, or authorization succeeded, failed, or is pending, and the amount.
We never read: We never receive or store card numbers or bank credentials.
Market and event data
We read: Public information about your area — comparable listing rates, occupancy trends, and local events.
We never read: No customer data is sent to obtain this information.
Access is read-only unless you explicitly approve a specific action. Cabinator does not move money, message guests, or alter your calendar on its own.
How to revoke access
You can disconnect any system at any time from Cabinator's connections screen, which deletes the stored authorization token immediately. You can also revoke Cabinator from the provider's side in its own account settings — typically under a "Connected apps," "Integrations," or "API access" section. Revoking from either side stops all further reads. To have your account and its data deleted entirely, email support@cabinator.ai and we will confirm deletion within 30 days.
Where data is stored, and for how long
Customer data is stored in managed databases hosted in the United States, encrypted in transit (TLS) and at rest. Operational data — properties, reservations, and the recommendations you approved or rejected — is retained while your account is active so Cabinator can compare year over year. Trial-request contact details are retained for up to 24 months unless you ask us to remove them sooner. When an account is closed we delete or de-identify its data within 30 days, apart from records we must keep for tax or legal purposes.
AI processing
Cabinator uses Anthropic's Claude models for AI processing. Under our agreement, our AI provider is contractually barred from using customer data to train or improve its models. What Cabinator learns about your business is stored in your own account, not in a shared model.
Sub-processors we name
- Anthropic — AI model processing (Claude).
- Netlify — application hosting.
- Supabase — database and authentication hosting.
- Stripe — subscription payments. Card details go to Stripe directly; PCBC LLC never stores card numbers.
We will update this list before adding a sub-processor that handles customer data.
Security contact
To report a security concern, contact support@cabinator.ai or call (870) 682-3324. We acknowledge reports within one business day and will not pursue researchers who report issues in good faith.
See also our Privacy Policy and Terms of Service.