Privacy Policy

This policy describes the information GuestFly processes. It does not claim that a privacy certification or a formal legal review has been completed.

Legal entity
Not yet provided
Contact
Not yet provided
Registration, address, VAT
Not yet provided
Governing law
Not yet provided

Data collected

GuestFly stores hotel account details, staff names and roles, guest names, room or unit references, messages, requests, service orders, feedback, and technical records needed to keep sessions and payments reliable.

Guest data

A guest reaches the concierge through a private link. The conversation, the request, and any service they confirm are stored for that hotel. Guests are not asked to create a GuestFly account.

Hotel data

Hotel knowledge, service catalogs, staff membership, and operational history belong to the hotel workspace. One hotel cannot read another hotel’s records.

AI processing

Guest messages may be sent to OpenAI so the concierge can understand the request and reply. A separate operational classification may be produced for staff. The original guest message is kept. AI output is checked before it is stored. If a live provider is not configured, a clearly labeled development classifier is used instead.

Supabase

Account data, messages, requests, and files are stored in Supabase, which provides the database and authentication. Access is limited by hotel membership.

OpenAI

When an OpenAI key is configured, conversation text needed to understand a guest request is sent to OpenAI. GuestFly does not send a request to OpenAI for static hotel facts that are already known.

Stripe

When a hotel configures Stripe, payment details for a guest service or a future subscription are handled by Stripe. GuestFly stores the payment status reported by Stripe. The browser return from Checkout is not treated as proof of payment.

Cookies

GuestFly uses essential cookies for hotel staff sign-in and for the guest session. Non-essential analytics or advertising cookies are not set.

Retention

Operational records are kept while the hotel uses GuestFly and for as long as needed to resolve a request, complete a payment, or meet a later legal obligation. A specific retention schedule will be published with the legal entity.

Security

Staff access uses Supabase authentication. Guest links use a private token stored only as a hash. Database access is isolated by hotel. Secrets such as service keys stay on the server.

User rights

Hotels and guests may ask to access, correct, or delete personal information associated with their stay or account. Those requests go to the published contact. The available rights depend on the law that will apply once a jurisdiction is chosen. That jurisdiction is not yet provided.

Contact

Privacy questions should use the contact on this page. If it is not yet provided, GuestFly cannot yet process a formal privacy request.