Privacy

GBA Connections LLC Privacy Policy

Effective Date: August 20, 2026
Last Updated: August 20, 2026
Contact: hello@whatweexperience.com

1. Scope

This policy applies to GBA Connections LLC (“GBA,” “we,” “us,” or “our”) and covers: (a) the public hospitality website at WhatWeExperience.com; and (b) GBA's internal, read-only financial connector. The connector is for GBA-authorized business use and is not used to collect guest or other consumer bank-account data.

2. Public website information

Information we may collect

  • Anonymous or pseudonymous site analytics, such as page visits, clicked links, device type, general traffic source, and time spent on property pages.
  • Inquiry details, such as name, email address, and the property referenced, only when a visitor submits that information.
  • A one-way hashed IP fingerprint used to help identify duplicate sessions; GBA does not store the raw IP address for this purpose.

Information the website does not collect

  • Passwords or full payment-card details.
  • Information entered inside the Hospitable booking widget.
  • Internal property addresses, reviewer names, or reviewer email addresses.

Exact property addresses are shared only with confirmed guests when appropriate for their stay; they are not published on the public site.

Analytics and browser storage

We use Google Analytics 4 and PostHog to understand which pages and guides are useful. Advertising features are not used. The site uses a limited amount of localStorage and sessionStorage to remember an anonymous visitor ID and the current session. Each analytics provider may use cookies or similar storage under its own privacy policy.

3. Current Sandbox-only status

GBA is testing a read-only connector using Plaid Sandbox, a test environment that supplies synthetic financial data. The test data is not a real person's or business's bank data. GBA has also created a separate, empty Production infrastructure shell, but it is not connected to Plaid Production and contains no financial data or Plaid credentials.

GBA will not connect a real business financial account unless Plaid approves Production access, the owner separately authorizes the connection, and this policy is reviewed for accuracy before that processing begins.

4. Data that a future authorized Production connection may process

If the owner later authorizes a Production connection for GBA's own business accounts, the connector is intended to receive only the read-only data needed for the approved internal use:

  • Account metadata, such as account name, type, subtype, masked account number, and Plaid account identifier.
  • Account balance values included with the authorized account data, where made available by the selected Plaid connection.
  • Transaction records, such as date, merchant or description, amount, pending status, payment channel, category information, account identifier, and currency.

The current implementation does not use Plaid Identity, Liabilities, Statements, Payments, or Transfer products and has no money-movement capability. It does not create accounting rules, make payments, or change a financial account.

5. How authorization works

  • The account owner initiates Plaid Link and chooses the financial institution and accounts to connect.
  • Bank login credentials are entered through the institution/Plaid flow; GBA does not receive or store those credentials.
  • Plaid access tokens and Item identifiers remain server-side. They are not returned in browser or ChatGPT tool output.
  • Human administration routes and the machine-facing connector use separate authentication controls.

Plaid processes information under its own terms and privacy notice. See the Plaid End User Privacy Policy.

6. Purpose and use

Authorized financial data would be used only for GBA's internal, read-only review and reporting. GBA does not sell financial data, use it for advertising, or expose it through public pages.

7. Service providers and disclosures

We use service providers only as needed to operate the applicable service. These may include Hospitable for booking interactions, Google Analytics 4 and PostHog for website measurement, Cloudflare for hosting, access controls, and server-side storage, and Plaid for an owner-authorized financial connection. Providers process information under their own terms and instructions.

We do not sell personal information or share it with advertising networks. We may disclose information when required by law, to protect rights or security, or as part of a business transaction, subject to appropriate safeguards.

8. Security

GBA uses administrative and technical measures appropriate to the current system, including:

  • Separate Sandbox and Production environments, with Production intentionally empty until approved.
  • Server-side storage for Plaid tokens and financial data, with no persistent financial credentials sent to the browser or ChatGPT output.
  • Access controls, short-lived authentication for protected routes, and least-privilege, read-only tools.
  • Encrypted network connections and provider-supported encryption for stored data.

No system can guarantee absolute security. We review safeguards as the connector changes.

9. Retention and deletion

We retain website inquiries and analytics only as long as reasonably needed for the purposes described above. Synthetic Sandbox data may be retained for controlled testing and evidence. If Production is later activated, GBA will retain authorized financial data and connection records only as long as needed for the approved internal purpose, security, or applicable requirements. Unused Plaid Items and related tokens should be revoked or deleted when no longer needed.

10. Choices and requests

  • Visitors can use browser controls to limit cookies or storage, although some site functions may be affected.
  • A person who submitted an inquiry may ask GBA to review or delete that information, subject to applicable requirements.
  • The GBA owner can disconnect any future authorized business financial connection and request deletion of related stored data.

11. Changes and contact

We may update this policy when our services, providers, or data practices change. The public version shows its effective date. Questions or data requests may be sent to hello@whatweexperience.com.

We track anonymous page visits to improve the guest experience. no names or addresses unless you submit an inquiry. Privacy