Last Updated: January 15, 2025
Security and data integrity are foundational to everything GracyRein builds. Our guests, property owners, and management partners trust us with sensitive information โ access codes, financial data, personal contact details โ and we treat that responsibility as non-negotiable.
This page describes the technical, organizational, and procedural safeguards we maintain across our platform.
The Platform is hosted on Amazon Web Services (AWS) US-East-1 (Northern Virginia) with multi-Availability-Zone deployment for high availability. Auto-scaling groups handle seasonal traffic surges during Florida's peak vacation seasons without degradation.
GracyRein follows a five-step incident response process:
GDPR Data Breach Notification: We notify the relevant supervisory authority within 72 hours of confirming a personal data breach. Affected individuals are notified without undue delay when the breach is likely to result in a high risk to their rights.
| Log Type | Retention | Details |
|---|---|---|
| Email delivery logs | 90 days | Recipient (hashed), message type, delivery status, timestamp |
| User access logs | 12 months | Login events, IP address, actions performed |
| Template change logs | 12 months | Who changed, what changed, approval status |
| Configuration change logs | 12 months | Setting modifications (sending rules, rate limits, routing) |
All logs are stored in tamper-evident storage. Export is available on request for compliance review.
GracyRein maintains compliance with the following regulations and frameworks:
For details on data handling, see our Privacy Policy. For email-specific policies, see our Acceptable Use Policy.
This section expands on the email safeguards summarized on our main page.
Every recipient must have a verified email address. Staff and managers verify via confirmation link during registration. Guest emails are validated through the booking channel. Disposable email domains are flagged for review, and known invalid domains are rejected outright.
Our global suppression list is updated in real time from three sources: hard bounces, spam complaints (via FBL), and manual removal requests. The suppression list is consulted before every outbound send. Addresses on the list are never contacted again unless the recipient explicitly re-subscribes through a verified flow.
We are enrolled in FBL programs with major ISPs (Gmail, Yahoo/AOL, Microsoft). Complaint data feeds back into our suppression engine within minutes. Monthly complaint triage reports are reviewed by the compliance team.
Per-account and per-template rate caps prevent unexpected volume surges. Our anomaly detector compares current sending against a rolling 7-day baseline; any spike exceeding 2ร the norm automatically pauses sending and alerts the operations team for manual review.
Only users with the Admin role can create or modify email templates, adjust sending rules, or change routing configurations. All such changes require peer approval (second Admin or designated approver). Changes are logged with timestamp, user identity, and diff.
Every template edit, sending-rule change, or suppression-list override is recorded in an immutable audit log retained for 12 months. Access logs (who viewed/exported delivery data) are retained for the same period.
If you believe you received an unwanted message from a GracyRein-powered notification, please contact abuse@gracyreinflorida.com. We investigate every report within one business day.
We welcome responsible security research. If you discover a vulnerability:
For security or trust-related inquiries:
Security & Compliance Team
GracyRein Florida, Inc.
2740 Ponce de Leon Blvd, Suite 210
Coral Gables, FL 33134
Email: security@gracyreinflorida.com
Phone: +1 (786) 429-3187