Legal
Privacypolicy.
What we do with personal data, in the two different roles we play — and what you can ask us to do about it.
Who we are
HotelOS is operated by Island Inventions Inc., a Delaware corporation with its principal place of business in San Francisco, California, USA ("HotelOS", "we", "us"). This policy explains what personal data we handle, why, and what you can ask us to do about it.
For questions about this policy, or to exercise any right described in it, write to [email protected]. We answer every request from a real person, not a ticket queue.
The two roles we play
HotelOS handles personal data in two distinct capacities, and your rights differ depending on which one applies.
- We are the controller
- for the data of the people who deal with us directly: hotel staff who hold HotelOS accounts, people who submit our contact and walkthrough forms, and visitors to hotelos.ai. We decide why and how that data is processed, and this policy governs it.
- We are the processor
- for the operating data inside a customer's workspace — guest profiles, reservations, folios, messages, tasks, and financial records belonging to the hotel. The hotel is the controller. We act only on its documented instructions under the agreement at /legal/dpa, and a guest's request is answered by the hotel, not by us.
What data we handle
As controller, we handle a deliberately small set of data:
- Account data — name, work email, phone number where given, job role, the property or group you belong to, and your permission set.
- Authentication data — hashed credentials, session and refresh tokens, single sign-on identifiers from your identity provider, and the audit record of sign-ins.
- Enquiry data — anything you type into our contact or walkthrough forms, plus the campaign parameters, referrer and landing page carried by that visit.
- Support and correspondence — the emails, messages and call notes exchanged while we help you.
- Billing data — the contact and company details needed to invoice you. Card details are entered directly with our payment processor; we never receive or store them.
- Technical data — IP address, user agent, device and language settings, and the diagnostic logs our systems produce while serving a request.
As processor, we handle whatever operating data a customer chooses to put into its workspace. That typically includes guest names and contact details, stay and reservation records, payment tokens issued by the hotel's payment provider, requests and preferences, staff scheduling data, and accounting records. We do not decide what enters that workspace; the hotel does.
Why we process it, and on what legal basis
Where the GDPR or an equivalent law applies, we rely on the following bases for the data we control:
- Performance of a contract
- Creating and securing accounts, delivering the products a customer has subscribed to, providing support, and invoicing.
- Legitimate interests
- Keeping the platform secure and available, preventing abuse, understanding aggregate product usage so we can improve it, and responding to business enquiries people send us. We balance these against your interests and stop where yours prevail.
- Consent
- Optional analytics beyond what is strictly necessary, and marketing email. Consent is asked for separately and can be withdrawn at any time without affecting the service.
- Legal obligation
- Tax, accounting and record-keeping duties, and responses to lawful requests from authorities.
We do not sell personal data, we do not share it with advertising networks, and we do not use it to build cross-site advertising profiles. We do not use customer or guest data to train machine-learning models.
Cookies, storage and analytics
hotelos.ai and the product applications use a short list of browser storage, all of it first-party:
- Essential authentication cookies
- Set on hotelos.ai and its application subdomains to keep you signed in, protect against cross-site request forgery, and separate production from staging. They are strictly necessary; the products cannot work without them, and they are not used for tracking.
- Local storage preferences
- Your chosen language and light or dark theme are kept in your browser's local storage so the site opens the way you left it. They never leave your device.
- Product analytics
- We use PostHog to understand how the product is used. It is configured for privacy: person profiles are created only for identified, signed-in users, we do not run advertising or cross-site pixels, and IP addresses are used for coarse location and abuse prevention rather than individual tracking.
Where consent is required for analytics, we ask for it and honour a refusal. Browser "do not track" and global privacy control signals are respected as an opt-out of non-essential analytics.
Who we share data with
We share personal data only with service providers who help us run HotelOS, and only to the extent they need it. Each one is bound by a written contract with confidentiality and security obligations at least as strict as ours, and is security-reviewed before onboarding. The current list, with purpose and location, is published at /legal/subprocessors.
Beyond that, we disclose data only where a customer instructs us to (for example, connecting an integration), where a professional adviser is bound by confidentiality, where a corporate transaction requires it and the acquirer accepts these commitments, or where the law compels us under the process below. Where we are legally permitted to tell you about a compelled disclosure, we will.
Government and law-enforcement requests
When a government, court, regulator or law-enforcement authority asks us for personal data, we do not produce it automatically. Every such request is handled under the following process, which applies whether we act as controller or as processor:
- Legality review
- A designated reviewer — typically the founder responsible for data protection, with counsel where the request warrants it — examines the request before any data is disclosed. We check that the issuing body has authority, that the instrument is valid on its face (for example a warrant, subpoena, court order or equivalent legal process), that it identifies the data sought with enough specificity to act on, and that the applicable law actually requires us to comply.
- Challenge of unlawful requests
- If a request appears unlawful, overbroad, procedurally defective, or outside the issuer's authority, we push back. That includes seeking clarification or narrowing, objecting in writing, and where proportionate pursuing available legal remedies to resist or quash the request. We do not comply with informal or voluntary asks that lack a binding legal basis.
- Data minimisation
- Where we are compelled to respond, we disclose only the minimum personal data strictly necessary to satisfy the lawful scope of the request. We do not volunteer additional fields, related records, or bulk extracts beyond what the instrument requires.
- Documentation
- We keep a written record of each request and our handling of it: the instrument received, the date, the requesting authority, the data categories sought, our legal reasoning, whether we challenged or narrowed the request, what (if anything) we disclosed and when, and the people who reviewed and approved the response. Those records are retained for so long as needed to demonstrate compliance and to defend our handling.
Where we are the processor for a customer's workspace data, we also notify the customer of the request before responding, unless the law prohibits that notice or a genuine emergency makes prior notice impossible — in which case we notify as soon as we are permitted. Where we are legally allowed to tell an affected individual about a disclosure of data we control, we will.
International transfers
Customers elect a data residency region at provisioning — United States (Virginia), European Union (Frankfurt), or Asia-Pacific (Singapore). Stateful data, object storage and backups stay in the elected region, and we do not move them across regions without written instruction.
Some support, engineering and administrative access necessarily reaches across borders, and some of our service providers operate in the United States. Where such a transfer leaves the European Economic Area, the United Kingdom or Switzerland, it is covered by the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss equivalent, together with the supplementary technical measures described in our DPA. Copies of the clauses we rely on are available from [email protected].
How long we keep it
- Account data is kept for as long as the account exists, and deleted or anonymised within 90 days of the account closing.
- Customer workspace data is kept for the term of the agreement and handled on exit as described in the DPA — exportable during the wind-down window, then deleted.
- Enquiry and correspondence data is kept for up to 24 months from the last exchange, so we can pick up a conversation where it left off.
- Security, audit and access logs are kept for 12 months, except where a longer period is needed to investigate an incident.
- Financial and tax records are kept for the period the applicable law requires, typically seven years.
How we protect it
Data is encrypted with AES-256 at rest and TLS 1.3 in transit, with keys managed per tenant. Access is role-based and least-privilege, administrative access is logged to an append-only audit trail, and privileged sessions are recorded and reviewed. Backups are continuous with point-in-time recovery. Our full security posture, including certification status, is published at /trust.
Your rights
Subject to the law that applies to you, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, provide it in a portable format, or withdraw a consent you previously gave. You may also ask us not to subject you to a decision based solely on automated processing.
Write to [email protected]. We respond within 30 days, and tell you if we need longer. Exercising a right never costs you anything and never degrades your service. If you are unhappy with our answer, you may complain to your local supervisory authority.
If you are a hotel guest and your data sits inside a hotel's HotelOS workspace, the hotel is the controller. Send your request to the hotel; if it reaches us instead, we forward it promptly and help the hotel answer it.
Breach notification
We commit to notifying affected customers within 72 hours of confirming a material personal data breach, with a written remediation plan inside 14 days. This commitment is codified in every customer DPA, and it applies whether the breach originates with us or with a sub-processor.
Children
HotelOS is a business tool sold to hotels. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 as controller. A hotel may hold data about a minor travelling as part of a booking; that data is processed on the hotel's instructions under the DPA. If you believe a child's data has reached us in error, write to [email protected] and we will delete it.
Changes to this policy
We update this policy as the product and our obligations change. The date at the top always reflects the current version. For material changes we email account owners at least 30 days before the change takes effect, so there is time to object or to leave.
Contact
Island Inventions Inc., San Francisco, California, USA. Privacy and data protection: [email protected]. Security reports: [email protected]. Everything else: [email protected].
Other legal documents
Questions about this document
Data protection and contract questions go to a person, not a queue. Write to us and we answer within one business day.